Stránka 1 z 1

Prosím o preventivní kontrolu

Napsal: 19 lis 2015 20:59
od curt-xx
Dobrý den,

prosím o preventivní kontrolu. Zvlaste pri prohlizeni internetovych stranek pc "zlobi", kdy misto pozadovanych stranek otevira "nahodile reklamni stranky atd. Predem dekuji

Logfile of random's system information tool 1.10 (written by random/random)
Run by Jíra at 2015-11-19 20:55:54
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 273 GB (59%) free of 459 GB
Total RAM: 3830 MB (37% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:55:58, on 19.11.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe
C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe
C:\Users\Jíra\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\Automatické vypnutí počítače\avp.exe
C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Emsa Save My Work\SaveMyWork.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Users\Jíra\AppData\Roaming\OpenCandy\E68FE3DB6D3B4E6EA90770E199AA61F2\dhk576.exe
C:\Program Files\My Lockbox\mylbx.exe
C:\Users\Jíra\AppData\Roaming\OpenCandy\E68FE3DB6D3B4E6EA90770E199AA61F2\PCTU-CS-1-day-2200632.exe
C:\Windows\syswow64\MsiExec.exe
C:\Program Files (x86)\AVG\AVG PC TuneUp\TUInstallHelper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Jíra\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\Jíra.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=16194
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: Shell=C:\PROGRA~3\qpopgtawqlivptjnadb.bat
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NOBuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [NokiaPCInternetAccess] "C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe" /b
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Jíra\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Jíra\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_F92D31A4AE9877BDA93E3AF1E3C5622E] "C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
O4 - HKCU\..\Run: [SaveMyWork] C:\Program Files (x86)\Emsa Save My Work\SaveMyWork.exe
O4 - Startup: Automatické vypnutí počítače.lnk = ?
O4 - Startup: crossbrowse.lnk = C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: DEBridge - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - c:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: hpqwmiex - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\windows\system32\srvany.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\windows\SysWOW64\NLSSRV32.EXE
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14661 bytes

======Scheduled tasks folder======

C:\windows\tasks\2a43a216-2033-4249-9fd5-329443c38ff8-1-6.job - C:\Program Files (x86)\CinemaP-1.9cV29.08\2a43a216-2033-4249-9fd5-329443c38ff8-1-6.exe /rawdata=RNi4D4lcQp2+blWlbvC9px/vK0mlhZd3eeiZAsufJ3mjZi7YIg+lloMcPgA0//0rsctxWMWzG8CY+3BwFb2JLzbxm36b3dnVpDMgrLB/qfaeNiaUYDytTerk9lFISLhw7W1QHGq0L08A21+56N56fHJpOJwjHWBlUNEhZZSN2dlvMTfadwkGgluIWHbQCEAKWgG7mOnzWoQEKSkVaoXEzUMGm2le9/tFz/+rTd1RH533vnCEOzw6w1AqZJzL2qeJ+4CFyIQLbU/X+3YQN3sHhacRyUPjtoPxn0GWPT+a3lrRNPvkLmB8n3ccCCN47qjyOj3CWNgYkVPjbaX+L1RDTATxV+QJPUve2howxwu90ozEkeKQKgPIN6YOnufzof0FASg/VKE0PjMhxfrSZgM8IOyIghTphQifBr4B9WaQ1OLT3l8etqT9q3FVOVuEhOTq/+SopqmAhfdN+SS5DLgtY6yhZcvBkU9yqXKBA0qn6ZFkxpSl6rL0BvAUccdP8tzBT1135c4egtD4thZhsVc8XroYnoMarPWDSwbBS0NezHTXmFtsVwlKdv23dzQUrwfmFTUdh7dQONk7q3wKsuPhSs+PcX5O1zf9fOK/HYDs/nrwpSmZ9rBRzEteDLy9vgRoOi/99Nr1h3N6J3nX8fBpwsyV8Qb7QVKEK2LuXcoPH/cNtgJhXYccdddF3YQOGP28y0R5vDGbKoEpUuTtkTVHj+uYfciRpf6t6b/Nm41ABmxNRB5hCruJqG1pOPohnSEK17p+hpGlm5APjT5JBvaQzw2DTwskMFsjCsgQlwIuAAsnSM7+mS6yi1BgfipUk6LplquFrvEeF99yvi9vgom7HGEOIiS0WuQfuXkl5AWLPgZjqt361brFr/McanQpFBe7TvLzFWjSwgRNJPuItMcJzhGfPJ/MJYV7X7SoboPW6AN0QPhTxJg6K+8kW2HmOr8+CwmCFuSDoU71UBXRSDm+J3TeF6xywasJ8KlqISzimJEhnyvk8RARI6y2tpYRO2QUeNVnaThRCU2WoWTgGpcutLVRxpAhcaRfLUSa6Bvl9RCHZHN0+J1KRsH3P8Z8OKcSAi4v3+QXLGhDGSofZW97+PKKAx6niVYwz5jZ+s7jabLD5a+our4jYfwmkW0YOEseqeZ0vcjp/a+xOAIZ4GybsPbPvtBbv7wlKEUeSfRqjNBI5pKsUVqeH593HFsIB6vcOrCePH+MevcJLJOiujF91OyzbokkFOAtWGVhEM+mvub1qszgr7W2zrlGoxD4FsVIyom9L6luid/itiM+qtVl1/EvB/xr3dtzlPnDXsbVxWgF0H+7btB+mgRBH9LwOhi7ZaUrExXxg8XtKKqcvMudxA==
C:\windows\tasks\2a43a216-2033-4249-9fd5-329443c38ff8-1-7.job - C:\Program Files (x86)\CinemaP-1.9cV29.08\2a43a216-2033-4249-9fd5-329443c38ff8-1-7.exe /rawdata=ZumAEoMSLC5CiBZDSAA8UOiaGCyUOyZ3ciyO+26HUezvgNnW3zMvmJ0Gp9tBdhTwbKODKNrxzLQcc5MUrqr8T4ylTu8inCPi/plG1JaoSSug+lRu4IFBU1ykwwkOc7INrWcLtyvufRu32At9ZBOsTXAL9/cWk3/3Z/yyx6NP0uluSskulgADbO+pDztYKgy/tkQu+WZh6DGz/LkxEtyvzZ0gWywZyn/Q6+lHEx6/LK2qnhJ6ziyNNXI46qvT9Y9O9i6XrIRKC/hO+KY/kXIDibP+2yE1sSCeTsLtywdjnzXKi+cgbnr55zFkGQ8y3yCruQKxBvIIx46P2VRBIoT+cgg+5AQUcZ8LOGqq5AqOeyb+P3cCKW6hArjiEGYOP4hcFqWyxfz9I/eqw5saY/z54iqeLJNk+SFauugW9dB6UcyBHSHry1LNg0ZoNmwHZeC/kO2D/9T4KcUD+vuRy4J44d+igpF++wUtdBno+pARd++gmtgfKlzxkCvzDMkgZJatdTyoETc1FXTfzN2ozKfmsNzCpsiigUkUHvVFsB4xWe7nizHIKMyS6vvtRdH7DLu2QeLoSmCLflWNSi2/vLb5Y3uIQeiv8pZvJK+jo0O9zObGYFgd4toizouffzETjv9C51F2It6AnKzj4sFOS+9S+RS0FSLjErr/SUEwOPQInGrE4ZsBmAWWGKpN4/WzwfRqbUHNuSuqae8HEmZQpHY9ScHZyaUj7QVb0p7DKpS8qyrchEX8R8/Mi+y+Mg95UIm0NRJyMclmPAP6cYzcaJZ3t3QpelsS6bw8y2rBE4mRKk4G3549Vy5QWBR0eEZlaBDOBBAzaUYlvAGz4S7VuqCmfSk38W7qMi5o5sV31z6bK9g9OTTwN8zJv1fIReX8hcyo8ETSaGIdyWLtcxC5MSdUequLW9V91hkjbJ55pL3cdIrzQVyX5YUzZN4Pd1e978z5ovxYnLhIS+uvOi7GnjCYiht7NY4stdkHgr7/yZtCsBet5g1pwFoWEUur3XqzMWHGrezzwj4RZHVL8ghywluwz5UDb+iINMdqnfTjdX7arqsNs/DeeHAh/1saWYpJ9BhT9QhQxznxLamX+8UXvDgkkqFAjWcJ2eMlIE/tMyQlX4ZxQS2ymZkcIJBeGc6ji/7aXEOS96chzlXZKWl2RHh8X3zKVxVmBCJnkzqV+nQcS5Kaq8OB0BpccCuAtKFMa1RxR3mhzTbUXtF9+oaVWELhrffqsTYsgaLIEITS37Wcdd0ba6oVNlJ3bZ1SVM9rMsKLp1JLN9W3wOpDz/VLv6HnQMYmV3dQwDrrKAi+BiCNQK3jWGaSlgOw4CAsXSylWK4qUlQ/EwCMQmRQ95n5k/ufU8Efica2xEYAeGI824qzdLmdUm4XMnPe3bDzgyGZOCisiZCN6RTyV0sS8mmm0WIorySRXw4zlBCF67jK6PH/nFu7/ZtKag/ZRPAYiPTpbakf/gIQ/B55zGlH81ngoLBxc8QgsqULevszz4jROjRqSmSyW/9XUBLNrOJgPKxjootG
C:\windows\tasks\2a43a216-2033-4249-9fd5-329443c38ff8-10_user.job - C:\Program Files (x86)\CinemaP-1.9cV29.08\2a43a216-2033-4249-9fd5-329443c38ff8-10.exe /rawdata=bpGB6ZY9sFFCwkVUev/JADLFH8XtzYuGUN7J0GkevK8QAuXIVZ8qC63susSe4erSX77/JqAdM9DP5NbClm7OeaWZNGfrx6/SwpQuEThY47N1d9i+9B9GcjqpYVuV0VnxV2BNBo3AbcFUKngXZebweB+PsZbHmGSSM5SYZaHdTAU+apBRlUL/hOGAxvqNlwpTkMjc2CTVWyOaNQ3G7HiNP2YAhzmcjCKVB/EM7Y6i0wL4D6nu81Fatgg5699VOvQ6fFM47jJnFxp5mzvRqB5aZKIAtoCkM+ogJbdGhF4URy4+qOEs0ix6NA5nujfRq+tN+gzIsipIe54iRGH+bOU5I7rfMq0j6Iem+0clHVWiFWBQC6yAfVFe8+L6HTjvCr/Q1Qhtf9pPpQqu2raGJ1gjEUXdTObYp5AjhvLLgcrMMGmSLkkWoB5HY2473KcQgr1Kq7Qu1J4Cq/QTsggOyCZz2LjPXEiH3t4nogJTtxePJmq5NcmmPDLg941ppNHs048LHyadGBGVe8Timk01c343jbZzruv1ZhRlzV86c48W5zgbjsuu83oh7aH2EWVZCvOnvIjrJlSTFHY76n2hO7HDAGpxSjXneK1COpnsj6HOFSafUwrMV8Fnusaa5WTKwdz2kqXFJyYux+QdyB/bb2RjUAsS4PB+AKmZdhhI43JED5gScXgIlPzqPkK4kFEFOefEV9mQJoS2FbdhoCiR0SdYygDCRQF8qFrO4oCx4uV/5faJwJaa21xPgjARxIbTKvjt01wudzm/DU9WEMKg6FkEediTy3aRZ/EJRXz47vy84IZ1iFbivQL7Z9qmCCdcWZzbyavEMwiXDFtzKB4JQYBFxA==
C:\windows\tasks\2a43a216-2033-4249-9fd5-329443c38ff8-11.job - C:\Program Files (x86)\CinemaP-1.9cV29.08\2a43a216-2033-4249-9fd5-329443c38ff8-11.exe /rawdata=oWjK9bIN4qJupHiJEEVycUa6HSQ02iPG7n56H4Yd0He1imRHnTgNQTTqo7G2Cv3IO9bNzyyseDIYn6khBQg1e0CHCls+JruDN7QrztbmQZhHh0A25WexKHci1UpkdXojeAYT5ftE0oQVnxp+hDZWjI6OeRm6OARe19EB2ZQl/KxzFhyMfwMgw74yxDu393YIJjzhxA0uBk/Ph5dyByHExXOevFUtJniU6B1eLDNeIpI8uE+zw7zJG5aYaQ2LIn692pX/mIUzDmTxBaK5BbY68+LLtHQ1r/X7e1TSQJWgcr/tNYMUo1f4XjsW90LKjm3PFdgFAbkZKj0LPmLn16SXTVGVxewXQMXeqvc7LTDl3CvcYvjyXB3+xlEiy4BGtE7AkhtxJIGxLpY5nujaivYh5MKalP5hGq3WoZbSxQPTRPPZE4+7S+t95eNrD6wrkbW63+7Z8KvU+zpZmRAwZ64m1v+dD+5Gh/KTtC37BYZA2NjMGGi6kZKE2Bt9qQT/VxfTjUrRcOh1LJ/T209tQXUu8+QdWBRAsuelbUP1+5ub5U7vvFUWDz+C4z4PcDSyRUkz2jNpsbFXP83ZVJ1fVcTcSg03WOIUzb4HSU5F+t0iVCoHqHw96RihIRfaRLzRbb4MSsHYOfXoPw4ctP6y0o04bDBHMhiLLa9JGcQNgGRbS1AeqqwI2EKUAr2CinCBLiaxpExNBEaxe4X/0UdnvpWy/HiR8iZPRY0p9k6I9h6k4QUpMeRTmyrHJSaYyNQ2PDuWnkTLX4ycqQFLOLdJNN75DqxxjwFWli+mwpGUu0dI3vbVldG2vNSpgF97LWJBvhCc2SkPZbF7NFHOEULa8SYcZw3td6AHRjHGqwn7s8R8KhWNdu/LU4+EpBtcvD8EWqQ0XXXC2GuZL2nItvbgmBPsD7xrwGgorcWrku2XQofjhbb2bZffa3/mNeKUUn5Xm09ReHmKrXEzbjsWRUCAzSQcoRMo21gsKVhoQCSLa+nv0LsnuYVsRv75F7MLRfyKeO0uix+sRmYcKHqFHWDmpbuO0IfbA7nJPT5P7pe2SeqfBjtNuLZz3yJNtVT04cPYQt7rSPkJZJ/28Fd30rEqA6E1KEHV1AWzAEfgCRKzhKeo3EQ9FMNo95NroRe2Gr2eBRaA3slseLJUuwRd6m2uAAwR/LVAHxTXYuzUgh79SfHYcFNZPJ5oXbShNUjS7dD3lkp13wOVOV7zMNPnoGfB0Uk6axKjiO/g8Xg4ZH/oJ1Ez4OEBi1OkE6LRyCpgscjGDD8bBku8Z+I0Q9lHvHxc9HEldtAfzgGlbkDxme9rpkR3ceX3dIBDmmsmGtTH4B0CW0IDHKXZ/vrlZFULsLldvo5DJS8AWoi1AAqQ71YBSFKFa+aT1OgB0VwbQ4nCgt2xoe+g4doDFfR3B2CZhpXFmucpQF1aC3pImw8QEGytyhvndM/8wM36kB01O2MFfqUz1aEfxhTqG67evWBpAGN5aGqb6GpqFxKoGX8pmO4j2FWLyLTFTMgGeyDKfvhYGnVJF8Xwf+ymMsRwkElxevOOOJ8GvY3vx9c+KBR7ve8uYMAMsXLAo7QzFLZpfXn3BtupfGlmE4DrNh3PMb/WbotJTnHPVn+lKj4B40at2ppxkITFji/JbhZvOOQz1il2eAKBEJ4F+k9pV+ilTHJ27kNkJLAAxxxLNFGueD/f+QhWJ14MFjJFCrotFy6gwZw5U7CNqexBUSlwh+fgzsK5OskTzgJrl8GyoFaj4DbGzT+R8XaOijSVutqM4T0Uu33H2Z3yNnVhKr7mda5J65D5a16HYO6oaMSsg84o6RWeX1oHFESKlHwa9dbCQ8XV4PfRf5YHDvpJ8AKCGHjoRc0fotIpdvRizk9cpZfUtt2ls2BvAhInNaK7+6QnyAUuttgVlTG46dwwTiciPlWZJ5v0CrPA65NRbeVIfSg82S3tUt3/ceMSmAiYM5f6LodF4PVIItyov6QUzYB/C83ihE2vSWEmtC3m7Xif9yj5LuUkVJllZ720z5Lbg/WWHzP/NWKgOQOG1VIoiQoLAnCpB/jtffT1FsdNhyBuzAoyW0SpP27PBQ/TAgn2Wdi59tYGBmjJPvFWdl2hXsUXeWJLJtIn5pf3IZol22mI6mp7DoHd9B5Sct0A4+f0xDFT5ijn/6y9edlh8fGFstHOeM90eghsW99vJ4peU7sCwe6h55oS4m/ekgMFD/Ryld7VfKOVO2dRh/BdcV5Egvl0+qqxY3NaqDTX0iKfcHFs8mqmWTRnwo7TiQFSgTytK8BLertkWAogcUVNmM7PJrDHC/1LbFQzVlbYeYJdhOpnFxITpGDfDouWtWcfEIIbRdSEflWz+QjmUDuYHdTqSG4fWTiaElwpcXhJ8weBhg==
C:\windows\tasks\2a43a216-2033-4249-9fd5-329443c38ff8-4.job - C:\Program Files (x86)\CinemaP-1.9cV29.08\2a43a216-2033-4249-9fd5-329443c38ff8-4.exe /rawdata=mc/4ua29GIA6uZTX8rd/We5L4CJlZdEYUvaLTBpvAhjtoxRDKYjERzAWlzybO9/5w0qyHtwp2z1puEX3kzLzTsVLZs7s65znmUmVMsnRx3yxGqYruiSaORd7PrmUx/yl5kz0AOH8Nbkfc7aT24+P/eEhLeiFUupKs9uu6YG6dJeym9o96sz0120sbQhQ6ADc0L5a4Q3/XEYog3aHn44FxrkX+M6e7kUPnJelIvf78O7zvyuzzLhnwO0ZRmcECjIPFV/VInrUMJiB1rEdW9XY3ebW0/foJQ9Cc4FXTuioHCxglb+hIL84dF06tBEpm0w0m8YJKpuai1Waze0JibMSP47Na4ZNCybqncwm4jg/00qEqyI//KsY3dBbzhKn6utTdkyK5gmK+EkLKSNOJGzzXiv/3UrWc5s/7un3pscgcoB5f7E5RFgXX0PHhF6d7xWiY+C43ZZmqT53oYGQoB291Ei40lnt3OaRgfeE3wdOQ2naHKvsCEhlwq40pC4ajTw7oMSLJ5kBD9CuIHaadsHw4knRAiykShf/AV+4dsZJV5t5XqMGdE3F0Vzl2XHD0CVMOHungMnQg1+JpEDxQQXtJ8Dlsf++RYAU4vXr+5GZiepJTWLTIvS9zkNGT7sfGKN/yZXqlPZk9lnK9o4p6U+wtjAT5VaDpsQ2R/SD7vlFoAZrO7/qly+gziZnawwaC5D3sU0KjsnG2bMP3kZp8shXoXWh2/XD7lxsnbIjgkLLTEPxRp3EUh5apKj+VHKnxwdJFqM547PnNBrzGZCaH8yO0VgNSgT+hLnR2qiBIh96NBjw/BOiMq4FjRzUIzhzPPzdI6eonoio2OUrFA6bkEuHMIoSCylqmiu+VpreJUCnRT0XSgibsHok5IPS1o1K+OGWCwI6ZWY+paXbwf26xBZUrsMb81urxCIOJhHo3nL1izkP2XepIg4cNfOEUSb3LYggbcYLG2jxFy3UKEe8vxCP2xpRV8m3HxUxRrULMi9ObbSezP/z44chlBKDQwPSZ0rVBAvywjMKCPRe8zoaaC1F+Z/mY3Mn35vZkoVBGcSNYwuKW6+2LQIiDUwzugvfdyM5KAC4oOZQ/IG0nCRlobBG6gCRjhVO6dSliiSPxI6EwsdrrtNVb6vFnw74WfKLIy6FWZ1OanAeyO8w6/QY1pu6+JNuC2WnB6VMGY+p+4wGZChtlmUjKL9jxCbdshBRODKlOQuCX00xuLWL4v+3zRm59GqzttGFZh9duMRm3zeMw74Wi8JfAf93+fbjht9JG/2OpIED2iW2Yd7tTK2OoSjZViS1pR6uiwySpvVFaUNVKT9EpxOAVgAoXvUlyvswBLY5pCq2Yn+BTXI/mdg/gUeE70lSgXYAOsbKNfn91dMyzEdyDfN3udfkF73OrAQfaYrE2pi90mL6AAsRGRLR7tzGDWHeu0TobmOQB0HSBSxKGqgI/682939Bmzydv5FDJgBjtVUvrEwA/lhlUtb0fKZ/ZECk3kc0+qLNUQDuVjmK5fWj/jU7VbwH7WV7aCYAxwoKrB5JbdfwFriUByRhJaWxNdsWsZONgewARBKwkE0d0/whnVJjObn6YbrvUVT4sHoY/VRI05SxTBzxGRijCKqARDnTSircyzKwLTyEMm8WlD54JU42PsAVkoHNDe7bUD2Edm0WexcMQZw6MDKXEjW2S5JuqkzuXsP5nKfpsGTpNXjAWHNyQ6vcJfoy5Lur59ww5ZrvsmG5wNmN4BjEOKxHc6bxE7t+PWwpRRNvLeQWRlxm44AW2POM5tdxARWwM7+h5X0Ru63V61ielN5d8LeUqkjK5nCOWmpxcv9bFnZgOCIxJWIEZHCsCXREUnIimGFV7ETj2pKpXiZHHwFWEM3kw51DtlAFXuGKYWk9KJEv7aS3kSAzV5JUD7/fsuFWkJN410bEoLhFRSxP/UO8zhJX8xz+SLHLo4yBcb4cerPqwf9wAKlMOwQIRYL7uVS85EPR8MNnt9czj6e76Vt07uMaHzKpHgoLwHcSDgXNXXlUTkcexyWtzlQSix81s8Dlytl6
C:\windows\tasks\2a43a216-2033-4249-9fd5-329443c38ff8-5.job - C:\Program Files (x86)\CinemaP-1.9cV29.08\2a43a216-2033-4249-9fd5-329443c38ff8-5.exe /rawdata=Q0DlfQCo6uSQ5oD/83Lna8aDSgVvcpiBFgoQTp4cajQLVIJ1GNU4Qs9OFmidEq7YcVqJuukzFRk2fsnuxNgvWleIkUVzfRHy9Os75eePjq8BjYOhsHYMjqC028EjJBoCuZmIsl2ow6n1FsRDcnJ3frUxAEGDOiaySNIcCFMFWv7CFHnVxflpM7kR4AzlQsy+b2hXnJazH9ml9hCV8DEz0UVo+CckonSOYRoKpXqKfuAgZVbbIW+/dtn6jx47IrNV135q+vobAiHffwCcqDSxsC4qWHcJGKVof0ywfYcmRDB+P34gaFGqTM4OG6/vXwDVyHqT43lrBXt33C03tHpEl3H42GA40uzyVAaaXfTKFfUCBsqGwCq9GksEK5QfsmOqIxAvpSWmnzGWE6bkfT4YWsclVNeHMDefctMtf94qey0PeP/uEQUH2dfercT51SqhSF5VHdaOxYl8a+4qUD0dXZxhLjkJxMAYWxATMPXl6GmJm1bjoCq4srLL19zQhxe7vWphgd7cqZobJhhWqVUr1Z1U4sCKYrqgunktUfRG3Pk9ZSvJyKfl6qR/l/51POjSwPFNUKxX9uPOXhMyxkKMA414S1csINMAxa8Cn+luD+HBHhOqN4TX+2nc8wZSOScr7Zyun/koYVV2Do9JFwEoSM+vVE4+57Jgx8JypXJVpP81kfXSxGvqQ0kjZGRV3U5BO5LIAag4zCpvRuKiwEF8+mj6Kurc89IVCmY6p9DY2xW29av/sA+bSBYR5L+H/rRlqOr+NeJwSNK3z+TCBZ9KQ+CqapzgroXlT+zAcqNJALWbSwTHOG4HMKmWyP+OX6UxP9YCI+h/iYBJmW+eiBh0aHTpA6d8cgH68kn/tek/S0/ibjdrw4x89+oDCMMdukJKSFPLQgug4nemFiKdZ3UwiNQ7DDTxSV70YFG9Lx2xJqaudj0T4OGgT3/LbhX1hD1qzShdyNhSg3aHjzO+MONm37n27HSTVDpoQBzrwFLg9IfCpxhVfncQdc3Qjg8O34Qu
C:\windows\tasks\2a43a216-2033-4249-9fd5-329443c38ff8-5_user.job - C:\Program Files (x86)\CinemaP-1.9cV29.08\2a43a216-2033-4249-9fd5-329443c38ff8-5.exe /rawdata=Q0DlfQCo6uSQ5oD/83Lna8aDSgVvcpiBFgoQTp4cajQLVIJ1GNU4Qs9OFmidEq7YcVqJuukzFRk2fsnuxNgvWleIkUVzfRHy9Os75eePjq8BjYOhsHYMjqC028EjJBoCuZmIsl2ow6n1FsRDcnJ3frUxAEGDOiaySNIcCFMFWv7CFHnVxflpM7kR4AzlQsy+b2hXnJazH9ml9hCV8DEz0UVo+CckonSOYRoKpXqKfuAgZVbbIW+/dtn6jx47IrNV135q+vobAiHffwCcqDSxsC4qWHcJGKVof0ywfYcmRDB+P34gaFGqTM4OG6/vXwDVyHqT43lrBXt33C03tHpEl3H42GA40uzyVAaaXfTKFfUCBsqGwCq9GksEK5QfsmOqIxAvpSWmnzGWE6bkfT4YWsclVNeHMDefctMtf94qey0PeP/uEQUH2dfercT51SqhSF5VHdaOxYl8a+4qUD0dXZxhLjkJxMAYWxATMPXl6GmJm1bjoCq4srLL19zQhxe7vWphgd7cqZobJhhWqVUr1Z1U4sCKYrqgunktUfRG3Pk9ZSvJyKfl6qR/l/51POjSwPFNUKxX9uPOXhMyxkKMA414S1csINMAxa8Cn+luD+HBHhOqN4TX+2nc8wZSOScr7Zyun/koYVV2Do9JFwEoSM+vVE4+57Jgx8JypXJVpP81kfXSxGvqQ0kjZGRV3U5BO5LIAag4zCpvRuKiwEF8+mj6Kurc89IVCmY6p9DY2xW29av/sA+bSBYR5L+H/rRlqOr+NeJwSNK3z+TCBZ9KQ+CqapzgroXlT+zAcqNJALWbSwTHOG4HMKmWyP+OX6UxP9YCI+h/iYBJmW+eiBh0aCDy0hb5F6gpCHD9vtXUGWchjL0PpXus7aVnvTx5/1kyT37VsrrG2QM6mUFBY3d8J+VtYvCbzG5yh/eG2LBIxe09kco9LCKmADBa+gAQ2GeEbu7pknrMAhmFWed0vf49XChBZj3MpTZOYsYoP0pLpozAASS1Ge75AH9Uwkfu+RiQ
C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\Crossbrowse.job - C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe /rawdata='ZVHk/JVRtA7GeV4V568i4D644ZpSPits8Jd5sCZ1wz8TRDaI9vqeKqfq0C3r4RenHoGXhWxGJsAZWA1kkhDKdlFyRHKIb0k5c06UMziQet8sjFFoQHH//y2GSZcUKNaBCaI6pgcq1tmEWZfiUCVkWkJAd4XhuzjCBG+i9id/PcmOJlJxzHbdN1UU2NWRmwAzni18LVv9vNx3M33KPDR3bJ9s0bUgp7DjbkLiI1oWbWs6zlH/ELysBsNS7A8JypQJ76JsqicGDL5u4irVc5im61BdW3dRu1F7Py+VuhyThYBiwaRN3jYRN8duk5A4u5kzpDnoyUynMN3uDpT+kgH1Uw=='
C:\windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /c
C:\windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /ua /installsource scheduler
C:\windows\tasks\YTAHYdlRo2dI8r.job - C:\Users\J�ra\AppData\Roaming\YTAHYdlRo2dI8r.exe --c=TLhhaRGcfzWUJkjumjm7wR1u39/rkIbPsBRKU+eAzeyPufEstVW0cKVAKBD0mw6t5fXs9PqQh1fjIrF6Emqnz08o2GeNNbhqUygNoI/BaoHZ3enhz1FsKmCtFbB7b8r4Es3CYV4Hxt2o4Xe7c9zVJDNa0triSth+uDKRu9wUvh+dCYobAKNwRkFgr70jxlwq66F+p5eunxaBG4cZbw2QcsYadTei0iZ5h3a3/1RvZymSZbnEEUYgnWjGPars3o1xSAHU44Z5N0u5v5UTuVVkieyg1+Pv3pdey5HWkWL3NcJoA7doYe5qusZg4UTW8LN0kcUNdDKAjyIvSMrTeOvV1g==

=========Mozilla firefox=========

ProfilePath - C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "otis@digitalpersona.com:5.0.0.4238, {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0.0.479, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.7, {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"

"otis@digitalpersona.com"=c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 19.0.0.245 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.17.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll

C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\extensions\
AVJYFVOD75109374@HCDE39471360.com
{1122b43d-30ee-403f-9bfa-3cc99b0caddd}
{3d7eb24f-2740-49df-8937-200b1cc08f8a}
{ea614400-e918-4741-9a97-7a972ff7c30b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2010-01-19 117248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2010-04-02 1471752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-03-19 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Sof [2012-09-09 6516280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-03-19 170912]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2010-03-01 256056]
"File Sanitizer"=C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2010-01-19 11266048]
"NortonOnlineBackupReminder"=C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NOBuActivation.exe [2009-12-03 3331944]
"AvastUI.exe"=C:\Program Files\AVAST Sof [2012-09-09 6516280]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2010-02-22 2363392]
"NokiaPCInternetAccess"=C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [2009-05-26 651264]
"cz.seznam.software.autoupdate"=C:\Users\Jíra\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Jíra\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]
"GoogleChromeAutoLaunch_F92D31A4AE9877BDA93E3AF1E3C5622E"=C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe [2015-05-12 637440]
"SaveMyWork"=C:\Program Files (x86)\Emsa Save My Work\SaveMyWork.exe [2004-12-12 471040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Users\Jíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Automatické vypnutí počítače.lnk - C:\Program Files (x86)\Automatické vypnutí počítače\avp.exe
crossbrowse.lnk - C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2009-12-07 75320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MSIServer]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=i420vfw.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.VP60"=C:\windows\system32\vp6vfw.dll
"vidc.VP61"=C:\windows\system32\vp6vfw.dll
"vidc.yv12"=yv12vfw.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2015-11-19 19:36:37 ----D---- C:\Users\Jíra\AppData\Roaming\AVG
2015-11-19 19:36:13 ----D---- C:\Program Files (x86)\AVG
2015-11-19 19:34:50 ----HD---- C:\ProgramData\Common Files
2015-11-19 19:34:50 ----D---- C:\ProgramData\AVG
2015-11-19 19:34:27 ----D---- C:\Users\Jíra\AppData\Roaming\OpenCandy
2015-11-19 19:26:41 ----A---- C:\SetupSaveMyWork.exe
2015-11-11 18:56:29 ----D---- C:\Program Files (x86)\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2015-11-19 20:55:59 ----D---- C:\windows\temp
2015-11-19 20:55:56 ----D---- C:\Program Files (x86)\trend micro
2015-11-19 19:36:33 ----SHD---- C:\windows\Installer
2015-11-19 19:36:13 ----D---- C:\Program Files (x86)
2015-11-19 19:36:03 ----D---- C:\Config.Msi
2015-11-19 19:36:03 ----AD---- C:\Windows
2015-11-19 19:34:50 ----D---- C:\ProgramData
2015-11-19 19:34:27 ----RD---- C:\Program Files
2015-11-19 19:28:51 ----D---- C:\Program Files (x86)\Emsa Save My Work
2015-11-19 19:28:30 ----D---- C:\windows\inf
2015-11-19 19:27:37 ----D---- C:\windows\System32
2015-11-19 19:26:35 ----D---- C:\Users\Jíra\AppData\Roaming\Seznam.cz
2015-11-19 19:22:28 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-19 19:21:31 ----A---- C:\windows\avp.ini
2015-11-11 09:05:13 ----D---- C:\windows\SysWOW64
2015-11-11 09:05:11 ----A---- C:\windows\SysWOW64\FlashPlayerApp.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\windows\SysWOW64\drivers\aswRvrt.sys []
R0 aswVmm;avast! VM Monitor; C:\windows\SysWOW64\drivers\aswVmm.sys []
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\windows\system32\DRIVERS\AtiPcie.sys []
R0 FSProFilter2;FSPro File Filter 2; C:\windows\System32\Drivers\FSPFltd2.sys []
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys []
R0 PxHlpa64;PxHlpa64; C:\windows\System32\Drivers\PxHlpa64.sys []
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys []
R0 SafeBoot;SafeBoot; C:\windows\SysWOW64\drivers\SafeBoot.sys [2010-02-02 110520]
R0 SbAlg;SbAlg; C:\windows\SysWOW64\drivers\SbAlg.sys [2010-02-02 51800]
R0 SbFsLock;SbFsLock; C:\windows\SysWOW64\drivers\SbFsLock.sys [2010-02-02 13256]
R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys []
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\drivers\vmbus.sys []
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys []
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys []
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys []
R1 RsvLock;RsvLock; C:\windows\SysWOW64\drivers\RsvLock.sys [2010-02-02 40088]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\windows\system32\DRIVERS\vpcnfltr.sys []
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\windows\system32\drivers\vpcvmm.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys []
R2 aswHwid;avast! HardwareID; C:\windows\system32\drivers\aswHwid.sys []
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys []
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys []
R2 rimspci;rimspci; C:\windows\system32\DRIVERS\rimspe64.sys []
R2 risdpcie;risdpcie; C:\windows\system32\DRIVERS\risdpe64.sys []
R2 rixdpcie;rixdpcie; C:\windows\system32\DRIVERS\rixdpe64.sys []
R3 Accelerometer;HP Accelerometer; C:\windows\system32\DRIVERS\Accelerometer.sys []
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys []
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys []
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys []
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\windows\system32\drivers\AtiHdmi.sys []
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\windows\system32\DRIVERS\bcmwl664.sys []
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys []
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys []
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys []
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys []
R3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys []
R3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys []
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys []
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys []
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys []
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys []
R3 STHDA;IDT High Definition Audio CODEC; C:\windows\system32\DRIVERS\stwrt64.sys []
R3 tap0901;TAP-Win32 Adapter V9; C:\windows\system32\DRIVERS\tap0901.sys []
R3 TPM;TPM; C:\windows\system32\drivers\tpm.sys []
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\windows\system32\DRIVERS\vpchbus.sys []
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\windows\system32\DRIVERS\vpcusb.sys []
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys []
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\windows\system32\drivers\nmwcdnsux64.sys []
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys []
S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys []
S3 sdbus;sdbus; C:\windows\system32\drivers\sdbus.sys []
S3 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys []
S3 VMBusHID;VMBusHID; C:\windows\system32\drivers\VMBusHID.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ac.sharedstore;ActivIdentity Shared Store Service; C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-04 277032]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-10-28 82128]
R2 AESTFilters;Andrea ST Filters Service; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe [2009-03-03 89600]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agr64svc.exe [2010-01-21 16896]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe []
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Sof [2012-09-09 6516280]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-12-29 873248]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 20992]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2010-03-31 462088]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-03-24 121344]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2010-04-05 103992]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-04-05 103992]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe [2010-06-14 90112]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; c:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2009-12-10 251448]
R2 HpFkCryptService;Drive Encryption Service; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2010-02-02 281192]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2010-01-19 297984]
R2 hpHotkeyMonitor;HP Hotkey Monitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-03-01 264248]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe []
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-02-22 73728]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\windows\SysWOW64\NLSSRV32.EXE [2012-04-12 69640]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-04-06 624856]
R2 STacSV;Audio Service; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe [2010-03-17 244736]
R2 TeamViewer7;TeamViewer 7; C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-02 2923392]
R3 DEBridge;DEBridge; c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [2010-02-02 704512]
R3 hpqwmiex;hpqwmiex; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2010-02-08 230968]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-08-29 68608]
S2 HP ProtectTools Service;HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2010-03-17 36864]
S2 KMService;KMService; C:\windows\system32\srvany.exe [2012-11-14 8192]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2010-02-18 1664304]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-11 269000]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\SysWOW64\flcdlock.exe [2009-12-07 362040]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-08-29 68608]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe /V []
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 50942144]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-11-11 147624]
S3 OpenVPNService;OpenVPN Service; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [2011-07-01 14848]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 RoxMediaDB10;RoxMediaDB10; c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-11-23 1120752]
S3 stllssvr;stllssvr; c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe [2009-10-16 74392]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe []
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------
"

Re: Prosím o preventivní kontrolu

Napsal: 19 lis 2015 21:49
od altrok
Krasny den Vam preju :bye:


:arrow: 10. listopadu byly vydany aktualizace operacniho systemu - alespon ty dulezite doinstalujte.

:arrow: Odinstalujte
  • Seznam Software - pokud nepouzivate, protoze velice casto byva instalovan jako adware
:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).

:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan, pote na Cleaning
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner[Cx].txt), jehoz obsah mi zkopirujte do pristi odpovedi

Re: Prosím o preventivní kontrolu

Napsal: 20 lis 2015 19:13
od curt-xx
# AdwCleaner v5.021 - Logfile created 20/11/2015 at 19:06:56
# Updated 14/11/2015 by Xplode
# Database : 2015-11-19.4 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : Jíra - HP
# Running from : C:\Users\Jíra\Desktop\adwcleaner_5.021.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : globalUpdate
[-] Service Deleted : globalUpdatem
[-] Service Deleted : PanService

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\globalUpdate
[-] Folder Deleted : C:\Program Files (x86)\PANDORA.TV
[-] Folder Deleted : C:\Program Files (x86)\Crossbrowse
[-] Folder Deleted : C:\Program Files (x86)\CinemaP-1.9cV29.08
[!] Folder Not Deleted : C:\Program Files (x86)\Crossbrowse
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossbrowse
[!] Folder Not Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossbrowse
[-] Folder Deleted : C:\Users\Jíra\AppData\Local\globalUpdate
[-] Folder Deleted : C:\Users\Jíra\AppData\Local\Crossbrowse
[!] Folder Not Deleted : C:\Users\Jíra\AppData\Local\Crossbrowse
[-] Folder Deleted : C:\Users\Jíra\AppData\Roaming\OpenCandy
[-] Folder Deleted : C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\Smartbar
[-] Folder Deleted : C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\ValueApps
[-] Folder Deleted : C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\Extensions\{1122b43d-30ee-403f-9bfa-3cc99b0caddd}
[-] Folder Deleted : C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
[-] Folder Deleted : C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\Extensions\AVJYFVOD75109374@HCDE39471360.com
[#] Folder Deleted : C:\windows\SysNative\Tasks\Crossbrowse
[#] Folder Deleted : C:\windows\SysNative\Tasks\Crossbrowse

***** [ Files ] *****

[-] File Deleted : C:\Users\Jíra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\crossbrowse.lnk
[-] File Deleted : C:\Users\Jíra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\crossbrowse.lnk
[-] File Deleted : C:\Users\Jíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk
[-] File Deleted : C:\Users\Public\Desktop\crossbrowse.lnk

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : BrowserProtect
[-] Task Deleted : Crossbrowse
[-] Task Deleted : EPUpdater
[-] Task Deleted : globalUpdateUpdateTaskMachineCore
[-] Task Deleted : globalUpdateUpdateTaskMachineUA
[-] Task Deleted : 2a43a216-2033-4249-9fd5-329443c38ff8-1-6
[-] Task Deleted : 2a43a216-2033-4249-9fd5-329443c38ff8-1-7
[-] Task Deleted : 2a43a216-2033-4249-9fd5-329443c38ff8-10_user
[-] Task Deleted : 2a43a216-2033-4249-9fd5-329443c38ff8-11
[-] Task Deleted : 2a43a216-2033-4249-9fd5-329443c38ff8-4
[-] Task Deleted : 2a43a216-2033-4249-9fd5-329443c38ff8-5
[-] Task Deleted : 2a43a216-2033-4249-9fd5-329443c38ff8-5_user
[-] Task Deleted : 2a43a216-2033-4249-9fd5-329443c38ff8-1-6
[-] Task Deleted : 2a43a216-2033-4249-9fd5-329443c38ff8-1-7
[-] Task Deleted : 2a43a216-2033-4249-9fd5-329443c38ff8-11
[-] Task Deleted : 2a43a216-2033-4249-9fd5-329443c38ff8-4
[-] Task Deleted : 2a43a216-2033-4249-9fd5-329443c38ff8-5
[-] Task Deleted : globalUpdateUpdateTaskMachineCore
[-] Task Deleted : globalUpdateUpdateTaskMachineUA
[-] Task Deleted : globalUpdateUpdateTaskMachineCore
[-] Task Deleted : globalUpdateUpdateTaskMachineUA

***** [ Registry ] *****

[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
[-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
[-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Mediaplayer\Shiminclusionlist\crossbrowse.exe
[-] Key Deleted : HKLM\SOFTWARE\Classes\CRSBRWSHTML
[-] Key Deleted : HKLM\SOFTWARE\Clients\StartMenuInternet\Crossbrowse
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\crossbrowse.exe
[-] Value Deleted : HKLM\SOFTWARE\Classes\.htm\OpenWithProgids [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\Classes\.html\OpenWithProgids [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\RegisteredApplications [Crossbrowse]
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe
[-] Value Deleted : HKLM\SOFTWARE\Classes\.xht\OpenWithProgIDs [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\Classes\.webp\OpenWithProgIDs [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\Classes\.shtml\OpenWithProgIDs [CRSBRWSHTML]
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
[-] Key Deleted : HKCU\Software\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2A563926-CF4B-4363-A760-F71E46205B7E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKCU\Software\GlobalUpdate
[-] Key Deleted : HKCU\Software\InstalledBrowserExtensions
[-] Key Deleted : HKCU\Software\CrossBrowser
[-] Key Deleted : HKCU\Software\YorkNewCin
[-] Key Deleted : HKCU\Software\HighDefAction
[-] Key Deleted : HKCU\Software\ArenaHD
[-] Key Deleted : HKCU\Software\CinemaP-1.9cV29.08-nv-ie
[-] Key Deleted : HKCU\Software\Crossbrowse
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
[-] Key Deleted : HKLM\SOFTWARE\AppDataLow\SOFTWARE\Crossrider
[-] Key Deleted : HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
[-] Key Deleted : HKLM\SOFTWARE\GlobalUpdate
[-] Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Key Deleted : HKLM\SOFTWARE\YorkNewCin
[-] Key Deleted : HKLM\SOFTWARE\HighDefAction
[-] Key Deleted : HKLM\SOFTWARE\ArenaHD
[-] Key Deleted : HKLM\SOFTWARE\CinemaP-1.9cV29.08
[-] Key Deleted : HKLM\SOFTWARE\CinemaP-1.9cV29.08-nv-ie
[-] Key Deleted : HKLM\SOFTWARE\Crossbrowse
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaP-1.9cV29.08
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Crossbrowse
[-] Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Key Deleted : [x64] HKLM\SOFTWARE\YorkNewCin
[-] Key Deleted : [x64] HKLM\SOFTWARE\HighDefAction
[-] Key Deleted : [x64] HKLM\SOFTWARE\ArenaHD
[-] Key Deleted : HKU\.DEFAULT\Software\CinemaP-1.9cV29.08-nv-ie
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
[-] Key Deleted : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GLOBALUPDATE.EXE
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3792E102-8369-434F-AE70-0C536F59005A}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{53D3390A-64CA-4CEE-9CEC-4356CE7DE179}

***** [ Web browsers ] *****

[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.1000082.isPlayDisplay", "true");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description\":\"California Rock - Rock\",\"url\":\"hxxp://www.feedlive.net/california.asx\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.FirstTime", "true");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.FirstTimeFF3", "true");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.TopHitsConfig.enc", "ew0KICAgICJzcHJpdGVVcmwiOiAiaHR0cDovL3N0b3JhZ2UuY29uZHVpdC5jb20vcHMvVG9wSGl0c0dlbmVyaWNBcHAvY29uZmlncy9VUy1VSy1EYW5jZS1Sb2NrLVJhcC9zcHJpdGUucG5nIiwNCiAgICAiaX[...]
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.UserID", "UN40200047275717492");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.YTbyClickFavorites.enc", "W10=");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.YTbyClickRecent.enc", "W10=");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.addressBarTakeOverEnabledInHidden", "true");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.appOptions", "{}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.countryCode", "CZ");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.enlargeSearchBox", "{\"enabled\":true,\"maxWidth\":1000,\"minWidth\":250,\"width\":500}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.firstTimeDialogOpened", "true");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.fixPageNotFoundErrorByUser", "TRUE");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.fixPageNotFoundErrorInHidden", "true");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.fullUserID", "UN40200047275717492.XP.20140103130329");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.installType", "DirectDownload");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.isCheckedStartAsHidden", true);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.isFirstTimeToolbarLoading", "false");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.lastNewTabSettings", "{\"isEnabled\":false,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3298566&octid=CT3298566&SearchSource=15&CUI=UN40200047275717492&SSPV=&Lay=1&UM=2\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.lastVersion", "10.23.0.822");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.mam_gk_installer_preapproved.enc", "VFJVRQ==");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.fcviktoria.cz%2Fcs%2Fforum%2Fviktorka-obecne\",\"EB_MAIN_FRAME_TITLE\":\"Viktorka%20obecn%C4%9B%20%C2%BB%20FC%20[...]
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.revertSettingsEnabled", "false");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.search.searchAppId", "130110228003246321");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.search.searchCount", "0");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.searchFromAddressBarEnabledByUser", "false");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.searchInNewTabEnabledByUser", "false");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.searchInNewTabEnabledInHidden", "true");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.searchSuggestEnabledByUser", "false");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.searchUninstallUserMode", "2");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.searchUserMode", "2");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3298566\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://MixiDJV30.OurToolbar.com//xpi\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"MixiDJ V30 \"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_services_Configuration_lastUpdate", "1391019468988");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1388750617832");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_services_appsMetadata_lastUpdate", "1388750617323");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1388750617378");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_services_login_10.23.0.822_lastUpdate", "1391019468606");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1388750617470");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_services_searchAPI_lastUpdate", "1391019468964");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_services_serviceMap_lastUpdate", "1391019468702");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_services_setupAPI_lastUpdate", "1388750616178");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_services_toolbarContextMenu_lastUpdate", "1388750617421");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_services_toolbarSettings_lastUpdate", "1391026669418");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.serviceLayer_services_translation_lastUpdate", "1391019468707");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.settingsINI", true);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.showToolbarPermission", "false");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.smartbar.CTID", "CT3298566");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.smartbar.Uninstall", "0");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.smartbar.toolbarName", "MixiDJ V30 ");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.toolbarBornServerTime", "3-1-2014");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.toolbarCurrentServerTime", "27-1-2014");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.toolbarDisabled", "true");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.toolbarInstallDate", "03-01-2014 13:03:36");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.toolbarLoginClientTime", "Fri Jan 03 2014 13:37:30 GMT+0100");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566.userIdGenerationCounter", "1");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("CT3298566_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1391019462374,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("extensions.aAVJYFVOD75109374HCDE39471360com72895.72895.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.co.uk%22%2C%22amazon.com%22%2C%22anth[...]
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("extensions.aAVJYFVOD75109374HCDE39471360com72895.72895.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22%[...]
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("extensions.crossrider.bic", "14f7a3715da6f2176839d20e0f50dd75");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("plugin.state.npconduitfirefoxplugin", 2);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("smartbar.machineId", "RWZPSVIQGSFUB6TW9K4DHM6X/HTDWK0GFDCVFVEIGEW5RXWIJQ2UNKLRYTMH027M7WFNXCVTRESMEJVQNZZBPQ");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appStateReportTime", "31333838373530363232363332");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appStateReportTime.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appState_Clarity_Active", "6F6E");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appState_Clarity_Active.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appState_CouponBuddy", "6F6E");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appState_CouponBuddy.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appState_Easytobook", "6F6E");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appState_Easytobook.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appState_Easytobook_targeted", "6F6E");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appState_Easytobook_targeted.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appState_PriceGong", "6F6E");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appState_PriceGong.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appsDefaultEnabled", "74727565");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_appsDefaultEnabled.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_calledSetupService", "31");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_calledSetupService.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_currentVersion", "312E31332E302E3137");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_currentVersion.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_existingUsersRecoveryDone", "31");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_existingUsersRecoveryDone.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_first_time", "31");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_first_time.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_lastLoginTime", "31333838373530363233303937");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_lastLoginTime.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_localization.storedInFile", true);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_mamEnabled", "74727565");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_mamEnabled.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_migrated_from_ls", "31");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_migrated_from_ls.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_new_welcome_experience", "31");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_new_welcome_experience.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_settings1.12.0.5.storedInFile", true);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_showWelcomeGadget", "66616C7365");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_showWelcomeGadget.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_stamp", "35345F30");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_stamp.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_userBornDate", "4E2F41");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_userBornDate.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_userId", "34373336393238322D656262372D343639352D616361332D363538653135323761383366");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_userId.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_user_approval_interacted", "31");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_user_approval_interacted.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_welcomeDialogMode", "31");
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.CT3298566.mam_gk_welcomeDialogMode.storedInFile", false);
[-] [C:\Users\Jíra\AppData\Roaming\Mozilla\Firefox\Profiles\0i7xvw87.default\prefs.js] [Preference] Deleted : user_pref("valueApps.storage.mam_gk_userId", "34373336393238322D656262372D343639352D616361332D363538653135323761383366");
[-] [C:\Users\Jíra\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : babylon.com

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [37527 bytes] ##########

Re: Prosím o preventivní kontrolu

Napsal: 20 lis 2015 23:02
od altrok
:arrow: Dejte log FRST.txt, prilozte i Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101