tak posílám logy:
Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by zdenek.konecny on źt 31.01.2019 at 13:06:57,36.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\zdenek.konecny.PTACEKPS\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
31.1.2019 13:08:16 Zoek.exe System Restore Point Created Successfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
C:\PROGRA~2\AGEIA Technologies deleted successfully
C:\PROGRA~2\Deskshare deleted successfully
C:\PROGRA~2\GUMB724.tmp deleted successfully
C:\PROGRA~2\KMPConnect deleted successfully
C:\PROGRA~2\Nokia deleted successfully
C:\Program Files\AnyDATA deleted successfully
C:\PROGRA~3\Elcomsoft Password Recovery deleted successfully
C:\Users\NTBPSP01\AppData\Local\GHISLER deleted successfully
C:\Users\NTBPSP01\AppData\Local\VirtualStore deleted successfully
C:\Users\zdenek.konecny\AppData\Local\calibre-cache deleted successfully
C:\Users\zdenek.konecny\AppData\Local\GHISLER deleted successfully
C:\Users\zdenek.konecny\AppData\Local\SystemDir deleted successfully
C:\Users\zdenek.konecny\AppData\Local\WMTools Downloaded Files deleted successfully
C:\Users\zdenek.konecny.PTACEKPS\AppData\Local\GHISLER deleted successfully
C:\Users\zdenek.konecny.PTACEKPS\AppData\Local\SystemDir deleted successfully
C:\Users\zdenek.konecny.PTACEKPS\AppData\Local\WMTools Downloaded Files deleted successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\CrashDumps deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\
web2pdfextension.17@acrobat.adobe.com deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\
web2pdfextension.17@acrobat.adobe.com deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\ZDENEK~1.KON\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\prefs.js:
user_pref("browser.startup.homepage", "
http://www.seznam.cz/");
user_pref("browser.search.selectedEngine", "ПоиŃĐş@Mail.Ru");
user_pref("browser.search.useDBForOrder", false);
Added to C:\Users\ZDENEK~1.KON\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\ZDENEK~1.KON\AppData\Roaming\TomTom\HOME\Profiles\aex6rkh2.default\prefs.js:
Added to C:\Users\ZDENEK~1.KON\AppData\Roaming\TomTom\HOME\Profiles\aex6rkh2.default\prefs.js:
Deleted from C:\Users\ZDENEK~1.PTA\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\prefs.js:
user_pref("browser.startup.homepage", "
http://www.seznam.cz/");
user_pref("browser.search.selectedEngine", "ПоиŃĐş@Mail.Ru");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\ZDENEK~1.PTA\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\ZDENEK~1.PTA\AppData\Roaming\TomTom\HOME\Profiles\aex6rkh2.default\prefs.js:
Added to C:\Users\ZDENEK~1.PTA\AppData\Roaming\TomTom\HOME\Profiles\aex6rkh2.default\prefs.js:
ProfilePath: C:\Users\ZDENEK~1.KON\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238
---- FireFox user.js and prefs.js backups ----
user_31.01.2019_1332_.backup
prefs_31.01.2019_1332_.backup
ProfilePath: C:\Users\ZDENEK~1.KON\AppData\Roaming\TomTom\HOME\Profiles\aex6rkh2.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_31.01.2019_1332_.backup
ProfilePath: C:\Users\ZDENEK~1.PTA\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238
---- Lines search.com removed from prefs.js ----
user_pref("browser.onboarding.tour.onboarding-tour-singlesearch.completed", true);
---- Lines searches removed from prefs.js ----
user_pref("browser.urlbar.suggest.searches", false);
---- Lines
web2pdfextension.17@acrobat.adobe.com removed from prefs.js ----
user_pref("extensions.webextensions.uuids", "{\"
web2pdfextension.17@acrobat.adobe.com\":\"5393704b-7bd4-40d9-9c74-53a6bb6628b3\",\"screenshots@mozilla
---- FireFox user.js and prefs.js backups ----
user_31.01.2019_1332_.backup
prefs_31.01.2019_1332_.backup
ProfilePath: C:\Users\ZDENEK~1.PTA\AppData\Roaming\TomTom\HOME\Profiles\aex6rkh2.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_31.01.2019_1332_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~2\AGEIA Technologies not found
C:\PROGRA~2\Deskshare not found
C:\PROGRA~2\GUMB724.tmp not found
C:\PROGRA~2\KMPConnect not found
C:\PROGRA~2\Nokia not found
C:\Users\zdenek.konecny.PTACEKPS\AppData\Roaming\calibre deleted
C:\Users\zdenek.konecny\.android deleted
C:\Users\zdenek.konecny.PTACEKPS\.android deleted
C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\zdenek.konecny\AppData\Local\cache deleted
C:\Users\zdenek.konecny.PTACEKPS\AppData\Local\oobelibMkey.log deleted
C:\Users\zdenek.konecny.PTACEKPS\AppData\Local\cache deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\oobelibMkey.log deleted
C:\Users\ZDENEK~1.KON\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\.autoreg deleted
C:\Users\ZDENEK~1.PTA\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\searchplugins\qipsearch.xml deleted
C:\Users\ZDENEK~1.PTA\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\.autoreg deleted
"C:\Users\zdenek.konecny.PTACEKPS\AppData\Roaming\XnView\category.db" deleted
"C:\Users\zdenek.konecny.PTACEKPS\AppData\Roaming\XnView\default.bar" deleted
"C:\Users\zdenek.konecny.PTACEKPS\AppData\Roaming\XnView" deleted
==== Orphaned Tasks deleted from Registry ======================
Imperia Online D1 deleted
Imperia Online N deleted
Imperia Online W1 deleted
Imperia Online W2 deleted
Imperia Online W3 deleted
Imperia Online W4 deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\ZDENEK~1.KON\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\ZDENEK~1.PTA\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions ======================
ProfilePath: C:\Users\ZDENEK~1.KON\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238
- IE Tab - C:\Users\zdenek.konecny\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\extensions\
coralietab@mozdev.org
- IE Tab - C:\Users\zdenek.konecny\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
- IE Tab 2 FF 3.6 - C:\Users\zdenek.konecny\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
- Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
- IE Tab - %ProfilePath%\extensions\
coralietab@mozdev.org
- WebTran - %ProfilePath%\extensions\{003D3EDC-99B9-4a34-9C20-60CB94F7E829}
- IE Tab 2 FF 3.6 - %ProfilePath%\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
- IE Tab - %ProfilePath%\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
- TimeLapse for Firefox - %ProfilePath%\extensions\{7c402354-dd42-4ef3-8d2d-2aa1445b4747}.xpi
ProfilePath: C:\Users\ZDENEK~1.KON\AppData\Roaming\TomTom\HOME\Profiles\aex6rkh2.default
- Map status indicator - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\
MapShare-status@tomtom.com
- TomTom HOME default theme - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\
baseTheme@tomtom.com
- Emulator - %ProfilePath%\extensions\
Navcore.9.510.1234792@tomtom.com
ProfilePath: C:\Users\ZDENEK~1.PTA\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238
- IE Tab - %ProfilePath%\extensions\
coralietab@mozdev.org
- WebTran - %ProfilePath%\extensions\{003D3EDC-99B9-4a34-9C20-60CB94F7E829}
- IE Tab 2 FF 3.6 - %ProfilePath%\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
- IE Tab - %ProfilePath%\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
- TimeLapse for Firefox - %ProfilePath%\extensions\{7c402354-dd42-4ef3-8d2d-2aa1445b4747}.xpi
ProfilePath: C:\Users\ZDENEK~1.PTA\AppData\Roaming\TomTom\HOME\Profiles\aex6rkh2.default
- Map status indicator - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\
MapShare-status@tomtom.com
- TomTom HOME default theme - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\
baseTheme@tomtom.com
- Emulator - %ProfilePath%\extensions\
Navcore.9.510.1234792@tomtom.com
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
==== Firefox Plugins ======================
Profilepath: C:\Users\zdenek.konecny.PTACEKPS\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238
- C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_114.dll - [?]
B2F9B974857B8BA96734684813F6448C - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrlui.dll - Microsoft® Silverlight
EEDFF839EE4882DDA6F423298478F5A3 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll - Silverlight Plug-In
- C:\Program Files x86\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll - [?]
- C:\Program Files x86\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll - [?]
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
efaidnbmnnnibpcajpcglclefindmkaj - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx[01.11.2017 15:27]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
https://www.seznam.cz/"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
https://www.seznam.cz/"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} -
http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTer ... ORM=IESR02
==== Reset Google Chrome ======================
C:\Users\NTBPSP01\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\NTBPSP01\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\NTBPSP01\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\zdenek.konecny.PTACEKPS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\ZDENEK~1.PTA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\zdenek.konecny\AppData\Local\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\cache2 emptied successfully
C:\Users\zdenek.konecny.PTACEKPS\AppData\Local\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\cache2 emptied successfully
C:\Users\ZDENEK~1.KON\AppData\Local\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\cache2 emptied successfully
C:\Users\ZDENEK~1.PTA\AppData\Local\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\NTBPSP01\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=1259 folders=74 168405841 bytes)
==== Empty Temp Folders ======================
C:\Users\admin\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\zdenek.konecny\AppData\Local\Temp emptied successfully
C:\Users\zdenek.konecny.PTACEKPS\AppData\Local\Temp will be emptied at reboot
C:\Users\ZDENEK~1.KON\AppData\Local\Temp emptied successfully
C:\Users\ZDENEK~1.PTA\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\ZDENEK~1.PTA\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on źt 31.01.2019 at 13:45:09,41 ======================
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Professional x64
Ran by zdenek.konecny (Administrator) on źt 31.01.2019 at 13:47:24,69
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 1
Successfully deleted: C:\Users\zdenek.konecny.PTACEKPS\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\user.js (File)
Deleted the following from C:\Users\zdenek.konecny.PTACEKPS\AppData\Roaming\Mozilla\Firefox\Profiles\v26ol8g8.default-1441634397238\prefs.js
user_pref(
extensions.yasearch@yandex.ru.defender.homepage.enabled, );
Registry: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 31.01.2019 at 13:48:44,00
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~