Dobře, Windows Defender jsem tedy vypnul
.
Toto mi vyhodilo FRST:
Fix result of Farbar Recovery Scan Tool (x64) Version: 24-05-2015 01
Ran by Správce at 2015-05-24 20:39:14 Run:1
Running from C:\Users\Správce\Desktop
Loaded Profiles: ACER & UpdatusUser & Správce (Available Profiles: ACER & UpdatusUser & Správce)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-1808696115-1385625353-2641224543-1184\...\RunOnce: [Report] => \AdwCleaner\AdwCleaner[S4].txt [2927 2015-05-23] ()
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
http://www.bing.com/search?q={searchTer ... DF&PC=AV01
HKU\S-1-5-21-1808696115-1385625353-2641224543-1000\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.bing.com/search?q={searchTer ... DF&PC=AV01
HKU\S-1-5-21-1808696115-1385625353-2641224543-1000\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/?pc=AV01
HKU\S-1-5-21-1808696115-1385625353-2641224543-1000\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.msn.com/?pc=AV01
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL =
http://www.bing.com/search?q={searchTer ... DF&PC=AV01
SearchScopes: HKU\S-1-5-21-1808696115-1385625353-2641224543-1000 -> {2F27E06B-8CD1-4584-80B7-151BFA5E1C89} URL =
http://search.seznam.cz/?q={searchTerms ... chmodule_2
SearchScopes: HKU\S-1-5-21-1808696115-1385625353-2641224543-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL =
http://www.bing.com/search?q={searchTer ... DF&PC=AV01
SearchScopes: HKU\S-1-5-21-1808696115-1385625353-2641224543-1000 -> {A4C7980E-53D9-478F-A8E7-CA233A843A88} URL =
https://search.f-secure.com/search?quer ... o=provider
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
FF DefaultSearchEngine: F-Secure Search
FF SelectedSearchEngine: F-Secure Search
FF SearchPlugin: C:\Users\Správce\AppData\Roaming\Mozilla\Firefox\Profiles\ijs4ep1w.default\searchplugins\f-secure-search.xml [2014-05-12]
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-17 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15 268464]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-17 116648]
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BingDesktop" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tresorit" /f
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-1808696115-1385625353-2641224543-1184\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Report => value Removed successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-1808696115-1385625353-2641224543-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-1808696115-1385625353-2641224543-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-1808696115-1385625353-2641224543-1000\Software\Microsoft\Internet Explorer\Main\\Search Bar => value Removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => key Removed successfully
HKCR\Wow6432Node\CLSID\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} => key not found.
"HKU\S-1-5-21-1808696115-1385625353-2641224543-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2F27E06B-8CD1-4584-80B7-151BFA5E1C89}" => key Removed successfully
HKCR\CLSID\{2F27E06B-8CD1-4584-80B7-151BFA5E1C89} => key not found.
"HKU\S-1-5-21-1808696115-1385625353-2641224543-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => key Removed successfully
HKCR\CLSID\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} => key not found.
"HKU\S-1-5-21-1808696115-1385625353-2641224543-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A4C7980E-53D9-478F-A8E7-CA233A843A88}" => key Removed successfully
HKCR\CLSID\{A4C7980E-53D9-478F-A8E7-CA233A843A88} => key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value Removed successfully
HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => key not found.
Firefox DefaultSearchEngine Removed successfully
Firefox SelectedSearchEngine Removed successfully
C:\Users\Správce\AppData\Roaming\Mozilla\Firefox\Profiles\ijs4ep1w.default\searchplugins\f-secure-search.xml => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
AdobeARMservice => Service Removed successfully
gupdate => Service Removed successfully
SkypeUpdate => Service Removed successfully
AdobeFlashPlayerUpdateSvc => Service Removed successfully
gupdatem => Service Removed successfully
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BingDesktop" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tresorit" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts restored successfully.
EmptyTemp: => Removed 254.6 MB temporary data.
The system needed a reboot.
==== End of Fixlog 20:40:10 ====