RogueKiller V9.2.13.0 [Sep 25 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 7 (6.1.7600 ) 32 bits version
Spuštěno v : Normální režim
Uživatel : Ivča [Práva správce]
Mód : Odebrat -- Datum : 10/01/2014 14:34:37
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 11 ¤¤¤
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5BACC0E3-511C-4A89-A4A0-4754FE1E4B13} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{5BACC0E3-511C-4A89-A4A0-4754FE1E4B13} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{5BACC0E3-511C-4A89-A4A0-4754FE1E4B13} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NAHRAZENO ()
[PUM.Policies] HKEY_USERS\S-1-5-21-1935359104-4094134921-1001328300-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> VYMAZÁNO
[PUM.Policies] HKEY_USERS\S-1-5-21-1935359104-4094134921-1001328300-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> VYMAZÁNO
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NAHRAZENO (0)
[PUM.HomePage] HKEY_USERS\S-1-5-21-1935359104-4094134921-1001328300-1000\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> NAHRAZENO (http://go.microsoft.com/fwlink/p/?LinkId=255141)
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: NAHRÁNO) ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST9500325AS ATA Device +++++
--- User ---
[MBR] 7277234bba87c440d407b7517242bc61
[BSP] 102a61b6d82184655e983cabfa21319d : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 40962 MB
1 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 83891430 | Size: 435967 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_DEL_10012014_000821.log - RKreport_SCN_10012014_000609.log - RKreport_SCN_10012014_143411.log
Prosím o kontrolu logu
Re: Prosím o kontrolu logu
Zoek.exe v5.0.0.0 Updated 30-09-2014
Tool run by Ivźa on st 01.10.2014 at 14:39:20,67.
Microsoft Windows 7 Ultimate 6.1.7600 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\IVA~1\Desktop\zoek.exe [Scan all users] [Quick Scan] [Auto Clean]
==== System Restore Info ======================
1.10.2014 14:41:09 Zoek.exe System Restore Point Created Succesfully.
==== Empty Folders Check ======================
C:\Program Files\Common Files\MicroWorld deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== Registry Fix Code ======================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Opera\shell\open\command]
@="C:\\Program Files\\Opera\\Opera.exe"
==== Files Recently Created / Modified ======================
====== C:\Windows ====
2014-09-29 18:44:35 5EAC9B8D6D4201E91A744AC9F68AC498 28 ----a-w- C:\Windows\Lic.xxx
====== C:\Users\IVA~1\AppData\Local\Temp ====
2014-09-30 21:27:33 E0DC8C6BBC787B972A9A468648DBFD85 1008128 ----a-w- C:\Users\IVA~1\AppData\Local\Temp\jrt\libiconv2.dll
2014-09-30 21:27:33 D202BAA425176287017FFE1FB5D1B77C 103424 ----a-w- C:\Users\IVA~1\AppData\Local\Temp\jrt\libintl3.dll
2014-09-30 21:27:33 57CAC848FA14AE38F14F9441F8933282 140288 ----a-w- C:\Users\IVA~1\AppData\Local\Temp\jrt\pcre3.dll
2014-09-30 21:27:33 547C43567AB8C08EB30F6C6BACB479A3 79360 ----a-w- C:\Users\IVA~1\AppData\Local\Temp\jrt\regex2.dll
2014-09-30 21:27:33 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Users\IVA~1\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
====== Java Cache =====
====== C:\Windows\system32 =====
2014-09-30 17:42:46 0DC5AF80D059DEC792B665ED598C6567 536576 ----a-w- C:\Windows\System32\sqlite3.dll
2014-09-29 18:44:22 5042D3932A04FF6B4B6385B99C4F36BE 632064 ----a-w- C:\Windows\System32\msvcr80.dll
2014-09-29 18:44:21 3EE76894C28BB5666C1770D8A965F8F2 554240 ----a-w- C:\Windows\System32\msvcp80.dll
2014-09-29 18:44:20 9EDF5EB3D091D4823C96A00B6B45DF45 522 ----a-w- C:\Windows\System32\Microsoft.VC80.CRT.manifest
2014-09-29 18:44:20 38F07D89C0DCB4826F508B78087215D8 34048 ----a-w- C:\Windows\System32\eEmpty.exe
====== C:\Windows\system32\drivers =====
2014-09-30 21:57:51 A1965DFC0CD91E7CFC42925F8F597274 34808 ----a-w- C:\Windows\System32\drivers\TrueSight.sys
2014-09-30 17:47:03 12E71DA845D76665B56753AD149E32B3 110296 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-09-30 17:46:32 BD27D97297934FD4217A37FD28A7ABC7 51928 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-09-30 17:46:32 8683C1B450F4B3872839308D836E0F92 23256 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-09-30 17:46:32 1AA835E8A0B8EDF3D676B4ED4BF5EF07 74456 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-09-15 19:13:42 4E39E113E8F5FEE3C49160A0D657A4D5 26136 ----a-w- C:\Windows\System32\drivers\aswKbd.sys
2014-09-15 19:13:12 EAA4A59CFA4AB73843B13E86B50F573D 270752 ----a-w- C:\Windows\System32\drivers\aswNdisFlt.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-09-16 08:51:39 -------- d-----w- C:\Program Files\rajce
======= C: =====
====== C:\Users\IVA~1\AppData ======
2014-09-30 21:55:09 -------- d-----w- C:\Users\IVA~1\AppData\Local\Adobe
2014-09-29 10:51:56 -------- d-----w- C:\Users\IVA~1\AppData\Local\Diagnostics
2014-09-16 08:51:34 -------- d-----w- C:\Users\IVA~1\AppData\Local\Programs
====== C:\Users\IVA~1 ======
2014-09-30 21:57:45 -------- d-----w- C:\ProgramData\RogueKiller
2014-09-30 21:56:51 C69C34DB8DC6C2E4BF242C9596C51CFD 4893784 ----a-w- C:\Users\IVA~1\Desktop\RogueKiller.exe
2014-09-30 21:24:31 620D4168BF050BE55182FC1C4794FD3A 1699276 ----a-w- C:\Users\IVA~1\Desktop\JRT.exe
2014-09-30 19:11:43 8088DBF6AAB0E1465D4B4C2748828AF5 2857022 ----a-w- C:\Users\IVA~1\Downloads\vstudio10.exe
2014-09-30 17:44:57 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\IVA~1\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-30 17:40:00 1B151CCE618BE06C22B55FD4B502B75E 1373475 ----a-w- C:\Users\IVA~1\Desktop\adwcleaner_3.310.exe
2014-09-30 17:38:53 D9DE89F0FAF18019BC9595F0F47BCA61 50688 ----a-w- C:\Users\IVA~1\Downloads\ATF-Cleaner.exe
2014-09-29 18:44:14 -------- d-----w- C:\ProgramData\MicroWorld
2014-09-29 18:38:16 8834AD50E9FF20D72BA98F7D6A25D5F5 68866904 ----a-w- C:\Users\IVA~1\Downloads\mwav.exe
2014-09-27 10:22:44 -------- d-----r- C:\Users\IVA~1\Disk Google
2014-09-27 10:21:31 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-09-24 17:28:19 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player
2014-09-19 08:07:05 F15A1DB113DE5214880C4A01D01FF83E 9074264 ----a-w- C:\Users\IVA~1\Downloads\vuex6494.exe
2014-09-16 08:51:42 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rajče
====== C: exe-files ==
2014-09-30 21:56:51 C69C34DB8DC6C2E4BF242C9596C51CFD 4893784 ----a-w- C:\Users\Ivča\Desktop\RogueKiller.exe
2014-09-30 21:27:33 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
2014-09-30 21:24:31 620D4168BF050BE55182FC1C4794FD3A 1699276 ----a-w- C:\Users\Ivča\Desktop\JRT.exe
2014-09-30 19:11:43 8088DBF6AAB0E1465D4B4C2748828AF5 2857022 ----a-w- C:\Users\Ivča\Downloads\vstudio10.exe
2014-09-30 17:44:57 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\Ivča\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-30 17:40:00 1B151CCE618BE06C22B55FD4B502B75E 1373475 ----a-w- C:\Users\Ivča\Desktop\adwcleaner_3.310.exe
2014-09-30 17:38:53 D9DE89F0FAF18019BC9595F0F47BCA61 50688 ----a-w- C:\Users\Ivča\Downloads\ATF-Cleaner.exe
2014-09-29 18:44:20 38F07D89C0DCB4826F508B78087215D8 34048 ----a-w- C:\Windows\System32\eEmpty.exe
2014-09-29 18:38:16 8834AD50E9FF20D72BA98F7D6A25D5F5 68866904 ----a-w- C:\Users\Ivča\Downloads\mwav.exe
2014-09-27 10:16:02 6CF617A12FB9B7169B6C69D328F63389 39975504 ----a-w- C:\Program Files\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\37.0.2062.124\37.0.2062.124_chrome_installer.exe
2014-09-25 12:41:45 CC127EE542BC41BFD7EB3CF6F6DBAA3B 697690 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\AC3 Filter\unins000.exe
2014-09-25 12:41:45 A6C9085DB29CEB92FA32D9EFBAB0471D 90112 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\AC3 Filter\spdif_test.exe
2014-09-25 12:41:45 8367988DC0585700CFA758F18A2EF1AC 87552 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\AC3 Filter\ac3config.exe
2014-09-25 12:41:37 AF4223C2577E752413784ECE83765354 137728 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\Haali media splitter\mkv2vfr.exe
2014-09-25 12:41:37 5DE59A417828FA4648D49EA0DAD6E5BE 358400 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\Haali media splitter\gdsmux.exe
2014-09-25 12:41:37 30AA0674FB6DA80F9480E11513D9661C 113152 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\Haali media splitter\dsmux.exe
2014-09-25 12:41:36 3C4D75D33CD2B3D53D0445C3594F881A 42305 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\Haali media splitter\uninstall.exe
2014-09-25 12:41:28 CF3CF034CFABA8AC68B6B502A1044F59 1175371 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\FFDShow\unins000.exe
2014-09-25 12:22:28 7CA4092A339EA30DE8FF06D3FF79D6ED 749648 ----a-w- C:\Program Files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\37.0.2062.124\37.0.2062.124_37.0.2062.120_chrome_updater.exe
=== C: other files ==
2014-10-01 12:25:14 DE0983FE4B830699312D35A990B3AE1B 1945 ----a-w- C:\Users\Ivča\AppData\Local\Temp\_MEI29842\resources\chrome_ext\nknebiagdodnminbdpflhpkgfpeijdbf_live.crx
2014-10-01 12:25:14 82F5C942549405F61A8808D0EA0FA9E2 25575 ----a-w- C:\Users\Ivča\AppData\Local\Temp\_MEI29842\resources\chrome_ext\apdfllckaahabafndbhieahigkjlhalf_live.crx
2014-09-30 21:57:51 A1965DFC0CD91E7CFC42925F8F597274 34808 ----a-w- C:\Windows\System32\drivers\TrueSight.sys
2014-09-30 21:27:33 E65FD31C267E8B8187F72E9F6B74882C 15127 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\get.bat
2014-09-30 21:27:33 DD1E4D974B1672ABD09EFFB225791C4A 1230 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\TDL4.bat
2014-09-30 21:27:33 C7B1E724E387DA744B894454AD44CB05 157105 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\misc.bat
2014-09-30 21:27:33 AD2F52DC72B10AF331692E4A4DD80DFC 18670 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\medfos.bat
2014-09-30 21:27:33 8E6020C14F982CF11B3FE7DBB0CB8EDE 24738 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\searchlnk.bat
2014-09-30 21:27:33 86707BCE5CBB65D9B1C41E249B4423BA 152733 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\firefox.bat
2014-09-30 21:27:33 83F691D8398F0E37E71E9355BF730DB9 719 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\ev_clear.bat
2014-09-30 21:27:33 654E9FE74B930A454EE5BDE165794B65 85 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\delorphans.bat
2014-09-30 21:27:33 5B71358F97544D9DE58A9A0893079506 39458 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\prelim.bat
2014-09-30 21:27:33 53B191266B30D57F2F835ABBF54C68C5 13963 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\chrome.bat
2014-09-30 21:27:33 4D80C7010E2CE44AB25FA25B013649E4 8085 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\mws.bat
2014-09-30 21:27:33 38A0BDF322ACCC968B0A824C38D50157 29635 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\ask.bat
2014-09-30 21:27:33 335DFF8F23E5EC02B5426362F0F8509B 31401 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\iexplore.bat
2014-09-30 21:27:33 2B588C39A2346DCD91B0F83244A39305 9542 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\runvalues.bat
2014-09-30 21:27:33 0C4649A62845AB5D5DBCC4998477FF6D 1813 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\delfolders.bat
2014-09-30 17:47:03 12E71DA845D76665B56753AD149E32B3 110296 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-09-30 17:46:32 BD27D97297934FD4217A37FD28A7ABC7 51928 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-09-30 17:46:32 8683C1B450F4B3872839308D836E0F92 23256 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-09-30 17:46:32 1AA835E8A0B8EDF3D676B4ED4BF5EF07 74456 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-09-29 18:49:52 C094918F834721D8150089B5BCAD2197 44517 ----a-w- C:\Users\Ivča\Documents\pinfect.zip
2014-09-29 09:47:19 7A1DD0ACAE667A54057192892E571F19 595074126 ----a-w- C:\Users\Ivča\Downloads\Irsko-2014.zip
2014-09-24 17:35:03 87A09EC6C719DCA4F01C78184D391DC1 62087763 ----a-w- C:\Users\Ivča\Desktop\školička\Voltametrie\231020132251.zip
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-1935359104-4094134921-1001328300-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\DTLite.exe -autorun"
"GoogleDriveSync"="C:\Program Files\Google\Drive\googledrivesync.exe /autostart"
"CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner.exe /MONITOR"
"RESTART_STICKY_NOTES"="C:\Windows\System32\StikyNot.exe"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe"
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\DTLite.exe -autorun"
"GoogleDriveSync"="C:\Program Files\Google\Drive\googledrivesync.exe /autostart"
"CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner.exe /MONITOR"
"RESTART_STICKY_NOTES"="C:\Windows\System32\StikyNot.exe"
==== Startup Folders ======================
==== Task Scheduler Jobs ======================
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [16.08.2014 22:29]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [16.08.2014 22:29]
==== Other Scheduled Tasks ======================
"C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\SmartDefrag_Startup" [C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe]
"C:\Windows\system32\tasks\{8F0D6EEB-1A2C-46FD-A239-72FC3E7C5924}" ["c:\program files\opera\opera.exe"]
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [15.09.2014 21:13]
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[16.08.2014 22:28]
Google Docs - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Last updated at time on date - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb
Google Search - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Google Wallet - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Search Page"="http://www.google.com"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}"
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Empty IE Cache ======================
C:\Users\IVA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\IVA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
C:\Users\IVA~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=0 folders=0 0 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\IVA~1\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\IVA~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\IVA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
==== EOF on st 01.10.2014 at 15:03:13,05 ======================
Tool run by Ivźa on st 01.10.2014 at 14:39:20,67.
Microsoft Windows 7 Ultimate 6.1.7600 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\IVA~1\Desktop\zoek.exe [Scan all users] [Quick Scan] [Auto Clean]
==== System Restore Info ======================
1.10.2014 14:41:09 Zoek.exe System Restore Point Created Succesfully.
==== Empty Folders Check ======================
C:\Program Files\Common Files\MicroWorld deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== Registry Fix Code ======================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Opera\shell\open\command]
@="C:\\Program Files\\Opera\\Opera.exe"
==== Files Recently Created / Modified ======================
====== C:\Windows ====
2014-09-29 18:44:35 5EAC9B8D6D4201E91A744AC9F68AC498 28 ----a-w- C:\Windows\Lic.xxx
====== C:\Users\IVA~1\AppData\Local\Temp ====
2014-09-30 21:27:33 E0DC8C6BBC787B972A9A468648DBFD85 1008128 ----a-w- C:\Users\IVA~1\AppData\Local\Temp\jrt\libiconv2.dll
2014-09-30 21:27:33 D202BAA425176287017FFE1FB5D1B77C 103424 ----a-w- C:\Users\IVA~1\AppData\Local\Temp\jrt\libintl3.dll
2014-09-30 21:27:33 57CAC848FA14AE38F14F9441F8933282 140288 ----a-w- C:\Users\IVA~1\AppData\Local\Temp\jrt\pcre3.dll
2014-09-30 21:27:33 547C43567AB8C08EB30F6C6BACB479A3 79360 ----a-w- C:\Users\IVA~1\AppData\Local\Temp\jrt\regex2.dll
2014-09-30 21:27:33 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Users\IVA~1\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
====== Java Cache =====
====== C:\Windows\system32 =====
2014-09-30 17:42:46 0DC5AF80D059DEC792B665ED598C6567 536576 ----a-w- C:\Windows\System32\sqlite3.dll
2014-09-29 18:44:22 5042D3932A04FF6B4B6385B99C4F36BE 632064 ----a-w- C:\Windows\System32\msvcr80.dll
2014-09-29 18:44:21 3EE76894C28BB5666C1770D8A965F8F2 554240 ----a-w- C:\Windows\System32\msvcp80.dll
2014-09-29 18:44:20 9EDF5EB3D091D4823C96A00B6B45DF45 522 ----a-w- C:\Windows\System32\Microsoft.VC80.CRT.manifest
2014-09-29 18:44:20 38F07D89C0DCB4826F508B78087215D8 34048 ----a-w- C:\Windows\System32\eEmpty.exe
====== C:\Windows\system32\drivers =====
2014-09-30 21:57:51 A1965DFC0CD91E7CFC42925F8F597274 34808 ----a-w- C:\Windows\System32\drivers\TrueSight.sys
2014-09-30 17:47:03 12E71DA845D76665B56753AD149E32B3 110296 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-09-30 17:46:32 BD27D97297934FD4217A37FD28A7ABC7 51928 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-09-30 17:46:32 8683C1B450F4B3872839308D836E0F92 23256 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-09-30 17:46:32 1AA835E8A0B8EDF3D676B4ED4BF5EF07 74456 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-09-15 19:13:42 4E39E113E8F5FEE3C49160A0D657A4D5 26136 ----a-w- C:\Windows\System32\drivers\aswKbd.sys
2014-09-15 19:13:12 EAA4A59CFA4AB73843B13E86B50F573D 270752 ----a-w- C:\Windows\System32\drivers\aswNdisFlt.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-09-16 08:51:39 -------- d-----w- C:\Program Files\rajce
======= C: =====
====== C:\Users\IVA~1\AppData ======
2014-09-30 21:55:09 -------- d-----w- C:\Users\IVA~1\AppData\Local\Adobe
2014-09-29 10:51:56 -------- d-----w- C:\Users\IVA~1\AppData\Local\Diagnostics
2014-09-16 08:51:34 -------- d-----w- C:\Users\IVA~1\AppData\Local\Programs
====== C:\Users\IVA~1 ======
2014-09-30 21:57:45 -------- d-----w- C:\ProgramData\RogueKiller
2014-09-30 21:56:51 C69C34DB8DC6C2E4BF242C9596C51CFD 4893784 ----a-w- C:\Users\IVA~1\Desktop\RogueKiller.exe
2014-09-30 21:24:31 620D4168BF050BE55182FC1C4794FD3A 1699276 ----a-w- C:\Users\IVA~1\Desktop\JRT.exe
2014-09-30 19:11:43 8088DBF6AAB0E1465D4B4C2748828AF5 2857022 ----a-w- C:\Users\IVA~1\Downloads\vstudio10.exe
2014-09-30 17:44:57 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\IVA~1\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-30 17:40:00 1B151CCE618BE06C22B55FD4B502B75E 1373475 ----a-w- C:\Users\IVA~1\Desktop\adwcleaner_3.310.exe
2014-09-30 17:38:53 D9DE89F0FAF18019BC9595F0F47BCA61 50688 ----a-w- C:\Users\IVA~1\Downloads\ATF-Cleaner.exe
2014-09-29 18:44:14 -------- d-----w- C:\ProgramData\MicroWorld
2014-09-29 18:38:16 8834AD50E9FF20D72BA98F7D6A25D5F5 68866904 ----a-w- C:\Users\IVA~1\Downloads\mwav.exe
2014-09-27 10:22:44 -------- d-----r- C:\Users\IVA~1\Disk Google
2014-09-27 10:21:31 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-09-24 17:28:19 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player
2014-09-19 08:07:05 F15A1DB113DE5214880C4A01D01FF83E 9074264 ----a-w- C:\Users\IVA~1\Downloads\vuex6494.exe
2014-09-16 08:51:42 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rajče
====== C: exe-files ==
2014-09-30 21:56:51 C69C34DB8DC6C2E4BF242C9596C51CFD 4893784 ----a-w- C:\Users\Ivča\Desktop\RogueKiller.exe
2014-09-30 21:27:33 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
2014-09-30 21:24:31 620D4168BF050BE55182FC1C4794FD3A 1699276 ----a-w- C:\Users\Ivča\Desktop\JRT.exe
2014-09-30 19:11:43 8088DBF6AAB0E1465D4B4C2748828AF5 2857022 ----a-w- C:\Users\Ivča\Downloads\vstudio10.exe
2014-09-30 17:44:57 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\Ivča\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-30 17:40:00 1B151CCE618BE06C22B55FD4B502B75E 1373475 ----a-w- C:\Users\Ivča\Desktop\adwcleaner_3.310.exe
2014-09-30 17:38:53 D9DE89F0FAF18019BC9595F0F47BCA61 50688 ----a-w- C:\Users\Ivča\Downloads\ATF-Cleaner.exe
2014-09-29 18:44:20 38F07D89C0DCB4826F508B78087215D8 34048 ----a-w- C:\Windows\System32\eEmpty.exe
2014-09-29 18:38:16 8834AD50E9FF20D72BA98F7D6A25D5F5 68866904 ----a-w- C:\Users\Ivča\Downloads\mwav.exe
2014-09-27 10:16:02 6CF617A12FB9B7169B6C69D328F63389 39975504 ----a-w- C:\Program Files\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\37.0.2062.124\37.0.2062.124_chrome_installer.exe
2014-09-25 12:41:45 CC127EE542BC41BFD7EB3CF6F6DBAA3B 697690 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\AC3 Filter\unins000.exe
2014-09-25 12:41:45 A6C9085DB29CEB92FA32D9EFBAB0471D 90112 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\AC3 Filter\spdif_test.exe
2014-09-25 12:41:45 8367988DC0585700CFA758F18A2EF1AC 87552 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\AC3 Filter\ac3config.exe
2014-09-25 12:41:37 AF4223C2577E752413784ECE83765354 137728 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\Haali media splitter\mkv2vfr.exe
2014-09-25 12:41:37 5DE59A417828FA4648D49EA0DAD6E5BE 358400 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\Haali media splitter\gdsmux.exe
2014-09-25 12:41:37 30AA0674FB6DA80F9480E11513D9661C 113152 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\Haali media splitter\dsmux.exe
2014-09-25 12:41:36 3C4D75D33CD2B3D53D0445C3594F881A 42305 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\Haali media splitter\uninstall.exe
2014-09-25 12:41:28 CF3CF034CFABA8AC68B6B502A1044F59 1175371 ----a-w- C:\Users\Ivča\AppData\Roaming\BSplayer\FFDShow\unins000.exe
2014-09-25 12:22:28 7CA4092A339EA30DE8FF06D3FF79D6ED 749648 ----a-w- C:\Program Files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\37.0.2062.124\37.0.2062.124_37.0.2062.120_chrome_updater.exe
=== C: other files ==
2014-10-01 12:25:14 DE0983FE4B830699312D35A990B3AE1B 1945 ----a-w- C:\Users\Ivča\AppData\Local\Temp\_MEI29842\resources\chrome_ext\nknebiagdodnminbdpflhpkgfpeijdbf_live.crx
2014-10-01 12:25:14 82F5C942549405F61A8808D0EA0FA9E2 25575 ----a-w- C:\Users\Ivča\AppData\Local\Temp\_MEI29842\resources\chrome_ext\apdfllckaahabafndbhieahigkjlhalf_live.crx
2014-09-30 21:57:51 A1965DFC0CD91E7CFC42925F8F597274 34808 ----a-w- C:\Windows\System32\drivers\TrueSight.sys
2014-09-30 21:27:33 E65FD31C267E8B8187F72E9F6B74882C 15127 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\get.bat
2014-09-30 21:27:33 DD1E4D974B1672ABD09EFFB225791C4A 1230 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\TDL4.bat
2014-09-30 21:27:33 C7B1E724E387DA744B894454AD44CB05 157105 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\misc.bat
2014-09-30 21:27:33 AD2F52DC72B10AF331692E4A4DD80DFC 18670 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\medfos.bat
2014-09-30 21:27:33 8E6020C14F982CF11B3FE7DBB0CB8EDE 24738 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\searchlnk.bat
2014-09-30 21:27:33 86707BCE5CBB65D9B1C41E249B4423BA 152733 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\firefox.bat
2014-09-30 21:27:33 83F691D8398F0E37E71E9355BF730DB9 719 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\ev_clear.bat
2014-09-30 21:27:33 654E9FE74B930A454EE5BDE165794B65 85 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\delorphans.bat
2014-09-30 21:27:33 5B71358F97544D9DE58A9A0893079506 39458 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\prelim.bat
2014-09-30 21:27:33 53B191266B30D57F2F835ABBF54C68C5 13963 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\chrome.bat
2014-09-30 21:27:33 4D80C7010E2CE44AB25FA25B013649E4 8085 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\mws.bat
2014-09-30 21:27:33 38A0BDF322ACCC968B0A824C38D50157 29635 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\ask.bat
2014-09-30 21:27:33 335DFF8F23E5EC02B5426362F0F8509B 31401 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\iexplore.bat
2014-09-30 21:27:33 2B588C39A2346DCD91B0F83244A39305 9542 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\runvalues.bat
2014-09-30 21:27:33 0C4649A62845AB5D5DBCC4998477FF6D 1813 ----a-w- C:\Users\Ivča\AppData\Local\Temp\jrt\delfolders.bat
2014-09-30 17:47:03 12E71DA845D76665B56753AD149E32B3 110296 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-09-30 17:46:32 BD27D97297934FD4217A37FD28A7ABC7 51928 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-09-30 17:46:32 8683C1B450F4B3872839308D836E0F92 23256 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-09-30 17:46:32 1AA835E8A0B8EDF3D676B4ED4BF5EF07 74456 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-09-29 18:49:52 C094918F834721D8150089B5BCAD2197 44517 ----a-w- C:\Users\Ivča\Documents\pinfect.zip
2014-09-29 09:47:19 7A1DD0ACAE667A54057192892E571F19 595074126 ----a-w- C:\Users\Ivča\Downloads\Irsko-2014.zip
2014-09-24 17:35:03 87A09EC6C719DCA4F01C78184D391DC1 62087763 ----a-w- C:\Users\Ivča\Desktop\školička\Voltametrie\231020132251.zip
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-1935359104-4094134921-1001328300-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\DTLite.exe -autorun"
"GoogleDriveSync"="C:\Program Files\Google\Drive\googledrivesync.exe /autostart"
"CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner.exe /MONITOR"
"RESTART_STICKY_NOTES"="C:\Windows\System32\StikyNot.exe"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe"
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\DTLite.exe -autorun"
"GoogleDriveSync"="C:\Program Files\Google\Drive\googledrivesync.exe /autostart"
"CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner.exe /MONITOR"
"RESTART_STICKY_NOTES"="C:\Windows\System32\StikyNot.exe"
==== Startup Folders ======================
==== Task Scheduler Jobs ======================
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [16.08.2014 22:29]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [16.08.2014 22:29]
==== Other Scheduled Tasks ======================
"C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\SmartDefrag_Startup" [C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe]
"C:\Windows\system32\tasks\{8F0D6EEB-1A2C-46FD-A239-72FC3E7C5924}" ["c:\program files\opera\opera.exe"]
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [15.09.2014 21:13]
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[16.08.2014 22:28]
Google Docs - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Last updated at time on date - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb
Google Search - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Google Wallet - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - IVA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Search Page"="http://www.google.com"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}"
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Empty IE Cache ======================
C:\Users\IVA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\IVA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
C:\Users\IVA~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=0 folders=0 0 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\IVA~1\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\IVA~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\IVA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
==== EOF on st 01.10.2014 at 15:03:13,05 ======================
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Platform: Windows 7 (WinNT 6.00.3504) ----- doinstaluj si SP1.
Co problémy?
Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu
Momentálně vše ok, ale při zapnutí mi neustále vyskakuje toto okno
Re: Prosím o kontrolu logu
a děkuji mockrát za pomoc
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Odinstaluj všechny emulátory virtuálních mechanik:
Stáhni si SPTD
Vyber verzi svého operačního systému (64 nebo 32bit). Ulož na plochu a spusť.
zvol možnost Uninstall a restartuj PC.
Stáhni a spusť Defogger
Klikni na "Disable" a restartuj PC.
Pak odinstaluj DT , použij Ccleaner.
a znova ho zkus nainstalovat.
Stáhni si SPTD
Vyber verzi svého operačního systému (64 nebo 32bit). Ulož na plochu a spusť.
zvol možnost Uninstall a restartuj PC.
Stáhni a spusť Defogger
Klikni na "Disable" a restartuj PC.
Pak odinstaluj DT , použij Ccleaner.
a znova ho zkus nainstalovat.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu
Co znamená zkratka DT?:-)
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Daemon Tools
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu
Akorát tenhle program instalovaný nemám, jen mi s nim vyskakuje okno při zapnutí
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Píšu , aby si to přeinstaloval., nebo to je lite? Bez instalace?
hlavně doinstaluj ten service pack1.
hlavně doinstaluj ten service pack1.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu
service pack1 jsem doinstalovala, už mi to neblbne, tak děkuji mockrát za pomoc 

- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Stáhni si zde DelFix
ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci
Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci
Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 100 hostů