Zoek.exe v5.0.0.0 Updated 20-September-2014
Tool run by Martin on so 11.10.2014 at 11:52:12,07.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\Martin\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
11.10.2014 11:55:07 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1049051548-3391704481-1815163041-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32004B8A-44A9-43E7-84E9-808838809519} deleted successfully
HKEY_USERS\S-1-5-21-1049051548-3391704481-1815163041-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5CF4A951-78FA-414F-9F3F-846FE5644384} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{1283E7D0-B598-4B2D-A20F-59A9DDE270A8} deleted successfully
HKEY_USERS\S-1-5-21-1049051548-3391704481-1815163041-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{1283E7D0-B598-4B2D-A20F-59A9DDE270A8} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\aqr23xqi.default\prefs.js:
user_pref("browser.startup.homepage", "http://go.microsoft.com/fwlink/?LinkId=69157");
user_pref("browser.search.defaultengine", "Ask Search");
user_pref("browser.search.order.1", "Ask Search");
user_pref("extensions.APN_TB.first-previous-keyword-url", "");
user_pref("extensions.ORJ-V7.my-keyword-url", "\"\"");
user_pref("extensions.ORJ-V7.previous-keyword-url", "\"\"");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\aqr23xqi.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("extensions.APN_TB.first-previous-keyword-url", "");
user_pref("extensions.ORJ-V7.my-keyword-url", "\"\"");
user_pref("extensions.ORJ-V7.previous-keyword-url", "\"\"");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Lenka\AppData\Roaming\Mozilla\Firefox\Profiles\upkt3dc2.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.seznam.cz/|http://www.facebook.com/home.php");
user_pref("browser.search.defaultenginename", "WebHledani");
user_pref("browser.search.selectedEngine", "WebHledani");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Lenka\AppData\Roaming\Mozilla\Firefox\Profiles\upkt3dc2.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Martin\AppData\Roaming\Broad Intelligence\MediaCoder\Profiles\hq6e0f1b.default\prefs.js:
Added to C:\Users\Martin\AppData\Roaming\Broad Intelligence\MediaCoder\Profiles\hq6e0f1b.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js:
Added to C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\zyyvk1yd.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.search.defaultengine", "");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "");
user_pref("extensions.APN_TB.first-previous-keyword-url", "");
user_pref("extensions.ORJ-V7.my-keyword-url", "\"\"");
user_pref("extensions.ORJ-V7.previous-keyword-url", "\"\"");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\zyyvk1yd.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("extensions.APN_TB.first-previous-keyword-url", "");
user_pref("extensions.ORJ-V7.my-keyword-url", "\"\"");
user_pref("extensions.ORJ-V7.previous-keyword-url", "\"\"");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\MIKAKI~1\AppData\Roaming\Mozilla\Firefox\Profiles\xb30wj5b.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.idnes.cz/|http://atlas.centrum.cz/|http://www.seznam.cz/|http://web.volny.cz/");
user_pref("browser.search.defaultenginename", "Bing ");
user_pref("browser.search.selectedEngine", "Bing ");
user_pref("browser.search.order.1", "Ask Search");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\MIKAKI~1\AppData\Roaming\Mozilla\Firefox\Profiles\xb30wj5b.default\prefs.js:
ProfilePath: C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\aqr23xqi.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_11.10.2014_1216_.backup
ProfilePath: C:\Users\Lenka\AppData\Roaming\Mozilla\Firefox\Profiles\upkt3dc2.default
user.js not found
---- Lines {336D0C35-8A85-403a-B9D2-65C292C39087} removed from prefs.js ----
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.extensionFirstRun", false);
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.lastExtensionVersion", "2.0.0.474");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_installer_name", "sg_6OyKpkD212_active_MB179_MB180_UA-25323614-19_2012-08-08-14-51-30");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_product_name", "Web Assistant");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_product_version", "2.0.0.474");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_temp_installer_name", "sg_6OyKpkD212_active_MB179_MB180_UA-25323614-19_2012-08-08-14-51-3
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_toolbarID", "149ebe71bd864a5c850d4a23ee1c3095");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_dailyPing", "true|||1357138395656");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_debugMode", "not set");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_dialogVersion", "not set");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_gtQueryParam", "UA-25323614-19");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_inactive_by_user", "not set");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_installedPing", "true|||8641346222653196");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_lastUpdate", "1357051995464|||8641357051995465");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_redirectQueryParam1", "MB179");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_redirectQueryParam2", "MB180");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_showDialog", "not set");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_showtoaster", "not set");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_status", "active");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_toasterID", "not set");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_toolbar_query", "not set");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_upn2", "6OyKpkD212");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.setdefaultsearch_2.0.0.474", false);
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.setdnscatch_2.0.0.413", false);
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.setdnscatch_2.0.0.474", false);
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.sethomepage_2.0.0.474", false);
---- FireFox user.js and prefs.js backups ----
prefs_11.10.2014_1216_.backup
ProfilePath: C:\Users\Martin\AppData\Roaming\Broad Intelligence\MediaCoder\Profiles\hq6e0f1b.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_11.10.2014_1216_.backup
ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\0
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_11.10.2014_1216_.backup
ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\zyyvk1yd.default
user.js not found
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 0);
---- FireFox user.js and prefs.js backups ----
prefs_11.10.2014_1216_.backup
ProfilePath: C:\Users\MIKAKI~1\AppData\Roaming\Mozilla\Firefox\Profiles\xb30wj5b.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_11.10.2014_1216_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted
C:\PROGRA~3\{3155EF3F-3778-4C4C-B0F3-3E48423B8965} deleted
C:\PROGRA~3\{32364CEA-7855-4A3C-B674-53D8E9B97936} deleted
C:\PROGRA~3\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F} deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\autoconfig.js deleted
C:\PROGRA~2\SopCast deleted
C:\Odinstalovat produkt.exe deleted
C:\Users\Martin\AppData\Roaming\All CPU MeterV3_Settings.ini deleted
C:\Users\Martin\AppData\Roaming\GPU MeterV2_Settings.ini deleted
C:\Users\Martin\AppData\Roaming\Network Meter_Usage.ini deleted
C:\PROGRA~3\boost_interprocess deleted
C:\PROGRA~3\ICQ deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Martin\AppData\Local\BIT5428.tmp deleted
C:\Users\Martin\AppData\Local\cache deleted
C:\Users\Martin\AppData\Local\CrashRpt deleted
C:\Users\MIKAKI~1\AppData\Local\BIT1BEA.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BIT4D76.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BIT4F3B.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BIT4F79.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BIT568B.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BIT5C57.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BIT6C4C.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BIT6F37.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BIT8C4B.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BIT9867.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BIT9B47.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BITA120.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BITA574.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BITB404.tmp deleted
C:\Users\MIKAKI~1\AppData\Local\BITC2E1.tmp deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG SafeGuard toolbar deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Security Toolbar deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Vuze_Remote deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\PriceGong deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Conduit deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\ConduitEngine deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\zyyvk1yd.default\CT2269050 deleted
C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\zyyvk1yd.default\CT3065462 deleted
C:\Users\MIKAKI~1\AppData\Roaming\Mozilla\Firefox\Profiles\xb30wj5b.default\searchplugins\aol-search.xml deleted
"C:\Windows\Installer\76e6ff.msi" deleted
"C:\Users\Martin\AppData\Local\LumaEmu" deleted
"C:\ProgramData\Application Support" deleted
"C:\ProgramData\Authentication" deleted
"C:\ProgramData\Automatic Filter" deleted
"C:\ProgramData\Automator" deleted
"C:\ProgramData\Brother" deleted
"C:\ProgramData\Bundle" deleted
"C:\ProgramData\CMMs" deleted
"C:\ProgramData\Configure Folder Actions" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{F003DA68-8256-4b37-A6C4-350FA04494DF}"="C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt" [02.08.2014 13:27]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\aqr23xqi.default
- Undetermined - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.7.598
- Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
ProfilePath: C:\Users\Lenka\AppData\Roaming\Mozilla\Firefox\Profiles\upkt3dc2.default
- Undetermined - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.7.598
- Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
- Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\zyyvk1yd.default
- Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
ProfilePath: C:\Users\MIKAKI~1\AppData\Roaming\Mozilla\Firefox\Profiles\xb30wj5b.default
- Undetermined - C:\Users\Miškařík Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\xb30wj5b.default\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a16}
- Undetermined - C:\Users\Miškařík Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\xb30wj5b.default\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a17}
- Undetermined - C:\Users\Miškařík Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\xb30wj5b.default\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a18}
- Undetermined - C:\Users\Miškařík Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\xb30wj5b.default\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a19}
- Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
- Ovi maps browser plugin - %ProfilePath%\extensions\maps@ovi.com
- Firefox Synchronisation Extension - %ProfilePath%\extensions\synchronize@nokia.suite
- Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
- Stylish Profile - %ProfilePath%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA80}
- QAssistant - %ProfilePath%\extensions\{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
- 7645f4b1-1f19-13dd-2d6b-0200600c2a56 - %ProfilePath%\extensions\{7645f4b1-1f19-13dd-2d6b-0200600c2a56}
- 8675f4b3-2f19-11ed-2d6b-0800600c0a16 - %ProfilePath%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a16}
- 8675f4b3-2f19-11ed-2d6b-0800600c0a17 - %ProfilePath%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a17}
- 8675f4b3-2f19-11ed-2d6b-0800600c0a18 - %ProfilePath%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a18}
- 8675f4b3-2f19-11ed-2d6b-0800600c0a19 - %ProfilePath%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a19}
- Usage Stat - %ProfilePath%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA96}.xpi
- VFT Flv - %ProfilePath%\extensions\{8675f4b3-2f19-11ed-2d6b-1823600c0a19}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\zyyvk1yd.default
DFC9460CC37E5C414DC4680B10C19E7A - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll - Shockwave Flash
0CA4180B21C6B728578F3B0433BB740E - C:\Martin\PROGRAMY\VLC\npvlc.dll - VLC Web Plugin
9297A960E3DA318A1D0832375EC37953 - C:\Users\Martin\AppData\Roaming\ACEStream\player\npace_plugin.dll - Ace Stream P2P Multimedia Plug-in
0E8B2D0D9E3415A91EF259CE1112C579 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll - Shockwave for Director / Shockwave for Director
A64F2C388DC26BE3E469EDC3657B14F4 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll - RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit)
C45F7E59F2A0A6D3C4E90117F4752414 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll - RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit)
F7AEAD4303A056F2D1685B43024776CA - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll - RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit)
FA0A3008589567CB7196620B05C9F28D - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll - RealDownloader Plugin
AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[16.04.2013 03:11]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx[17.01.2012 12:45]
ochbjojkpcmlfeagbaahkofepalngihg - No path found[]
RealDownloader - Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji
AT_Rampage_v2 - Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\cknkimpcfkpmmikggddpidpmaljigegp
Skype Click to Call - Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
AdBlock - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
RealDownloader - MIKAKI~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji
==== Chromium Startpages ======================
C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.google.com",
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Reset Google Chrome ======================
C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\MIKAKI~1\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A8640317F35F8964C8903A93AEB3506E deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acerportal.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acpanel_win.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adobe air application installer.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccleaner64.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gpcl.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\live update.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsu3ui.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pmbbrowser.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pmbinit.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\realconverter.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\realplay.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\realtrimmer.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rnxproc.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\skype.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\teamviewer.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tunngle.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\unins000.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninst.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ochbjojkpcmlfeagbaahkofepalngihg deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7130468A-F53F-4698-8C09-A339EA3B05E6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A8640317F35F8964C8903A93AEB3506E deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\MIKAKI~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=505 folders=117 48595074 bytes)
==== Empty Temp Folders ======================
C:\Users\AppData\AppData\Local\temp emptied successfully
C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Eva\AppData\Local\temp emptied successfully
C:\Users\Guest\AppData\Local\temp emptied successfully
C:\Users\Lenka\AppData\Local\temp emptied successfully
C:\Users\Martin\AppData\Local\Temp will be emptied at reboot
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Users\TEMP\AppData\Local\temp emptied successfully
C:\Users\MIKAKI~1\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
Prosím o kontrolu logu - zpomalené PC Vyřešeno
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu - zpomalené PC
Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu - zpomalené PC Vyřešeno
Už je to ok díky moc 

Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 110 hostů