vyskak. oken, reklam, spojeno s detekcí škodlivostí Avastem Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Budkyns
Level 2.5
Level 2.5
Příspěvky: 252
Registrován: srpen 09
Pohlaví: Nespecifikováno
Stav:
Offline

Re: vyskak. oken, reklam, spojeno s detekcí škodlivostí Avas

Příspěvekod Budkyns » 28 čer 2015 18:48

HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D0F01C7A-D51C-4F48-9CBB-868EDE8195EF} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D12B6A8A-6C7D-4B02-9F71-EB904E1D172C} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1D4CDB8-470C-48E7-80B2-9F7DDCC20E4} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D2A29C1E-4509-4697-8956-B6254733CC7} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D2C6410-4A7E-4957-AF96-E342E4BECCC1} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D2FE29C5-FB75-4A37-843D-2FA8F3FB5517} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D30CC1A3-3543-4A11-9C71-DA392207566} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D3369F00-2F3D-49C2-8E1E-58C7D12566E} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D354A6BC-2A7-49E9-9748-CDAC947525A3} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D36CB150-F2E5-4BF4-BFBC-7D5CC53629B6} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D3E18D47-FDCF-4AAA-83F5-4A711CE18DFF} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D3FB815F-6-4A10-A569-B077ABE77666} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D41A6B56-EAD-46E2-A7F7-BB77821A1FE7} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D46009F5-299E-4FA6-AA56-7F7E52D51C5} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D4828592-7F84-485A-AF5B-7178A1E6B64B} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D4A74DA5-68B4-4841-BA69-574245637E65} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D4E6790A-E32-4E1F-85C5-B5C05857CF6} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D500565A-6400-4AB2-B04D-60E6A9B85CDD} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5B96FF0-67F1-4FB5-89FD-B4BF3394F} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5EFE1B8-CA79-4C55-B54-C2BD8EDABC36} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6027982-E144-484D-AEC1-9EF29296CEB3} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6207E61-3CE8-4357-9E6C-D32BC750C824} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D62F5CD7-EF51-4564-AA12-90FCB92521B6} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D648670E-955C-474B-80C5-78DE8F3C99} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D66DB3FE-976A-4DD5-8DFE-C0854A241BB8} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D685F6D0-2433-4808-B1AB-B99B7DC4FF95} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D699FA20-9EC0-4EA3-AA9-CDA48B79FE8B} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6C2892F-ADC6-4C97-98D5-E5FF4122A75} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6FE645B-4AA-48D8-B33E-4096A567701A} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D765BDE5-B8DA-4CAC-870-F176C73410} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D790B58A-9CC6-44B4-8FDC-79A2EA91C22} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7B5BEE7-8803-4BDE-AE5E-64F516C8D9D7} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D81A91BF-591E-40B1-AF87-41EAC342757E} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D83DE6C9-5C6-485F-8D3C-6E482D5024B1} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D8646063-984F-4106-84DE-5B369965AEE0} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D88E3E5-28DB-4FC5-B0A7-58A1D2BF6F7C} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D8A79C4E-473F-4C67-AE49-E3ABD3E94E37} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D8B261B6-26FE-4117-B371-68D0A2DD2B39} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D8D99EE-220C-49F9-92F2-79EC29C6472} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D8EEAF66-44C1-4902-A6CB-91FEE04836C3} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D8EEB86-8B93-4A71-A2BC-6D84E968F5} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DA20B5E4-3D08-4FFF-8BD4-CBE3BD83BF64} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DA9EE151-F716-4145-B76B-3E5880D0EB12} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB5D725E-25C7-42CC-A0C4-E3AC1AAA70} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB8772C6-AB3-40A8-8256-8D6814AC254C} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB8F71B9-9F63-48F3-921A-D586618541E} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DBA3C433-1E13-41B4-B3FE-81E3CE9171D9} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DBD2B2F5-9E61-4C91-AF18-712B8112C69} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DBF9446B-8194-47BE-A67-C26C33E1C039} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DC0F4C15-FD8F-4B48-BC8D-F9CDF8E6D1A} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DC2B2090-43AD-421D-8BAD-E76E86FF5C30} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DC482C9F-F0C7-49B0-9CDD-B64D14CC6678} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DC4959C4-74A0-4835-A560-56888FAB201} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DC8673CA-8D98-4AB9-9FD9-5985F6E2EC} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DCA6E761-9F9C-43D9-95A8-6483F33E8E7} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DCD90853-F6F5-4118-98F9-3506E5522EB} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD280EF3-B113-4C97-A539-CBCCB138BB5} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD82E356-5B53-49A5-81B0-39ABD41B2025} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD843582-C6A4-4555-B9B1-BF521F8DA87} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD95BEC2-8BC2-4AAE-899-6E9E777105B} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDA7D791-DF0E-45F8-B7D7-4FF33FFE82FD} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDCF98D4-B1C9-4B4B-9B5B-1CD0523CA9} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDF6AE74-C483-4E9C-B2EF-229DAD1EF6CF} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE4C7253-9415-4F89-A113-6442CF07F60} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE57ECAC-6EB9-4408-82C-2F6AF2DF223C} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE7A9E36-11EA-4098-AD8-43FC1A495B59} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DEA725CF-4D3E-47DB-BEA9-6BF1BFA42D2E} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DEAC06DE-7476-4492-994F-8BB1402BAB58} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DEBB4B2D-405E-44F4-8DF-E7B1C7A3AC6D} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DF5B61CB-D3BC-4064-B4F1-8814A09D40BF} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DFBA90EB-36EA-406B-BA3D-47A79D78A0D} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DFD18661-4A7C-426D-816A-71DA15E5EB9} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E007A88E-9DC8-4BAC-BCD9-3D4FE64B34C9} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E01330E7-EF4-4643-8DA3-C125964D8AB2} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0281CA5-8144-47C9-BEE7-2245A1C23C7} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0344B85-A47A-4E4B-BFE4-78A7DAD9B7E} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0D7A66C-10BA-4951-9AE0-129EF9E1ACD5} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0DD29E6-D661-46AC-BB3F-5BD01A567E3} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E15D63A8-7D2-48E0-BD4-3A4BFB99EF2} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E1924FEB-A849-4430-84A6-15118382315} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E24DD634-F926-4CCB-AC94-33865B49D1C2} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E27CD3D9-C38B-43EC-8CD9-F6544C524B75} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E27FB61C-E49C-4BF5-B23D-6475C98110} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E2945632-B0F0-433A-9D35-294325C37F1} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E2E932AC-CDFE-483E-BBAC-1047579A12F0} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E3151CB3-1E21-4677-BA4A-38953AF24E6C} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E32FC408-99FF-4882-A57-9EBA3CD9864E} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E36AD0B1-8CB3-4ADF-8A7-7E754B2B5834} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E390C7F8-A88C-4F55-A5E4-F09695F8386} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E3D4F3C2-D19E-4F4E-96FF-94F69F1A8A2} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E3FCED36-E67F-4138-89BA-E5357860538} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E43DD376-AB08-4EEB-BB2A-BDF2413A57FF} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E44DF465-C9A8-4D0A-89C7-6964ED8B2BF} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E469078A-95AC-4CFA-8F44-635B72732F7} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E4F07E5-1984-4898-9161-B2B8CC3AFC38} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E516CDD2-F0A8-4013-BC9B-D56F98A672} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E51EB4DD-60C6-4850-A5A1-9C5025AEA737} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E5679152-EB58-4BA1-8726-4F27E9692E3A} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E5A2FE0F-88BA-45FA-9637-25A9E8E877C4} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E5C836D9-6A18-4B38-ABEA-998622AA80D6} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E5DC52D5-8358-43A2-9DF7-CBDEB2552A8} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6377CE5-C43D-433F-BE16-EE55756A096} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E645891E-3E3E-4175-9349-4512617EAB} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E687563B-2E1C-475A-8717-8A3D90558FC} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6C47496-76DB-45E4-A49D-9727DB5C9EB} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E71395B7-E6A9-44C6-B5F0-BF9E6EE7969} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E71C5D52-2A23-4219-8FF6-14359179AFDA} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E730B56C-9512-4009-9F1F-74BC83642CC} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E773349C-7D0-4949-80E-AB951479B1D1} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E773A4D8-5D44-4530-BB95-C4954175B98B} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7BCE2F9-C874-43DE-B271-AD5EA1E98A1} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E899F54A-C9E-4D6B-A6B5-795275D1D39} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E8F9A5-3E22-4A52-BA2A-6A4F2D378C8E} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E9179510-22E-436F-AA57-C4D5CF19DD26} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E92B2F0-5F3-4563-8B80-7452282DB567} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E99B351E-16F1-4D5F-91C0-A2746774F7AA} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E9A8CA-81E2-4819-B19C-7741DF788CB} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA3B5CF0-E63F-4426-8DFE-AD4C5EAFF5F1} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA4FA937-C582-4A32-BF76-701A2BEF3BBE} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA803D3-EDD-4CF1-BECD-875912932D31} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EAAF4D82-50A5-4ED5-8A52-4A8C501C24} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EAD05F78-8A86-4B2F-BA54-90954778EFE} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EB072E8-6F7E-4E6B-8E1C-BA3EE2C1B336} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EB8D0A7A-1604-4249-BB2A-F4E0F7BEBBB} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EB8FB0C9-C470-4ECF-B92C-C75494387936} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EBBF9A1F-10EB-4583-9DA3-88AB8E4224D1} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EBE238B9-4E16-4878-9082-11FDA9B3424} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC3664CD-DE34-460A-B6DF-311B11EF9D8} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC7EC385-A532-42F6-8B6-2E3AB8C764DE} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC80B1E-58F6-45D2-8A59-8CA9AED99155} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC98DD92-1195-4FFC-917F-BDDF7B3484E3} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC9C5B66-A344-4DFF-93AA-83CF70B7F24} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC9DD240-A074-4AA5-B3EC-269F5F322330} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ECA06B2E-DC0C-4A75-BAC-ACF413C7990} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ECA1C85E-377E-4215-AE57-EF9F55A47366} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ECBCBFDD-49B-4E66-B858-D1FA67E8BB8} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ED5D3BE9-606C-4A3D-A795-96D7CAD4591A} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ED7D263-88E6-483D-91BD-7893D9A253A5} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ED80B6C2-5BE8-4186-AC83-7C697B1131CD} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ED8C5B14-B5D6-4D00-B749-401CA84D3A4C} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ED90576F-AFD3-45D7-8DB4-9D1DF713FCE} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDF24220-9A1D-4813-A5B0-728BADC423B} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDF5F807-B16D-43D1-892D-BDB54F49AB7A} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE68A1B1-32B8-4F8C-8559-C824BB67B0C3} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE9CF037-442F-4342-ACDA-282AFA2E45C2} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EECA16D3-5E8-4BB2-9C8-FFD21D35CCBE} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EECB6029-ABDE-4B80-9DA5-6E7EFCA0DB1E} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEDEC9C-A05B-45F3-B7FA-CEF8896B15B} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EF52FED8-E166-4DDA-8BC0-97C71B79962} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EF530953-A1C6-48D7-866F-A883728C24B0} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EF5539C9-705B-432D-9A35-9C6D619B8C} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFFBFDC2-9583-436F-9D5D-E6D23CD44219} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F01320ED-EEB8-48E4-AA8-8BA2D33047B5} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F030F0CB-D747-4874-9A7A-76B5E4E08C8F} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F04633F9-2E00-428B-B4AA-6B4C5925EB0} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F06FB5D1-13D6-4851-A6E0-92AA2FA4753} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F0730438-F6A3-446B-8C82-3270867EEF7} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F07E928A-5A90-4ABF-80A-3234DDB23977} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F08C26A6-E82D-40E3-BE67-43CE617FE55F} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F0962796-E78-494A-94EE-E0E2B772BC5C} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F0A77FBE-5E3B-47E3-8BE3-35EAB6139BF7} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F0BC302A-3D0B-4A95-9E6-4873592D232D} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F0E01BEA-2B5C-423B-98D0-5EC587D384A6} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F10774B-F0B6-4FDC-B85C-CBFC6316E43} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F15575B1-863-4E46-BA0-B190A25A64A} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F17E5E5E-941B-4076-8112-38C3C98A3EA} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F187053B-E9EC-4DC5-945C-B3FB75F49C91} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F1D76D36-1BC8-4F47-A35C-57BA74B27615} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F205AEB6-B56E-4E81-B38E-A259A7240B2} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F20CCE88-ECBF-4351-BB83-477218D5DC6} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F2E4314D-D4C2-4A86-9A4D-CB6EEFCFD044} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F304063B-1CAF-433E-BD8-1EE1C571159E} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F31F8D52-2C53-4881-99AF-472155A591} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F390D6DE-1148-4A7E-A8F-9E43C223691} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F395256A-F8C8-460D-A0CE-ABB14392742B} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F45718D2-AAEE-4019-804-68B0586B532} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4585DB-6489-4907-B6C0-F7656589F5E3} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F46275F0-7508-407F-A62B-374FA1EB1AAD} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4B7E146-A9-452A-BB51-EF862DE0E353} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4BEA692-3D03-4ABB-A5E6-4CA583FA9C89} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F52EB1B8-CE97-4B77-BF4B-FF2F8484F69} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F598A9BD-2EDE-4480-B3E7-20F957E917A5} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F5A07426-3BBF-4A9E-9B20-1943B689EFE} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F5A8DFBA-7423-4D28-BCD4-29488F23D17} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F5B47A6C-4D5E-47FD-AF4F-9F8F93FF877} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F5CF4F49-32DC-4B2F-BCC3-9E98A0AA29B5} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F5E72BDB-8F05-4C45-84BE-57E31F284D97} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F5EF4C30-8A1D-4AFF-B187-A65838B12A2A} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F5FD0164-BA04-43A8-BFB9-3C2729D973F3} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F61CED35-617D-4591-9A2B-486C8B1DD7B2} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F629651E-B6ED-4C16-BA6F-D1FCD99FB48E} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F6B6293F-C25F-4787-893E-AF2F6DAFDE16} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F6B9AD59-CAB6-4404-B463-CBBED9B9C7D0} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F6DE83FA-BEEC-44DB-981C-8225B11614FF} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F6FC4773-884B-454B-B48-147D35F4BD4} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F71D916-5EAA-4C9F-976D-3ECB13A12D5A} deleted successfully

Reklama
Budkyns
Level 2.5
Level 2.5
Příspěvky: 252
Registrován: srpen 09
Pohlaví: Nespecifikováno
Stav:
Offline

Re: vyskak. oken, reklam, spojeno s detekcí škodlivostí Avas

Příspěvekod Budkyns » 28 čer 2015 18:49

HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F72E937A-CF21-4692-92C0-D326CDF7613C} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F73DBBC3-DA7D-4BEE-B160-796CE691620} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F7CF2997-9EA7-4BA8-9355-B6BCD831F7} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F830B833-D357-46C2-9BD9-987B1194F074} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F8407E61-A4EF-4E1F-B6A-CBC0C2C039AC} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F851DA85-144A-4C27-8526-4B2A5A903BA8} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F89044F5-D0B2-4BEB-9B33-EEDFC8131F59} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F8925A2-75C3-46B1-B6E6-375D51156F8} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F8A2B631-D40-4F3C-8EC2-94B591A74A80} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F8F340A7-2591-4C5E-883A-84493608AE8} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F90B495-3694-471A-8AEE-ED3ECD3E229} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F918D62-891A-4721-9722-3DF313506B90} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F950F737-4226-4960-B61D-BD754D133B3A} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9538DA9-A197-4725-8BD7-ACFCB990DC} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F970757-9797-4C38-BE5D-5D59D541249E} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9EAF690-F84A-4BE0-8D53-EF4B6E38371} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA16B946-12A0-4FAA-A1FA-18634C4C89CA} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FB9F85A2-B433-4572-AC7B-1AA687DB8} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FBB821D6-9F30-45BF-B14E-1213BA6B2CE0} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FC111A10-F906-4F12-A70-4F5A972D374C} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FC1A4080-F0C2-4216-B30-7FBF6BD27EC1} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FC2A00CA-2270-4315-B255-6D855369AD4} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FC5BC11A-3278-4D44-97BF-3143AEA2479} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FCA355E7-EC5B-4351-A6C-A65D6381B164} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FCABA8BD-1ACF-4971-BE40-53B3AA84711} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FCE9E68C-9170-4A6D-8748-5D3581F26D38} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FD0D0E73-BF49-44DF-BD59-34CEAF429042} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FD25EADE-D216-45BA-B9A1-EAEBE6455C7} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FD835A3F-B333-408E-BEBB-65D9F8D0E2FF} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FD96B5B8-5215-4616-89B9-95BA7782E52} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FDC17B8B-2BA7-4D04-A862-CC1C1F6BD5E} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE82A689-6E27-4B90-B1A6-529FCB1BB88} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE84ABD9-EBD9-4C1E-9C30-1E41BF21EB5} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE856A18-1AF9-429C-8AE6-31AD9898A877} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE8F18C9-8181-4F88-AAE1-C282BDC8A4B} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FEA8A4F-4303-4D31-971F-5DC26C87981C} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FECA8DE-189E-443C-82BC-B1F2712B1871} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FEFD2689-82AE-4FC6-A3AD-8147CAA6D19} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FF09DB62-897F-4D5C-93D1-77EC23C6666C} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FF43CD27-AB31-4F64-9EDC-437087064B9} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FF7A7B7F-8B5F-4EF1-AA7E-918D19682C2} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FF86FBD9-C2F8-4946-8735-583B5D72ECA} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFF0AC16-2F12-47B2-89A5-87A31254D448} deleted successfully
HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFF8594-4DA6-421D-9E1A-14EA1F99FB73} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{23b36184-5e9a-43d2-9581-011e3e4f0439} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.com/?trackid=sp-006");
user_pref("browser.search.defaulturl", "https://www.google.com/search/?trackid=sp-006");
user_pref("browser.search.defaultengine", "Google (avast)");
user_pref("browser.search.selectedEngine", "Google (avast)");
user_pref("browser.search.order.1", "Google (avast)");
user_pref("keyword.URL", "https://www.google.com/search/?trackid=sp-006");

Added to C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default

user.js not found
---- Lines aBMNEMEGJ50257956NMROOPQ94813992com61859 removed from prefs.js ----
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.active", true);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.addressbar", "NA");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.addressbarenhanced", "");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.asyncdb.was_copied", "true");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.asyncinternaldb.was_copied", "true");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.backgroundver", 2);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.BMNEMEGJ50257956@NMROOPQ94813992.comaBMNEMEGJ50257956NMROOPQ94813992com61859_dbWa
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.BMNEMEGJ50257956@NMROOPQ94813992.comaBMNEMEGJ50257956NMROOPQ94813992com61859_dbWa
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.BMNEMEGJ50257956@NMROOPQ94813992.comasyncdb_dbWasSet", true);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.BMNEMEGJ50257956@NMROOPQ94813992.comasyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.BMNEMEGJ50257956@NMROOPQ94813992.comasyncinternaldb_dbWasSet", true);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.BMNEMEGJ50257956@NMROOPQ94813992.comasyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.certdomaininstaller", "");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.au.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.au.value", "%222015-2-4%22");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.cnt.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.cnt.value", "%22CZ%22");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.first_run.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.first_run.value", "%221%22");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.install.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.install.value", "%222014-9-15%22");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.InstallationTime.value", "%221407324158%22");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.InstallerParams.value", "%7B%22source_id%22%3A%22001825%22%2C%22sub_id%22%
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.isEnabled.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.isEnabled.value", "%221%22");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.mt_dte.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.mt_dte.value", "4");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.mtLimit.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.mtLimit.value", "1");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.pstm.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.pstm.value", "1423009936015");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.testingGaq.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.cookie.testingGaq.value", "%22http%3A//extclickmedia-maynemyltf.netdna-ssl.com/Ex
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.description", "Images Zoom Extension");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.domain", "");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.enablesearch", false);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.homepage", "");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.changeprevious", false);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.iframe", false);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.InstallationThankYouPage", true);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.InstallationTime", 1407324158);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.__defualt_browser__.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.__defualt_browser__.value", "%22ch%22");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb._installer_additional_info.expiration", "Fri Feb 01 2030 00:00:00 GMT+
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb._installer_additional_info.value", "%7B%22asw%22%3A%5B1%2C-2139094715%
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100")
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%224ABA506197FD
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.InstallerParams.value", "%7B%22source_id%22%3A%22001825%22%2C%22sub_id
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100")
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A%22001825%22%2C%22s
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb 01 2030 00:00:00 G
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.InstallerUserIdentifiersCache.value", "%7B%22installer_bic%22%3A%224AB
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.monetization_plugin_bundledUrls.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.monetization_plugin_bundledWithHash.expiration", "Fri Feb 01 2030 00:0
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.monetization_plugin_bundledWithHash.value", "null");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.monetization_plugin_notBundledArr_.expiration", "Fri Feb 01 2030 00:00
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.monetization_plugin_notBundledArr_.value", "%5B%5D");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.monetization_plugin_regBundledWithSoftware.expiration", "Fri Feb 01 20
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.monetization_plugin_regBundledWithSoftware.value", "%7B%7D");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.reporting_user_key.expiration", "Tue Dec 31 2024 00:43:04 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.reporting_user_key.value", "false");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.reporting_user_key_index.expiration", "Sun Jan 12 2025 21:05:42 GMT+01
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.reporting_user_key_index.value", "685");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.Resources_appVer.value", "82");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.Resources_nextCheck.expiration", "Wed Feb 04 2015 07:31:18 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.Resources_remote_resources.expiration", "Fri Feb 01 2030 00:00:00 GMT+
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.internaldb.Resources_remote_resources.value", "%7B%22remoteId%22%3A0%7D");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.lastDailyReport", "1423009874880");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.lastUpdate", "1423009875416");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.manifesturl", "");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.newtab", "");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.opensearch", "");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.pluginsurl", "http://js.ourdatagenserv.com/plugin/apps/61859/plugins/na/ff/plugin
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.pluginsversion", 77);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.publisher", "Joseph CM");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.searchstatus", 0);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.setnewtab", false);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.thankyou", "");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.updateinterval", 360);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.61859.ver", 82);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.apps", "61859");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.bic", "1487a967415290d6a314f43ef1961034");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.cid", 61859);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.firstrun", false);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.hadappinstalled", true);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.installationdate", 1410805954);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.installerAdditionalInfo", "{\"asw\":[1, -2139094715, 536870912]}");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.modetype", "production");
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.reportInstall", true);
user_pref("extensions.aBMNEMEGJ50257956NMROOPQ94813992com61859.statsDailyCounter", 68);
---- FireFox user.js and prefs.js backups ----

prefs_201528.06._1828_.backup

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Amazon not found
C:\PROGRA~2\URUSoft not found
C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\windows\SysNative\Tasks\avastBCLRestartS-1-5-21-4138806220-3288153000-4149962190-1005 deleted
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Web TuneUp deleted
C:\WINDOWS\tasks\0215tb_RML.job deleted
C:\windows\SysNative\tasks\0215tb_RML deleted
C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default\jetpack deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [30. 01. 2015 18:06]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default
- autotranslatorkobayashich - %ProfilePath%\extensions\autotranslator@kobayashi.ch
- b9acf540acba11e18ccb001fd0e08bd4 - %ProfilePath%\extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default
DFC9460CC37E5C414DC4680B10C19E7A - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll - Shockwave Flash
3CD19649B2C3023D65E67C056457A2BC - C:\Users\Bodlinka\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin
71B61A08992B0F895288CAAB2B43E3F7 - C:\Users\Bodlinka\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
eofcbnmajmjmplflapaojjnihcjkigck - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx[17. 12. 2014 18:32]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[17. 12. 2014 18:32]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[01. 05. 2015 11:17]

Avast SafePrice - Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
AdBlock - Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Avast Online Security - Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Skype Click to Call - Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl

Budkyns
Level 2.5
Level 2.5
Příspěvky: 252
Registrován: srpen 09
Pohlaví: Nespecifikováno
Stav:
Offline

Re: vyskak. oken, reklam, spojeno s detekcí škodlivostí Avas

Příspěvekod Budkyns » 28 čer 2015 18:49

==== Chromium Startpages ======================

C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Preferences
dll","version":""},{"enabled":true,"name":"Chrome PDF Viewer","path":"C:\\Users\\Bodlinka\\AppData\\Local\\Google\\Chrome\\Application\\43.0.2357.130\\pdf.dll","version":""},{"enabled":true,"name":"Intel® Identity Protection Technology","path":"C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\IPT\\npIntelWebAPIIPT.dll","version":"2.1.42.0"},{"enabled":true,"name":"Intel® Identity Protection Technology","path":"C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\IPT\\npIntelWebAPIUpdater.dll","version":"2.1.42.0"},{"enabled":true,"name":"Google Update","path":"C:\\Users\\Bodlinka\\AppData\\Local\\Google\\Update\\1.2.183.39\\npGoogleOneClick8.dll","version":"1.2.183.39"},{"enabled":true,"name":"Adobe Flash Player"},{"enabled":true,"name":"Chrome PDF Viewer"},{"enabled":true,"name":"Chrome Remote Desktop Viewer"},{"enabled":true,"name":"Google Update"},{"enabled":true,"name":"Intel® Identity Protection Technology"},{"enabled":true,"name":"Native Client"}],"removed_old_component_pepper_flash_settings":true},"printing":{"print_preview_sticky_settings":{"appState":"{\"version\":2,\"selectedDestinationId\":\"Save as PDF\",\"isGcpPromoDismissed\":false,\"marginsType\":0,\"isColorEnabled\":null,\"isDuplexEnabled\":null,\"isHeaderFooterEnabled\":null,\"isLandscapeEnabled\":null,\"isCollateEnabled\":null,\"isCssBackgroundEnabled\":null,\"selectedDestinationOrigin\":\"local\",\"customMargins\":null,\"undefined\":{\"version\":\"1.0\",\"printer\":{\"collate\":{\"default\":true},\"copies\":{\"default\":1},\"duplex\":{\"option\":[{\"type\":\"NO_DUPLEX\",\"is_default\":true},{\"type\":\"LONG_EDGE\",\"is_default\":false}]},\"page_orientation\":{\"option\":[{\"type\":\"PORTRAIT\",\"is_default\":true},{\"type\":\"LANDSCAPE\"}]}}},\"selectedDestinationName\":\"Uložit jako PDF\",\"selectedDestinationAccount\":\"\",\"selectedDestinationCapabilities\":null,\"mediaSize\":{\"height_microns\":297000,\"is_default\":true,\"name\":\"ISO_A4\",\"width_microns\":210000,\"custom_display_name\":\"A4\"}}","savePath":"C:\\Users\\Bodlinka\\Documents"}},"profile":{"avatar_bubble_tutorial_shown":1,"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{"[*.]estory.cz,*":{"setting":1},"[*.]exashare.com,*":{"setting":1},"[*.]g.cz,*":{"setting":1},"[*.]milujeme-serialy-cz.webnode.cz,*":{"setting":1},"[*.]novaplus.nova.cz,*":{"setting":1},"[*.]simpsonovi.nikee.net,*":{"setting":1},"[*.]stream-a-ams1xx2sfcdnvideo5269.cz,*":{"setting":1},"[*.]www.exashare.com,*":{"setting":1},"[*.]www.milujemeserialy.eu,*":{"setting":1},"[*.]www.sledujuserialy.cz,*":{"setting":1},"[*.]youbo.iprima.cz,*":{"setting":1},"https://[*.]www.youtube.com:443,*":{"setting":1},"https://openload.io:443,http://www.milujemeserialy.eu:80":{"setting":1}},"geolocation":{},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{"https://www.facebook.com:443,*":{"setting":1},"https://www.google.cz:443,*":{"setting":2}},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{"https://www.lide.cz:443,*":{"setting":2}},"plugins":{"*,*":{"per_resource":{"npsitesafety.dll":1}}},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{"*,*":{"per_plugin":{"npsitesafety.dll":1}},"[*.]estory.cz,*":{"fullscreen":1},"[*.]exashare.com,*":{"fullscreen":1},"[*.]g.cz,*":{"fullscreen":1},"[*.]milujeme-serialy-cz.webnode.cz,*":{"fullscreen":1},"[*.]novaplus.nova.cz,*":{"fullscreen":1},"[*.]simpsonovi.nikee.net,*":{"fullscreen":1},"[*.]stream-a-ams1xx2sfcdnvideo5269.cz,*":{"fullscreen":1},"[*.]www.exashare.com,*":{"fullscreen":1},"[*.]www.milujemeserialy.eu,*":{"fullscreen":1},"[*.]www.sledujuserialy.cz,*":{"fullscreen":1},"[*.]youbo.iprima.cz,*":{"fullscreen":1},"https://[*.]www.youtube.com:443,*":{"fullscreen":1},"https://openload.io:443,http://www.milujemeserialy.eu:80":{"fullscreen":1},"https://www.facebook.com:443,*":{"last_used":{"media-stream-mic":1427983040.42931},"media-stream-mic":1},"https://www.google.cz:443,*":{"media-stream-mic":2},"https://www.lide.cz:443,*":{"notifications":2}},"plugin_whitelist":{"npsitesafety":{"dll":true}},"pref_version":1},"created_by_version":"23.0.1271.97","default_content_settings":{},"exit_type":"Normal","exited_cleanly":true,"gaia_info_update_time":"13079979296070540","icon_version":3,"is_managed":false,"managed_user_id":"","managed_users":{},"migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"První uživatel","password_manager_enabled":false,"password_manager_groups_for_domains":[null,null,null,null,null,null,4],"per_host_zoom_levels":{}},"protection":{"macs":{}},"reverse_autologin":{"enabled":false},"safebrowsing":{"enabled":true},"savefile":{},"selectfile":{"last_directory":"C:\\Users\\Bodlinka\\Documents"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13034713337666768","urls_to_restore_on_startup":null},"sync":{"acknowledged_types":["Bookmarks","Preferences","Passwords","Autofill Profiles","Autofill","Themes","Typed URLs","Extensions","Search Engines","Sessions","Apps","App settings","Extension settings","App Notifications","Encryption keys"],"app_list":true,"app_notifications":true,"app_settings":true,"apps":true,"autofill":true,"autofill_profile":true,"bookmarks":true,"dictionary":true,"encryption_bootstrap_token":"AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAP99vBT+Jj0y0K26+YxkDPwAAAAACAAAAAAAQZgAAAAEAACAAAAAPaN9GFFfb5gXQba6fqwbLUNKtmeDMzeIbSQKJcs0EDgAAAAAOgAAAAAIAACAAAABjT/fWvdg7OktnJ5oNohYfX1wPcsjYsSSRZXExTgRYxkAAAAAam+PCHsqOwrmIJfQ6lTqxOQbkrqz7ZliyDfbKCE/69vi4/XuEe4hDMgjGxXcNkz0WqL4HLix6MquWaGUymnTUQAAAAFnufVqXp8iD5Y/n/Dm+zTEJdROO3pthYZqTRvWXAxwQQlgOADq7zQeP7Kr6WjN8XpoFbkwqirrOYilhuXTpvM8=","extension_settings":true,"extensions":true,"favicon_images":true,"favicon_tracking":true,"favicons_syncing_enabled":true,"first_sync_time":"13054021319339997","has_auth_error":true,"has_setup_completed":true,"history_delete_directives":true,"keep_everything_synced":true,"keystore_encryption_bootstrap_token":"AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAA4cuMil5c7EW6LWZ+nZSX4QAAAAACAAAAAAAQZgAAAAEAACAAAAC+lfmbXECXiaz8p4GM94aNhRSvOPHz8Zrf3Jnl7dQW+QAAAAAOgAAAAAIAACAAAAC5iK0DJ1URtn470MVe65TrsMLrvn+qPrGLjlxP+XLdGlAAAACa4YfC/sW0CV+xcp6fbHCYBv3OucHdyhLDYAnjQvPeGzUs3qy1HkYaSpsCAEtickGrmW/G/uQc3YNdM/xFSWNhy/7Mi8xvS9OsNbfGifshQEAAAAAVyjabI+Rfp8mxvdbid9yRx5okyeUj2YR8tp5lSGmK2UIyat2rRAyVtPQw8OqixsqbogIBXmo+GwkuoY6ZKbQy","last_synced_time":"13079979303304226","managed_user_settings":true,"managed_user_shared_settings":true,"managed_user_whitelists":true,"managed_users":true,"passwords":true,"preferences":true,"priority_preferences":true,"search_engines":true,"session_sync_guid":"session_syncijy3+mnSmH4BwdTCC4EcDw==","sessions":true,"suppress_start":false,"synced_notifications":true,"tabs":true,"themes":true,"typed_urls":true},"sync_promo":{"startup_count":4,"view_count":4},"synced_notification":{"enabled_sending_services":["Google+"],"first_run":false,"initialized_sending_services":["Google+"]},"translate_accepted_count":{"de":0,"en":0,"sk":0,"tr":0,"und":0},"translate_blocked_languages":["cs"],"translate_denied_count":{"de":20,"en":226,"sk":22,"tr":1,"und":2},"translate_last_denied_time":1.412857e+12,"translate_too_often_denied":true,"translate_whitelists":{},"zerosuggest":{"cachedresults":""}}
dll","version":""},{"enabled":true,"name":"Chrome PDF Viewer","path":"C:\\Users\\Bodlinka\\AppData\\Local\\Google\\Chrome\\Application\\43.0.2357.130\\pdf.dll","version":""},{"enabled":true,"name":"Intel® Identity Protection Technology","path":"C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\IPT\\npIntelWebAPIIPT.dll","version":"2.1.42.0"},{"enabled":true,"name":"Intel® Identity Protection Technology","path":"C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\IPT\\npIntelWebAPIUpdater.dll","version":"2.1.42.0"},{"enabled":true,"name":"Google Update","path":"C:\\Users\\Bodlinka\\AppData\\Local\\Google\\Update\\1.2.183.39\\npGoogleOneClick8.dll","version":"1.2.183.39"},{"enabled":true,"name":"Adobe Flash Player"},{"enabled":true,"name":"Chrome PDF Viewer"},{"enabled":true,"name":"Chrome Remote Desktop Viewer"},{"enabled":true,"name":"Google Update"},{"enabled":true,"name":"Intel® Identity Protection Technology"},{"enabled":true,"name":"Native Client"}],"removed_old_component_pepper_flash_settings":true},"printing":{"print_preview_sticky_settings":{"appState":"{\"version\":2,\"selectedDestinationId\":\"Save as PDF\",\"isGcpPromoDismissed\":false,\"marginsType\":0,\"isColorEnabled\":null,\"isDuplexEnabled\":null,\"isHeaderFooterEnabled\":null,\"isLandscapeEnabled\":null,\"isCollateEnabled\":null,\"isCssBackgroundEnabled\":null,\"selectedDestinationOrigin\":\"local\",\"customMargins\":null,\"undefined\":{\"version\":\"1.0\",\"printer\":{\"collate\":{\"default\":true},\"copies\":{\"default\":1},\"duplex\":{\"option\":[{\"type\":\"NO_DUPLEX\",\"is_default\":true},{\"type\":\"LONG_EDGE\",\"is_default\":false}]},\"page_orientation\":{\"option\":[{\"type\":\"PORTRAIT\",\"is_default\":true},{\"type\":\"LANDSCAPE\"}]}}},\"selectedDestinationName\":\"Uložit jako PDF\",\"selectedDestinationAccount\":\"\",\"selectedDestinationCapabilities\":null,\"mediaSize\":{\"height_microns\":297000,\"is_default\":true,\"name\":\"ISO_A4\",\"width_microns\":210000,\"custom_display_name\":\"A4\"}}","savePath":"C:\\Users\\Bodlinka\\Documents"}},"profile":{"avatar_bubble_tutorial_shown":1,"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{"[*.]estory.cz,*":{"setting":1},"[*.]exashare.com,*":{"setting":1},"[*.]g.cz,*":{"setting":1},"[*.]milujeme-serialy-cz.webnode.cz,*":{"setting":1},"[*.]novaplus.nova.cz,*":{"setting":1},"[*.]simpsonovi.nikee.net,*":{"setting":1},"[*.]stream-a-ams1xx2sfcdnvideo5269.cz,*":{"setting":1},"[*.]www.exashare.com,*":{"setting":1},"[*.]www.milujemeserialy.eu,*":{"setting":1},"[*.]www.sledujuserialy.cz,*":{"setting":1},"[*.]youbo.iprima.cz,*":{"setting":1},"https://[*.]www.youtube.com:443,*":{"setting":1},"https://openload.io:443,http://www.milujemeserialy.eu:80":{"setting":1}},"geolocation":{},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{"https://www.facebook.com:443,*":{"setting":1},"https://www.google.cz:443,*":{"setting":2}},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{"https://www.lide.cz:443,*":{"setting":2}},"plugins":{"*,*":{"per_resource":{"npsitesafety.dll":1}}},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{"*,*":{"per_plugin":{"npsitesafety.dll":1}},"[*.]estory.cz,*":{"fullscreen":1},"[*.]exashare.com,*":{"fullscreen":1},"[*.]g.cz,*":{"fullscreen":1},"[*.]milujeme-serialy-cz.webnode.cz,*":{"fullscreen":1},"[*.]novaplus.nova.cz,*":{"fullscreen":1},"[*.]simpsonovi.nikee.net,*":{"fullscreen":1},"[*.]stream-a-ams1xx2sfcdnvideo5269.cz,*":{"fullscreen":1},"[*.]www.exashare.com,*":{"fullscreen":1},"[*.]www.milujemeserialy.eu,*":{"fullscreen":1},"[*.]www.sledujuserialy.cz,*":{"fullscreen":1},"[*.]youbo.iprima.cz,*":{"fullscreen":1},"https://[*.]www.youtube.com:443,*":{"fullscreen":1},"https://openload.io:443,http://www.milujemeserialy.eu:80":{"fullscreen":1},"https://www.facebook.com:443,*":{"last_used":{"media-stream-mic":1427983040.42931},"media-stream-mic":1},"https://www.google.cz:443,*":{"media-stream-mic":2},"https://www.lide.cz:443,*":{"notifications":2}},"plugin_whitelist":{"npsitesafety":{"dll":true}},"pref_version":1},"created_by_version":"23.0.1271.97","default_content_settings":{},"exit_type":"Normal","exited_cleanly":true,"gaia_info_update_time":"13079979296070540","icon_version":3,"is_managed":false,"managed_user_id":"","managed_users":{},"migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"První uživatel","password_manager_enabled":false,"password_manager_groups_for_domains":[null,null,null,null,null,null,4],"per_host_zoom_levels":{}},"protection":{"macs":{}},"reverse_autologin":{"enabled":false},"safebrowsing":{"enabled":true},"savefile":{},"selectfile":{"last_directory":"C:\\Users\\Bodlinka\\Documents"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13034713337666768","urls_to_restore_on_startup":null},"sync":{"acknowledged_types":["Bookmarks","Preferences","Passwords","Autofill Profiles","Autofill","Themes","Typed URLs","Extensions","Search Engines","Sessions","Apps","App settings","Extension settings","App Notifications","Encryption keys"],"app_list":true,"app_notifications":true,"app_settings":true,"apps":true,"autofill":true,"autofill_profile":true,"bookmarks":true,"dictionary":true,"encryption_bootstrap_token":"AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAP99vBT+Jj0y0K26+YxkDPwAAAAACAAAAAAAQZgAAAAEAACAAAAAPaN9GFFfb5gXQba6fqwbLUNKtmeDMzeIbSQKJcs0EDgAAAAAOgAAAAAIAACAAAABjT/fWvdg7OktnJ5oNohYfX1wPcsjYsSSRZXExTgRYxkAAAAAam+PCHsqOwrmIJfQ6lTqxOQbkrqz7ZliyDfbKCE/69vi4/XuEe4hDMgjGxXcNkz0WqL4HLix6MquWaGUymnTUQAAAAFnufVqXp8iD5Y/n/Dm+zTEJdROO3pthYZqTRvWXAxwQQlgOADq7zQeP7Kr6WjN8XpoFbkwqirrOYilhuXTpvM8=","extension_settings":true,"extensions":true,"favicon_images":true,"favicon_tracking":true,"favicons_syncing_enabled":true,"first_sync_time":"13054021319339997","has_auth_error":true,"has_setup_completed":true,"history_delete_directives":true,"keep_everything_synced":true,"keystore_encryption_bootstrap_token":"AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAA4cuMil5c7EW6LWZ+nZSX4QAAAAACAAAAAAAQZgAAAAEAACAAAAC+lfmbXECXiaz8p4GM94aNhRSvOPHz8Zrf3Jnl7dQW+QAAAAAOgAAAAAIAACAAAAC5iK0DJ1URtn470MVe65TrsMLrvn+qPrGLjlxP+XLdGlAAAACa4YfC/sW0CV+xcp6fbHCYBv3OucHdyhLDYAnjQvPeGzUs3qy1HkYaSpsCAEtickGrmW/G/uQc3YNdM/xFSWNhy/7Mi8xvS9OsNbfGifshQEAAAAAVyjabI+Rfp8mxvdbid9yRx5okyeUj2YR8tp5lSGmK2UIyat2rRAyVtPQw8OqixsqbogIBXmo+GwkuoY6ZKbQy","last_synced_time":"13079979303304226","managed_user_settings":true,"managed_user_shared_settings":true,"managed_user_whitelists":true,"managed_users":true,"passwords":true,"preferences":true,"priority_preferences":true,"search_engines":true,"session_sync_guid":"session_syncijy3+mnSmH4BwdTCC4EcDw==","sessions":true,"suppress_start":false,"synced_notifications":true,"tabs":true,"themes":true,"typed_urls":true},"sync_promo":{"startup_count":4,"view_count":4},"synced_notification":{"enabled_sending_services":["Google+"],"first_run":false,"initialized_sending_services":["Google+"]},"translate_accepted_count":{"de":0,"en":0,"sk":0,"tr":0,"und":0},"translate_blocked_languages":["cs"],"translate_denied_count":{"de":20,"en":226,"sk":22,"tr":1,"und":2},"translate_last_denied_time":1.412857e+12,"translate_too_often_denied":true,"translate_whitelists":{},"zerosuggest":{"cachedresults":""}}
//mail.google.com/mail/ca"]},"current_locale":"cs","default_locale":"en","description":"Rychlý e-mail s možností vyhledávání a menším množstvím spamu.","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB","manifest_version":2,"name":"Gmail","options_page":"https://mail.google.com/mail/ca/#settings","permissions":["notifications"],"update_url":"http://clients2.google.com/service/update2/crx","version":"8.1"},"page_ordinal":"n","path":"pjkljhegncpnkpknbcohdijeoejaedia\\8.1_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false}}},"google":{"services":{"last_username":"minibodlina@seznam.cz","username":"minibodlina@seznam.cz"}},"homepage":"http://www.google.com/","homepage_is_newtabpage":false,"pinned_tabs":[],"prefs":{"preference_reset_time":"13079958203996999"},"protection":{"macs":{"browser":{"show_home_button":"9AC8853FA0F8E6117D06255B40E0E06626B6E8B1FB83438052800037D8CCE7B3"},"default_search_provider":{"keyword":"71F144E6BD00677B9E7D8453E35D0C1EAB4F26A766B33326100B0E4CFC0E07F2","name":"B7604AD72E83F9C60CEDBE2D3B207DDFE3DEF28ED92A2260A304960A49632BAF","search_url":"5665F77993F90DD3EE6E998C5793CF03F1836C0D58AAEA228ECA1AE887C6ABCB"},"default_search_provider_data":{"template_url_data":"ABA220AC407E4635663D4299C7B79D072068CF954C96A899EFF2B8A19D5A0B2B"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":"668AF499AA80ABA694ADCA39E378F68F04DCF4D08F707347A7F405A919661072","apdfllckaahabafndbhieahigkjlhalf":"882CEAE46D32C738FF501897BF09101697AA78E611EBE0D77D8004E15EC2C3E4","bepbmhgboaologfdajaanbcjmnhjmhfn":"6579FE0378F032571D1CB20E89C458BBD7F7C3559594833FD521CDB154232DF7","blpcfgokakmgnkcojhhkbfbldkacnbeo":"1EC0F6F1BD94A65BD70A0876BB87D850F747C1E278206A405CBD4E1B68AF291D","coobgpohoikkiipiblmjeljniedjpjpf":"603153B26D89643B47C71E7240ECA1CAD8BFCEF3418F265BE4FC2C2CC8D86D9B","eemcgdkfndhakfknompkggombfjjjeno":"81DF25C81A4E00EECF61CFCFA2469FAFAAC91DAD48CE13779A223E2E6F9B8624","ennkphjdgehloodpbhlhldgbnhmacadg":"DE2CF1C3BDB3234265A4BF8DAD3BC79864332E8A6C35DB477F755CD90198E834","eofcbnmajmjmplflapaojjnihcjkigck":"C338816F5FB105401DE660966C6DD82B3260EC5213600348F3206AB2D3F47B38","fjbbjfdilbioabojmcplalojlmdngbjl":"0F01A798DDACB35C9F94A0F21EE6135B3EF475C6C8DE720CDD8CB135F094224E","gfdkimpbcpahaombhbimeihdjnejgicl":"8531D0C9A9260B1F029A8EF771BDAD58710C475F9B5FDEA61F8B3CB84F71BCD5","gighmmpiobklfepjocnamgkkbiglidom":"725088D97183DF12C86187237FFD65E8584CC9743F9FE153D18553C53F540595","gomekmidlodglbbmalcneegieacbdmki":"0ACAEDF6EC576347D5FEDBF2C9F358A92B12821C95A9B87656B95970EC807861","kmendfapggjehodndflmmgagdbamhnfd":"0C906A5CD4647E022ACD37896101A0DEA21E2F546386C3AC41322541B9409F0A","lifbcibllhkdhoafpjfnlhfpfgnpldfl":"CFDC1E374E9A48697C11395C9FAB0986F27D1EACA04EC43482097A9F8DDE39BE","mfehgcgbbipciphmccgaenjidiccnmng":"3E57B7259A3E85A62353D6A420BA9737860309F24AEA7CC002440A4EB7C40655","mgndgikekgjfcpckkfioiadnlibdjbkf":"9A53516D880F9477D3BC9BACE0B80EFE75F1A79AA9599389E388098C3B9E63CD","mhjfbmdgcfjbbpaeojofohoefgiehjai":"3487301A2DF7DB5B1FA7587707D1594AF724163FB8BAFDC51A23E69414575464","mihcahmgecmbnbcchbopgniflfhgnkff":"294E7CB9ABB62FF5451F33A48F4001DC7A746F3E7DFAF147A18AB7A3A53339F0","neajdppkdcdipfabeoofebfddakdcjhd":"9F9BDCA85D68B1A360D8ADAE6D783AD48094F699232B3A4E47D6C29FFD63305E","nkeimhogjdpnpccoofpliimaahmaaome":"2D07652A4281298D909B04A28BC67596CD43570120050C4BEB6BE50F63DB5704","nmmhkkegccagdldgiimedpiccmgmieda":"7730035888DC758170DB7A5C9C7C063D77D1480F514A1CD60A08C3BC4B30572C","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"AB70375C2FA30711E1A72E2A68C43387BCA5CC970328CED11CBF12846255E38C","pjkljhegncpnkpknbcohdijeoejaedia":"A271FF6D2DDB271FA27021BBDB1FA0603A7E7D1B899DB01E36F38B2BE2F6097F"}},"google":{"services":{"last_username":"B9A6FF90590A852CBBEE23AF6CC53AA1227052A8D539D3FB552E378B319D3867","username":"5AD7117FAED941267FA9EEDD2C75299D0767100F7E7817730B04314B6E4E5950"}},"homepage":"F37154B9DF834BD22B080AC92D0D316B5BE667D738BC52809BA61B58CB849080","homepage_is_newtabpage":"2DD9281B7916E55AB38D2628B24001104E5398F10525B07FA6020B5783A86726","pinned_tabs":"C235D94D66691650BA089ABC418C14DDC9027A8441873B68C5D1F86BB692D290","prefs":{"preference_reset_time":"DE64B8B709F0590386E98E810C369A06FAB1771E43191EF387BEE0CF664DA311"},"profile":{"reset_prompt_memento":"C0FD8DC357BF59D3CC7C62F6A59892B0CA1C718355D53DC575CC4966193D0A84"},"safebrowsing":{"incidents_sent":"0AB317326C2DBD5A8C894EF777A4C8F12C47D4EFD749459914DDA91C9DAE6A18"},"search_provider_overrides":"05CB17172FBA2EE383D1E8F7521AF9D35CEE42CA7543913EA0C8E97928D44A20","session":{"restore_on_startup":"C1F3CA5AC98B373275AFF3A005CB7360F08CE57D276E80433B9D07ACC9AE1568","startup_urls":"56AD7DC7748DE8525B88E3F2F33B6B9C52B243CC6759CDA338FC70DC327B17F3"},"software_reporter":{"prompt_reason":"9B727C61BA5F01F9C23F6519315044E12138B31171FEA5FFDF2E49A18CD0BDEF","prompt_seed":"ED0F4363119794067541163F553CAD26219ED0B255908CDD381256D870F06ADA","prompt_version":"D271E1D089AB14031C7E68B680BBC1AE003478B26B436DE8892659A324A75185"},"sync":{"remaining_rollback_tries":"07B9976A900A218EB9CBE0C05C0F54E4EF43DA006F67BAC731522513F99F0583"}},"super_mac":"9EEBFEFED790299FB98E3E007F50E0EC9F34BDAE174CE351385443D7F01E735C"},"session":{"restore_on_startup":5,"startup_urls":["https://www.google.cz/"]},"software_reporter":{"prompt_reason":0,"prompt_version":"3.20.1"},"sync":{"remaining_rollback_tries":0}}


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="https://www.google.com/search?trackid=sp-006&q={searchTerms}"
"Search Bar"="https://www.google.com/?trackid=sp-006"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.google.com"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{17C42D0A-F186-4D38-92DD-D39D63B8B17A} Unknown Url="Not_Found"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz="
{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} Google Url="https://www.google.com/search?trackid=sp-006&q={searchTerms}"

==== Reset Google Chrome ======================

C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Bodlinka\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\Bodlinka\AppData\Roaming\Opera Software\Opera Stable\Web Data was reset successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\SearchScopes\{17C42D0A-F186-4D38-92DD-D39D63B8B17A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{17C42D0A-F186-4D38-92DD-D39D63B8B17A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{17C42D0A-F186-4D38-92DD-D39D63B8B17A} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Registry Keys ======================

HKEY_CURRENT_USER\Software\Policies\Google deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Bodlinka\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Bodlinka\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\Bodlinka\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=148 folders=24 21509059 bytes)

==== Empty Temp Folders ======================

C:\Users\Bodlinka\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Bodlinka\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted

==== EOF on ne 28. 06. 2015 at 18:34:46,01 ======================

Budkyns
Level 2.5
Level 2.5
Příspěvky: 252
Registrován: srpen 09
Pohlaví: Nespecifikováno
Stav:
Offline

Re: vyskak. oken, reklam, spojeno s detekcí škodlivostí Avas

Příspěvekod Budkyns » 28 čer 2015 18:50

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:28-06-2015
Ran by Bodlinka (administrator) on LENOVO on 28-06-2015 18:40:02
Running from C:\Users\Bodlinka\Desktop
Loaded Profiles: UpdatusUser & Bodlinka (Available Profiles: UpdatusUser & Bodlinka)
Platform: Windows 8.1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(PS Media s.r.o.) C:\Windows\SysWOW64\ssins.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332STI.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\Bluetooth Headset Helper.exe
(Microsoft Corporation) C:\Windows\System32\LocationNotifications.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\TiWorker.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2864016 2012-08-08] (ELAN Microelectronics Corp.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-15] (Conexant Systems, Inc.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2012-09-21] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2012-09-21] (Lenovo(beijing) Limited)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332STI.EXE [548864 2012-03-20] (Vimicro)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-26] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-19] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227648 2015-03-14] (AVAST Software)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [847576 2015-02-03] (BlueStack Systems, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-4138806220-3288153000-4149962190-1001\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2014-11-21] (Microsoft Corporation)
HKU\S-1-5-21-4138806220-3288153000-4149962190-1001\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\Run: [Google Update] => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-10-25] (Google Inc.)
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\Run: [Facebook Update] => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-11-06] (Facebook Inc.)
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [28785280 2015-06-02] (Skype Technologies S.A.)
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8358680 2015-06-01] (Piriform Ltd)
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Bubbles.scr [788480 2014-11-21] (Microsoft Corporation)
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
AppInit_DLLs: C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll [184048 2013-12-26] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2012-09-21]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2014-12-17] (AVAST Software)
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com
URLSearchHook: [S-1-5-21-4138806220-3288153000-4149962190-1001] ATTENTION ==> Default URLSearchHook is missing
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-12-17] (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-04-04] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-12-17] (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-04-04] (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3014BA86-BC67-4086-9604-766C3E1BACA9}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{4B5B69B9-CCAC-4574-A33A-D96164722021}: [DhcpNameServer] 10.0.1.2

FireFox:
========
FF ProfilePath: C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll [2014-10-09] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll [2014-10-09] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-04-04] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2014-07-18] (Pando Networks)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4138806220-3288153000-4149962190-1005: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Bodlinka\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-4138806220-3288153000-4149962190-1005: @tools.google.com/Google Update;version=3 -> C:\Users\Bodlinka\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin HKU\S-1-5-21-4138806220-3288153000-4149962190-1005: @tools.google.com/Google Update;version=9 -> C:\Users\Bodlinka\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin HKU\S-1-5-21-4138806220-3288153000-4149962190-1005: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Bodlinka\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-01-10] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-4138806220-3288153000-4149962190-1005: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2014-07-18] (Pando Networks)
FF SearchPlugin: C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default\searchplugins\google-avast.xml [2014-12-17]
FF Extension: autotranslatorkobayashich - C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default\Extensions\autotranslator@kobayashi.ch [2014-08-07]
FF Extension: b9acf540acba11e18ccb001fd0e08bd4 - C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4} [2014-08-07]
FF Extension: Adblock Plus - C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-09]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-12-17]
FF Extension: No Name - C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default\extensions\BMNEMEGJ50257956@NMROOPQ94813992.com [not found]

Chrome:
=======
CHR Profile: C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-28]
CHR Extension: (Google Docs) - C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-28]
CHR Extension: (Google Drive) - C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-12-25]
CHR Extension: (YouTube) - C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-25]
CHR Extension: (Google Search) - C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-25]
CHR Extension: (Avast SafePrice) - C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-01-01]
CHR Extension: (Google Sheets) - C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-28]
CHR Extension: (Avast Online Security) - C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-01-01]
CHR Extension: (Skype Click to Call) - C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-12-07]
CHR Extension: (Google Wallet) - C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-08]
CHR Extension: (Gmail) - C:\Users\Bodlinka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-25]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2014-12-17]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-17]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]

Opera:
=======
OPR Extension: (No Name) - C:\Users\Bodlinka\AppData\Roaming\Opera Software\Opera Stable\Extensions\fhpakgdnncieelihbbgoamgmaijegbmg [2014-08-06]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-17] (AVAST Software)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-09-04] (Broadcom Corporation.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [409304 2015-02-03] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [388824 2015-02-03] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [794328 2015-02-03] (BlueStack Systems, Inc.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-11-21] (Microsoft Corporation)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [953720 2012-08-27] (Broadcom Corporation.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1663880 2014-05-06] ()
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 ssinstall; C:\windows\SysWOW64\ssins.exe [2324216 2014-09-04] (PS Media s.r.o.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-17] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-17] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-17] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-17] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-17] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-17] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-17] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-12-17] ()
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-09-04] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [6824520 2012-07-10] (Broadcom Corporation)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122072 2015-02-03] (BlueStack Systems)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-11-21] (Microsoft Corporation)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [146856 2013-06-04] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2012-12-28] (DT Soft Ltd)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-28 18:40 - 2015-06-28 18:40 - 00024494 _____ C:\Users\Bodlinka\Desktop\FRST.txt
2015-06-28 18:39 - 2015-06-28 18:40 - 00000000 ____D C:\FRST
2015-06-28 18:38 - 2015-06-28 18:38 - 02112512 _____ (Farbar) C:\Users\Bodlinka\Desktop\FRST64.exe
2015-06-28 18:36 - 2015-06-28 18:36 - 00261954 _____ C:\Users\Bodlinka\Desktop\zoek-results.txt
2015-06-28 18:32 - 2015-06-28 17:39 - 00024064 _____ C:\WINDOWS\zoek-delete.exe
2015-06-28 17:42 - 2015-06-28 18:34 - 00261951 _____ C:\zoek-results.log
2015-06-28 17:39 - 2015-06-28 18:33 - 00000000 ____D C:\zoek_backup
2015-06-28 17:36 - 2015-06-28 17:37 - 01308672 _____ C:\Users\Bodlinka\Downloads\zoek.exe
2015-06-28 16:56 - 2015-06-28 16:56 - 00000000 ____D C:\Users\Bodlinka\AppData\Local\CrashDumps
2015-06-28 12:50 - 2015-06-28 12:50 - 00002950 _____ C:\Users\Bodlinka\Desktop\RKreport_SCN_06282015_124937.log
2015-06-28 12:31 - 2015-06-28 17:16 - 00037624 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-06-28 12:31 - 2015-06-28 12:50 - 00000000 ____D C:\ProgramData\RogueKiller
2015-06-28 12:30 - 2015-06-28 12:08 - 02950808 _____ (Malwarebytes Corporation) C:\Users\Bodlinka\Desktop\JRT.exe
2015-06-28 12:29 - 2015-06-28 12:29 - 00000000 ____D C:\Users\Bodlinka\AppData\Local\Adobe
2015-06-28 12:28 - 2015-06-28 12:28 - 21471480 _____ C:\Users\Bodlinka\Downloads\RogueKillerX64.exe
2015-06-28 11:35 - 2015-06-28 11:35 - 00000207 _____ C:\WINDOWS\tweaking.com-regbackup-LENOVO-Windows-8.1-(64-bit).dat
2015-06-28 11:35 - 2015-06-28 11:35 - 00000000 ____D C:\RegBackup
2015-06-28 11:33 - 2015-06-28 11:33 - 02950961 _____ (Malwarebytes Corporation) C:\Users\Bodlinka\Downloads\JRT.exe
2015-06-27 23:06 - 2015-06-28 12:17 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-06-27 23:06 - 2015-06-27 23:06 - 00001129 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-27 23:06 - 2015-06-27 23:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-27 23:06 - 2015-06-27 23:06 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-27 23:06 - 2015-06-27 23:06 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-06-27 23:06 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-06-27 23:06 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-06-27 23:06 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-06-27 23:00 - 2015-06-28 11:27 - 00000000 ____D C:\AdwCleaner
2015-06-27 22:58 - 2015-06-27 22:59 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Bodlinka\Downloads\mbam-setup-2.1.6.1022.exe
2015-06-27 22:57 - 2015-06-27 22:57 - 02244096 _____ C:\Users\Bodlinka\Downloads\adwcleaner_4.207.exe
2015-06-27 22:57 - 2015-06-27 22:57 - 02244096 _____ C:\Users\Bodlinka\Downloads\adwcleaner_4.207 (1).exe
2015-06-27 22:57 - 2015-06-27 22:57 - 00000000 ____D C:\Users\Bodlinka\AppData\Local\Broadcom
2015-06-27 22:50 - 2015-06-27 22:50 - 00448512 _____ (OldTimer Tools) C:\Users\Bodlinka\Downloads\TFC.exe
2015-06-27 22:46 - 2015-06-27 22:47 - 00050688 _____ (Atribune.org) C:\Users\Bodlinka\Downloads\ATF-Cleaner.exe
2015-06-27 22:42 - 2015-06-28 18:33 - 00161500 _____ C:\WINDOWS\PFRO.log
2015-06-27 22:25 - 2015-06-27 22:25 - 00388608 _____ (Trend Micro Inc.) C:\Users\Bodlinka\Downloads\hijackthis.exe
2015-06-27 22:25 - 2015-06-27 22:25 - 00014097 _____ C:\Users\Bodlinka\Downloads\hijackthis.log
2015-06-27 20:50 - 2015-06-28 18:33 - 00001505 _____ C:\WINDOWS\setupact.log
2015-06-27 20:50 - 2015-06-27 20:50 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-06-27 20:49 - 2015-06-27 20:49 - 00000000 ____D C:\Program Files (x86)\ESET
2015-06-27 20:47 - 2015-06-27 20:47 - 02870984 _____ (ESET) C:\Users\Bodlinka\Downloads\esetsmartinstaller_csy.exe
2015-06-27 20:38 - 2015-06-28 18:38 - 00932874 _____ C:\WINDOWS\WindowsUpdate.log
2015-06-27 20:00 - 2015-06-27 20:00 - 00002792 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2015-06-27 20:00 - 2015-06-27 20:00 - 00000845 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-06-27 20:00 - 2015-06-27 20:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-06-27 20:00 - 2015-06-27 20:00 - 00000000 ____D C:\Program Files\CCleaner
2015-06-27 19:56 - 2015-06-27 19:56 - 06565736 _____ (Piriform Ltd) C:\Users\Bodlinka\Downloads\ccsetup507.exe
2015-06-23 22:02 - 2015-06-23 23:43 - 1824027666 _____ C:\Users\Bodlinka\Downloads\Jurský-park-3-HQ.avi
2015-06-23 20:57 - 2015-06-23 20:58 - 00000000 ____D C:\Users\Bodlinka\AppData\Roaming\Microsoft Games
2015-06-23 20:56 - 2015-06-23 20:56 - 00000000 ____D C:\ProgramData\Microsoft Games
2015-06-23 20:51 - 2015-06-23 20:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Games
2015-06-23 12:40 - 2015-06-23 15:01 - 2544739442 _____ C:\Users\Bodlinka\Downloads\Jurský-park-2-HQ.avi
2015-06-16 14:04 - 2015-06-16 16:19 - 2433064241 _____ C:\Users\Bodlinka\Downloads\Breaking.Bad.S04E13.Face.Off.720p.BluRay.X264.CZ-GHDC.mkv
2015-06-16 14:03 - 2015-06-16 16:10 - 2265249904 _____ C:\Users\Bodlinka\Downloads\Breaking.Bad.S04E11.Crawl.Space.720p.Bluray.DD5.1.x264.CZ-GHDC.mkv
2015-06-16 14:03 - 2015-06-16 16:07 - 2216675203 _____ C:\Users\Bodlinka\Downloads\Breaking.Bad.S04E12.End.Times.720p.BluRay.X264.CZ-GHDC.mkv
2015-06-16 14:02 - 2015-06-16 16:10 - 2277501841 _____ C:\Users\Bodlinka\Downloads\Breaking.Bad.S04E10.Salud.720p.BluRay.X264.CZ-GHDC.mkv
2015-06-16 14:00 - 2015-06-16 14:18 - 315974122 _____ C:\Users\Bodlinka\Downloads\Breaking-Bad-Season-04-Episode-09---Bug.mp4
2015-06-14 16:25 - 2015-06-14 16:39 - 00000000 ____D C:\Users\Bodlinka\Documents\akordy
2015-06-10 16:02 - 2015-04-02 00:42 - 03097600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-06-10 16:02 - 2015-04-02 00:30 - 02483712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-06-10 16:02 - 2015-03-20 05:49 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
2015-06-10 16:02 - 2015-03-20 05:08 - 00477184 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2015-06-10 16:02 - 2015-03-20 04:37 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2015-06-10 16:02 - 2015-03-20 04:07 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2015-06-10 16:01 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-06-10 16:01 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-06-10 16:01 - 2015-05-25 15:23 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
2015-06-10 16:01 - 2015-05-25 15:07 - 01430528 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-06-10 16:01 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-06-10 16:01 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2015-06-10 16:01 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-06-10 16:01 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-06-10 16:01 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2015-06-10 16:01 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-06-10 16:01 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-06-10 16:01 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-06-10 16:01 - 2015-05-23 04:47 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-06-10 16:01 - 2015-05-23 04:43 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-06-10 16:01 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-06-10 16:01 - 2015-05-23 04:38 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-06-10 16:01 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-06-10 16:01 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-06-10 16:01 - 2015-05-23 04:28 - 01042944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-06-10 16:01 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-06-10 16:01 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-06-10 16:01 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-06-10 16:01 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-06-10 16:01 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-06-10 16:01 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-06-10 16:01 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-06-10 16:01 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-06-10 16:01 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-06-10 16:01 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2015-06-10 16:01 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-06-10 16:01 - 2015-05-22 20:23 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-06-10 16:01 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-06-10 16:01 - 2015-05-22 20:15 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-06-10 16:01 - 2015-05-22 20:09 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-06-10 16:01 - 2015-05-22 20:08 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-06-10 16:01 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-06-10 16:01 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-06-10 16:01 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-06-10 16:01 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-06-10 16:01 - 2015-05-22 19:49 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-06-10 16:01 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-06-10 16:01 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-06-10 16:01 - 2015-04-25 04:34 - 00653824 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2015-06-10 16:01 - 2015-04-25 04:33 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2015-06-10 16:01 - 2015-04-16 08:17 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-06-10 16:01 - 2015-04-14 00:37 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\authz.dll
2015-06-10 16:01 - 2015-04-14 00:34 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authz.dll
2015-06-10 16:01 - 2015-04-10 02:40 - 01249280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-06-10 16:01 - 2015-04-10 02:17 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-06-10 16:01 - 2015-04-09 00:41 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rgb9rast.dll
2015-06-10 16:01 - 2015-04-09 00:07 - 00410336 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-06-10 16:01 - 2015-04-01 06:21 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2015-06-10 16:01 - 2015-04-01 06:18 - 00468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2015-06-10 16:01 - 2015-04-01 06:17 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssphtb.dll
2015-06-10 16:01 - 2015-04-01 06:08 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2015-06-10 16:01 - 2015-04-01 05:46 - 03633664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2015-06-10 16:01 - 2015-04-01 05:17 - 02551808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-06-10 16:01 - 2015-04-01 05:17 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2015-06-10 16:01 - 2015-04-01 04:53 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2015-06-10 16:01 - 2015-04-01 04:53 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2015-06-10 16:01 - 2015-04-01 04:45 - 02749952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2015-06-10 16:01 - 2015-04-01 04:45 - 00699392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2015-06-10 16:01 - 2015-04-01 04:14 - 01920000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-06-10 16:01 - 2015-04-01 04:12 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2015-06-10 16:01 - 2015-03-02 03:43 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastapi.dll
2015-06-10 16:01 - 2015-03-02 03:21 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastapi.dll
2015-06-10 16:00 - 2015-05-21 18:47 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-06-07 18:00 - 2015-06-07 18:00 - 00000000 ____D C:\Users\Bodlinka\AppData\Local\GWX
2015-06-07 16:42 - 2015-05-22 15:08 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-06-07 16:42 - 2015-05-21 15:08 - 01119232 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-06-07 16:42 - 2015-05-21 15:08 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-06-07 16:42 - 2015-05-21 15:08 - 00756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-06-07 16:42 - 2015-05-21 15:08 - 00422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-06-07 16:42 - 2015-05-21 15:08 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2015-06-07 16:42 - 2015-05-21 15:08 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-06-07 16:42 - 2015-04-17 00:07 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-28 18:40 - 2014-11-06 19:35 - 00000954 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA.job
2015-06-28 18:40 - 2014-11-06 19:35 - 00000932 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core.job
2015-06-28 18:37 - 2012-12-25 17:27 - 00000000 ____D C:\Users\Bodlinka\AppData\Roaming\Skype
2015-06-28 18:35 - 2014-12-17 18:34 - 00004182 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-06-28 18:34 - 2014-09-04 17:40 - 00000000 _____ C:\WINDOWS\SysWOW64\sinstall.log
2015-06-28 18:33 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-06-28 18:21 - 2012-12-25 11:14 - 00000988 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA.job
2015-06-28 18:00 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-06-28 16:22 - 2015-05-28 13:34 - 00003974 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{642DF2B1-016C-482E-967C-922BC321B5DC}
2015-06-28 15:35 - 2015-05-28 14:32 - 00000000 ____D C:\Users\Bodlinka\AppData\Local\Popcorn-Time
2015-06-28 12:28 - 2014-11-21 06:53 - 01745984 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-06-28 12:28 - 2014-11-21 06:10 - 00739924 _____ C:\WINDOWS\system32\perfh005.dat
2015-06-28 12:28 - 2014-11-21 06:10 - 00151610 _____ C:\WINDOWS\system32\perfc005.dat
2015-06-28 12:03 - 2012-12-25 10:52 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4138806220-3288153000-4149962190-1005
2015-06-28 11:35 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-06-28 11:27 - 2012-12-25 10:47 - 00000998 _____ C:\Users\Bodlinka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-06-27 22:42 - 2014-06-16 21:37 - 00000000 ____D C:\ProgramData\AVG2014
2015-06-27 22:42 - 2014-06-16 21:33 - 00000000 ____D C:\ProgramData\MFAData
2015-06-27 22:41 - 2015-02-18 19:29 - 00000000 ____D C:\Users\Bodlinka
2015-06-27 22:41 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-06-27 22:40 - 2014-06-16 21:37 - 00000000 ___HD C:\$AVG
2015-06-27 22:40 - 2012-07-26 10:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-06-27 22:25 - 2012-12-25 10:46 - 00000000 ____D C:\Users\Bodlinka\AppData\Local\VirtualStore
2015-06-27 22:09 - 2014-01-21 20:30 - 00000000 ____D C:\Users\Bodlinka\AppData\Roaming\uTorrent
2015-06-27 22:09 - 2013-01-16 00:46 - 00000000 ____D C:\Users\Bodlinka\Documents\INSTALAČKY
2015-06-27 20:04 - 2015-02-06 04:10 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2015-06-27 20:04 - 2014-02-28 01:12 - 00000000 ____D C:\Users\Bodlinka\AppData\Roaming\TeamViewer
2015-06-27 20:04 - 2012-12-28 23:24 - 00000000 ____D C:\Users\Bodlinka\AppData\Roaming\DAEMON Tools Lite
2015-06-27 20:03 - 2015-02-18 19:13 - 00000000 ___DC C:\WINDOWS\Panther
2015-06-27 18:10 - 2014-11-30 01:16 - 00000000 ____D C:\Users\Bodlinka\Documents\Peďák
2015-06-25 21:04 - 2012-07-26 09:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-06-23 20:57 - 2012-09-21 03:24 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-06-23 12:00 - 2013-02-11 00:49 - 00000000 ____D C:\Users\Bodlinka\AppData\Roaming\BSplayer
2015-06-23 10:40 - 2012-12-25 11:14 - 00002447 _____ C:\Users\Bodlinka\Desktop\Google Chrome.lnk
2015-06-22 19:00 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2015-06-20 05:02 - 2015-04-20 02:22 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-06-20 05:02 - 2015-04-20 02:22 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-16 21:08 - 2014-12-18 00:31 - 00000000 ____D C:\Users\Bodlinka\AppData\Roaming\vlc
2015-06-16 14:11 - 2013-06-26 07:39 - 00000000 ____D C:\Users\Bodlinka\Documents\Ostatní
2015-06-13 17:33 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2015-06-13 09:52 - 2013-08-22 16:44 - 00483368 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-06-13 09:40 - 2013-08-22 17:36 - 00000000 ___RD C:\WINDOWS\ToastData
2015-06-13 09:40 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-06-10 21:10 - 2012-12-28 23:45 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-10 21:06 - 2013-08-13 13:42 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-06-10 20:55 - 2012-12-19 09:14 - 140135120 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-06-10 20:52 - 2012-07-26 07:26 - 00000191 _____ C:\WINDOWS\win.ini
2015-06-07 17:42 - 2012-12-25 17:27 - 00000000 ____D C:\ProgramData\Skype
2015-06-07 17:30 - 2015-04-20 02:13 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-06-07 17:30 - 2014-11-21 14:14 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2015-05-29 20:08 - 2015-05-28 13:32 - 00016186 _____ C:\GingerSetupHelper.log
2015-05-29 20:08 - 2015-05-28 13:32 - 00002254 _____ C:\GingerSetup.log
2015-05-29 20:07 - 2013-10-10 21:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

==================== Files in the root of some directories =======

2012-09-21 03:35 - 2012-09-21 03:35 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-28 12:37

==================== End of log ============================

Budkyns
Level 2.5
Level 2.5
Příspěvky: 252
Registrován: srpen 09
Pohlaví: Nespecifikováno
Stav:
Offline

Re: vyskak. oken, reklam, spojeno s detekcí škodlivostí Avas

Příspěvekod Budkyns » 28 čer 2015 18:50

Additional scan result of Farbar Recovery Scan Tool (x64) Version:28-06-2015
Ran by Bodlinka at 2015-06-28 18:41:28
Running from C:\Users\Bodlinka\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-4138806220-3288153000-4149962190-500 - Administrator - Disabled)
Bodlinka (S-1-5-21-4138806220-3288153000-4149962190-1005 - Administrator - Enabled) => C:\Users\Bodlinka
Guest (S-1-5-21-4138806220-3288153000-4149962190-501 - Limited - Disabled)
UpdatusUser (S-1-5-21-4138806220-3288153000-4149962190-1001 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKLM-x32\...\uTorrent) (Version: 3.3.0.29111 - BitTorrent Inc.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 17.0.0.144 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader XI - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.7 - Atheros Communications Inc.)
Avanquest update (HKLM-x32\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.34 - Avanquest Software)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.9.11.4119 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\...\{E78B4959-B348-4913-874B-FF982378E035}) (Version: 0.9.11.4119 - BlueStack Systems, Inc.)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.64.1073 - AB Team, d.o.o.)
CCleaner (HKLM\...\CCleaner) (Version: 5.07 - Piriform)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.46.1.0327 - DT Soft Ltd)
DJ OldGames Package: Bomberman (NES) (HKLM-x32\...\BombermanNES40) (Version: 1.0.3.0 - DJ)
Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.8000.16 - Dolby Laboratories Inc)
Dropbox (HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 8.0.2.4 - Lenovo)
Energy Management (x32 Version: 8.0.2.4 - Lenovo) Hidden
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Free YouTube to MP3 Converter version 3.12.44.820 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.44.820 - DVDVideoSoft Ltd.)
Google Chrome (HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\Google Chrome) (Version: 43.0.2357.130 - Google Inc.)
GroupDynamics 1.0.1 (HKLM-x32\...\{A9F459AD-DE84-44C4-A297-B78A221C0DE5}_is1) (Version: 1.0.1 - Simone Capretti)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.4.1001 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Java 7 Update 13 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217013F0}) (Version: 7.0.130 - Oracle)
Java 7 Update 21 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217017FF}) (Version: 7.0.210 - Oracle)
Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.1901 - Broadcom Corporation)
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0333}) (Version: 1.12.824.1 - Vimicro)
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.0710 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.0.0.0710 - CyberLink Corp.) Hidden
Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.3.3 - ELAN Microelectronic Corp.)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4310.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.4310.52 - CyberLink Corp.) Hidden
Lenovo Solution Center (HKLM\...\{2F45A217-E9C7-4984-B0AC-5BE31FF4712B}) (Version: 2.4.003.00 - Lenovo Group Limited)
Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.1.3127 - CyberLink Corp.)
Lenovo YouCam (x32 Version: 4.1.3127 - CyberLink Corp.) Hidden
Lenovo_Wireless_Driver (HKLM-x32\...\{5D642A72-8194-4A22-80DA-11FE610CCA8E}) (Version: 6.30.5926 - Lenovo)
Malwarebytes Anti-Malware verze 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MediaHuman YouTube to MP3 Converter verze 3.7.3 (HKLM-x32\...\MediaHuman YouTube to MP3 Converter_is1) (Version: 3.7.3 - )
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{59E4543A-D49D-4489-B445-473D763C79AF}) (Version: 2.0.672.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mozilla Firefox 35.0.1 (x86 cs) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 cs)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
NVIDIA Ovladače grafiky 306.97 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 306.97 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.0613 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0613 - NVIDIA Corporation)
NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
Ovládací panel NVIDIA 306.97 (Version: 306.97 - NVIDIA Corporation) Hidden
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
Popcorn Time (HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\Popcorn Time) (Version: - Popcorn Official)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.9109 - CyberLink Corp.)
QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39030 - Realtek Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
Seznam Instalátor (HKLM-x32\...\ssinstall) (Version: - Seznam.cz)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.5 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.102 - Skype Technologies S.A.)
SugarSync Manager (HKLM-x32\...\SugarSync) (Version: 1.9.61.90905 - SugarSync, Inc.)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.26297 - TeamViewer)
The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.0.615 - Electronic Arts)
Total Commander (Remove or Repair) (HKLM-x32\...\Totalcmd) (Version: 7.57a - Ghisler Software GmbH)
Unity Web Player (HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\UnityWebPlayer) (Version: - Unity Technologies ApS)
UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.9 - Lenovo)
UserGuide (x32 Version: 1.0.0.9 - Lenovo) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Driver Package - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) (HKLM\...\71BC3FD63F450BA0A957AAECBDB4A000C4F2BE42) (Version: 06/15/2012 8.1.0.1 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) (HKLM\...\8A223E56FB1ED4F697B54E5BF96F1EB63B512684) (Version: 06/19/2012 10.13.29.733 - Lenovo)
Zoo Tycoon 2 - Extinct Animals (HKLM-x32\...\InstallShield_{15292416-A464-4FBA-BB96-7298EAACFC07}) (Version: 1.00.0000 - Microsoft Game Studios)
Zoo Tycoon 2 - Extinct Animals (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden
ZTE Drivers (HKLM-x32\...\{ACC9984D-E78B-4fcd-BE44-4E3F186DDA33}) (Version: 1.2059.0.12 - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Bodlinka\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Bodlinka\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Bodlinka\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bodlinka\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bodlinka\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bodlinka\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bodlinka\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bodlinka\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bodlinka\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bodlinka\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bodlinka\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points =========================

10-06-2015 20:35:03 Windows Update
18-06-2015 00:21:54 Naplánovaný kontrolní bod
23-06-2015 20:49:05 Installed Zoo Tycoon 2 - Extinct Animals
27-06-2015 18:27:03 Windows Update

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2015-06-28 17:43 - 00000753 ____A C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {159F586C-45B6-46F5-AAEB-9C0E43143B4B} - System32\Tasks\Lenovo\LSC\Time72Task => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {187ACF1E-EE3C-4C84-B9F7-931F3D1BED81} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2012-07-27] (CyberLink)
Task: {300667B9-0A25-471A-96D3-2553E5D7498B} - \avastBCLRestartS-1-5-21-4138806220-3288153000-4149962190-1005 No Task File <==== ATTENTION
Task: {36410C99-1870-4A3F-973D-2F60496EDB26} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {556300AB-3317-4FEF-B133-580F40DD3F60} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-06-18] (Avast Software s.r.o.)
Task: {5A0A8A0C-B01F-46AD-8C7B-80820AC9130A} - System32\Tasks\{E8402788-111C-488E-B2F6-32A7883267C2} => Chrome.exe http://www.skype.com/go/downloading?sou ... tError=404
Task: {74C0471E-DDE8-43FA-8D16-0EAAD8CE83E3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-11-06] (Facebook Inc.)
Task: {769F9C91-0CE1-4193-9D31-1D01C3DD6295} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-06-10] (Microsoft Corporation)
Task: {841BAF0E-6CBF-4EA7-921C-2AA22A90F0DE} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\BrowserChoice\browserchoice.exe
Task: {97AE706A-C44A-4C06-B10E-AA4565662FF1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-25] (Google Inc.)
Task: {C0C16589-851B-48F6-8949-1FEC70FCFC64} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-25] (Google Inc.)
Task: {C6A2C352-F2EE-42C6-AEDC-CEB6710C56E1} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-11-06] (Facebook Inc.)
Task: {D105CA2D-DA96-420E-AFC5-9504D7F8E696} - System32\Tasks\{8CA195E5-4E80-42D9-9386-D9182981E2C1} => pcalua.exe -a "C:\Program Files (x86)\RCP\unins000.exe"
Task: {D19CABF9-A2D8-4470-8B75-FB985D6433AA} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
Task: {D210FCDB-AB6C-4F5D-8959-F0D3F5A7B788} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {D71D7A4C-BFF8-40DE-A66F-FD4F56EEB71A} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-05-06] (Lenovo)
Task: {DBD8C28C-4787-416C-9D8D-5743CF7B83F0} - System32\Tasks\{D6B13D25-BF74-4F39-9354-231C4DBBCF6B} => Chrome.exe http://ui.skype.com/ui/0/6.9.0.106/cs/a ... rogressBar
Task: {DC233F8F-DF11-408D-87A5-BB456F084E79} - System32\Tasks\Lenovo\LSC\RebootCountTask => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {E381F116-0F12-4337-A92A-4717B3085BE5} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-06-01] (Piriform Ltd)
Task: {F25DFB29-0B5A-4361-9456-629148572690} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2014-05-06] (Lenovo)
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core.job => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA.job => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core.job => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA.job => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2013-12-26 20:42 - 2013-12-26 20:42 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2012-08-27 00:48 - 2012-08-27 00:48 - 00044408 _____ () C:\Program Files\Lenovo\Bluetooth Software\BtwLeAPI.dll
2014-01-30 00:02 - 2014-01-30 00:02 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2015-06-01 19:28 - 2015-06-01 19:28 - 00047104 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2015-06-28 12:34 - 2015-06-28 12:34 - 02952704 _____ () C:\Program Files\AVAST Software\Avast\defs\15062800\algo.dll
2015-03-14 18:35 - 2015-03-14 18:35 - 38714440 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2012-09-21 03:24 - 2012-06-25 19:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\mojebanka.cz -> hxxps://etrading.mojebanka.cz


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4138806220-3288153000-4149962190-1001\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\Bodlinka\Downloads\the_avengers-2560x1600.jpg
DNS Servers: 192.168.1.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "RemoteControl10"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{2C5CE87B-FC61-4356-9A4E-8F39406956AF}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [TCP Query User{869F57E0-9AAF-46EA-82F5-D4B7958DA5E2}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [{89EF83D6-ADFD-415F-BD03-4917E21AFDD1}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{3C94F290-5CB8-421A-9643-4FB72E8C4B2D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{F483EFE9-80D2-42F9-971E-16B43790B4DC}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgdiagex.exe
FirewallRules: [{F8EE02B2-A5FB-4683-8A35-05318D413315}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgdiagex.exe
FirewallRules: [UDP Query User{2E997CD6-D7B6-4508-BEA3-2EEEA7AB34ED}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [TCP Query User{385FEF68-9280-4ABA-AB51-E7ABB66C3972}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [{DC093D6E-E44A-4957-B3B8-D0AADE4D453F}] => (Allow) C:\Users\Bodlinka\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{3B1EBEBF-68FA-4862-AF0C-1A2336D2D235}] => (Allow) C:\Users\Bodlinka\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{672BE683-E518-4422-A7B3-AB49B8E02771}] => (Allow) C:\Users\Bodlinka\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{37126C50-0AF1-44E5-9CF1-79DE1F5B651E}] => (Allow) C:\Users\Bodlinka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{21E4E38C-18A6-4D8B-9EBC-DBDD038ABA46}] => (Allow) C:\Users\Bodlinka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D1A061FF-7433-4656-8B40-E861372C8DD7}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{DEBF5EEF-F6E0-4113-A40C-B9F6A43D204B}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{58A793D7-DB24-41ED-842A-A6D3B0008DE2}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{637DD08A-1F4F-425C-8B38-DDE2FB478D72}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{63DD79E0-46F0-4B46-B97B-AF80E0F357A8}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{EC62CFD6-1C8A-4D99-863F-2037CB9FFBFF}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{3AB38C9A-31CC-49D9-887A-F10E74CBFA70}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [UDP Query User{D0F5E1C5-996C-4287-8F27-84E24A29A3E7}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{245D1C1D-B30E-4328-9E97-680825534565}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{7050B2A3-62AA-456A-8699-D7B279126608}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{80D30990-7647-4381-A73A-7B7A396BBB67}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{0954F511-8D6E-4CF9-81B5-FED2D993F57B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{6907862D-C252-4FA1-9DE2-7017F35A6F7C}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [UDP Query User{8FB7FB52-0DAF-41DD-81DE-C1F629F351C8}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{EEA63692-CE09-414C-A80D-F92105230A47}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{3471054B-EC46-41A7-8102-CEAD28EC0E2E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{578C5D1B-6E49-44A9-8E41-6B25478A1855}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{737A81E1-3DAE-4E75-A925-44880A696874}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{C724A037-F451-4307-8CC0-CAF3738EE773}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{B9F0D814-31D9-49DA-8BBD-87A3A923FE84}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{92EE6836-353C-4F4E-9617-8F39AA1A5A0A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [TCP Query User{D5D4ADB6-7AFF-462E-B41F-E2774D7FD103}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{8FD889A0-C655-4750-8943-768E03F1152A}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{99417659-827D-464E-99FA-FBB32302F791}C:\users\bodlinka\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\bodlinka\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{1F400F2C-5D5F-4BFA-B3CD-71E0C93F742F}C:\users\bodlinka\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\bodlinka\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{60B3172E-F8FD-483E-B61D-A9182AC4664D}] => (Allow) C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe
FirewallRules: [{A3731E8C-993A-4916-BDCB-45D48AB185C0}] => (Allow) C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/28/2015 06:34:29 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Službu nelze spustit. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
v BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
v System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (06/28/2015 05:34:21 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Službu nelze spustit. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
v BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
v System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (06/28/2015 04:58:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: insB564.tmp, verze: 3.0.0.0, časové razítko: 0x40daa4fa
Název chybujícího modulu: insB564.tmp, verze: 3.0.0.0, časové razítko: 0x40daa4fa
Kód výjimky: 0xc0000005
Posun chyby: 0x00058b94
ID chybujícího procesu: 0x1b08
Čas spuštění chybující aplikace: 0xinsB564.tmp0
Cesta k chybující aplikaci: insB564.tmp1
Cesta k chybujícímu modulu: insB564.tmp2
ID zprávy: insB564.tmp3
Úplný název chybujícího balíčku: insB564.tmp4
ID aplikace související s chybujícím balíčkem: insB564.tmp5

Error: (06/28/2015 04:54:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Explorer.EXE, verze: 6.3.9600.17667, časové razítko: 0x54c6f7c2
Název chybujícího modulu: SHELL32.dll, verze: 6.3.9600.17680, časové razítko: 0x54dc3611
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000000545a5
ID chybujícího procesu: 0x9fc
Čas spuštění chybující aplikace: 0xExplorer.EXE0
Cesta k chybující aplikaci: Explorer.EXE1
Cesta k chybujícímu modulu: Explorer.EXE2
ID zprávy: Explorer.EXE3
Úplný název chybujícího balíčku: Explorer.EXE4
ID aplikace související s chybujícím balíčkem: Explorer.EXE5

Error: (06/28/2015 00:24:49 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Službu nelze spustit. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
v BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
v System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (06/28/2015 11:33:09 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Službu nelze spustit. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
v BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
v System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (06/28/2015 01:16:20 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2 na řádku C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.

Error: (06/28/2015 01:16:20 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2 na řádku C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.

Error: (06/28/2015 01:05:25 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2 na řádku C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.

Error: (06/28/2015 01:05:25 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2 na řádku C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.


System errors:
=============
Error: (06/28/2015 06:38:55 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba NVIDIA Update Service Daemon přestala během spouštění reagovat.

Error: (06/28/2015 06:34:29 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba BlueStacks Android Service byla ukončena s následující chybou:
%%1064

Error: (06/28/2015 06:28:27 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/28/2015 06:28:26 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/28/2015 06:28:26 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/28/2015 06:28:25 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/28/2015 06:28:25 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/28/2015 05:34:21 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba BlueStacks Android Service byla ukončena s následující chybou:
%%1064

Error: (06/28/2015 01:44:15 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x800f0244): Intel Corporation driver update for Intel(R) HD Graphics.

Error: (06/28/2015 01:24:04 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x800f0244): Intel Corporation driver update for Intel(R) HD Graphics.


Microsoft Office:
=========================
Error: (06/28/2015 06:34:29 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Službu nelze spustit. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
v BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
v System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (06/28/2015 05:34:21 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Službu nelze spustit. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
v BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
v System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (06/28/2015 04:58:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: insB564.tmp3.0.0.040daa4fainsB564.tmp3.0.0.040daa4fac000000500058b941b0801d0b1b192019398C:\Users\Bodlinka\AppData\Local\Temp\insB564.tmpC:\Users\Bodlinka\AppData\Local\Temp\insB564.tmp14a52262-1da6-11e5-bf2c-c0143dc92474

Error: (06/28/2015 04:54:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Explorer.EXE6.3.9600.1766754c6f7c2SHELL32.dll6.3.9600.1768054dc3611c000000500000000000545a59fc01d0b18cbc66a802C:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\SHELL32.dll9917da88-1da5-11e5-bf2c-c0143dc92474

Error: (06/28/2015 00:24:49 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Službu nelze spustit. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
v BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
v System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (06/28/2015 11:33:09 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Službu nelze spustit. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
v BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
v System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (06/28/2015 01:16:20 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Bodlinka\Downloads\esetsmartinstaller_csy.exe

Error: (06/28/2015 01:16:20 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Bodlinka\Downloads\esetsmartinstaller_csy.exe

Error: (06/28/2015 01:05:25 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Bodlinka\Downloads\esetsmartinstaller_csy.exe

Error: (06/28/2015 01:05:25 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Bodlinka\Downloads\esetsmartinstaller_csy.exe


CodeIntegrity Errors:
===================================
Date: 2014-12-12 05:27:22.113
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\windows\SysWOW64\WerFault.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: Intel(R) Pentium(R) CPU B950 @ 2.10GHz
Percentage of memory in use: 34%
Total physical RAM: 3959.77 MB
Available physical RAM: 2597.21 MB
Total Pagefile: 5303.77 MB
Available Pagefile: 3884.91 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB

==================== Drives ================================

Drive c: (Windows8_OS) (Fixed) (Total:883.4 GB) (Free:476.27 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.78 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: BF01C911)

Partition: GPT Partition Type.

==================== End of log ============================

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: vyskak. oken, reklam, spojeno s detekcí škodlivostí Avas

Příspěvekod jaro3 » 28 čer 2015 21:24

Odinstaluj:
ESET
AVG2014


Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\Run: [Google Update] => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-10-25] (Google Inc.)
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\Run: [Facebook Update] => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-11-06] (Facebook Inc.)
URLSearchHook: [S-1-5-21-4138806220-3288153000-4149962190-1001] ATTENTION ==> Default URLSearchHook is missing
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
FF Extension: No Name - C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default\extensions\BMNEMEGJ50257956@NMROOPQ94813992.com [not found]
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Bodlinka\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Bodlinka\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
Task: {300667B9-0A25-471A-96D3-2553E5D7498B} - \avastBCLRestartS-1-5-21-4138806220-3288153000-4149962190-1005 No Task File <==== ATTENTION
Task: {74C0471E-DDE8-43FA-8D16-0EAAD8CE83E3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-11-06] (Facebook Inc.)
Task: {97AE706A-C44A-4C06-B10E-AA4565662FF1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-25] (Google Inc.)
Task: {C0C16589-851B-48F6-8949-1FEC70FCFC64} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-25] (Google Inc.)
Task: {C6A2C352-F2EE-42C6-AEDC-CEB6710C56E1} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-11-06] (Facebook Inc.)
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core.job => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA.job => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core.job => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA.job => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe


(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.

Aktualizuj javu:
[url= http://www.oracle.com/technetwork/java/ ... 33155.html
]Java SE Runtime Environment 8[/url]

Klikni na Accept License Agreement
Vyber si OS (Windows nebo Windows x64, Offline Installation)
jre-8-windows-i586-p.exe nebo
jre-8-windows-x64.exe
Stáhni ( download) a nainstaluj.
Ostatní javy odeber v přidat/odebrat programy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Budkyns
Level 2.5
Level 2.5
Příspěvky: 252
Registrován: srpen 09
Pohlaví: Nespecifikováno
Stav:
Offline

Re: vyskak. oken, reklam, spojeno s detekcí škodlivostí Avas

Příspěvekod Budkyns » 28 čer 2015 21:54

Fix result of Farbar Recovery Scan Tool (x64) Version:28-06-2015
Ran by Bodlinka at 2015-06-28 21:53:30 Run:1
Running from C:\Users\Bodlinka\Desktop
Loaded Profiles: UpdatusUser & Bodlinka (Available Profiles: UpdatusUser & Bodlinka)
Boot Mode: Normal
==============================================

fixlist content:
*****************
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\Run: [Google Update] => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-10-25] (Google Inc.)
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\...\Run: [Facebook Update] => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-11-06] (Facebook Inc.)
URLSearchHook: [S-1-5-21-4138806220-3288153000-4149962190-1001] ATTENTION ==> Default URLSearchHook is missing
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
FF Extension: No Name - C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default\extensions\BMNEMEGJ50257956@NMROOPQ94813992.com [not found]
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Bodlinka\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Bodlinka\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
Task: {300667B9-0A25-471A-96D3-2553E5D7498B} - \avastBCLRestartS-1-5-21-4138806220-3288153000-4149962190-1005 No Task File <==== ATTENTION
Task: {74C0471E-DDE8-43FA-8D16-0EAAD8CE83E3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-11-06] (Facebook Inc.)
Task: {97AE706A-C44A-4C06-B10E-AA4565662FF1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-25] (Google Inc.)
Task: {C0C16589-851B-48F6-8949-1FEC70FCFC64} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-25] (Google Inc.)
Task: {C6A2C352-F2EE-42C6-AEDC-CEB6710C56E1} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-11-06] (Facebook Inc.)
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core.job => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA.job => C:\Users\Bodlinka\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core.job => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA.job => C:\Users\Bodlinka\AppData\Local\Google\Update\GoogleUpdate.exe
*****************

HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value removed successfully
HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update => value removed successfully
Could not restore Default URLSearchHook.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}" => key removed successfully
HKCR\Wow6432Node\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => key removed successfully
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
"HKU\S-1-5-21-4138806220-3288153000-4149962190-1005\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}" => key removed successfully
HKCR\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found.
C:\Users\Bodlinka\AppData\Roaming\Mozilla\Firefox\Profiles\v43kt7dg.default\extensions\BMNEMEGJ50257956@NMROOPQ94813992.com not found.
"HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}" => key removed successfully
"HKU\S-1-5-21-4138806220-3288153000-4149962190-1005_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{300667B9-0A25-471A-96D3-2553E5D7498B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{300667B9-0A25-471A-96D3-2553E5D7498B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avastBCLRestartS-1-5-21-4138806220-3288153000-4149962190-1005" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{74C0471E-DDE8-43FA-8D16-0EAAD8CE83E3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{74C0471E-DDE8-43FA-8D16-0EAAD8CE83E3}" => key removed successfully
C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{97AE706A-C44A-4C06-B10E-AA4565662FF1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{97AE706A-C44A-4C06-B10E-AA4565662FF1}" => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C0C16589-851B-48F6-8949-1FEC70FCFC64}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C0C16589-851B-48F6-8949-1FEC70FCFC64}" => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C6A2C352-F2EE-42C6-AEDC-CEB6710C56E1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6A2C352-F2EE-42C6-AEDC-CEB6710C56E1}" => key removed successfully
C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core" => key removed successfully
C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core.job => moved successfully.
C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA.job => moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005Core.job => moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4138806220-3288153000-4149962190-1005UA.job => moved successfully.

==== End of Fixlog 21:53:31 ====

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: vyskak. oken, reklam, spojeno s detekcí škodlivostí Avas

Příspěvekod jaro3 » 29 čer 2015 09:16

Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Budkyns
Level 2.5
Level 2.5
Příspěvky: 252
Registrován: srpen 09
Pohlaví: Nespecifikováno
Stav:
Offline

Re: vyskak. oken, reklam, spojeno s detekcí škodlivostí Avas  Vyřešeno

Příspěvekod Budkyns » 29 čer 2015 09:23

mnohem lepší, zdá se, že v pořádku :-) moc děkuji, označuji fajfkou


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 66 hostů