Problémy mi to bohužel neopravilo, jen vedlejší ztráty se kterými jsem počítal. Smazalo mi to totiž historii, custom nastavení prohlížečů a některé oblíbené programy. Naví mi vznikla služba po spuštění, se kterou nejde nijak hnout, ani se podívat na vlastnosti, zřejmě odinstalovaná aplikae Lightshot od Skillbrains. Viz obrázek.
Dále na obrázku je, že mi některý z programů zřejmě nějak poškodil hosts soubor (Zoek). Viz obrázek.
Všiml jsi si v některém logu něčeho zajímavého? Hádám, že žádný vir jsem v notebooku ani neměl ne? Děkuji ti mo za pomo, i když to bylo k ničemu, nenapadá mě, o s tím dělat, tak asi zavolám technika od Dell, ať přijede s klávesnicí. Ještě zkusím vymyslet nějak ověřit tu myš, jestli skutečně nekliká dvakrát někdy, všiml jsem si toho ale už ve vícce programech. Tak celkově nevím o s tím, znamenalo by to velký špatný, když bbne jak klávesnie, tak i myš.Ale to by zase neblbla jen nejspíš jedná klávesa to céčko. Nechápu co se mi to zase děje, HW nerozumím, ale obvykle tehnické věci nemám problém pochopit.
RKRogueKiller Anti-Malware V14.4.0.0 (x64) [Apr 1 2020] (Free) by Adlice Software
mail :
https://adlice.com/contact/Website :
https://adlice.com/download/roguekiller/Operating System : Windows 10 (10.0.18362) 64 bits
Started in : Normal mode
User : Petr [Administrator]
Started from : C:\Users\Petr\Desktop\RogueKiller_portable64.exe
Signatures : 20200401_101244, Driver : Loaded
Mode : Standard Scan, Delete -- Date : 2020/04/04 20:04:22 (Duration : 00:09:05)
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUM.Proxy (Potentially Malicious)] HKEY_USERS\S-1-5-21-1655598053-1459283977-1014168971-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings|ProxyServer -- -> Deleted
[PUM.Proxy (Potentially Malicious)] network.proxy.http -- server.cz -> Deleted
[PUM.Proxy (Potentially Malicious)] network.proxy.http_port -- 3128 -> Deleted
ZoekZoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by Petr on 04.04.2020 at 20:08:21,36.
Microsoft Windows 10 Home 10.0.18362 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Petr\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
04.04.2020 20:10:19 Zoek.exe System Restore Point Created Successfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
C:\PROGRA~2\COMMON~1\IObit deleted successfully
C:\PROGRA~3\SoftwareDistribution deleted successfully
C:\PROGRA~3\ssh deleted successfully
C:\PROGRA~3\SupportAssist deleted successfully
C:\Users\outlook\AppData\Local\VirtualStore deleted successfully
C:\Users\outlook.DESKTOP-7GJSA1T\AppData\Local\PlaceholderTileLogoFolder deleted successfully
C:\Users\outlook.DESKTOP-7GJSA1T\AppData\Local\VirtualStore deleted successfully
C:\Users\Petr\AppData\Local\DBG deleted successfully
C:\Users\Petr\AppData\Local\GHISLER deleted successfully
C:\Users\Petr\AppData\Local\gtk-3.0 deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\DBG deleted successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Packages deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\outlook.DESKTOP-7GJSA1T\AppData\Roaming\Mozilla\Firefox\Profiles\xyzrb2ju.default-release\prefs.js:
Added to C:\Users\outlook.DESKTOP-7GJSA1T\AppData\Roaming\Mozilla\Firefox\Profiles\xyzrb2ju.default-release\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\tk5p2pf2.default-release\prefs.js:
Added to C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\tk5p2pf2.default-release\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Petr\AppData\Roaming\Thunderbird\Profiles\u83iqws3.default\prefs.js:
Added to C:\Users\Petr\AppData\Roaming\Thunderbird\Profiles\u83iqws3.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\25qzwwv1.default\prefs.js:
Added to C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\25qzwwv1.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\outlook.DESKTOP-7GJSA1T\AppData\Roaming\Mozilla\Firefox\Profiles\xyzrb2ju.default-release
user.js not found
---- Lines searchengine removed from prefs.js ----
user_pref("browser.pageActions.persistedActions", "{\"version\":1,\"ids\":[\"bookmark\",\"pinTab\",\"bookmarkSeparator\",\"copyURL\",\"emailLink\",\"a
---- FireFox user.js and prefs.js backups ----
prefs__2039_.backup
ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\tk5p2pf2.default-release
user.js not found
---- Lines searchengine removed from prefs.js ----
user_pref("browser.pageActions.persistedActions", "{\"version\":1,\"ids\":[\"bookmark\",\"pinTab\",\"bookmarkSeparator\",\"copyURL\",\"emailLink\",\"a
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 3);
---- FireFox user.js and prefs.js backups ----
prefs__2039_.backup
ProfilePath: C:\Users\Petr\AppData\Roaming\Thunderbird\Profiles\u83iqws3.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__2039_.backup
ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\25qzwwv1.default
user.js not found
---- FireFox user.js and prefs.js backups ----
==== Deleting Files \ Folders ======================
C:\Users\Petr\AppData\Roaming\Code deleted
C:\Users\Petr\AppData\Roaming\GitHub Desktop deleted
C:\Users\Petr\.android deleted
C:\PROGRA~2\Skillbrains deleted
C:\PROGRA~3\{2F8AE550-5F50-4773-BF82-805D99AD42B5} deleted
C:\PROGRA~3\{D76294E6-03B8-4971-AF2E-3F846161A690} deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Petr\AppData\Local\updater.log deleted
C:\Users\Petr\AppData\Local\cache deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd36c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd3ad.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd3be.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd3d0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd3d2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd3e4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd3f5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd407.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd419.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd42a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd43c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd44d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd44f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd461.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd473.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd484.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd486.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd498.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-158-d8c-5fd4aa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a08e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a0bf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a0d0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a0e2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a0f4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a105.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a117.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a129.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a12b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a13c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a14e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a150.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a161.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a173.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a185.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a1a6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a1a8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a1c9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16b8-1060-67a1cb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a76080.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a760a1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a760b3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a76151.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a76163.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a76175.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a76186.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a76198.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a761a9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a761da.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a7624a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a7625b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a7627d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a7628e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a762af.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a762c1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a76350.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a76361.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1894-ac0-a76373.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7a4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7b6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7b8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7ba.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7cc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7ce.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7d0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7e1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7e3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7e5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7f7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7f9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac7fb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac80c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac81e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac820.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac822.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac824.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1fa4-21c4-1ac826.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-2048508a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-2048509c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-204850ae.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-204850bf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-204850d1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-204850e3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-204850e5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-204850f6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-20485108.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-20485119.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-2048511b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-2048512d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-2048513f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-20485150.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-20485162.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-20485164.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-20485176.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-20485187.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-28c0-63d4-20485199.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae164.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae1c4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae1e5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae206.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae227.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae239.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae24b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae25c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae26e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae28f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae2a1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae2b2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae2d4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae2e5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae307.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae328.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae339.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae35b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b28-2b10-ae3ca.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-32267a4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-32267d5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-32267e6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-3226807.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-3226819.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-322681b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-322682d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-322683e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-3226850.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-3226862.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-3226873.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-3226875.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-3226887.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-3226898.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-32268aa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-32268bc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-32268cd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-32268cf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c10-1740-32268e1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a2400.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a2411.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a2423.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a2434.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a2446.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a2448.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a245a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a246b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a247d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a247f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a2491.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a24a2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a24b4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a24c5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a24d7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a24d9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a24fa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a24fc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2f24-2fa4-a250e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d57b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d59c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d5ad.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d5af.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d5c1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d5c3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d5d5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d5d7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d5e8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d5ea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d5fc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d5fe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d610.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d612.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d614.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d625.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d637.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d639.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3264-22ec-32d64a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f6681.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f66a2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f66b3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f66b5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f66c7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f66e8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f66ea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f670c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f671d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f673e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f676f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f68d9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f68ea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f691b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f693c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f694e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f697f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f6991.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-58c0-1cb4-1a4f69a2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea3a0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea3b2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea3c4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea3d5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea3e7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea3e9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea3fa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea40c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea42d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea44f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea451.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea462.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea483.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea495.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea497.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea4b8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea4da.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea4eb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-a34-900-2ea50c.tmp deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deleted
C:\Users\Petr\AppData\Roaming\Thunderbird\Profiles\u83iqws3.default\extensions\staged deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\outlook.DESKTOP-7GJSA1T\AppData\Roaming\Mozilla\Firefox\Profiles\xyzrb2ju.default-release
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\tk5p2pf2.default-release
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Petr\AppData\Roaming\Thunderbird\Profiles\u83iqws3.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\25qzwwv1.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions ======================
ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\tk5p2pf2.default-release
- Firefox Multi-Account Containers - %ProfilePath%\extensions\@testpilot-containers.xpi
- esk slovnk pro kontrolu pravopisu - %ProfilePath%\extensions\cs@dictionaries.addons.mozilla.org.xpi
- BuiltWith - %ProfilePath%\extensions\gary@builtwith.com.xpi
- __MSG_name__ - %ProfilePath%\extensions\jid0-jJRRRBMgoShUhb07IvnxTBAl29w@jetpack.xpi
- short_ __MSG_extensionDescription__ - %ProfilePath%\extensions\jid1-KKzOGWgsW3Ao4Q@jetpack.xpi
- __MSG_name__ - %ProfilePath%\extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi
- Page Hacker - %ProfilePath%\extensions\pagehacker-nico@nc.xpi
- Self Destroying Cookies - %ProfilePath%\extensions\selfdestroyingcookies@dirtylittlehelpers.com.xpi
- manifest_version:2__MSG_manifest_app_name__version:2.5.20description:__MSG_manifest_app_description__key:MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkhwZJT76btQ04EEMOFtZPLESD1TmSVjbLjs0OyesD9Ht8YllFPfJ3qmtbSQGVuvmxH1GKjUO2QcEWb8bHuOjoRlq20fi5j5Aq90O8FKETy5D8PxCyi3WmnquiEwaE5cNmaCswG2JlObZOtdQQKOvMxBAegABYimEGfSvCMVUEvpymys0gBhLoch72zPAiJUBkf0z8BtjYTueMRcRXkrSeRPLygUDQnZ1TkQWMYYBpzqpD5ggxytAklEMQzR9Hn0lqu5s7iuUAgihbysPn8Wh00Zj5FySpKKcpG3JS7UWxC28oSt8z5ZR3YimnXHX3P36V0mC1pgM4o7wIDAQABicons:16:imgiconsomega-action-16.png24:imgiconsomega-action-24.png32:imgiconsomega-action-32.png48:imgiconsomega-48.png64:imgiconsomega-64.png128:imgiconsomega-128.pngdefault_locale:enbrowser_action:browser_style:falsedefault_icon:16:imgiconsomega-action-16.png19:imgiconsomega-action-19.png24:imgiconsomega-action-24.png32:imgiconsomega-action-32.pngdefault_title:__MSG_manifest_icon_default_title__default_popup:popupindex.htmlbackground:page:background.htmlminimum_chrome_version:22.0.0options_page:options.htmloptions_ui:page:options.htmlbrowser_style:falseopen_in_tab:truepermissions:[proxytabsalarmsstoragewebRequestwebRequestBlockingcontextMenushttp:https:<all_urls>]commands:_execute_browser_action:suggested_key:default:AltShiftOapplications:gecko:id:switchyomega@feliscatus.addons.mozilla.orgstrict_min_version:55.0a1 - %ProfilePath%\extensions\switchyomega@feliscatus.addons.mozilla.org.xpi
- short_ YT NonStop - %ProfilePath%\extensions\{0d7cafdd-501c-49ca-8ebb-e3341caaa55e}.xpi
- Flagfox - %ProfilePath%\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi
- theme: images: theme_frame: ff35_header7.jpg colors: frame: d6b98b tab_background_text: 5c4c39 version: 2.0 A Web Browser Renaissance manifest_version: 2 description: Within the web today a browsing transformation is underway. We\u00e2\u20ac\u2122re seeing constant advancement from the static browsing Middle Ages of old and the ushering in of a new Modern Era of openness speed and security.\n\nTaking advantage of all the glorious advancements this new era has to offer has never been easier with the newly relased Firefox 3.5 - %ProfilePath%\extensions\{2c5529f0-50b9-4b77-a149-4a3f0378ef33}.xpi
- Disable JavaScript - %ProfilePath%\extensions\{41f9e51d-35e4-4b29-af66-422ff81c8b41}.xpi
- JavaScript Toggle On and Off - %ProfilePath%\extensions\{479f0278-2c34-4365-b9f0-1d328d0f0a40}.xpi
- Empty Cache Button - %ProfilePath%\extensions\{4cc4a13b-94a6-7568-370d-5f9de54a9c7f}.xpi
- Javascript Control - %ProfilePath%\extensions\{591abe66-4392-4d7e-aad5-12f04be2539e}.xpi
- Popup Blocker Ultimate - %ProfilePath%\extensions\{60B7679C-BED9-11E5-998D-8526BB8E7F8B}.xpi
- Cookie Quick Manager - %ProfilePath%\extensions\{60f82f00-9ad5-4de5-b31c-b16a47c51558}.xpi
- NoScript - %ProfilePath%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
- short_ Distill - %ProfilePath%\extensions\{7a73dc4b-1b38-40e7-ac56-7d356dd4af34}.xpi
- __MSG_appName__short_Web of Trustversion:20200329.0wotmanifest_version:2description:__MSG_appDescription__default_locale:enauthor:MyWOTicons:16:images16x16.png18:images18x18.png20:images20x20.png24:images24x24.png32:images32x32.png40:images40x40.png48:images48x48.png96:images96x96.png128:images128x128.pngpermissions:[tabscontextMenushttp:www.mywot.comhttp:api.mywot.comhttps:api.mywot.comwebNavigationwebRequestwebRequestBlockinghttp:https:storage]browser_action:default_icon:20:images20x20.png40:images40x40.png48:images48x48.pngdefault_title:__MSG_appTooltip__default_popup:popup.htmlbackground:scripts:[scriptscrossbrowser.jslibslodash.min.jslibsredux.min.jslibsredux-thunk.min.jslibsreact-chrome-redux.jsscriptssharedconstants.jsscriptssharedutils.jsscriptssharedwotCrypto.jsscriptssharedwotApi.jsscriptssharedwotAuthApi.jsscriptssharedpiFilter.jsscriptsbackgroundappcommonmyClass.jsscriptsbackgroundappcommoncommon.jsscriptsbackgroundappdefaultState.jsscriptsbackgroundapptabsCache.jsscriptsbackgroundappactions.jsscriptsbackgroundappaliases.jsscriptsbackgroundapplp-handler.jsscriptsbackgroundappreducers.jsscriptsbackgroundappmain.jsscriptsbackgroundindex.js]content_scripts:[matches:[http:https:]css:[stylesmain.css]js:[scriptscrossbrowser.jslibslodash.min.jslibsreact.min.jslibsreact-dom.min.jslibsreact-redux.min.jslibsreact-chrome-redux.jsscriptssharedconstants.jsscriptssharedfonts.jsscriptssharedutils.jsscriptssharedwotCrypto.jsscriptssharedwotApi.jsscriptsbackgroundappactions.jsscriptscontentcomponentscommonwarningReportsContainer.jsscriptscontentcomponentscommonbuttonAction.jsscriptscontentcomponentscommonreputationBubble.jsscriptscontentcomponentscommonsecurityBubble.jsscriptscontentcomponentsdonutdonut.jsscriptscontentcomponentsdonutdonutTooltip.jsscriptspopupcomponentsformattedString.jsscriptscontentcomponentswarningwarningAttributes.jsscriptscontentcomponentswarningwarningActionsContainer.jsscriptscontentcomponentswarningwarningMessageContainer.jsscriptscontentcomponentswarningwarningStrip.jsscriptscontentcomponentswarningoptoutStrip.jsscriptscontentcomponentswarningbadRatingNotification.jsscriptscontentcomponentswarningwarning.jsscriptscontentcomponentscommonextendHandler.jsscriptscontentcomponentscommonpreviewHandler.jsscriptscontentserpHandler.jsscriptscontentredirectHandler.jsscriptscontentsharingHandler.jsscriptscontentwarningHandler.jsscriptscontentsocialAuthHandler.jsscriptscontentindex.js]run_at:document_endall_frames:truematches:[:.mywot.com]js:[scriptscontentextInfo.js]run_at:document_startall_frames:false]web_accessible_resources:[images.gifstyles.cssresources.json]options_ui:page:options.htmlchrome_style:falseopen_in_tab:trueapplications:gecko:id:a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7strict_min_version:48.0 - %ProfilePath%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}.xpi
- short_ Updatescan - %ProfilePath%\extensions\{c07d1a49-9894-49ff-a594-38960ede8fb9}.xpi
- short_ __MSG_name__ - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- Javascript Switcher - %ProfilePath%\extensions\{d7e0a6e7-9a50-490a-be5c-3b448be39b42}.xpi
- Image Search - %ProfilePath%\extensions\{eca87045-b95d-4180-8a0e-16d877af69b8}.xpi
- Toolbox for Google Play Store - %ProfilePath%\extensions\{f7e00fda-62e6-4361-8450-a335408e1efe}.xpi
ProfilePath: C:\Users\Petr\AppData\Roaming\Thunderbird\Profiles\u83iqws3.default
- Undetermined - %ProfilePath%\extensions\cs@dictionaries.addons.mozilla.org
- DKIM Verifier - %ProfilePath%\extensions\dkim_verifier@pl.xpi
- QuickFolders - %ProfilePath%\extensions\quickfolders@curious.be.xpi
- __MSG_appName__ - %ProfilePath%\extensions\sendlater3@kamens.us.xpi
- Remove Duplicate Messages Alternate - %ProfilePath%\extensions\{a300a000-5e21-4ee0-a115-9ec8f4eaa92b}.xpi
- Undetermined - %ProfilePath%\extensions\{a62ef8ec-5fdc-40c2-873c-223b8a6925cc}.xpi
- Undetermined - %ProfilePath%\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}.xpi
ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\25qzwwv1.default
- Undetermined - %ProfilePath%\extensions\sko-extension@firma.seznam.cz
- Undetermined - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
==== Firefox Plugins ======================
Profilepath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\tk5p2pf2.default-release
- C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_344.dll - [?]
B1E9E7809E3793A7950D4F761C782C3E - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
==== Fake Chromium Profiles Check ======================
Fake profile C:\Users\outlook\AppData\Local\Google\Chrome deleted
Fake profile C:\Users\outlook.DESKTOP-7GJSA1T\AppData\Local\Google\Chrome deleted
==== Chromium Look ======================
Chrome Media Router - Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/?clid=29530"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/?clid=29530"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} -
http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
HKCU\SearchScopes\{06DAA207-9C8C-40C1-B0A4-07098DE84C67} -
http://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_29530
HKCU\SearchScopes\{2D9969DC-AB37-4F71-825F-11359CFEA908} -
http://www.firmy.cz/?q={searchTerms}&sourceid=QuickSearch_29530
HKCU\SearchScopes\{3FF70CAB-C0B3-42A3-9946-2AE726F26CC9} -
http://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_29530
HKCU\SearchScopes\{6A861BF9-14A3-43B9-AC57-504598E5093F} -
http://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_29530
HKCU\SearchScopes\{745E554D-1A9F-40C8-8A56-E3878178E0DE} -
http://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_29530
HKCU\SearchScopes\{B2D51387-0CE4-4F81-9360-DCE690596A1E} -
http://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=QuickSearch_29530
HKCU\SearchScopes\{CD59AA6C-C521-493A-B273-CC2145A5B505} -
http://www.mapy.cz/?query={searchTerms}&sourceid=QuickSearch_29530
HKCU\SearchScopes\{DC6B39B1-C79E-4E2E-8990-73F4B88FD55D} -
http://www.novinky.cz/hledej?w={searchTerms}&sourceid=QuickSearch_29530
==== Reset Google Chrome ======================
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web Data.ReadOnly was reset successfully
==== Empty IE Cache ======================
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Petr\AppData\Local\Mozilla\Firefox\Profiles\tk5p2pf2.default-release\cache2 emptied successfully
==== Empty Edge Cache ======================
Edge Cache Emptied Successfully
==== Empty Chrome Cache ======================
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=448 folders=290 47950757 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\outlook\AppData\Local\Temp emptied successfully
C:\Users\outlook.DESKTOP-7GJSA1T\AppData\Local\Temp emptied successfully
C:\Users\Petr\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\Users\Petr\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on 04.04.2020 at 20:49:58,46 ======================
ZemanaInformace o kontroly
Název produktu : Zemana AntiMalware
Stav kontroly : Dokončena
Datum kontroly : 04.04.2020 20:58:07
Typ kontroly : Inteligentní kontrola
Čas trvání : 00:00:38
Zkontrolované objekty : 1936
Zjištěné objekty : 5
Vyloučené objekty : 0
Automatické odesílání : Ano
Operační systém : Windows 10 x64
Procesor : 4X Intel(R) Core(TM) i3-6006U CPU @ 2.00GHz
Režim systému BIOS : UEFI
Informace o doméně : WORKGROUP,False,NetSetupWorkgroupName
CUID : 149C3A2F578B524B86982D
Odhalení
MD5 :
Stav : Zkontrolováno
Objekt : c:\users\petr\appdata\roaming\mozilla\firefox\profiles\tk5p2pf2.default-release\extensions\jid0-jjrrrbmgoshuhb07ivnxtbal29w@jetpack.xpi
Vydavatel :
Velikost : 0
Odhalení : HijackExt:FirefoxPlugin/jid0-jJRRRBMgoShUhb07IvnxTBAl29w@jetpack
Akce : Vymazat
-----------------------------------------------------------------------
MD5 :
Stav : Zkontrolováno
Objekt : c:\users\petr\appdata\roaming\mozilla\firefox\profiles\tk5p2pf2.default-release\extensions\selfdestroyingcookies@dirtylittlehelpers.com.xpi
Vydavatel :
Velikost : 0
Odhalení : HijackExt:FirefoxPlugin/selfdestroyingcookies@dirtylittlehelpers.com
Akce : Vymazat
-----------------------------------------------------------------------
MD5 :
Stav : Zkontrolováno
Objekt : c:\users\petr\appdata\roaming\mozilla\firefox\profiles\tk5p2pf2.default-release\extensions\{0d7cafdd-501c-49ca-8ebb-e3341caaa55e}.xpi
Vydavatel :
Velikost : 0
Odhalení : HijackExt:FirefoxPlugin/{0d7cafdd-501c-49ca-8ebb-e3341caaa55e}
Akce : Vymazat
-----------------------------------------------------------------------
MD5 :
Stav : Zkontrolováno
Objekt : c:\users\petr\appdata\roaming\mozilla\firefox\profiles\tk5p2pf2.default-release\extensions\{2c5529f0-50b9-4b77-a149-4a3f0378ef33}.xpi
Vydavatel :
Velikost : 0
Odhalení : HijackExt:FirefoxPlugin/{2c5529f0-50b9-4b77-a149-4a3f0378ef33}
Akce : Vymazat
-----------------------------------------------------------------------
MD5 :
Stav : Zkontrolováno
Objekt : c:\users\petr\appdata\roaming\mozilla\firefox\profiles\tk5p2pf2.default-release\extensions\{eca87045-b95d-4180-8a0e-16d877af69b8}.xpi
Vydavatel :
Velikost : 0
Odhalení : HijackExt:FirefoxPlugin/{eca87045-b95d-4180-8a0e-16d877af69b8}
Akce : Vymazat
-----------------------------------------------------------------------
HJTLogfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:30:29, on 04.04.2020
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.18362.0001)
Boot mode: Normal
Running processes:
C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\WindowsApps\48405AmbientSoftware.WidgetsFree_3.3.39.0_x86__agy8jafheqhng\WidgetsDesktop\WidgetsDesktop.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Users\Petr\Desktop\HijackThis.exe
C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.4\Lightshot.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/?clid=29530R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/p/?LinkId=255141R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/p/?LinkId=255141R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_211\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_211\bin\jp2ssv.dll
O4 - HKLM\..\Run: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
O4 - HKLM\..\Run: [Lightshot] C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [ManicTimeC34F57B2DA6E6758] C:\Program Files (x86)\ManicTime\ManicTime.exe /minimized /name:
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - Startup: DeskPins.lnk = C:\Program Files (x86)\DeskPins\DeskPins.exe
O4 - Startup: Sledovat výstrahy inkoustu - HP Deskjet 1510 series (kopie 1).lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel -
res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - (no CLSID) - (no file)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Unknown owner - C:\WINDOWS\System32\drivers\AdminService.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\ki127390.inf_amd64_e1ccb879ece8f084\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\ki127390.inf_amd64_e1ccb879ece8f084\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_7c8a7 - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: Dell Command | Power Manager Notify (dcpm-notify) - Unknown owner - C:\Program Files\Dell\CommandPowerManager\NotifyService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @oem14.inf,%ServiceDisplayName%;Intel(R) Dynamic Platform and Thermal Framework service (esifsvc) - Unknown owner - C:\WINDOWS\System32\Intel\DPTF\esif_uf.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\ki127390.inf_amd64_e1ccb879ece8f084\igfxCUIService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: Waves Audio Services (WavesSysSvc) - Waves Audio Ltd. - C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11671 bytes