LOG z ComboFixComboFix 13-02-24.01 - doma 24.02.2013 18:16:55.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3071.2173 [GMT 1:00]
Spuštěný z: c:\users\doma\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\doma\AppData\Local\Temp\sfamcc00001.dll
c:\users\doma\AppData\Local\Temp\sfareca00001.dll
c:\windows\security\Database\tmp.edb
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-24 do 2013-02-24 )))))))))))))))))))))))))))))))
.
.
2013-02-24 17:37 . 2013-02-24 17:40 -------- d-----w- c:\users\doma\AppData\Local\temp
2013-02-24 17:37 . 2013-02-24 17:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-02-24 16:47 . 2013-02-24 16:47 388096 ----a-r- c:\users\doma\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-02-24 16:47 . 2013-02-24 16:47 -------- d-----w- c:\program files\Trend Micro
2013-02-24 01:28 . 2012-12-16 14:13 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-02-24 01:28 . 2012-12-16 14:13 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-02-24 01:14 . 2013-01-08 22:01 768000 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-24 00:57 . 2013-02-24 00:57 71024 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-24 00:57 . 2013-02-24 00:57 691568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-24 00:17 . 2013-02-24 00:17 -------- d-----w- c:\users\doma\Doctor Web
2013-02-23 23:27 . 2013-01-04 03:00 2347008 ----a-w- c:\windows\system32\win32k.sys
2013-02-23 23:27 . 2012-11-22 04:45 626688 ----a-w- c:\windows\system32\usp10.dll
2013-02-23 23:27 . 2012-11-09 04:43 492032 ----a-w- c:\windows\system32\win32spl.dll
2013-02-23 23:25 . 2012-11-30 04:45 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-02-23 23:24 . 2012-12-07 10:46 43520 ----a-w- c:\windows\system32\csrr.rs
2013-02-23 23:23 . 2012-11-20 04:51 220160 ----a-w- c:\windows\system32\ncrypt.dll
2013-02-23 23:23 . 2012-11-23 02:48 49152 ----a-w- c:\windows\system32\taskhost.exe
2013-02-23 23:23 . 2013-01-04 04:50 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-02-23 23:18 . 2013-02-23 23:18 -------- d-----w- c:\users\doma\AppData\Local\Adobe
2013-02-23 23:11 . 2013-02-19 02:58 6954968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{48A96613-31C1-49CF-953E-77B579D84959}\mpengine.dll
2013-02-23 21:49 . 2013-02-23 21:49 -------- d-----w- c:\users\doma\AppData\Local\Apple
2013-02-23 20:44 . 2013-02-23 20:44 -------- d-----w- c:\users\UpdatusUser
2013-02-23 20:43 . 2013-01-31 09:01 2859296 ------w- c:\windows\system32\nvsvc.dll
2013-02-23 20:43 . 2013-01-31 09:01 3970848 ------w- c:\windows\system32\nvcpl.dll
2013-02-23 20:43 . 2013-01-31 09:00 634656 ------w- c:\windows\system32\nvvsvc.exe
2013-02-23 20:43 . 2013-01-31 09:00 62752 ------w- c:\windows\system32\nvshext.dll
2013-02-23 20:43 . 2013-01-31 09:00 2557728 ------w- c:\windows\system32\nvsvcr.dll
2013-02-23 20:43 . 2013-01-31 09:00 108832 ------w- c:\windows\system32\nvmctray.dll
2013-02-23 20:43 . 2013-02-19 20:33 53024 ------w- c:\windows\system32\OpenCL.dll
2013-02-23 20:42 . 2013-02-23 20:42 -------- d-----w- c:\programdata\NVIDIA Corporation
2013-02-23 18:59 . 2013-02-23 18:59 -------- d-----w- c:\users\doma\AppData\Roaming\Malwarebytes
2013-02-23 18:54 . 2013-02-23 18:54 -------- d-----w- c:\programdata\Malwarebytes
2013-02-23 18:54 . 2013-02-23 18:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-02-23 18:54 . 2012-12-14 15:49 21104 ------w- c:\windows\system32\drivers\mbam.sys
2013-02-23 18:54 . 2013-02-23 18:54 -------- d-----w- c:\users\doma\AppData\Local\Programs
2013-02-23 17:44 . 2013-02-23 17:44 -------- d-----w- C:\7dni7noci
2013-02-19 20:32 . 2013-02-19 20:32 6162704 ------w- c:\windows\system32\nvopencl.dll
2013-02-19 20:32 . 2013-02-19 20:32 10919200 ------w- c:\windows\system32\drivers\nvlddmkm.sys
2013-02-19 20:32 . 2013-02-19 20:32 2446416 ------w- c:\windows\system32\nvapi.dll
2013-02-19 20:32 . 2013-02-19 20:32 17560352 ------w- c:\windows\system32\nvcompiler.dll
2013-02-19 20:32 . 2013-02-19 20:32 2577184 ------w- c:\windows\system32\nvcuvid.dll
2013-02-19 20:32 . 2013-02-19 20:32 1869088 ------w- c:\windows\system32\nvcuvenc.dll
2013-02-19 20:32 . 2013-02-19 20:32 15413704 ------w- c:\windows\system32\nvd3dum.dll
2013-02-19 20:32 . 2013-02-19 20:32 892704 ------w- c:\windows\system32\nvdispgenco32.dll
2013-02-19 20:32 . 2013-02-19 20:32 1010464 ------w- c:\windows\system32\nvdispco32.dll
2013-02-19 20:32 . 2013-02-19 20:32 7754560 ------w- c:\windows\system32\nvcuda.dll
2013-02-19 20:32 . 2013-02-19 20:32 19915552 ------w- c:\windows\system32\nvoglv32.dll
2013-02-16 16:09 . 2013-02-16 16:09 -------- d-----w- c:\program files\Astroburn Lite
2013-02-16 16:09 . 2013-02-16 16:09 -------- d-----w- c:\programdata\Astroburn Lite
2013-02-16 16:07 . 2013-02-16 16:07 242240 ------w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-02-16 16:07 . 2013-02-16 16:07 -------- d-----w- C:\DAEMON Tools Lite
2013-01-31 08:47 . 2013-01-31 08:47 -------- d-----w- c:\users\doma\.thumbnails
2013-01-31 08:42 . 2013-01-31 08:42 -------- d-----w- c:\users\doma\AppData\Roaming\EPSON
2013-01-31 08:40 . 2013-01-31 08:40 -------- d-----w- c:\users\doma\AppData\Local\fontconfig
2013-01-31 08:40 . 2013-02-23 23:40 -------- d-----w- c:\users\doma\.gimp-2.8
2013-01-31 08:40 . 2013-01-31 08:40 -------- d-----w- c:\users\doma\AppData\Local\gegl-0.2
2013-01-31 08:37 . 2013-01-31 08:39 -------- d-----w- c:\program files\GIMP 2
2013-01-28 16:06 . 2013-01-28 16:06 -------- d-----w- c:\users\doma\AppData\Local\Macromedia
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-19 13:25 . 2012-10-23 07:47 33112 ------w- c:\windows\system32\drivers\avgtpx86.sys
2013-01-17 00:28 . 2012-03-19 15:47 232336 ------w- c:\windows\system32\MpSigStub.exe
2012-12-18 11:46 . 2012-12-17 20:54 138032 ------w- c:\windows\system32\drivers\PnkBstrK.sys
2012-12-18 11:45 . 2012-12-17 20:38 281688 ------w- c:\windows\system32\PnkBstrB.exe
2012-12-18 11:45 . 2012-12-15 11:24 281688 ------w- c:\windows\system32\PnkBstrB.xtr
2012-12-17 20:54 . 2012-12-14 19:39 281688 ------w- c:\windows\system32\PnkBstrB.ex0
2012-12-17 20:38 . 2012-12-17 20:38 76888 ------w- c:\windows\system32\PnkBstrA.exe
2013-01-28 16:50 . 2013-01-28 16:49 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\daemon tools lite\DTLite.exe" [2013-01-08 3674320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
.
c:\users\doma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
speedfan – zástupce.lnk - c:\program files\SpeedFan\speedfan.exe [2012-9-12 4679672]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
TP-LINK Wireless Client Utility.lnk - c:\program files\TP-LINK\COMMON\TWCU.exe [2002-1-1 10918400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-03-19 15:48 136176 ----atw- c:\users\doma\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 07:04 252848 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R2 vToolbarUpdater14.2.0;vToolbarUpdater14.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe [x]
R3 AIDA64Driver;FinalWire AIDA64 Kernel Driver;c:\program files\FinalWire\AIDA64 Extreme Edition\kerneld.x32 [x]
R3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TpMediaServer;TpMediaServer;c:\program files\TP-LINK\COMMON\RaMediaServer.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 MxEFUF;Matrox Extio Upper Function Filter;c:\windows\system32\DRIVERS\MxEFUF32.sys [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 TeamViewer8;TeamViewer 8;c:\program files\TeamViewer\Version8\TeamViewer_Service.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 netr28u;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28u.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2013-02-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4020533193-2274794661-2165323434-1000Core.job
- c:\users\doma\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-19 15:48]
.
2013-02-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4020533193-2274794661-2165323434-1000UA.job
- c:\users\doma\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-19 15:48]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.google.comuInternet Settings,ProxyOverride = <local>
TCP: DhcpNameServer = 83.240.0.214 83.240.0.136
FF - ProfilePath - c:\users\doma\AppData\Roaming\Mozilla\Firefox\Profiles\kqzmicoi.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{70DF8D13-BDD3-448E-944C-EFDE21B77161} - (no file)
WebBrowser-{E9DF9360-97F8-4690-AFE6-996C80790DA4} - (no file)
MSConfigStartUp-Advanced SystemCare 5 - c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe
MSConfigStartUp-DriverMax - c:\program files\Innovative Solutions\DriverMax\drivermax.exe
MSConfigStartUp-DriverMax_RESTART - c:\program files\Innovative Solutions\DriverMax\drivermax.exe
MSConfigStartUp-DriverUpdaterPro - c:\program files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe
MSConfigStartUp-RivaTunerStartupDaemon - c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe
MSConfigStartUp-USBToolTip - c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AIDA64Driver]
"ImagePath"="\??\c:\program files\FinalWire\AIDA64 Extreme Edition\kerneld.x32"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\programdata\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\conhost.exe
c:\program files\TP-LINK\COMMON\RaRegistry.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\windows\system32\PrintIsolationHost.exe
.
**************************************************************************
.
Celkový čas: 2013-02-24 18:46:54 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-02-24 17:46
.
Před spuštěním: Volných bajtů: 165 181 259 776
Po spuštění: Volných bajtů: 164 985 782 272
.
- - End Of File - - F459DA0CB39AFF62F4AC9D55F133739D
LOG z AdwCleaner# AdwCleaner v2.113 - Logfile created 02/24/2013 at 17:35:12
# Updated 23/02/2013 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (32 bits)
# User : doma - DOMA-PC
# Boot Mode : Normal
# Running from : C:\Users\doma\Downloads\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Deleted on reboot : C:\Program Files\Common Files\AVG Secure Search
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
Folder Deleted : C:\Program Files\AVG Secure Search
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\SweetIM
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\Users\doma\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\doma\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\doma\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\doma\AppData\Roaming\OpenCandy
***** [Registry] *****
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36BCB13-778D-4A40-99C1-D686086D268F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CCA8F2AB-BE4E-41F0-A289-4D960CEA58EA}
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\hidjnkeodmholilgafgdlgmgggbhnigl
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\Software\SimilarSites
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FE69C007-C452-4D3E-86D2-1730DF8BC871}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{FE69C007-C452-4D3E-86D2-1730DF8BC871}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16464
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] =
hxxp://isearch.avg.com/?cid={9AB531E1-7017-4269-9F08-F9C47B32D5CD}&mid=1a86271312fc47d090665aebac0090a8-9b57334846ff2a4d5544c29494dcb10110af52a6&lang=cs&ds=is015&pr=sa&d=2012-10-23 09:47:17&v=13.2.0.5&sap=hp -->
hxxp://www.google.com-\\ Mozilla Firefox v18.0.1 (cs)
File : C:\Users\doma\AppData\Roaming\Mozilla\Firefox\Profiles\kqzmicoi.default\prefs.js
[OK] File is clean.
-\\ Google Chrome v24.0.1312.57
File : C:\Users\doma\AppData\Local\Google\Chrome\User Data\Default\Preferences
Deleted [l.12] : homepage = "hxxp://home.sweetim.com/?crg=3.1010000.10014&barid={7CF3CBF3-4A7D-11E2-9FC5-001D9[...]
Deleted [l.16] : urls_to_restore_on_startup = [ "hxxp://home.sweetim.com/?crg=3.1010000.10014&barid={7CF3CB[...]
Deleted [l.1875] : homepage = "hxxp://home.sweetim.com/?crg=3.1010000.10014&barid={7CF3CBF3-4A7D-11E2-9FC5-001D92A6[...]
Deleted [l.2403] : urls_to_restore_on_startup = [ "hxxp://home.sweetim.com/?crg=3.1010000.10014&barid={7CF3CBF3-[...]
-\\ Opera v12.12.1707.0
File : C:\Users\doma\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [8402 octets] - [23/02/2013 20:20:16]
AdwCleaner[S1].txt - [7836 octets] - [24/02/2013 17:35:12]
########## EOF - C:\AdwCleaner[S1].txt - [7896 octets] ##########