Fix result of Farbar Recovery Scan Tool (x64) Version: 08-09-2019
Ran by Vašek (11-09-2019 21:42:09) Run:1
Running from C:\Users\Vašek\Desktop
Loaded Profiles: Vašek & (Available Profiles: Vašek & Naďa & Michal & Administrator)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {089D990C-42F1-424A-B532-3788FF7470FD} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {09DB112F-E1CA-405F-BF58-EB80F9CA2DE6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-20] (Google Inc -> Google Inc.)
Task: {2231CCCB-BEC9-4104-97AA-072D692A106C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {3116E1B2-D257-4BB3-9D82-5BCBA96CB533} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {4C3AB498-6A52-45A7-92D4-F8088C665E47} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {5765E675-C1D9-4420-A387-18D07D2246B5} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {6D216B22-671D-43CF-A0EE-1820DFB1ABD6} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {71A36A5C-8FD6-49E0-BC2A-D0AB9DBFF68E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7CD873D4-0211-4766-BA69-51C81182D695} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {AA43C5AC-9FA0-4199-B18F-F7858B873711} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {D3FD4348-BB36-4AEF-8201-3A60C30B2C3C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {EEDE1FA5-393E-494B-BAB0-6AF924A54B1A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
hxxp://www.lenovo.comSearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003 -> {012E1000-F331-11DB-8314-0800200C9A66} URL =
hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003 -> {03D63234-5DED-4CAC-8D12-1A01DE9F8202} URL =
hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003 -> {50583A84-F748-4DA2-89D4-40AF18332228} URL =
hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003 -> {796F72C7-801D-4023-B390-828094F13354} URL =
hxxp://www.novinky.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003 -> {D2AF6C43-5D37-402B-88FF-9478A75353BE} URL =
hxxp://www.firmy.cz/?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003 -> {D66B51DC-F487-4FEB-87FD-26F9FD134313} URL =
hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003 -> {EE11300D-69A8-425F-AA5A-D65663C61726} URL =
hxxp://www.mapy.cz/?query={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003 -> {F0F59DBB-18C9-4A3B-A569-CCD6A8CEF9E4} URL =
hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003 -> {FB5D1D42-CFC3-4C74-A2A1-FC4D57EB4106} URL =
hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {012E1000-F331-11DB-8314-0800200C9A66} URL =
hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {03D63234-5DED-4CAC-8D12-1A01DE9F8202} URL =
hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {50583A84-F748-4DA2-89D4-40AF18332228} URL =
hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {796F72C7-801D-4023-B390-828094F13354} URL =
hxxp://www.novinky.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {D2AF6C43-5D37-402B-88FF-9478A75353BE} URL =
hxxp://www.firmy.cz/?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {D66B51DC-F487-4FEB-87FD-26F9FD134313} URL =
hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {EE11300D-69A8-425F-AA5A-D65663C61726} URL =
hxxp://www.mapy.cz/?query={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {F0F59DBB-18C9-4A3B-A569-CCD6A8CEF9E4} URL =
hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {FB5D1D42-CFC3-4C74-A2A1-FC4D57EB4106} URL =
hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
BHO: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File
FF Plugin-x32: @videolan.org/vlc,version=2.2.5.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] -
hxxps://clients2.google.com/service/update2/crxCHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] -
hxxps://clients2.google.com/service/update2/crxCHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] -
hxxps://clients2.google.com/service/update2/crxS3 cpuz143; \??\C:\WINDOWS\temp\cpuz143\cpuz143_x64.sys [X]
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2019-09-09 15:45 - 2019-09-09 15:45 - 000088064 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_ctypes.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000128512 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_elementtree.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000914432 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_hashlib.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000027648 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_multiprocessing.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000036864 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_psutil_windows.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000046080 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_socket.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 001303552 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_ssl.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000020480 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_yappi.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000012800 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\common.time34.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000007168 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\hashobjs_ext.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000127488 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\pyexpat.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000682496 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\pysqlite2._sqlite.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000364544 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\pythoncom27.dll
2019-09-09 15:45 - 2019-09-09 15:45 - 000110080 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\pywintypes27.dll
2019-09-09 15:45 - 2019-09-09 15:45 - 000010240 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\select.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000017920 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\thumbnails_ext.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000686080 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\unicodedata.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000088064 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\usb_ext.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000098816 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32api.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000320512 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32com.shell.shell.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000011264 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32crypt.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000018432 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32event.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000119808 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32file.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000167936 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32gui.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000038912 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32inet.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000025600 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32pdh.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000024064 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32pipe.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000035840 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32process.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000017408 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32profile.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000108544 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32security.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000022528 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32ts.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000078848 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._animate.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 001067008 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._controls_.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 001176576 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._core_.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000806400 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._gdi_.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000077312 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._html2.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000733184 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._misc_.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000816128 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._windows_.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 000123392 ____R () [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._wizard.pyd
2019-09-09 15:45 - 2019-09-09 15:45 - 002459648 ____R (Python Software Foundation) [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\python27.dll
2019-09-09 15:45 - 2019-09-09 15:45 - 000155136 ____R (wxWidgets development team) [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wxbase30u_net_vc90.dll
2019-09-09 15:45 - 2019-09-09 15:45 - 002030592 ____R (wxWidgets development team) [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wxbase30u_vc90.dll
2019-09-09 15:45 - 2019-09-09 15:45 - 001251328 ____R (wxWidgets development team) [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wxmsw30u_adv_vc90.dll
2019-09-09 15:45 - 2019-09-09 15:45 - 004796928 ____R (wxWidgets development team) [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wxmsw30u_core_vc90.dll
2019-09-09 15:45 - 2019-09-09 15:45 - 000601088 ____R (wxWidgets development team) [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wxmsw30u_html_vc90.dll
2019-09-09 15:45 - 2019-09-09 15:45 - 000110080 ____R (wxWidgets development team) [File not signed] C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wxmsw30u_webview_vc90.dll
AlternateDataStreams: C:\ProgramData\Temp:5C321E34 [134]
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003\...\1001movie.com -> 1001movie.com
There are 6091 more sites.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\1001movie.com -> 1001movie.com
There are 6091 more sites.
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"
FirewallRules: [{2D0EA622-CCB9-49F3-9CF2-EECA1F97A943}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.4.0\AutoUpdate.exe No File
FirewallRules: [{C8D805D7-9EF1-4F4B-AE4A-EC5E35C02F55}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.4.0\AutoUpdate.exe No File
FirewallRules: [{40FBFDCE-AD66-4A36-8AF2-BFBE40CBEC12}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.4.0\DBDownloader.exe No File
FirewallRules: [{348ED8B4-55BC-4DE0-851C-8835D94B36AC}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.4.0\DBDownloader.exe No File
FirewallRules: [{AC86B456-2C27-470A-8A63-E63E00839398}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.4.0\DriverBooster.exe No File
FirewallRules: [{14C0C40B-346D-4DBB-A16E-7FA95F841A70}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.4.0\DriverBooster.exe No File
EmptyTemp:
End
*****************
Restore point was successfully created.
Processes closed successfully.
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{089D990C-42F1-424A-B532-3788FF7470FD}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{089D990C-42F1-424A-B532-3788FF7470FD}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{09DB112F-E1CA-405F-BF58-EB80F9CA2DE6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09DB112F-E1CA-405F-BF58-EB80F9CA2DE6}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2231CCCB-BEC9-4104-97AA-072D692A106C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2231CCCB-BEC9-4104-97AA-072D692A106C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3116E1B2-D257-4BB3-9D82-5BCBA96CB533}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3116E1B2-D257-4BB3-9D82-5BCBA96CB533}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4C3AB498-6A52-45A7-92D4-F8088C665E47}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4C3AB498-6A52-45A7-92D4-F8088C665E47}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5765E675-C1D9-4420-A387-18D07D2246B5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5765E675-C1D9-4420-A387-18D07D2246B5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6D216B22-671D-43CF-A0EE-1820DFB1ABD6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6D216B22-671D-43CF-A0EE-1820DFB1ABD6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{71A36A5C-8FD6-49E0-BC2A-D0AB9DBFF68E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71A36A5C-8FD6-49E0-BC2A-D0AB9DBFF68E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7CD873D4-0211-4766-BA69-51C81182D695}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7CD873D4-0211-4766-BA69-51C81182D695}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AA43C5AC-9FA0-4199-B18F-F7858B873711}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AA43C5AC-9FA0-4199-B18F-F7858B873711}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D3FD4348-BB36-4AEF-8201-3A60C30B2C3C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3FD4348-BB36-4AEF-8201-3A60C30B2C3C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EEDE1FA5-393E-494B-BAB0-6AF924A54B1A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EEDE1FA5-393E-494B-BAB0-6AF924A54B1A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
hxxp://www.lenovo.com => Error: No automatic fix found for this entry.
HKU\S-1-5-21-961389813-253083461-155772885-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} => removed successfully
HKLM\Software\Classes\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => not found
HKU\S-1-5-21-961389813-253083461-155772885-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{03D63234-5DED-4CAC-8D12-1A01DE9F8202} => removed successfully
HKLM\Software\Classes\CLSID\{03D63234-5DED-4CAC-8D12-1A01DE9F8202} => not found
HKU\S-1-5-21-961389813-253083461-155772885-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{50583A84-F748-4DA2-89D4-40AF18332228} => removed successfully
HKLM\Software\Classes\CLSID\{50583A84-F748-4DA2-89D4-40AF18332228} => not found
HKU\S-1-5-21-961389813-253083461-155772885-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{796F72C7-801D-4023-B390-828094F13354} => removed successfully
HKLM\Software\Classes\CLSID\{796F72C7-801D-4023-B390-828094F13354} => not found
HKU\S-1-5-21-961389813-253083461-155772885-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D2AF6C43-5D37-402B-88FF-9478A75353BE} => removed successfully
HKLM\Software\Classes\CLSID\{D2AF6C43-5D37-402B-88FF-9478A75353BE} => not found
HKU\S-1-5-21-961389813-253083461-155772885-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D66B51DC-F487-4FEB-87FD-26F9FD134313} => removed successfully
HKLM\Software\Classes\CLSID\{D66B51DC-F487-4FEB-87FD-26F9FD134313} => not found
HKU\S-1-5-21-961389813-253083461-155772885-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EE11300D-69A8-425F-AA5A-D65663C61726} => removed successfully
HKLM\Software\Classes\CLSID\{EE11300D-69A8-425F-AA5A-D65663C61726} => not found
HKU\S-1-5-21-961389813-253083461-155772885-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F0F59DBB-18C9-4A3B-A569-CCD6A8CEF9E4} => removed successfully
HKLM\Software\Classes\CLSID\{F0F59DBB-18C9-4A3B-A569-CCD6A8CEF9E4} => not found
HKU\S-1-5-21-961389813-253083461-155772885-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FB5D1D42-CFC3-4C74-A2A1-FC4D57EB4106} => removed successfully
HKLM\Software\Classes\CLSID\{FB5D1D42-CFC3-4C74-A2A1-FC4D57EB4106} => not found
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {012E1000-F331-11DB-8314-0800200C9A66} URL =
hxxp://www.google.com/search?q={searchTerms} => Error: No automatic fix found for this entry.
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {03D63234-5DED-4CAC-8D12-1A01DE9F8202} URL =
hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454 => Error: No automatic fix found for this entry.
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {50583A84-F748-4DA2-89D4-40AF18332228} URL =
hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454 => Error: No automatic fix found for this entry.
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {796F72C7-801D-4023-B390-828094F13354} URL =
hxxp://www.novinky.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454 => Error: No automatic fix found for this entry.
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {D2AF6C43-5D37-402B-88FF-9478A75353BE} URL =
hxxp://www.firmy.cz/?q={searchTerms}&sourceid=QuickSearch_12454 => Error: No automatic fix found for this entry.
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {D66B51DC-F487-4FEB-87FD-26F9FD134313} URL =
hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=QuickSearch_12454 => Error: No automatic fix found for this entry.
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {EE11300D-69A8-425F-AA5A-D65663C61726} URL =
hxxp://www.mapy.cz/?query={searchTerms}&sourceid=QuickSearch_12454 => Error: No automatic fix found for this entry.
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {F0F59DBB-18C9-4A3B-A569-CCD6A8CEF9E4} URL =
hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454 => Error: No automatic fix found for this entry.
SearchScopes: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762 -> {FB5D1D42-CFC3-4C74-A2A1-FC4D57EB4106} URL =
hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454 => Error: No automatic fix found for this entry.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF} => removed successfully
HKLM\Software\Classes\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF} => not found
"HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.5.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN" => not found
C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll => moved successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN" => not found
"C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll" => not found
"HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN" => not found
"C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll" => not found
"HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN" => not found
"C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll" => not found
"HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN" => not found
"C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll" => not found
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki => removed successfully
HKLM\System\CurrentControlSet\Services\cpuz143 => removed successfully
cpuz143 => service removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore" => not found
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_ctypes.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_elementtree.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_hashlib.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_multiprocessing.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_psutil_windows.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_socket.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_ssl.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\_yappi.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\common.time34.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\hashobjs_ext.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\pyexpat.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\pysqlite2._sqlite.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\pythoncom27.dll => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\pywintypes27.dll => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\select.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\thumbnails_ext.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\unicodedata.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\usb_ext.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32api.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32com.shell.shell.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32crypt.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32event.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32file.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32gui.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32inet.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32pdh.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32pipe.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32process.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32profile.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32security.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\win32ts.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._animate.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._controls_.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._core_.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._gdi_.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._html2.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._misc_.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._windows_.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wx._wizard.pyd => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\python27.dll => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wxbase30u_net_vc90.dll => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wxbase30u_vc90.dll => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wxmsw30u_adv_vc90.dll => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wxmsw30u_core_vc90.dll => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wxmsw30u_html_vc90.dll => moved successfully
C:\Users\Vašek\AppData\Local\Temp\_MEI55762\wxmsw30u_webview_vc90.dll => moved successfully
C:\ProgramData\Temp => ":5C321E34" ADS removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008i.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008k.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\00hq.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0190-dialers.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\01i.info => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\02pmnzy5eo29bfk4.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0411dd.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0511zfhl.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\05p.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0632qyw.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\07ic5do2myz3vzpk.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\08nigbmwk43i01y6.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\093qpeuqpmz6ebfa.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0calories.net => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0cj.net => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0scan.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-britney-spears-nude.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-domains-registrations.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-se.com => removed successfully
HKU\S-1-5-21-961389813-253083461-155772885-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1001movie.com => removed successfully
There are 6091 more sites. => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\008i.com -> 008i.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\008k.com -> 008k.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\00hq.com -> 00hq.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0190-dialers.com -> 0190-dialers.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\01i.info -> 01i.info => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0411dd.com -> 0411dd.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0511zfhl.com -> 0511zfhl.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\05p.com -> 05p.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0632qyw.com -> 0632qyw.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0calories.net -> 0calories.net => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0cj.net -> 0cj.net => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\0scan.com -> 0scan.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\1-domains-registrations.com -> 1-domains-registrations.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\1-se.com -> 1-se.com => Error: No automatic fix found for this entry.
IE restricted site: HKU\S-1-5-21-961389813-253083461-155772885-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09082019215730762\...\1001movie.com -> 1001movie.com => Error: No automatic fix found for this entry.
There are 6091 more sites. => Error: No automatic fix found for this entry.
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File) => Error: No automatic fix found for this entry.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk" => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\McAfee Security Scan Plus.lnk" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2D0EA622-CCB9-49F3-9CF2-EECA1F97A943}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C8D805D7-9EF1-4F4B-AE4A-EC5E35C02F55}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{40FBFDCE-AD66-4A36-8AF2-BFBE40CBEC12}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{348ED8B4-55BC-4DE0-851C-8835D94B36AC}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AC86B456-2C27-470A-8A63-E63E00839398}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{14C0C40B-346D-4DBB-A16E-7FA95F841A70}" => removed successfully
=========== EmptyTemp: ==========
BITS transfer queue => 10772480 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 104841242 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 125616 B
Edge => 1315809 B
Chrome => 392604159 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 6874 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
LocalService => 0 B
NetworkService => 0 B
NetworkService => 0 B
Vašek => 335304720 B
Naďa => 1288739 B
Michal => 21362 B
Administrator => 19072 B
RecycleBin => 292444 B
EmptyTemp: => 807.4 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 21:50:23 ====