Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Vyskakujici reklamy

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Ver
Návštěvník
Návštěvník
Příspěvky: 113
Registrován: 31 črc 2008 19:05

Vyskakujici reklamy

#1 Příspěvek od Ver »

Dobry den,
prosim o kontrolu logu, vyskakuji mi reklami a spoust oken :shock:
Predem dekuji :)
vkladam log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by mediamarkcruqius at 2014-01-07 14:02:10
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 10 GB (7%) free of 152 GB
Total RAM: 3959 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:02:21, on 7-1-2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\PROGRA~2\SearchProtect\SearchProtect\bin\cltmng.exe
C:\PROGRA~2\SearchProtect\UI\bin\cltmngui.exe
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\ProgramData\FLEXnet\Connect\11\agent.exe
C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE
C:\Users\mediamarkcruqius\AppData\Local\43D0D494-7FCC-4165-98F7-37C3B7ADF6AE\svchost.exe
C:\Users\mediamarkcruqius\AppData\Local\43D0D494-7FCC-4165-98F7-37C3B7ADF6AE\svchost.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\ProgramData\Updater\Updater.exe
C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe
C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe
C:\ProgramData\RHelpers\IeHelper\IeHelper.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files\trend micro\mediamarkcruqius.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds& ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds& ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: CrossriderApp0048978 - {11111111-1111-1111-1111-110411891178} - C:\Program Files (x86)\DP1818\DP1818-bho.dll
O2 - BHO: Websteroids - {44ed99e2-16a6-4b89-80d6-5b21cf42e78b} - C:\ProgramData\Websteroids\IE\common.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ValueApps Loader - {93DBF2BB-A2B3-4683-A92E-57E60751F346} - C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
O2 - BHO: WebexpEnhancedV1alpha2360 - {fd9425ac-8ec0-4faf-8f6c-3033cc2ddd26} - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ie\WebexpEnhancedV1alpha2360.dll
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
O4 - HKLM\..\Run: [Updater] C:\ProgramData\Updater\Updater.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKCU\..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Google Update] "C:\Users\mediamarkcruqius\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [lollipop_01070755_2] "c:\users\mediamarkcruqius\appdata\local\lollipop\lollipop_01070755_2.exe" lollipop_01070755_2
O4 - HKCU\..\Run: [ConduitFloatingPlugin_lcnnhcneegeeojhgpfijnlnocjdmlaon] "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\mediamarkcruqius\AppData\Roaming\ValueApps\CH\TBVerifier.dll",RunConduitFloatingPlugin lcnnhcneegeeojhgpfijnlnocjdmlaon
O4 - HKCU\..\Run: [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\mediamarkcruqius\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O4 - HKCU\..\Run: [Updater] C:\ProgramData\Updater\Updater.exe
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (file missing)
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: Search Protect by Conduit Service (CltMngSvc) - Conduit - C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Internet Updater (InternetUpdater) - Unknown owner - C:\ProgramData\InternetUpdater\InternetUpdaterService.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wpm Service (Wpm) - Cherished Technololgy LIMITED - C:\ProgramData\WPM\wprotectmanager.exe

--
End of file - 16277 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {9459C66F-50E9-451D-82A7-82B7E828A5F9}
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\TODDSrv.exe
"C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe"
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\PROGRA~2\SearchProtect\SearchProtect\bin\cltmng.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe"
"C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe"
WLIDSvcM.exe 2648
"C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe"
"C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\PROGRA~2\SearchProtect\UI\bin\cltmngui.exe"
"C:\Program Files\TOSHIBA\TECO\Teco.exe" /r
"C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
"C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
"C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe" -scheduler
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
C:\Windows\System32\alg.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2.exe -updatec:\users\mediamarkcruqius\appdata\local\lollipop\lollipop_01070755.exe
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe"
"C:\Program Files (x86)\Windows Live\Mail\wlmail.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe" -Embedding
C:\ProgramData\FLEXnet\Connect\11\agent.exe -Embedding
C:\Windows\splwow64.exe 12288
C:\Windows\system32\atibtmon.exe Global\Ati_VariBrightMonitorEvent
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"taskhost.exe"
"C:\Users\mediamarkcruqius\AppData\Local\43D0D494-7FCC-4165-98F7-37C3B7ADF6AE\svchost.exe" 6976 True false
"C:\Users\mediamarkcruqius\AppData\Local\43D0D494-7FCC-4165-98F7-37C3B7ADF6AE\svchost.exe" 1560 False false
rundll32 "C:\Users\mediamarkcruqius\AppData\Roaming\ValueApps\CH\TBVerifier.dll" RunConduitFloatingPlugin lcnnhcneegeeojhgpfijnlnocjdmlaon
C:\ProgramData\WPM\wprotectmanager.exe -service
"C:\Windows\SysWOW64\rundll32.exe" "C:\Users\mediamarkcruqius\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
"C:\ProgramData\Updater\Updater.exe" in10m
"C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe"
"C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe"
"C:\ProgramData\RHelpers\IeHelper\IeHelper.exe"
ctfmon.exe
C:\Windows\system32\msiexec.exe /V
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\ProgramData\InternetUpdater\InternetUpdaterService.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\mediamarkcruqius\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\AmiUpdXp.job
C:\Windows\tasks\DP1818-chromeinstaller.job
C:\Windows\tasks\DP1818-codedownloader.job
C:\Windows\tasks\DP1818-enabler.job
C:\Windows\tasks\DP1818-firefoxinstaller.job
C:\Windows\tasks\DP1818-updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-354615371-2128914143-2807093971-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-354615371-2128914143-2807093971-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1423, {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.27"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0]
"Description"=BlackBerry Web Software Loading Helper Plug-In for Mozilla browsers
"Path"=C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
avg_igeared.xml
mall-cz.xml
McSiteAdvisor.xml
nationzoom.xml

C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\
a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com
support@websteroidsapp.com
{94cd2cc3-083f-49ba-a218-4cda4b4829fd}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411891178}]
DP1818 - C:\Program Files (x86)\DP1818\DP1818-bho64.dll [2014-01-07 969216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93DBF2BB-A2B3-4683-A92E-57E60751F346}]
ValueApps - C:\Program Files\Conduit\ValueApps\IE\ValueAppsLoader.dll [2013-12-22 153376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-01-16 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411891178}]
DP1818 - C:\Program Files (x86)\DP1818\DP1818-bho.dll [2014-01-07 640512]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44ed99e2-16a6-4b89-80d6-5b21cf42e78b}]
Websteroids - C:\ProgramData\Websteroids\IE\common.dll [2013-12-18 409464]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~2\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{551A852F-39A6-44A7-9C13-AFBEC9185A9D}]
PlusIEEventHelper Class - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06 249856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93DBF2BB-A2B3-4683-A92E-57E60751F346}]
ValueApps - C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll [2013-12-22 127264]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-04-06 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
TOSHIBA Media Controller Plug-in - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2010-03-19 529784]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fd9425ac-8ec0-4faf-8f6c-3033cc2ddd26}]
Webexp Enhanced - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ie\WebexpEnhancedV1alpha2360.dll [2013-12-20 87552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-02-05 709976]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2010-03-10 520760]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2009-11-05 505696]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2009-03-09 52600]
"SmoothView"=C:\Program Files\Toshiba\SmoothView\SmoothView.exe [2009-08-13 570680]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2010-03-03 913720]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2010-03-17 1489760]
"TosWaitSrv"=C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [2010-02-23 705368]
"TosVolRegulator"=C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [2009-11-11 24376]
"IntelliPoint"=c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2010-07-21 2327952]
"Toshiba TEMPRO"=C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [2010-02-11 1050072]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2012-09-12 1289704]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"OfficeSyncProcess"=C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [2010-01-16 717696]
"ISUSPM"=C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2009-05-05 222496]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14 20584608]
"Google Update"=C:\Users\mediamarkcruqius\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-06 136176]
"lollipop_01070755_2"=c:\users\mediamarkcruqius\appdata\local\lollipop\lollipop_01070755_2.exe [2014-01-07 2734592]
"ConduitFloatingPlugin_lcnnhcneegeeojhgpfijnlnocjdmlaon"=C:\Windows\SysWOW64\Rundll32.exe [2009-07-14 44544]
"NextLive"=C:\Windows\SysWOW64\rundll32.exe [2009-07-14 44544]
"Updater"=C:\ProgramData\Updater\Updater.exe [2013-12-18 486264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent]
c:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe [2010-03-09 1086760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartFaceVWatcher]
C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [2009-10-19 238080]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration]
C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [2010-02-12 136136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosNC]
C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [2010-03-09 595816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosReelTimeMonitor]
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [2010-03-03 35672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TWebCamera]
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Default Manager"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2009-11-11 288088]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-01-21 91520]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"IndexSearch"=C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [2010-03-08 46368]
"ControlCenter4"=C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [2011-04-20 139264]
"BrStsMon00"=C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2011-10-07 2629632]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2013-11-02 152392]
"mobilegeni daemon"=C:\Program Files (x86)\Mobogenie\DaemonProcess.exe []
"Updater"=C:\ProgramData\Updater\Updater.exe [2013-12-18 486264]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-05-11 958576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Windows\SysWOW64\msiexec.exe"="C:\Windows\SysWOW64\msiexec.exe:*:Generic Host Process"
"C:\Windows\SysWOW64\svchost.exe"="C:\Windows\SysWOW64\svchost.exe:*:Generic Host Process"
"C:\Users\MEDIAM~1\AppData\Local\Temp\1349042551.exe"="C:\Users\MEDIAM~1\AppData\Local\Temp\1349042551.exe:*:Enabled:Microsoft Office"
"C:\Users\MEDIAM~1\AppData\Local\Temp\tmp57755b9e\elly.exe"="C:\Users\MEDIAM~1\AppData\Local\Temp\tmp57755b9e\elly.exe:*:Enabled:Microsoft Office"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-01-07 14:02:10 ----D---- C:\rsit
2014-01-07 13:58:20 ----D---- C:\ProgramData\InternetUpdater
2014-01-07 13:53:03 ----D---- C:\Program Files (x86)\Adobe
2014-01-07 13:52:29 ----SHD---- C:\Config.Msi
2014-01-07 13:49:27 ----D---- C:\Program Files (x86)\Lightspark 0.5.3-git
2014-01-07 13:48:02 ----D---- C:\Program Files (x86)\AmiExt
2014-01-07 13:48:00 ----D---- C:\ProgramData\Updater
2014-01-07 13:48:00 ----D---- C:\ProgramData\RHelpers
2014-01-07 13:47:57 ----D---- C:\ProgramData\Websteroids
2014-01-07 13:47:50 ----D---- C:\Users\mediamarkcruqius\AppData\Roaming\newnext.me
2014-01-07 13:45:00 ----D---- C:\ProgramData\WPM
2014-01-07 13:44:34 ----D---- C:\Program Files\Conduit
2014-01-07 13:44:33 ----D---- C:\Program Files (x86)\Conduit
2014-01-07 13:44:28 ----D---- C:\Users\mediamarkcruqius\AppData\Roaming\ValueApps
2014-01-07 13:44:06 ----D---- C:\Program Files (x86)\DP1818
2014-01-07 10:02:30 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-12-25 09:15:11 ----D---- C:\Program Files (x86)\WebexpEnhancedV1
2013-12-17 09:13:10 ----D---- C:\Windows\SYSWOW64\SearchProtect
2013-12-15 14:26:56 ----D---- C:\Program Files (x86)\SearchProtect

======List of files/folders modified in the last 1 month======

2014-01-07 14:02:18 ----D---- C:\Windows\Temp
2014-01-07 14:02:12 ----D---- C:\Program Files\trend micro
2014-01-07 13:58:20 ----D---- C:\ProgramData
2014-01-07 13:55:50 ----SHD---- C:\System Volume Information
2014-01-07 13:53:47 ----SHD---- C:\Windows\Installer
2014-01-07 13:53:29 ----D---- C:\Windows\Prefetch
2014-01-07 13:53:15 ----D---- C:\Windows\SysWOW64
2014-01-07 13:53:03 ----RD---- C:\Program Files (x86)
2014-01-07 13:53:03 ----D---- C:\ProgramData\Adobe
2014-01-07 13:53:03 ----D---- C:\Program Files (x86)\Common Files
2014-01-07 13:47:36 ----D---- C:\Windows\system32\Tasks
2014-01-07 13:47:33 ----D---- C:\Windows\Tasks
2014-01-07 13:44:34 ----RD---- C:\Program Files
2014-01-07 13:09:40 ----D---- C:\Windows\system32\config
2014-01-07 13:05:09 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-07 13:02:11 ----D---- C:\Users\mediamarkcruqius\AppData\Roaming\Skype
2014-01-07 08:54:13 ----A---- C:\Windows\SYSWOW64\log.txt
2013-12-15 20:45:52 ----D---- C:\Users\mediamarkcruqius\AppData\Roaming\vlc
2013-12-15 16:53:18 ----D---- C:\Users\mediamarkcruqius\AppData\Roaming\uTorrent
2013-12-15 16:50:13 ----D---- C:\Windows\System32
2013-12-15 16:50:13 ----D---- C:\Windows\inf
2013-12-15 16:50:13 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-12-15 16:30:39 ----D---- C:\Program Files (x86)\uTorrent
2013-12-13 21:36:24 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-12-13 21:15:19 ----D---- C:\Windows\system32\catroot2
2013-12-09 17:46:38 ----D---- C:\Windows\system32\drivers
2013-12-09 10:02:57 ----D---- C:\ProgramData\Skype
2013-12-09 10:02:55 ----RD---- C:\Program Files (x86)\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-01-15 538136]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2012-08-30 228768]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-09-12 834544]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-06-19 14472]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-03-15 6403072]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-15 188928]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-01-18 717368]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDMI64.sys [2010-03-05 720952]
R3 FwLnk;FwLnk Driver; C:\Windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-10 158720]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-02-22 75304]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 RimVSerPort;RIM Virtual Serial Port v2; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [2011-07-20 44032]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2009-07-14 11264]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\Windows\system32\DRIVERS\rtl8192se.sys [2010-04-26 1103904]
R3 StillCam;Still Serial Digital Camera Driver; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 12288]
R3 SynTP;Synaptics Pointing Device Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-03-15 6403072]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 cpuz132;cpuz132; \??\C:\Users\MEDIAM~1\AppData\Local\Temp\cpuz132\cpuz132_x64.sys []
S3 dc3d;MS Hardware Device Detection Driver (USB); C:\Windows\system32\DRIVERS\dc3d.sys [2010-07-07 51600]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 48488]
S3 Netaapl;Apple Mobile Device Ethernet Service; C:\Windows\system32\DRIVERS\netaapl64.sys [2012-03-26 22528]
S3 netr7364;RT73 USB Wireless LAN Card Driver for Vista; C:\Windows\system32\DRIVERS\netr7364.sys [2009-06-10 707072]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-30 128456]
S3 nmwcdcx64;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbox64.sys [2008-05-02 23552]
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmbx64.sys [2008-05-02 18432]
S3 Point64;Microsoft IntelliPoint Filter Driver; C:\Windows\system32\DRIVERS\point64.sys [2010-07-21 45456]
S3 RimUsb;BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [2011-07-25 74752]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-01 232992]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2008-05-02 8704]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbser;Nokia USB Serial Port; C:\Windows\system32\DRIVERS\usbser.sys [2009-07-14 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys [2008-05-02 8704]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S3 WSDPrintDevice;WSD Print Support via UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-15 202752]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 CltMngSvc;Search Protect by Conduit Service; C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe [2013-12-16 2251552]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 InternetUpdater;Internet Updater; C:\ProgramData\InternetUpdater\InternetUpdaterService.exe [2013-12-06 40448]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-12-09 268824]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2012-09-12 22072]
R2 PDFProFiltSrvPP;PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-03-08 144672]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2009-11-05 489312]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-09 2320920]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R2 Wpm;Wpm Service; C:\ProgramData\WPM\wprotectmanager.exe [2014-01-07 499856]
R3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2013-11-02 641352]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
R3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-06 136176]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-13 257416]
S3 BrYNSvc;BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [2010-01-25 245760]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-03-08 1492840]
S3 getPlusHelper;@C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-06 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe []
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-01-07 119408]
S3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-09-12 368896]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
S3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-07-18 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Vyskakujici reklamy

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Ver
Návštěvník
Návštěvník
Příspěvky: 113
Registrován: 31 črc 2008 19:05

Re: Vyskakujici reklamy

#3 Příspěvek od Ver »

tak tady je prvni log
ale ten druhy se stale nechce dodelat, cekala jsem nekolik hodin a stale se to nedokoncilo,
seklo se to v analyzing browsers...

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.9 (01.01.2014:1)
OS: Windows 7 Home Premium x64
Ran by mediamarkcruqius on di 07-01-2014 at 14:19:06,40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services

Successfully stopped: [Service] cltmngsvc
Successfully deleted: [Service] cltmngsvc



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ConduitFloatingPlugin_lcnnhcneegeeojhgpfijnlnocjdmlaon
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B?

Value Name Type Value Data
========================================================================================
NextLive REG_SZ C:\Windows\SysWOW64\rundll32.exe "C:\Users\mediamarkcruqius\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l




~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dynconie.dynconieobject
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dynconie.dynconieobject.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2830488C-079B-45C2-88B6-AFE4EAA2DF85}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{781CA792-9B6E-400B-B36F-15C097D2CA54}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\dynconie
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-354615371-2128914143-2807093971-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\speedupmypc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\speedupmypc_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\speedupmypc_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetim_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetim_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetimsetup_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetimsetup_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{99c91fc5-db5b-4aa0-bb70-5d89c5a4df96}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048978.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048978.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048978.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048978.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110411891178}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220422892278}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550455895578}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660466896678}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440444894478}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11111111-1111-1111-1111-110411891178}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220422892278}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550455895578}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660466896678}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440444894478}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048978.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048978.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048978.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048978.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550455895578}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660466896678}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440444894478}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411891178}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411891178}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\TaskScheduler_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\TaskScheduler_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550455895578}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660466896678}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440444894478}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\TaskScheduler_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\TaskScheduler_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411891178}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}



~~~ Files

Successfully deleted: [File] C:\Windows\Tasks\amiupdxp.job
Successfully deleted: [File] "C:\end"



~~~ Folders

Successfully deleted: [Folder] "C:\Users\mediamarkcruqius\appdata\local\conduit"
Failed to delete: [Folder] "C:\Users\mediamarkcruqius\appdata\local\lollipop"
Successfully deleted: [Folder] "C:\Users\mediamarkcruqius\appdata\local\searchprotect"
Successfully deleted: [Folder] "C:\Users\mediamarkcruqius\appdata\local\swvupdater"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Folder] "C:\Program Files (x86)\searchprotect"
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0032B18E-0B35-4C3A-BC2C-5C4E70355DE8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{00B43D10-9D8E-4DEF-899F-83D0BDAA2442}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0162F7CB-20EC-489A-BF1B-21505D8830CE}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0198DE8A-1EEE-4DB9-A1F9-E145C807A43C}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{01FA364A-E50A-435D-8EFA-A04EAAFEFE1F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{025E2EBB-F7DB-4176-9930-9E38A95D57AC}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{033CC58B-9795-4841-8F3A-628CA032CAF1}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{03819D38-D856-464F-AD1B-EED3EF9B0C01}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{038E22D1-22C2-4008-9874-3F83DCE6AADA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{03965CDA-937B-47E4-83E4-BE3EC3223A0D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{03A51252-1053-41E7-BF63-9B299A01F992}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{04EB1D37-1C3F-4C40-B454-609D42745DF3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0505966A-A3E7-4FD8-9863-A322516E3732}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{05AE854D-1722-4790-BE56-66949E7D4274}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0607F2A3-E0C7-4F92-AB3C-FFC9AB97C9B8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{064640EC-5490-4F23-8732-77005B5414A6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{06748BC7-5522-4395-AAF7-35B36282399D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{06A80F1D-1207-45E8-9200-C8715AD5B8EF}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{06DBBD85-C62F-42AC-A65A-442E9AC3DD27}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0704C5E6-4E8C-4DDF-B2C0-24457C021C01}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0770152E-FD5C-432D-B10A-76B09697FFE2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{092532A1-F31C-459F-9E91-6D211CEA5736}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{09A2963F-7CC0-406B-A7A7-9BDE98D0F0E6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0A584F46-4F40-4921-B866-C604E1991BD2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0A7C60E6-7199-48FC-972A-C13C39AA1A9A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0ABD91D3-98B2-4500-B495-C1F68CD3E7E9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0B1DDFAD-1717-43AD-99FE-6D7C2AB79B46}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0B6981C1-EA97-493B-9E12-E3B16A602215}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0B7FD79B-9763-4CCC-9C30-214B6FBBFDA8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0BC0995C-9A75-41A2-9D07-C85DC2CE7C43}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0C23750D-C8C6-4592-B24C-8AEEDC8A4732}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0C31B452-6C26-4E90-81A7-6C7D4E3CB576}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0C3436C0-3E39-404A-9916-F6D1C8861783}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0C3DDFE0-C52E-4E18-89C0-40353CD098E6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0CDA4B5D-2093-4B4F-B1E1-5399C636126F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0D6C5A7B-379C-42AB-AD8F-5ADFFECC0CC2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0D7F1E1F-7213-4872-AEB8-BF82A58B366F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0DEDD790-238A-44E3-9DBE-FAA5E7CA1299}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0EA77DB5-8CCA-45EB-AE64-D2AF0FB37BF5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{0FC42AB3-3A7F-4E9A-B443-A1CE731E6130}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1105601C-2EA0-492E-BBE8-D320EBDAD640}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{11121B53-5DF2-491F-B78B-F1D02B04DF13}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{115A02F9-E811-4A50-9828-D2BDEB806B2E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1181AF19-51B9-42D8-972D-8EA1281F0A88}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{11A246EE-BAE8-4467-9067-8545C495D317}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{12472192-8212-4FF3-A7E0-A113AAC00347}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{12880538-025F-4794-B50D-D2EE68B7ADD2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{12E9B2CF-0E69-449A-B143-83D504065E6D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1330C8AB-5BEC-476A-B1F1-21BEE425208F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{141254A4-1CC0-408A-9BAF-B996C72A3CD3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{141D68A7-27B7-4A3A-B0BD-3F3587F4D30D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1427C855-66D5-4BD8-B2B6-0D76B70FD4D9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{149C1229-CE42-4575-8EFE-D7E515D08699}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{14D7A2E3-CA97-4E8A-8D93-F53E840E0808}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1598A56F-3FA1-445A-ACC9-8BD6E975D06B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{15D8C654-65C4-4C73-AE90-9A1E00A93D88}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{15EF0D8D-7A69-4EF5-A7C4-6D6024B07274}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{17335354-1091-4F5A-A7E0-966F91796323}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{17384E0F-205E-4CAC-A843-0D59A16ADA62}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{18431125-2D3D-4AD8-BB05-0432C0D18B7F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{19C80B3C-C91E-4624-96A9-A1DA13212C01}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{19E3C9E2-81C0-4256-9E22-50575FCA149F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1A0D7B63-B2EA-4A7C-8FC3-85C801D47B42}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1A6B1FDA-4F8D-4E2F-A432-96E9DF438515}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1B1D2180-F59F-44B1-AC06-9392F9AA3CC3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1B27789D-3699-4D48-A647-660C0C9C70DB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1B2F57AB-C55C-4CE4-B5E6-5B4FD2C5FA5C}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1BD214D5-A1DA-4CE0-84D4-BC0FCF7DB8E7}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1BD7497A-32AB-4A84-B240-4EB760B03874}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1C0B127F-9106-4684-862F-747E2DE03634}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1C0DDEEA-1E85-401C-872D-BBA58B4D15F7}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1CB3EF6A-4759-4178-8896-CB721B9FD898}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1DF81385-8688-4662-9E48-27F91863EFF9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{1E60AAD5-17B7-41FD-9886-05B44C75BBA6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{21240308-F32A-4810-889D-7BE1008163E6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{21240CD4-F6A0-4F8C-9810-2C92C03B1629}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{21F5E41C-B57D-49B8-B6FE-E5B85B97996D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{2203D5B2-67A4-498F-96FD-5EAF892561A0}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{22C85228-D933-432D-8DE4-ECA181801790}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{233587D9-178A-4363-A034-4AACDE3AC7D7}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{23DE833B-39D3-435C-94FA-6E782878A660}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{24E83C79-3182-4362-ADC0-2425BCA843FF}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{251A89D8-B826-4E44-9FD6-DAEDFB8E18B4}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{25F2451C-FC17-4BB8-AE48-B51EBE97F204}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{267FD7D4-B39D-4EB2-A881-F8361C2B591A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{28130868-78A3-464A-96FB-DE6652E0151B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{282E4018-D97A-4534-9513-087F74A31B18}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{29B709C6-FEEE-4A2E-829B-39E2B18305E9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{29BC1F0D-ADDA-4628-AF54-FBC658D2F36B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{29D6E11C-3389-4FAF-8CF4-96627EE4A37C}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{2A4A3099-DE19-42F1-9AA4-BB9BC3E7A68A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{2BDA7BBD-3F8A-4971-A719-4A36AF4A542B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{2C49461F-80A6-4836-86F2-399BAE89D8C5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{2C8AECC0-77AD-423A-997F-7626F23A2E81}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{2C9ED737-0008-4425-A59A-BD9286F0EA93}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{2CD804B2-4113-409C-8EFF-96CECBA2377E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{2DF80190-4733-4453-AA4A-F024F92AEB6E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{2F392F2B-5AD4-4895-818B-277858760B28}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{30FB9B92-84B9-45CE-B95C-82EE32EAA999}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3138DA59-5400-4998-BC7D-C4C7F1907389}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{31D019BE-881E-4DB5-8BB7-F2A5077834D8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{326D8319-BF96-4BEC-A2F0-30BB3ADC2BAF}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{329E4EB9-1601-4599-9FB5-1E5E856008AC}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{340F21F6-D8F6-4236-BCAA-5274335AEFE3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{34BA2ABA-D330-4853-A5D9-D1F190E817BD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3581C261-D504-4260-812D-DF98944ABBA5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{372CC746-3252-4274-957B-E3864D39EB86}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{37A85AA7-48AC-4F35-8597-F19BFD0969DC}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3819AFAA-B55D-41C2-9105-3358E55D567B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3889B897-8C92-4B24-A7C3-90534558FF52}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{39D48CEE-78DB-446B-BAE5-A2D95ECA8E76}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3A8237C0-85FB-41D5-95AF-5155A17431BB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3A97B08E-4E9D-4D54-A782-3DDE757D250D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3AAEAF0B-EA18-439E-8E8D-13272C016D2E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3B338EEB-2971-4752-B278-FF6E84044366}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3B73BC46-E0D9-42D2-B48C-A8E97BDA27C9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3C151709-B381-4FF7-8CFA-55D7053652DC}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3C328D2F-7AF7-4194-B31A-3564F049DCCA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3CEADDAC-4DB9-41B9-ACB6-1C101D8EEB33}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3D4E7ACE-4652-4786-9C85-3E147BD881FF}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3D9911AC-A5AC-4A1E-9222-FB116A49159E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3DA9B92C-E395-488B-A3A7-BF61D9BF3D0C}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3F0F2842-8F75-4C9A-8CFF-1C8BDFE35751}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3F1A2E0F-AFDD-40D2-8C32-AD07186292D2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3F2338DC-7412-4DB2-A6B7-A6FCD3A037B0}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{3FF11A15-5B11-4FC3-A433-5258840566DB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{40012DD3-88CA-462A-97CD-5AD7D52A8354}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{40FDBB64-29B8-42FC-8004-37FA6EB126FE}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{41E111DE-21FD-4F83-BC0A-3FC5DFD62712}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{423BEE46-0D57-4AA6-81CF-0D9CC2C000B8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{425590AE-268F-4210-A2C4-A71A2BF49974}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{42BED627-BE84-480B-97C9-C34BE6D58989}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{42D17DFD-12A0-4C6A-87B9-F9A957C77A14}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{432FC5A6-0AE1-4EB3-95EC-0386FAD890F1}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{43568D7D-F188-4807-AFA8-93DBDF0E6A36}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{43F5EC0F-EC80-43F0-9F27-5CE81BB2718E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{45192F77-D1D4-4FBD-88A1-617DBF2D04B0}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{457C9DA8-7AAB-40C3-AC13-05D20C2EFD71}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{458AF2D1-0385-4F48-8F1C-C21E842B2871}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{45A0DE34-E120-4EE0-A3B6-B266883737E2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{46598867-42CE-4DDD-90F4-2225535AF4AA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{46613F0D-A2D3-425D-A2AB-5361A4EC8D54}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{46B71CD4-F2CF-43F1-9D37-6A49505CC0E9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4758CFD1-6C7E-44BC-B295-D4BAAC0AF138}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4796A7AB-C799-4839-A86E-173559A3404F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{483E4720-F82A-4480-9758-DF61FF1FB5E5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{48B6E74A-3F53-4347-BA47-E6B1651B0351}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{48F12593-576F-41A0-AFBB-FD08B164248B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4919DDED-D6AE-44F9-AF82-F7A897FC56D2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{496F0EEC-6DB0-4B2C-AE55-1A9E0824F7CE}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4A401020-D937-4CFC-A254-24B7A2F9C3BF}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4A88A14D-1924-4C9F-A865-BC671F454320}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4A8F4C7E-1077-4191-B620-0CF42D4447CE}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4B01B434-C973-4BC9-8123-5090D6EDD9C7}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4BE4367F-CE4F-4330-A9CB-817011432E22}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4C97599A-D602-4A31-854A-ACE7075054A3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4D143AC7-3448-4978-96A5-9FB55F6CAF5D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4D437261-5EEE-4922-880C-D1ECC00D7895}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4E33EF49-7950-405B-A9B6-BAF837154398}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4E57CC76-39B5-4FE7-8C58-8F16BDEDCF12}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4E96B30C-40F4-46D7-94F4-65C524A078A6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4EDD9AF9-4C4F-422E-BDF4-0D16F337589D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{4F65FB5E-B396-4E7E-963D-50F56EE3DBAF}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{52195A9D-D5A2-4002-9403-D37A001F5CCF}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{52E99A2F-1491-4637-B6C7-0E5CC2ED698B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{52E9BA9E-20E0-4CED-9223-969F9572E398}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{53E17D56-9778-4251-8049-AD88524DC5F6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{54C22BF4-1D3B-4740-90B1-A0B1FD51B109}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{55F206E1-BA9F-4F66-9473-F6CBE2F0A188}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5653B8EE-4207-4791-A453-450095F223E1}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5660421A-8487-4BC5-AE77-BD69B2C89F5E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{56859778-1F61-4C60-8296-6DE8CE5655F3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5844A0C4-B12F-400E-8246-FC408FB69BEA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{58ED0273-40FB-46BA-88D4-B000B550A35F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{591E49A3-4DF3-4D2D-995E-2BCCF72CF3FC}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{59610221-C157-448E-AB0F-E239D2F61B84}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{598A6C25-F48E-4588-AFDA-E65333F7B8D0}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{59984C96-CEF9-4CF0-866F-89415B253DE0}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{59DBB185-C454-4317-B847-3D7FCC833F94}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5A77B8AB-A06B-444C-9C40-523474B6A1BB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5B61AE9D-F131-4E81-A156-54341BA5157E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5B6D2CAB-A639-45CD-9BA3-3921A6236A77}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5C045E09-97E6-4FA4-9A8B-5A40B322B31C}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5D3BC575-33C5-443F-9E5A-CA40B22C06FE}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5D4CF97B-052B-4A60-AE69-A3C1061536FE}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5DBB3F70-870F-4A77-829F-671A81C047F8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5E4EFE84-DC95-4D27-8899-6C574EA3E734}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5E8E93C2-CC31-4C95-8819-594EEAA841BD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{5FC8CF68-00E1-439D-812C-110405067C7E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{60C1C855-F011-4B1D-B293-81EE9414CCBF}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{61040B7A-56AE-4A04-BF3E-7AADA53CA22A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{61CAC53C-CE64-4713-AB43-1D9205F6FEB9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6214913F-0D2A-4455-97FC-7062EC013EA4}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6227BB8E-77B8-4595-90D7-079D21891563}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{625DBACD-C9C9-4084-B106-4F0D532327DA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{627081EA-62F2-4935-A415-9AAE60559D12}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{62740C1D-5C0C-4D05-B088-F129F50FB957}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{630F839E-37F4-48B3-9FAB-F1345EC227A9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6400D1E9-96C9-467B-8155-96801192BCE3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6468408F-3425-4680-86AE-12E602E409B6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{64BF73E7-7F2A-4532-A75C-9891B4A02FAF}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{651DE275-8526-4444-8BED-445539B58BD9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{66091E36-7E72-4C2A-8D03-872042D3FC7B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{66793686-E0CA-49C9-A225-71F5A9660357}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{66A7E981-A653-4448-9F8B-BD03DC3D86E3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6732C4F4-BA23-445B-9061-ABB0E37AEF3A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6751E8EC-FC64-4F68-BEA6-92D8E17DB618}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{67706E96-95AF-477F-95F9-6D65D180B7BA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{67A056A9-1D2E-43DE-AAA2-990B4CBF964B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{67E5E0C9-C349-4D98-868E-B5B655E95F1F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{685B8EE3-2EBC-423B-9084-298C68B3F921}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{68725502-EAF8-41ED-90EF-3DF88BD89036}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{68CCAAA3-FF31-4E12-9BEA-C5BBBAF3A978}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{68DA207F-F52F-4D6D-A652-D9CE69C1B820}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{69B17B01-6633-4860-8649-30E738890903}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6A25D6E5-2EA6-4483-908B-C91BAA218044}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6AC6E757-035B-4772-8B7D-B223DEE86975}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6B0AAF8F-0311-4F4F-8191-F8EF38A4850B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6B133378-74D8-4F04-A969-9335375049BD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6BE4287D-CF2C-4036-A0E8-EAE62A98C741}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6CA50F7D-0FF0-4E96-AF43-4DC3AE4FC218}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6E185A6E-7965-4E02-A062-7CFF1BECBA6F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6E2E9503-796E-4E3C-8F38-6080A789CA2B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6E53BA83-F1D9-4EF1-B5F2-10293A360CAF}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6E6BBEA6-A6A9-495D-A47D-9F7E699560C2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6ECB6D40-3611-4614-B935-5509E3A6E5EA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{6F547AE9-785F-4BB6-91BD-EBC902EC31A5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7043B38F-A57E-4ABE-97F7-21EB94D4E02A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7065AD2C-A6B9-48BF-A236-553FC74DBE10}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{70AE6D30-55E4-4883-87DB-21BE40F7C838}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{711CD557-AE8B-4246-9F09-E91EDB533ABD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{714924FE-E280-4EE4-8473-EE3337B308AA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{718594ED-C62B-4C7B-9D06-FEFF3F04938C}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{71BB1F9F-328A-472C-957C-A3BC202D3E51}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7212A80B-8FB5-4284-9229-0A92826A60D4}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{721FA5E6-5E68-4D4A-B770-174158445F9E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{723482E8-5836-45C1-8A3D-C3D2C7B0EFAD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{741BEBF3-A51B-4BD0-B763-2D3852855EDA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{75DC92E5-6667-4FF7-8CC6-0EBD725283D2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{761DA73F-2200-400C-8F2B-047ACE992C09}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7626903E-76CE-4ADA-BA18-D06D96299538}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7682A0B4-B792-4EFF-A89C-70982C56E926}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{780A13B2-7F33-4354-8BC8-B5F83A3BBB1D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{78210639-4D4E-4E3D-AFF4-F46FACA099A9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{78BBE8BF-D54C-4BCF-9649-663C6AECBE8A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{79A673C9-9D92-4506-AD44-DDADDD388CEF}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{79EA57F6-3B3A-4965-B343-4EDC50FB8BE3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7C67166E-DD20-41F8-90FE-46580F0695C5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7CB7F161-D23E-4387-8EA9-5BFB69F54EA2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7D3ABE2A-7A4A-4390-A378-02E56C0D7520}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7DFE0434-6FA7-4626-AC84-9698D407282E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7E15F495-E8C6-4264-8E8A-B14F04C9721E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7E2AFAA0-FFA6-4FF2-9D82-458DE4DAF830}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7E35F788-6CB9-4748-8F61-14E1208CAA9A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7ECDE850-6663-4B09-81D6-D37AFA901EC6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7EFAABF0-CE72-4576-8A50-CC5A64230607}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7F2F8646-F521-495E-A380-3849E2BD5149}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{7F42687C-BCEE-4806-87C8-AAC775B7202D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{81A8CC84-F6D1-421D-919A-012A70B469F2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{82509851-35F8-4D4A-80C5-A610AC80EA1E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{82EF58CA-5B8B-4BFD-9B19-3D818215832A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8382F3FF-BDB4-4AAC-8E4C-B1A43143AB89}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{83F9D82B-9508-40F7-9496-739B727D2C69}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8425C440-BCA2-4CA4-9159-B525930E01D8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{844B4B84-577C-4257-8918-5AA1DDBAFE0E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{84674BC9-50B3-474A-BEC4-9C7821226E44}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{84C1481A-EB7C-4C7C-96A6-8BD1ABAAD569}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8540175A-813E-45BD-B1AB-C7030A0D4FD9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8582E549-D063-4BB2-AFA4-DF89DF84F47E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{85CF1FD1-36D3-416F-92BC-8B9601CD227B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{86117884-24F4-44C0-8CD1-AF44868A6BA1}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{861A67F4-0A6D-42B4-8935-2187A663F8C4}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{870D65F9-7B63-4380-B5D7-BEF781C7D82E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8723A965-A6B5-479A-A384-6CF2F1131A87}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{874396DF-9D40-4FBF-BF09-B5939245E273}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{88A417C7-5442-4A53-BB43-51540E28EADB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{88C298CF-5F3A-44C3-8B4A-C87FF50CC5B4}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{88D227E6-CBEE-49C7-937B-23E8C979FD63}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{88E975BB-1F96-4E21-9BAF-8F16D6B6E85E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8B29B8F0-E927-44B0-ADD2-FEEA804713F8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8C6CD1F7-BD7E-4A85-8616-57790F3BEB88}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8CDA6D97-3333-4501-A6CF-201F4305FA1F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8D136433-EF6E-448A-938F-001CC3900811}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8D5E69BF-D11A-4ED8-998D-150FB59E193D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8D69E693-C602-4658-A4AB-C716DDECE742}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8E8CAFAF-1232-4B4C-BC48-19560110F97A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8F71563C-A777-4A30-9C86-8BA684B1AFFC}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8F8D27B4-B9D7-4F08-8EAD-DB26FC9CD221}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8FC79192-247D-4014-BD99-56E49C203C02}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{8FDC35E4-B493-42B3-A3AE-BFCAD299ADCA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{90066805-187F-4E14-AF38-0F7C71C8F0A7}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9036E6E2-3B87-4DA6-B3C3-23F26DCA64B9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{90F19C66-6AF5-479F-87D9-4C40FDF432D2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9114395B-4783-4A2A-8671-1569A2C0AEA9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{91476571-6871-41F4-9F28-E5FD49B8FAFE}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{91B447B1-5C41-4302-9452-2A13E7A6B279}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{92A06B63-2E92-4548-BD9D-7CB9F032A678}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9306684A-8C9C-47CE-A0CC-E76984715187}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9416F53C-3E19-468E-B229-A1A3420FCC00}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9508A2A0-41E4-4092-9471-D1BBC2468054}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{958D381C-4015-4BEB-8E95-898AF03224F7}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{95BF6051-5544-4038-8611-5BBE03613FD1}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{965FD1CA-C1A9-4B94-A598-172DFCD01A24}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9664A7DB-C537-4DD7-9C4D-9936442288CC}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{96771B43-DAC5-43A7-AFB3-721BD2BE468D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{980785B6-7A3F-41EB-A1C6-C765DA3398E2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{980B0C27-B14F-4ED8-AFC0-7DFF1AAB95A0}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{980B85A7-F14C-4915-9CF5-60407BDECBBD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{986A1B48-5FED-442D-9448-2F2686BA4F76}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{993F858F-E390-4214-A05E-0532C554CB89}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{99D7EB82-0C5D-4370-97D1-D682B70F39BC}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9AA04893-9E94-412E-94C3-02E4C9E42ED6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9ADF91F3-03F3-441F-BFB3-08B68AF998E7}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9B23B397-B592-448E-963D-CEFD6EF789B9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9B6FB9BC-946A-4D54-B2B2-BDF6E2286D26}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9C00F307-7322-42DB-AE68-FA210CE636D0}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9F419A1A-2AFE-4DE9-935B-FA84365188B5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9F5F445A-E8D3-49B5-AA22-4D663D37E2A1}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{9FC52D60-27E2-4F8D-AC8E-219382D0BAEB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A02B81F1-0C8A-4708-B73D-EF33269A5D29}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A039E192-F474-409D-8C33-06EF4656E018}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A0BCC370-EA3B-45C8-A2BC-F57D2E8DBFCA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A174FE7F-B7E9-4B1C-A746-CFB30A9EA469}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A19302CC-96B1-463E-9DBD-040EB62D0042}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A356B852-0973-4078-A898-CDA0A4CD7910}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A430C252-50E2-4AC9-A4D2-FA739964DCFC}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A51A8343-261B-444A-89B3-A4EEDD451F85}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A555DC65-5C87-4BAC-8F9D-556ACA7DC35C}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A62536FB-60D5-42B8-87CE-AC8F5BFCEE0C}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A674A383-F29B-4C66-AA7B-60B1251C4C6A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A77845ED-252A-4268-ADD7-B85A3BEFE26E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A83B59B5-39F9-4B1D-97BE-9B92D1AFB7D6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A875CD2E-CC4C-4200-9847-606A2EC31952}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A8CE369F-C5F9-475E-B9ED-64B3E76D329F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A8E6C45B-7C55-41A6-9074-8BC5F49C3821}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A903CECE-D4AF-4212-AE36-BC81A72F4558}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{A9DF58FE-4EA4-4AFE-95AB-4A1429920B28}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{AA1CAA38-F8A0-49A7-8136-902AECE87F7F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{AAF516E4-86F7-4A25-BFD7-A7CE389FCE92}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{AB3C689A-B850-483E-9F89-DD48AECF78A3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{ABBCA37D-FE52-4531-98F7-B8EDBF6D494D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{ABE3B411-EA1A-44D8-B872-87623692B223}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{ACCDB69C-A671-4F0C-A0A8-9D7942609AF7}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{AD06882C-71AA-43E7-B4CC-1045BD42177B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{AD46DB55-5458-4955-B2F2-231634637F86}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{AEEDA7E5-3389-45F8-B261-F1796A3444DB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{AF951628-8EB2-4C79-AC85-B7A5AB7A8005}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B0123D44-AD87-459C-9843-C38E027FF68B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B0B49679-5794-41A1-B3CF-83280B077419}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B1D0D74D-C44D-4046-B6F5-8FEF22BCD0F8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B1F10E49-2577-430F-ACD1-E25B87A5F3D5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B23CD844-178D-497D-AEDD-AD7234951A2B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B268BFDC-5436-440D-AE73-A89AF142F6A0}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B295D3F6-2450-43A3-A80D-9107C252EE9A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B2C82296-7A09-4A12-AD47-EAC7AA7082EB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B363C48D-2EB0-4E21-B13E-B3398074E9C9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B3683455-5A1E-4ABC-A76E-06A2A628C580}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B372ECFA-862B-4141-8234-15F339312857}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B3D971B6-F12E-4038-9962-D5091BF9C410}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B42FBA32-71A9-4349-B472-F9CDA0E45A4B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B65B1EB6-FA0A-4836-9083-83E96589F36F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B69A4D57-1472-4F7E-9BB1-75383498E13C}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B6A731D5-D79E-4F8D-AE92-D794ED2A9BAC}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B8740CB9-26BE-47DF-9B1B-63918C797810}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B8CBB435-1DB8-4DF1-A165-4BC4993CE62D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B944653B-8948-47A2-B544-B2D2AC21FAAD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{B96D9BA5-3E9D-4C31-8BE0-AB851F497B58}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BA19C281-7D1A-4207-8A25-48AE8002C06C}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BA21CB00-EB23-4F53-9C81-A2F177377A89}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BAB1D521-0D95-44FD-B16E-38F68846ABD5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BAD16C5D-CEEE-4FE7-B107-E65473438A2B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BB2C6B03-043F-4BCD-A073-105B2856A32D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BBC6C3D9-24F1-4D78-861C-0370FC136F36}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BC34332F-2FA9-488E-9DB0-FDCFDE4E91B6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BCC10696-ED21-4966-B9BE-530D7D3812D9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BD2324AE-FC27-42CE-AAA6-EC34EC88E24B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BD3E8607-CF61-48D1-A5BE-23A91D6E57C1}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BD6E5AF3-57C7-4811-97C2-8A56CDE27ECD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BDBBF137-35F3-49B9-8668-23D03F342B3E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BF116C46-30DC-46D8-98D8-87B52DAF63EE}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BF3B2ED4-AB32-4479-B288-201D677D68E9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BF4A353C-2CD9-4858-93DD-2A4342C593C5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BF4D70F0-F236-4F1D-95D2-0E028380725D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BF7C437F-97FC-47B2-9645-1E2A670C832F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{BFFAC954-8AA0-4216-A2E2-91DBEA6A06F7}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C00175B8-FEE4-4E02-B80F-E4854B747F77}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C0353B9E-B869-46C2-A309-E9F57535077D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C0D4FDDC-BD5B-4E55-AB90-628B79C58777}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C14A19A2-5777-4C1D-87AB-FD9F268ECE3E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C1543BD5-F418-49C8-A7E9-97AEB51EE667}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C375F912-064C-4E23-A15E-113A69EB6FDD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C3824575-8B4F-44FB-B9D0-92119E25DECE}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C419C028-DB40-4A63-8173-222D1153F770}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C45C534B-FFEA-40F9-AC5C-D3304AE16033}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C56C352A-A507-43D6-B212-949F02906BDD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C5BC44F3-D02E-4952-A3CD-78F4BB7C71CA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C63620B0-2477-42A6-B623-F8F18A83B101}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C71608D1-6F61-46F2-AABF-4C720F4FBFBD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C75796D9-12FB-49AA-AD57-A27C636118B6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C813DAC7-F64B-41C3-8218-11FB8D6DE806}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C85EC72E-6C8A-47A0-AB50-0D952EF128F5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C91DEC0F-8D97-442C-8167-D037212A569B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C9C2AE97-5823-4553-AFEC-9F5ECA6E2385}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{C9C71DDF-E7A5-41DA-9DF0-9C8B66B9F49B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CA32F0AD-9399-4E96-954D-17872FECBDE6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CAAC51D4-605C-47F9-B5EA-177A0C17D957}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CB2727A0-1E2B-4553-8519-96BB28FB72F6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CB620C1A-A0C1-44C8-AAF6-EC93BA735A94}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CB826E24-B278-4DB6-9EA7-3C2C05E7BB66}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CB886E59-0693-4DE1-B7FC-CAA4DEF29244}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CBA2392B-EB4E-447F-9CBB-73D5F45592B0}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CD2965AA-8609-4E41-BE15-DB31BA9E7E2D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CD7E1453-16D6-412E-8923-0C6B31979DC5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CE10D314-6C72-40B5-9B11-BFB75B214A07}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CE154C4B-98EA-4EA5-97D9-5ED6804E2A43}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CE72222F-031E-4EB2-B80E-5AD25185EB92}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CEAE1FE9-1FD8-4393-ACB3-70EE8A0B1AA6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{CFC72F17-536D-4D7C-B429-C1DD0B934FA5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D1952E6B-0A54-42DF-89E8-5EE1F14C4CEE}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D2C5CF6B-99A5-4E1D-9FEC-42B7689829AB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D42DEEB8-92D4-4EF0-A32C-656D596A9BFB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D58181F0-F009-498F-AFE3-7C467866BC76}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D5976D93-D3E8-4171-AEEA-BA40F2D663C2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D5B20090-DD9B-41C1-B942-6AA63C982B54}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D737F37C-232F-4511-99B6-2FC472114A1F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D7522FE1-54D8-4769-953A-74A88483AB92}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D798F180-ACFE-4243-84AC-23AD3A5E5C06}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D7E2126B-C093-473B-9BD8-7D5EED6998FF}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D86EFE1F-6ABE-4EDF-AC8C-67D04F41AE9F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D878DFF5-70F3-46C2-8A5D-4DC44A909E02}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D8C32CF7-4B7F-4616-885A-627B23886841}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D901C5D0-705F-4575-A3A9-F140E9422FF9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D91FFDE1-C065-40DE-8F7A-0DA6F1EC148F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{D9C1E854-EAA7-486E-AAF9-5B023BA73CA3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DA3FC1FD-46F2-40A5-A4FF-5AC4801B432F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DA494612-510C-408A-8F52-6CA02E554E4A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DAB26DE9-0C36-4C25-B8B5-040151295CA2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DADBBF30-341A-4707-925F-7BB051D68702}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DAF43E6F-26CA-4034-BE28-853CF8209A2B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DBAC4AF0-7453-4693-87AB-88B25045CD82}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DC9F6729-C790-4ABE-ACCC-EDB1A075934D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DCCDC56E-9EE8-4F54-85F3-2A90CE4E1B17}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DD32C405-B24F-4DE5-9949-D5D81292C5B3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DDC61BB3-EF7C-4D3E-9F30-C0EEE805412E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DE8B7864-E730-47FD-AFA7-31155979060B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DEABBFEB-0532-4B25-B5CB-1CB5CF21C658}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DEF328D3-748C-4854-B9A0-44F112509AE8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{DF2CA921-1A42-442E-80BE-BC1C7E48CFD8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E0E6336C-6D33-4737-9357-4833F32AF847}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E1C81B3A-4B3A-48C1-9CD5-19832CF69A9A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E1CB139B-F12D-469A-A59C-18EEFD195A9A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E1D42F9C-6662-4CF0-BFBB-230E88CC6E18}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E1DC6AE9-9707-4268-AA7A-7ADAC000C8C3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E1F45244-5F7C-4B05-933A-0DFE8ECE6F5A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E2C08D4D-160B-4F43-8C55-85DFE1403135}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E2D5D915-E81D-407B-967D-EDEC0997A9EB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E2FFA60B-B47F-4591-9BF6-A5C80BFE7A94}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E37FAEAA-0269-4A6D-AB35-2F7C8F8F82D1}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E3E4DE26-6417-476B-A6E1-9CA34CCCD0CD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E4A2B672-2726-4C01-BC43-359532F18412}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E4F498E3-758E-4A55-B742-5E17C568D0BD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E5985955-7258-4841-8836-F5EC84E3E939}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E649D2B3-65E4-4A69-905B-E61B2F490CC9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E65074B3-B83B-4AC4-BDDA-CD0EB3AC9FA6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E68F1DDE-473F-470D-A381-2415B775A966}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E6FF117E-B713-43AF-A67B-F59771DEEE9A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E75C8433-7CCB-41BE-975D-9E585E1DA3F8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E76D12D5-D74B-4173-8FF1-89E03EA3AD9A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E871B4F2-1A71-494C-B426-11B62E2D6A98}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E88599AB-5D8C-4C37-A843-198B6BEA8695}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{E9AA83D5-730C-420B-B3F1-E6AE627F240A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{EA433D5B-3187-480B-A0DB-005F4AB8A0EA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{EA5774B6-722E-48D2-A034-9A79CD5AF2CC}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{EAA924DF-4CA1-4427-AF0D-7D210FA28995}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{EB3AE286-0233-4E53-B275-78AE8DF1754E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{EB7526A5-A09A-46BD-969B-90B2CB954CD2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{EBB943BC-E69B-4139-BDD8-B7156F5557C2}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{ED230B8C-7678-402A-9113-9CD18F2A0B9E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{ED3C325B-57D8-43B7-86B9-C2E208BBCA97}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{ED43A0BD-9FD2-43AE-9A28-D7417B428CA5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{EE396288-BA63-4997-89BD-6FDBAC00AB3F}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{EE94A0A7-A259-4B49-A465-D4DAEF39EEF4}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{EF4D64AD-AE1A-45D1-9F05-8BE62A10CE8B}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{EFEADB65-1054-4DF4-AAF5-6C519648BC8A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{EFF44022-88CD-4933-A280-7798422081B5}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{EFF79EFE-8F68-48B4-B5FF-A786E64672D6}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F16C3D29-DCA4-49B6-B016-8E69BADDC2EE}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F19497A5-0F6D-40A5-9E4C-64774C48531C}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F1C6C9C0-780F-4F31-90A1-6C9B89602814}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F1CA4AF6-2A36-4CE1-8390-C74A6652C5D9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F21A3078-35A2-4D72-9F4A-A6439E51A9D3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F2AD9C48-435F-4FB9-84C0-DA3630635EE3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F3D05C74-31EA-4518-8516-25D9A995B3B1}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F479F211-B196-47D8-8DD5-74974017914A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F498B825-8F85-4380-8867-443C5A2261D3}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F5351762-9FE9-416A-BAF1-C9D3E6739A37}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F7647FBE-C77A-455D-8EB8-851E2A72A26E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F782385A-9B12-4569-A36A-5DE6A80DEABA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F7A1EFE9-9F30-4BD2-955B-79978D8966EC}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F830BC65-A814-4AEA-8B70-D090580595FD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F89953AE-15B2-473F-9B57-23469EC5CA4D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F8A86B1D-E0FE-4CB8-9520-863876E6B0E8}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F918AB66-D212-4BF6-A822-445BBFBDB4AB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F942E207-F380-4317-9EFB-C692CFD0037A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F976391A-716A-4F24-B917-B4272695D180}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F998E60A-691D-4C29-8082-CE314961FFBB}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{F9E81E4A-A6B8-454F-831F-8D143B0E98BD}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FC05F876-907B-40F7-AB1F-472C1879DE16}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FC588B86-5F3A-414F-B349-0908F73846E7}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FC8EAD00-B1A2-4E38-8964-323EE20C5C6A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FD6D82C6-7015-4F58-B01E-E91DA782FD3A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FD7693E0-0B2B-4F36-AE3C-8F4792B4792A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FD879922-CB58-45D1-A363-331499E794D7}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FE251AF8-B81E-46F1-95D5-4018A22FF905}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FE276B64-46F2-4B31-9346-5A526FFA1B1D}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FE5B01D3-C749-4763-8257-BAB93DCDF1DA}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FE5C78BB-6840-49CB-B85D-E9FD5D1E43E9}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FE84182A-DC61-413D-A684-75B62230678E}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FF4478A0-532A-4A38-987E-CB6776B5956A}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FF91861B-F42B-49D5-B851-58E7B9D0035C}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FFCB90E5-C36D-452A-A4AB-56DD68F4C665}
Successfully deleted: [Empty Folder] C:\Users\mediamarkcruqius\appdata\local\{FFF12C59-1DCB-4520-9AB1-01BDEC895769}



~~~ FireFox

Successfully deleted: [File] C:\Users\mediamarkcruqius\AppData\Roaming\mozilla\firefox\profiles\3jrfjxl7.default\invalidprefs.js
Successfully deleted: [Folder] C:\Users\mediamarkcruqius\AppData\Roaming\mozilla\firefox\profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com
Successfully deleted the following from C:\Users\mediamarkcruqius\AppData\Roaming\mozilla\firefox\profiles\3jrfjxl7.default\prefs.js

user_pref("extensions.crossrider.bic", "1436cc033b94585c63b455882f5a332c");
Emptied folder: C:\Users\mediamarkcruqius\AppData\Roaming\mozilla\firefox\profiles\3jrfjxl7.default\minidumps [312 files]



~~~ Chrome

Successfully deleted: [Folder] C:\Users\mediamarkcruqius\appdata\local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Successfully deleted: [Folder] C:\Users\mediamarkcruqius\appdata\local\Google\Chrome\User Data\Default\Extensions\igjjkeeamkpihpncmmbgdkhdnjpcfmfb
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on di 07-01-2014 at 14:27:00,79
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Vyskakujici reklamy

#4 Příspěvek od vyosek »

Zkuste jej udelat v nouzovem rezimu
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Ver
Návštěvník
Návštěvník
Příspěvky: 113
Registrován: 31 črc 2008 19:05

Re: Vyskakujici reklamy

#5 Příspěvek od Ver »

Tak v nouzovem rezimu to same....

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Vyskakujici reklamy

#6 Příspěvek od vyosek »

Poprosim o log dle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Ver
Návštěvník
Návštěvník
Příspěvky: 113
Registrován: 31 črc 2008 19:05

Re: Vyskakujici reklamy

#7 Příspěvek od Ver »

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014
Ran by mediamarkcruqius (administrator) on ADMIN on 07-01-2014 23:50:08
Running from C:\Users\mediamarkcruqius\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\ProgramData\InternetUpdater\InternetUpdaterService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2.exe
(Updater) C:\ProgramData\Updater\updater.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(WatchDog) C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe
(WatchDog) C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe
(WatchDog) C:\ProgramData\RHelpers\IeHelper\IeHelper.exe
(Host Process for Windows Services) C:\Users\mediamarkcruqius\AppData\Local\43D0D494-7FCC-4165-98F7-37C3B7ADF6AE\svchost.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
(Host Process for Windows Services) C:\Users\mediamarkcruqius\AppData\Local\43D0D494-7FCC-4165-98F7-37C3B7ADF6AE\svchost.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(forum.viry.cz) C:\Users\mediamarkcruqius\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] ()
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe [520760 2010-03-10] (Conexant Systems, Inc.)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe [505696 2009-11-05] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] - C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [913720 2010-03-03] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] - C:\Program Files\TOSHIBA\TECO\Teco.exe [1489760 2010-03-17] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] - C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [705368 2010-02-23] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] - C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2327952 2010-07-21] (Microsoft Corporation)
HKLM\...\Run: [Toshiba TEMPRO] - C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1050072 2010-02-11] (Toshiba Europe GmbH)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1289704 2012-09-12] (Microsoft Corporation)
HKLM-x32\...\Run: [Microsoft Default Manager] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [288088 2009-11-11] (Microsoft Corporation)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [IndexSearch] - C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-08] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ControlCenter4] - C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139264 2011-04-20] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2629632 2011-10-07] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKLM-x32\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [486264 2013-12-18] (Updater)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [717696 2010-01-16] (Microsoft Corporation)
HKCU\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKCU\...\Run: [Google Update] - C:\Users\mediamarkcruqius\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2010-10-06] (Google Inc.)
HKCU\...\Run: [lollipop_01070755_2] - C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2.exe [2734592 2014-01-07] ()
HKCU\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\mediamarkcruqius\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKCU\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [486264 2013-12-18] (Updater)
HKU\Default\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [4581280 2010-03-03] (TOSHIBA)
HKU\Default User\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [4581280 2010-03-03] (TOSHIBA)
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [ ] ()
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP =
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs =
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds& ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds& ... earchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.nationzoom.com/?type=sc&ts=1 ... 016EETM1LX
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... earchTerms}
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... earchTerms}
SearchScopes: HKCU - {31C364F3-B160-47B4-9166-73B725E9E5BC} URL = http://www.webhledani.cz/results.aspx?i ... earchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... earchTerms}
SearchScopes: HKCU - {7667868F-49C5-4FD8-AB84-47E83C3639E5} URL = http://rover.ebay.com/rover/1/1346-7149 ... earchTerms}
SearchScopes: HKCU - {7FA6D6DA-F503-48DC-9540-5212D4F27FF1} URL = http://www.bing.com/search?FORM=IEFM1&q ... rer:source?}
SearchScopes: HKCU - {CBCBE449-3AC9-4DAC-93EC-A96AE5111749} URL = http://www.amazon.co.uk/gp/search?ie=UT ... nkCode=ur2
BHO: DP1818 - {11111111-1111-1111-1111-110411891178} - C:\Program Files (x86)\DP1818\DP1818-bho64.dll (mrlmedia)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: ValueApps - {93DBF2BB-A2B3-4683-A92E-57E60751F346} - C:\Program Files\Conduit\ValueApps\IE\ValueAppsLoader.dll (Conduit Ltd.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: ValueApps - {93DBF2BB-A2B3-4683-A92E-57E60751F346} - C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll No File
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
BHO-x32: Webexp Enhanced - {fd9425ac-8ec0-4faf-8f6c-3033cc2ddd26} - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ie\WebexpEnhancedV1alpha2360.dll ()
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default
FF NewTab: hxxp://www.nationzoom.com/newtab/?type=nt&ts=1 ... 016EETM1LX
FF DefaultSearchEngine: nationzoom
FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", "");
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: nationzoom
FF Homepage: hxxp://www.seznam.cz/
FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co"
FF NetworkProxy: "share_proxy_settings", true
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @lightspark.github.com/Lightspark;version=1 - C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll ( )
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\mediamarkcruqius\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\mediamarkcruqius\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\mediamarkcruqius\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\avg_igeared.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\nationzoom.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Widget context - C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi
FF Extension: DP1818 - C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\Extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com
FF Extension: Websteroids - C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\Extensions\support@websteroidsapp.com
FF Extension: Value Apps - C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\Extensions\{94cd2cc3-083f-49ba-a218-4cda4b4829fd}
FF Extension: anonymoX - C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\Extensions\client@anonymox.net.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha2360.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ff
FF Extension: Webexp Enhanced - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@flash-Enhancer.com] - C:\Program Files (x86)\AmiExt\flashEnhancer\ff
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.nationzoom.com/?type=sc&ts=1 ... 016EETM1LX

Chrome:
=======
CHR HomePage: hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP9C598A0B-21EA-43E6-80C2-CBEDFE22108F&SSPV=
CHR RestoreOnStartup: "hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP9C598A0B-21EA-43E6-80C2-CBEDFE22108F&SSPV="
CHR DefaultSearchKeyword: conduit.search
CHR DefaultSearchProvider: Conduit Search
CHR DefaultSearchURL: http://search.conduit.com/Results.aspx? ... rms}&SSPV=
CHR DefaultNewTabURL:
CHR Extension: (Extended Protection) - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0
CHR Extension: (DP1818) - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0
CHR Extension: (Google Wallet) - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Webexp Enhanced) - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\odnopkenikdonjcijkgpahfeamcodhlp\1.1_1
CHR Extension: (Widget context) - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\ombmmloebnfnpehgjnmkcgoegfachobp\3.0_0
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR HKLM-x32\...\Chrome\Extension: [odnopkenikdonjcijkgpahfeamcodhlp] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ch\WebexpEnhancedV1alpha2360.crx
CHR StartMenuInternet: Google Chrome - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\Application\chrome.exe http://www.nationzoom.com/?type=sc&ts=1 ... 016EETM1LX
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

S3 getPlusHelper; C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll [68000 2010-03-29] (NOS Microsystems Ltd.)
R2 InternetUpdater; C:\ProgramData\InternetUpdater\InternetUpdaterService.exe [40448 2013-12-06] ()
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22072 2012-09-12] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368896 2012-09-12] (Microsoft Corporation)
R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-08] (Nuance Communications, Inc.)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [124368 2010-02-11] (Toshiba Europe GmbH)
R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2014-01-07] (Cherished Technololgy LIMITED)
S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe" [x]

==================== Drivers (Whitelisted) ====================

R3 CnxtHdmiAudService; C:\Windows\System32\drivers\CHDMI64.sys [720952 2010-03-05] (Conexant Systems Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [228768 2012-08-30] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [128456 2012-08-30] (Microsoft Corporation)
S3 nmwcdcx64; C:\Windows\System32\drivers\ccdcmbox64.sys [23552 2008-05-02] (Nokia)
S3 nmwcdx64; C:\Windows\System32\drivers\ccdcmbx64.sys [18432 2008-05-02] (Nokia)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [74752 2011-07-25] (Research In Motion Limited)
R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44032 2011-07-20] (Research in Motion Ltd)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-09-12] ()
S3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerfltx64.sys [8704 2008-05-02] (Windows (R) Codename Longhorn DDK provider)
S3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltx64j.sys [8704 2008-05-02] (Windows (R) Codename Longhorn DDK provider)
U3 a42v9l0s; C:\Windows\System32\Drivers\a42v9l0s.sys [0 ] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 cpuz132; \??\C:\Users\MEDIAM~1\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-07 23:50 - 2014-01-07 23:51 - 00026543 _____ C:\Users\mediamarkcruqius\Desktop\FRST.txt
2014-01-07 23:49 - 2014-01-07 23:49 - 00000000 ____D C:\FRST
2014-01-07 23:48 - 2014-01-07 23:48 - 01931762 _____ (Farbar) C:\Users\mediamarkcruqius\Desktop\FRST64.exe
2014-01-07 23:46 - 2014-01-07 23:46 - 00112640 _____ (forum.viry.cz) C:\Users\mediamarkcruqius\Downloads\FRSTLauncher (1).exe
2014-01-07 23:46 - 2014-01-07 23:46 - 00112640 _____ (forum.viry.cz) C:\Users\mediamarkcruqius\Desktop\FRSTLauncher.exe
2014-01-07 14:28 - 2014-01-07 22:32 - 00000000 ____D C:\AdwCleaner
2014-01-07 14:28 - 2014-01-07 14:28 - 01233962 _____ C:\Users\mediamarkcruqius\Desktop\adwcleaner.exe
2014-01-07 14:18 - 2014-01-07 14:18 - 01036305 _____ (Thisisu) C:\Users\mediamarkcruqius\Desktop\JRT.exe
2014-01-07 14:18 - 2014-01-07 14:18 - 00000000 ____D C:\Windows\ERUNT
2014-01-07 14:02 - 2014-01-07 14:02 - 00000000 ____D C:\rsit
2014-01-07 14:01 - 2014-01-07 14:01 - 00935175 _____ C:\Users\mediamarkcruqius\Downloads\RSITx64.exe
2014-01-07 13:58 - 2014-01-07 13:58 - 00000000 ____D C:\ProgramData\InternetUpdater
2014-01-07 13:53 - 2014-01-07 13:53 - 00002026 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-01-07 13:53 - 2014-01-07 13:53 - 00000000 ____D C:\Program Files (x86)\Adobe
2014-01-07 13:49 - 2014-01-07 13:49 - 00000000 ____D C:\Program Files (x86)\Lightspark 0.5.3-git
2014-01-07 13:48 - 2014-01-07 13:55 - 00000000 ____D C:\Program Files (x86)\AmiExt
2014-01-07 13:48 - 2014-01-07 13:48 - 00000000 ____D C:\ProgramData\Updater
2014-01-07 13:48 - 2014-01-07 13:48 - 00000000 ____D C:\ProgramData\RHelpers
2014-01-07 13:47 - 2014-01-07 22:34 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Roaming\newnext.me
2014-01-07 13:47 - 2014-01-07 13:49 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Local\Mobogenie
2014-01-07 13:47 - 2014-01-07 13:48 - 00000000 ____D C:\ProgramData\Websteroids
2014-01-07 13:47 - 2014-01-07 13:47 - 00000000 ____D C:\Users\mediamarkcruqius\Documents\Mobogenie
2014-01-07 13:47 - 2014-01-07 13:47 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Local\genienext
2014-01-07 13:47 - 2014-01-07 13:47 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Local\cache
2014-01-07 13:47 - 2014-01-07 13:47 - 00000000 ____D C:\Users\mediamarkcruqius\.android
2014-01-07 13:47 - 2014-01-07 13:47 - 00000000 _____ C:\Users\mediamarkcruqius\daemonprocess.txt
2014-01-07 13:45 - 2014-01-07 13:45 - 00000000 ____D C:\ProgramData\WPM
2014-01-07 13:44 - 2014-01-07 22:34 - 00002014 _____ C:\Windows\Tasks\DP1818-firefoxinstaller.job
2014-01-07 13:44 - 2014-01-07 22:34 - 00001940 _____ C:\Windows\Tasks\DP1818-chromeinstaller.job
2014-01-07 13:44 - 2014-01-07 22:34 - 00001320 _____ C:\Windows\Tasks\DP1818-updater.job
2014-01-07 13:44 - 2014-01-07 22:34 - 00001272 _____ C:\Windows\Tasks\DP1818-codedownloader.job
2014-01-07 13:44 - 2014-01-07 22:34 - 00001144 _____ C:\Windows\Tasks\DP1818-enabler.job
2014-01-07 13:44 - 2014-01-07 13:44 - 00004350 _____ C:\Windows\System32\Tasks\DP1818-updater
2014-01-07 13:44 - 2014-01-07 13:44 - 00004302 _____ C:\Windows\System32\Tasks\DP1818-codedownloader
2014-01-07 13:44 - 2014-01-07 13:44 - 00004174 _____ C:\Windows\System32\Tasks\DP1818-enabler
2014-01-07 13:44 - 2014-01-07 13:44 - 00000000 ____D C:\Program Files\Conduit
2014-01-07 13:44 - 2014-01-07 13:44 - 00000000 ____D C:\Program Files (x86)\DP1818
2014-01-07 13:43 - 2014-01-07 23:51 - 00003752 _____ C:\Windows\System32\Tasks\Windows Update
2014-01-07 13:43 - 2014-01-07 13:43 - 00000000 __RHD C:\Users\mediamarkcruqius\AppData\Local\43D0D494-7FCC-4165-98F7-37C3B7ADF6AE
2014-01-07 13:42 - 2014-01-07 13:43 - 00336424 _____ (Amônétízé Ltd) C:\Users\mediamarkcruqius\Downloads\FlashPlayersetup__5047_i241433740_il3.exe
2014-01-07 10:02 - 2014-01-07 10:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-07 08:55 - 2014-01-07 08:55 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2013-12-25 09:29 - 2013-12-25 09:37 - 422205137 _____ C:\Users\mediamarkcruqius\Downloads\rychlyprachy71.wmv
2013-12-25 09:15 - 2013-12-25 09:15 - 00000000 ____D C:\Program Files (x86)\WebexpEnhancedV1
2013-12-25 09:06 - 2013-12-25 09:29 - 734624599 _____ C:\Users\mediamarkcruqius\Downloads\rychlyprachy63.wmv
2013-12-18 09:45 - 2013-12-18 09:55 - 00156909 _____ C:\Users\mediamarkcruqius\Desktop\Pavel Kundenliste - Copy 1 (Ambiente 2013).xlsx
2013-12-18 09:38 - 2013-12-02 17:12 - 00161293 _____ C:\Users\mediamarkcruqius\Desktop\Pavel Kundenliste - Copy.xlsx
2013-12-17 09:13 - 2013-12-17 09:13 - 00000000 ____D C:\Windows\SysWOW64\SearchProtect
2013-12-15 19:53 - 2013-12-15 21:02 - 128386599 _____ C:\Users\mediamarkcruqius\Downloads\Jay-Z---Magna-Carta-Holy-Grail-(2013).rar
2013-12-15 19:50 - 2013-12-15 21:03 - 179706685 _____ C:\Users\mediamarkcruqius\Downloads\JT.The.20-20.Experience.2of2.rar
2013-12-15 19:43 - 2013-12-15 21:03 - 167522625 _____ C:\Users\mediamarkcruqius\Downloads\Drake---Nothing-Was-The-Same-(Deluxe-Edition)-2013-320kbps.rar
2013-12-15 19:41 - 2013-12-15 20:40 - 116890319 _____ C:\Users\mediamarkcruqius\Downloads\Kanye-West---Yeezus-and-Extras-2013.rar
2013-12-15 17:01 - 2013-12-15 17:03 - 00000000 ____D C:\Users\mediamarkcruqius\Downloads\Bangerz (Deluxe Version)
2013-12-15 16:30 - 2013-12-15 16:30 - 00000867 _____ C:\Users\mediamarkcruqius\Desktop\µTorrent.lnk
2013-12-15 16:30 - 2013-12-15 16:30 - 00000847 _____ C:\Users\mediamarkcruqius\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2013-12-13 20:16 - 2013-12-13 20:16 - 00002219 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-12-09 21:54 - 2013-12-10 14:55 - 00000279 _____ C:\Users\mediamarkcruqius\Downloads\This.is.the.End.2013.720p.BluRay.x264-SPARKS.mkv
2013-12-09 13:30 - 2014-01-07 22:10 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Local\Lollipop

==================== One Month Modified Files and Folders =======

2014-01-07 23:51 - 2014-01-07 23:50 - 00026543 _____ C:\Users\mediamarkcruqius\Desktop\FRST.txt
2014-01-07 23:51 - 2014-01-07 13:43 - 00003752 _____ C:\Windows\System32\Tasks\Windows Update
2014-01-07 23:49 - 2014-01-07 23:49 - 00000000 ____D C:\FRST
2014-01-07 23:48 - 2014-01-07 23:48 - 01931762 _____ (Farbar) C:\Users\mediamarkcruqius\Desktop\FRST64.exe
2014-01-07 23:46 - 2014-01-07 23:46 - 00112640 _____ (forum.viry.cz) C:\Users\mediamarkcruqius\Downloads\FRSTLauncher (1).exe
2014-01-07 23:46 - 2014-01-07 23:46 - 00112640 _____ (forum.viry.cz) C:\Users\mediamarkcruqius\Desktop\FRSTLauncher.exe
2014-01-07 23:45 - 2009-07-14 05:45 - 00016304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-07 23:45 - 2009-07-14 05:45 - 00016304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-07 23:36 - 2012-09-15 11:08 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-07 23:14 - 2013-10-14 14:03 - 00001056 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-07 23:11 - 2013-10-18 08:01 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-354615371-2128914143-2807093971-1000UA.job
2014-01-07 22:34 - 2014-01-07 13:47 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Roaming\newnext.me
2014-01-07 22:34 - 2014-01-07 13:44 - 00002014 _____ C:\Windows\Tasks\DP1818-firefoxinstaller.job
2014-01-07 22:34 - 2014-01-07 13:44 - 00001940 _____ C:\Windows\Tasks\DP1818-chromeinstaller.job
2014-01-07 22:34 - 2014-01-07 13:44 - 00001320 _____ C:\Windows\Tasks\DP1818-updater.job
2014-01-07 22:34 - 2014-01-07 13:44 - 00001272 _____ C:\Windows\Tasks\DP1818-codedownloader.job
2014-01-07 22:34 - 2014-01-07 13:44 - 00001144 _____ C:\Windows\Tasks\DP1818-enabler.job
2014-01-07 22:34 - 2013-10-14 14:03 - 00001052 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-07 22:34 - 2013-09-02 16:15 - 00023586 _____ C:\Windows\setupact.log
2014-01-07 22:34 - 2013-01-28 10:04 - 00000374 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2014-01-07 22:34 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-07 22:32 - 2014-01-07 14:28 - 00000000 ____D C:\AdwCleaner
2014-01-07 22:10 - 2013-12-09 13:30 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Local\Lollipop
2014-01-07 22:09 - 2013-09-21 10:50 - 00002518 _____ C:\Windows\PFRO.log
2014-01-07 22:09 - 2012-05-01 23:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-07 14:28 - 2014-01-07 14:28 - 01233962 _____ C:\Users\mediamarkcruqius\Desktop\adwcleaner.exe
2014-01-07 14:18 - 2014-01-07 14:18 - 01036305 _____ (Thisisu) C:\Users\mediamarkcruqius\Desktop\JRT.exe
2014-01-07 14:18 - 2014-01-07 14:18 - 00000000 ____D C:\Windows\ERUNT
2014-01-07 14:02 - 2014-01-07 14:02 - 00000000 ____D C:\rsit
2014-01-07 14:02 - 2013-09-20 17:01 - 00000000 ____D C:\Program Files\trend micro
2014-01-07 14:01 - 2014-01-07 14:01 - 00935175 _____ C:\Users\mediamarkcruqius\Downloads\RSITx64.exe
2014-01-07 13:58 - 2014-01-07 13:58 - 00000000 ____D C:\ProgramData\InternetUpdater
2014-01-07 13:55 - 2014-01-07 13:48 - 00000000 ____D C:\Program Files (x86)\AmiExt
2014-01-07 13:53 - 2014-01-07 13:53 - 00002026 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-01-07 13:53 - 2014-01-07 13:53 - 00000000 ____D C:\Program Files (x86)\Adobe
2014-01-07 13:53 - 2010-04-06 09:56 - 00000000 ____D C:\ProgramData\Adobe
2014-01-07 13:52 - 2010-07-19 09:55 - 00000000 ___HD C:\Users\mediamarkcruqius\AppData\Local\Adobe
2014-01-07 13:49 - 2014-01-07 13:49 - 00000000 ____D C:\Program Files (x86)\Lightspark 0.5.3-git
2014-01-07 13:49 - 2014-01-07 13:47 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Local\Mobogenie
2014-01-07 13:48 - 2014-01-07 13:48 - 00000000 ____D C:\ProgramData\Updater
2014-01-07 13:48 - 2014-01-07 13:48 - 00000000 ____D C:\ProgramData\RHelpers
2014-01-07 13:48 - 2014-01-07 13:47 - 00000000 ____D C:\ProgramData\Websteroids
2014-01-07 13:47 - 2014-01-07 13:47 - 00000000 ____D C:\Users\mediamarkcruqius\Documents\Mobogenie
2014-01-07 13:47 - 2014-01-07 13:47 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Local\genienext
2014-01-07 13:47 - 2014-01-07 13:47 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Local\cache
2014-01-07 13:47 - 2014-01-07 13:47 - 00000000 ____D C:\Users\mediamarkcruqius\.android
2014-01-07 13:47 - 2014-01-07 13:47 - 00000000 _____ C:\Users\mediamarkcruqius\daemonprocess.txt
2014-01-07 13:47 - 2010-06-02 07:54 - 00000000 ____D C:\Users\mediamarkcruqius
2014-01-07 13:45 - 2014-01-07 13:45 - 00000000 ____D C:\ProgramData\WPM
2014-01-07 13:44 - 2014-01-07 13:44 - 00004350 _____ C:\Windows\System32\Tasks\DP1818-updater
2014-01-07 13:44 - 2014-01-07 13:44 - 00004302 _____ C:\Windows\System32\Tasks\DP1818-codedownloader
2014-01-07 13:44 - 2014-01-07 13:44 - 00004174 _____ C:\Windows\System32\Tasks\DP1818-enabler
2014-01-07 13:44 - 2014-01-07 13:44 - 00000000 ____D C:\Program Files\Conduit
2014-01-07 13:44 - 2014-01-07 13:44 - 00000000 ____D C:\Program Files (x86)\DP1818
2014-01-07 13:44 - 2011-09-26 13:19 - 00001644 _____ C:\Users\mediamarkcruqius\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-01-07 13:44 - 2011-02-01 17:38 - 00002640 _____ C:\Users\mediamarkcruqius\Desktop\Google Chrome.lnk
2014-01-07 13:44 - 2010-07-18 10:49 - 00002162 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-01-07 13:44 - 2010-06-02 09:39 - 00001666 _____ C:\Users\mediamarkcruqius\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-07 13:43 - 2014-01-07 13:43 - 00000000 __RHD C:\Users\mediamarkcruqius\AppData\Local\43D0D494-7FCC-4165-98F7-37C3B7ADF6AE
2014-01-07 13:43 - 2014-01-07 13:42 - 00336424 _____ (Amônétízé Ltd) C:\Users\mediamarkcruqius\Downloads\FlashPlayersetup__5047_i241433740_il3.exe
2014-01-07 13:02 - 2010-07-17 21:26 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Roaming\Skype
2014-01-07 10:11 - 2013-10-18 08:01 - 00001058 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-354615371-2128914143-2807093971-1000Core.job
2014-01-07 10:02 - 2014-01-07 10:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-07 08:55 - 2014-01-07 08:55 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-07 08:54 - 2010-05-18 10:00 - 01204647 _____ C:\Windows\WindowsUpdate.log
2013-12-25 09:37 - 2013-12-25 09:29 - 422205137 _____ C:\Users\mediamarkcruqius\Downloads\rychlyprachy71.wmv
2013-12-25 09:29 - 2013-12-25 09:06 - 734624599 _____ C:\Users\mediamarkcruqius\Downloads\rychlyprachy63.wmv
2013-12-25 09:15 - 2013-12-25 09:15 - 00000000 ____D C:\Program Files (x86)\WebexpEnhancedV1
2013-12-18 09:55 - 2013-12-18 09:45 - 00156909 _____ C:\Users\mediamarkcruqius\Desktop\Pavel Kundenliste - Copy 1 (Ambiente 2013).xlsx
2013-12-17 19:53 - 2009-07-14 06:08 - 00032574 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-17 09:39 - 2013-01-10 20:49 - 00000000 ____D C:\Users\mediamarkcruqius\Desktop\REST
2013-12-17 09:13 - 2013-12-17 09:13 - 00000000 ____D C:\Windows\SysWOW64\SearchProtect
2013-12-16 09:21 - 2013-03-04 12:13 - 00002187 _____ C:\Users\mediamarkcruqius\Desktop\Company shared folder - Shortcut.lnk
2013-12-15 21:03 - 2013-12-15 19:50 - 179706685 _____ C:\Users\mediamarkcruqius\Downloads\JT.The.20-20.Experience.2of2.rar
2013-12-15 21:03 - 2013-12-15 19:43 - 167522625 _____ C:\Users\mediamarkcruqius\Downloads\Drake---Nothing-Was-The-Same-(Deluxe-Edition)-2013-320kbps.rar
2013-12-15 21:02 - 2013-12-15 19:53 - 128386599 _____ C:\Users\mediamarkcruqius\Downloads\Jay-Z---Magna-Carta-Holy-Grail-(2013).rar
2013-12-15 20:45 - 2010-07-21 20:47 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Roaming\vlc
2013-12-15 20:40 - 2013-12-15 19:41 - 116890319 _____ C:\Users\mediamarkcruqius\Downloads\Kanye-West---Yeezus-and-Extras-2013.rar
2013-12-15 18:38 - 2013-08-18 09:47 - 00000000 ____D C:\Users\mediamarkcruqius\Downloads\Filmy
2013-12-15 17:03 - 2013-12-15 17:01 - 00000000 ____D C:\Users\mediamarkcruqius\Downloads\Bangerz (Deluxe Version)
2013-12-15 16:53 - 2010-10-30 17:53 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Roaming\uTorrent
2013-12-15 16:50 - 2009-07-14 10:16 - 00702266 _____ C:\Windows\system32\perfh013.dat
2013-12-15 16:50 - 2009-07-14 10:16 - 00133918 _____ C:\Windows\system32\perfc013.dat
2013-12-15 16:50 - 2009-07-14 06:13 - 01557090 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-15 16:30 - 2013-12-15 16:30 - 00000867 _____ C:\Users\mediamarkcruqius\Desktop\µTorrent.lnk
2013-12-15 16:30 - 2013-12-15 16:30 - 00000847 _____ C:\Users\mediamarkcruqius\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2013-12-15 16:30 - 2010-10-30 17:54 - 00000000 ____D C:\Program Files (x86)\uTorrent
2013-12-13 21:36 - 2012-09-15 11:08 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-13 21:36 - 2012-09-15 11:08 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-13 21:36 - 2011-11-21 13:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-13 20:16 - 2013-12-13 20:16 - 00002219 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-12-10 15:09 - 2010-10-06 18:54 - 00004052 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-10 15:09 - 2010-10-06 18:54 - 00003800 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-10 14:55 - 2013-12-09 21:54 - 00000279 _____ C:\Users\mediamarkcruqius\Downloads\This.is.the.End.2013.720p.BluRay.x264-SPARKS.mkv
2013-12-09 10:02 - 2011-10-17 20:37 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-12-09 10:02 - 2010-04-06 10:06 - 00000000 ____D C:\ProgramData\Skype

Files to move or delete:
====================
C:\ProgramData\dxcmatg.exe


Some content of TEMP:
====================
C:\Users\mediamarkcruqius\AppData\Local\Temp\1349035193.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\1349042551.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\1349055577.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\1349080472.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\dlLogic.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\drm_dyndata_7410004.dll
C:\Users\mediamarkcruqius\AppData\Local\Temp\EnableExtDll.dll
C:\Users\mediamarkcruqius\AppData\Local\Temp\fEBundle10_12_13.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\FlashPlayersetup__5047_i241433740_il3.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\LollipopInstaller_14633.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsa89CE.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsaB42B.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsb106F.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsb5C2.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsdA2BA.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsdA579.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsgB0F0.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsgE1D.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsl8700.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nslAE50.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsoAE42.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsoB101.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsq84AE.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsr12F0.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsr277.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsr8DF.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nst9FBD.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nstAB54.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\Quarantine.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\speedupmypc.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\SPSetup.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt1D44.tmp.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt36DD.tmp.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt3CC6.tmp.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt7CE.tmp.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt9BF3.tmp.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\uttBDDA.tmp.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-07 10:35




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: (WINDOWS) (Fixed) (Total:148.81 GB) (Free:9.38 GB) NTFS
Drive d: (Data) (Fixed) (Total:148.88 GB) (Free:66.4 GB) NTFS

Available physical RAM: 2317.92 MB
Total physical RAM: 3958.85 MB
Percentage of memory in use: 41%

==================== MBR and Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 28C93153)
Partition 1: (Active) - (Size=400 MB) - (Type=27)
Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=149 GB) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DP1818-chromeinstaller.job => C:\Program Files (x86)\DP1818\DP1818-chromeinstaller.exe
Task: C:\Windows\Tasks\DP1818-codedownloader.job => C:\Program Files (x86)\DP1818\DP1818-codedownloader.exe
Task: C:\Windows\Tasks\DP1818-enabler.job => C:\Program Files (x86)\DP1818\DP1818-enabler.exe
Task: C:\Windows\Tasks\DP1818-firefoxinstaller.job => C:\Program Files (x86)\DP1818\DP1818-firefoxinstaller.exe
Task: C:\Windows\Tasks\DP1818-updater.job => C:\Program Files (x86)\DP1818\DP1818-updater.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-354615371-2128914143-2807093971-1000Core.job => C:\Users\mediamarkcruqius\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-354615371-2128914143-2807093971-1000UA.job => C:\Users\mediamarkcruqius\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Microsoft Security Essentials (Disabled - Up to date) {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
AS: Microsoft Security Essentials (Disabled - Up to date) {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\mediamarkcruqius\Desktop" je 9520 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent
"c:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe" /WinStart [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartFaceVWatcher
%programFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration
C:\Program Files\Toshiba\Registration\ToshibaReminder.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosNC
%programFiles%\Toshiba\BulletinBoard\TosNcCore.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosReelTimeMonitor
%programFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TWebCamera
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Windows\\SysWOW64\\msiexec.exe"="C:\\Windows\\SysWOW64\\msiexec.exe:*:Generic Host Process"
"C:\\Windows\\SysWOW64\\svchost.exe"="C:\\Windows\\SysWOW64\\svchost.exe:*:Generic Host Process"
"C:\\Users\\MEDIAM~1\\AppData\\Local\\Temp\\1349042551.exe"="C:\\Users\\MEDIAM~1\\AppData\\Local\\Temp\\1349042551.exe:*:Enabled:Microsoft Office"
"C:\\Users\\MEDIAM~1\\AppData\\Local\\Temp\\tmp57755b9e\\elly.exe"="C:\\Users\\MEDIAM~1\\AppData\\Local\\Temp\\tmp57755b9e\\elly.exe:*:Enabled:Microsoft Office"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Vyskakujici reklamy

#8 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM-x32\...\Run: [Microsoft Default Manager] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [288088 2009-11-11] (Microsoft Corporation)
    HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)
    HKLM-x32\...\Run: [IndexSearch] - C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-08] (Nuance Communications, Inc.)
    HKLM-x32\...\Run: [ControlCenter4] - C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139264 2011-04-20] (Brother Industries, Ltd.)
    HKLM-x32\...\Run: [BrStsMon00] - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2629632 2011-10-07] (Brother Industries, Ltd.)
    HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
    HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
    HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
    HKLM-x32\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [486264 2013-12-18] (Updater)
    HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
    HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [717696 2010-01-16] (Microsoft Corporation)
    HKCU\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
    HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
    HKCU\...\Run: [Google Update] - C:\Users\mediamarkcruqius\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2010-10-06] (Google Inc.)
    HKCU\...\Run: [lollipop_01070755_2] - C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2.exe [2734592 2014-01-07] ()
    HKCU\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\mediamarkcruqius\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
    HKCU\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [486264 2013-12-18] (Updater)
    HKU\Default\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [4581280 2010-03-03] (TOSHIBA)
    HKU\Default User\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [4581280 2010-03-03] (TOSHIBA)
    AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [ ] ()
    Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
    Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP =
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs =
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.nationzoom.com/?type=sc&ts=1 ... 016EETM1LX
    SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
    SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
    SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
    SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
    SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
    SearchScopes: HKCU - {31C364F3-B160-47B4-9166-73B725E9E5BC} URL = http://www.webhledani.cz/results.aspx?i ... $&tp=ie&q={searchTerms}
    SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
    SearchScopes: HKCU - {7667868F-49C5-4FD8-AB84-47E83C3639E5} URL = http://rover.ebay.com/rover/1/1346-7149 ... 4?satitle={searchTerms}
    SearchScopes: HKCU - {7FA6D6DA-F503-48DC-9540-5212D4F27FF1} URL = http://www.bing.com/search?FORM=IEFM1&q={searchTerms}&src={referrer:source?}
    SearchScopes: HKCU - {CBCBE449-3AC9-4DAC-93EC-A96AE5111749} URL = http://www.amazon.co.uk/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibauk-win7-ie-search-21&index=blended&linkCode=ur2
    BHO: DP1818 - {11111111-1111-1111-1111-110411891178} - C:\Program Files (x86)\DP1818\DP1818-bho64.dll (mrlmedia)
    BHO: ValueApps - {93DBF2BB-A2B3-4683-A92E-57E60751F346} - C:\Program Files\Conduit\ValueApps\IE\ValueAppsLoader.dll (Conduit Ltd.)
    BHO-x32: ValueApps - {93DBF2BB-A2B3-4683-A92E-57E60751F346} - C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll No File
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
    
    FF ProfilePath: C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default
    FF NewTab: hxxp://www.nationzoom.com/newtab/?type= ... 016EETM1LX
    FF DefaultSearchEngine: nationzoom
    FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", "");
    FF SearchEngineOrder.3: Bing
    FF SelectedSearchEngine: nationzoom
    FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co"
    FF NetworkProxy: "share_proxy_settings", true
    FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\avg_igeared.xml
    FF Extension: DP1818 - C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\Extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com
    FF Extension: Websteroids - C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\Extensions\support@websteroidsapp.com
    FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha2360.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ff
    FF Extension: Webexp Enhanced - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ff
    FF HKLM-x32\...\Firefox\Extensions: [ext@flash-Enhancer.com] - C:\Program Files (x86)\AmiExt\flashEnhancer\ff
    FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.nationzoom.com/?type=sc&ts=1 ... 016EETM1LX
    
    CHR HomePage: hxxp://search.conduit.com/?ctid=CT33149 ... 108F&SSPV=
    CHR RestoreOnStartup: "hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP9C598A0B-21EA-43E6-80C2-CBEDFE22108F&SSPV="
    CHR DefaultSearchKeyword: conduit.search
    CHR DefaultSearchProvider: Conduit Search
    CHR DefaultSearchURL: http://search.conduit.com/Results.aspx? ... E22108F&q={searchTerms}&SSPV=
    CHR DefaultNewTabURL:
    CHR Extension: (Extended Protection) - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0
    CHR Extension: (DP1818) - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0
    CHR Extension: (Webexp Enhanced) - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\odnopkenikdonjcijkgpahfeamcodhlp\1.1_1
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
    CHR HKLM-x32\...\Chrome\Extension: [odnopkenikdonjcijkgpahfeamcodhlp] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ch\WebexpEnhancedV1alpha2360.crx
    CHR StartMenuInternet: Google Chrome - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\Application\chrome.exe http://www.nationzoom.com/?type=sc&ts=1 ... 016EETM1LX
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    
    R2 InternetUpdater; C:\ProgramData\InternetUpdater\InternetUpdaterService.exe [40448 2013-12-06] ()
    R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2014-01-07] (Cherished Technololgy LIMITED)
    S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe" [x]
    
    C:\Program Files (x86)\McAfee Security Scan
    C:\Users\mediamarkcruqius\AppData\Roaming\newnext.me\nengine.dll
    C:\PROGRA~2\SearchProtect
    C:\ProgramData\WPM
    C:\ProgramData\InternetUpdater
    C:\Users\mediamarkcruqius\AppData\Local\Lollipop
    C:\ProgramData\Updater
    C:\Users\mediamarkcruqius\AppData\Local\43D0D494-7FCC-4165-98F7-37C3B7ADF6AE
    C:\ProgramData\RHelpers
    2014-01-07 08:55 - 2014-01-07 08:55 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
    C:\ProgramData\dxcmatg.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\1349035193.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\1349042551.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\1349055577.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\1349080472.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\dlLogic.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\drm_dyndata_7410004.dll
    C:\Users\mediamarkcruqius\AppData\Local\Temp\EnableExtDll.dll
    C:\Users\mediamarkcruqius\AppData\Local\Temp\fEBundle10_12_13.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\FlashPlayersetup__5047_i241433740_il3.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\LollipopInstaller_14633.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsa89CE.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsaB42B.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsb106F.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsb5C2.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsdA2BA.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsdA579.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsgB0F0.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsgE1D.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsl8700.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nslAE50.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsoAE42.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsoB101.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsq84AE.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsr12F0.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsr277.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nsr8DF.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nst9FBD.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\nstAB54.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\Quarantine.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\speedupmypc.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\SPSetup.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\utt1D44.tmp.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\utt36DD.tmp.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\utt3CC6.tmp.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\utt7CE.tmp.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\utt9BF3.tmp.exe
    C:\Users\mediamarkcruqius\AppData\Local\Temp\uttBDDA.tmp.exe
    
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\DP1818-chromeinstaller.job => C:\Program Files (x86)\DP1818\DP1818-chromeinstaller.exe
    Task: C:\Windows\Tasks\DP1818-codedownloader.job => C:\Program Files (x86)\DP1818\DP1818-codedownloader.exe
    Task: C:\Windows\Tasks\DP1818-enabler.job => C:\Program Files (x86)\DP1818\DP1818-enabler.exe
    Task: C:\Windows\Tasks\DP1818-firefoxinstaller.job => C:\Program Files (x86)\DP1818\DP1818-firefoxinstaller.exe
    Task: C:\Windows\Tasks\DP1818-updater.job => C:\Program Files (x86)\DP1818\DP1818-updater.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-354615371-2128914143-2807093971-1000Core.job => C:\Users\mediamarkcruqius\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-354615371-2128914143-2807093971-1000UA.job => C:\Users\mediamarkcruqius\AppData\Local\Google\Update\GoogleUpdate.exe
    
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" /v "C:\\Windows\\SysWOW64\\msiexec.exe" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" /v "C:\\Windows\\SysWOW64\\svchost.exe" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" /v "C:\\Users\\MEDIAM~1\\AppData\\Local\\Temp\\1349042551.exe" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" /v "C:\\Users\\MEDIAM~1\\AppData\\Local\\Temp\\tmp57755b9e\\elly.exe" /f
    
    Hosts:
    CMD: shutdown /r /f /t 2
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Ver
Návštěvník
Návštěvník
Příspěvky: 113
Registrován: 31 črc 2008 19:05

Re: Vyskakujici reklamy

#9 Příspěvek od Ver »

tak tady to je

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-01-2014
Ran by mediamarkcruqius at 2014-01-08 10:51:29 Run:1
Running from C:\Users\mediamarkcruqius\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [Microsoft Default Manager] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [288088 2009-11-11] (Microsoft Corporation)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [IndexSearch] - C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-08] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ControlCenter4] - C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139264 2011-04-20] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2629632 2011-10-07] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKLM-x32\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [486264 2013-12-18] (Updater)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [717696 2010-01-16] (Microsoft Corporation)
HKCU\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKCU\...\Run: [Google Update] - C:\Users\mediamarkcruqius\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2010-10-06] (Google Inc.)
HKCU\...\Run: [lollipop_01070755_2] - C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2.exe [2734592 2014-01-07] ()
HKCU\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\mediamarkcruqius\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKCU\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [486264 2013-12-18] (Updater)
HKU\Default\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [4581280 2010-03-03] (TOSHIBA)
HKU\Default User\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [4581280 2010-03-03] (TOSHIBA)
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [ ] ()
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP =
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs =
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1 ... 016EETM1LX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.nationzoom.com/?type=sc&ts=1 ... 016EETM1LX
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
SearchScopes: HKCU - {31C364F3-B160-47B4-9166-73B725E9E5BC} URL = http://www.webhledani.cz/results.aspx?i ... $&tp=ie&q={searchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds& ... EETM1LX&q={searchTerms}
SearchScopes: HKCU - {7667868F-49C5-4FD8-AB84-47E83C3639E5} URL = http://rover.ebay.com/rover/1/1346-7149 ... 4?satitle={searchTerms}
SearchScopes: HKCU - {7FA6D6DA-F503-48DC-9540-5212D4F27FF1} URL = http://www.bing.com/search?FORM=IEFM1&q ... rer:source?}
SearchScopes: HKCU - {CBCBE449-3AC9-4DAC-93EC-A96AE5111749} URL = http://www.amazon.co.uk/gp/search?ie=UT ... nkCode=ur2
BHO: DP1818 - {11111111-1111-1111-1111-110411891178} - C:\Program Files (x86)\DP1818\DP1818-bho64.dll (mrlmedia)
BHO: ValueApps - {93DBF2BB-A2B3-4683-A92E-57E60751F346} - C:\Program Files\Conduit\ValueApps\IE\ValueAppsLoader.dll (Conduit Ltd.)
BHO-x32: ValueApps - {93DBF2BB-A2B3-4683-A92E-57E60751F346} - C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File

FF ProfilePath: C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default
FF NewTab: hxxp://www.nationzoom.com/newtab/?type= ... 016EETM1LX
FF DefaultSearchEngine: nationzoom
FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", "");
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: nationzoom
FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co"
FF NetworkProxy: "share_proxy_settings", true
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\avg_igeared.xml
FF Extension: DP1818 - C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\Extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com
FF Extension: Websteroids - C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\Extensions\support@websteroidsapp.com
FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha2360.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ff
FF Extension: Webexp Enhanced - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@flash-Enhancer.com] - C:\Program Files (x86)\AmiExt\flashEnhancer\ff
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.nationzoom.com/?type=sc&ts=1 ... 016EETM1LX

CHR HomePage: hxxp://search.conduit.com/?ctid=CT33149 ... 108F&SSPV=
CHR RestoreOnStartup: "hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP9C598A0B-21EA-43E6-80C2-CBEDFE22108F&SSPV="
CHR DefaultSearchKeyword: conduit.search
CHR DefaultSearchProvider: Conduit Search
CHR DefaultSearchURL: http://search.conduit.com/Results.aspx? ... E22108F&q={searchTerms}&SSPV=
CHR DefaultNewTabURL:
CHR Extension: (Extended Protection) - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0
CHR Extension: (DP1818) - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0
CHR Extension: (Webexp Enhanced) - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\odnopkenikdonjcijkgpahfeamcodhlp\1.1_1
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR HKLM-x32\...\Chrome\Extension: [odnopkenikdonjcijkgpahfeamcodhlp] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ch\WebexpEnhancedV1alpha2360.crx
CHR StartMenuInternet: Google Chrome - C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\Application\chrome.exe http://www.nationzoom.com/?type=sc&ts=1 ... 016EETM1LX
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

R2 InternetUpdater; C:\ProgramData\InternetUpdater\InternetUpdaterService.exe [40448 2013-12-06] ()
R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2014-01-07] (Cherished Technololgy LIMITED)
S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe" [x]

C:\Program Files (x86)\McAfee Security Scan
C:\Users\mediamarkcruqius\AppData\Roaming\newnext.me\nengine.dll
C:\PROGRA~2\SearchProtect
C:\ProgramData\WPM
C:\ProgramData\InternetUpdater
C:\Users\mediamarkcruqius\AppData\Local\Lollipop
C:\ProgramData\Updater
C:\Users\mediamarkcruqius\AppData\Local\43D0D494-7FCC-4165-98F7-37C3B7ADF6AE
C:\ProgramData\RHelpers
2014-01-07 08:55 - 2014-01-07 08:55 - 00000000 ____D C:\Users\mediamarkcruqius\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
C:\ProgramData\dxcmatg.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\1349035193.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\1349042551.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\1349055577.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\1349080472.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\dlLogic.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\drm_dyndata_7410004.dll
C:\Users\mediamarkcruqius\AppData\Local\Temp\EnableExtDll.dll
C:\Users\mediamarkcruqius\AppData\Local\Temp\fEBundle10_12_13.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\FlashPlayersetup__5047_i241433740_il3.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\LollipopInstaller_14633.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsa89CE.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsaB42B.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsb106F.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsb5C2.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsdA2BA.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsdA579.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsgB0F0.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsgE1D.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsl8700.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nslAE50.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsoAE42.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsoB101.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsq84AE.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsr12F0.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsr277.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsr8DF.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nst9FBD.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\nstAB54.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\Quarantine.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\speedupmypc.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\SPSetup.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt1D44.tmp.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt36DD.tmp.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt3CC6.tmp.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt7CE.tmp.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt9BF3.tmp.exe
C:\Users\mediamarkcruqius\AppData\Local\Temp\uttBDDA.tmp.exe

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DP1818-chromeinstaller.job => C:\Program Files (x86)\DP1818\DP1818-chromeinstaller.exe
Task: C:\Windows\Tasks\DP1818-codedownloader.job => C:\Program Files (x86)\DP1818\DP1818-codedownloader.exe
Task: C:\Windows\Tasks\DP1818-enabler.job => C:\Program Files (x86)\DP1818\DP1818-enabler.exe
Task: C:\Windows\Tasks\DP1818-firefoxinstaller.job => C:\Program Files (x86)\DP1818\DP1818-firefoxinstaller.exe
Task: C:\Windows\Tasks\DP1818-updater.job => C:\Program Files (x86)\DP1818\DP1818-updater.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-354615371-2128914143-2807093971-1000Core.job => C:\Users\mediamarkcruqius\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-354615371-2128914143-2807093971-1000UA.job => C:\Users\mediamarkcruqius\AppData\Local\Google\Update\GoogleUpdate.exe

REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration" /f
REG: reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" /v "C:\\Windows\\SysWOW64\\msiexec.exe" /f
REG: reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" /v "C:\\Windows\\SysWOW64\\svchost.exe" /f
REG: reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" /v "C:\\Users\\MEDIAM~1\\AppData\\Local\\Temp\\1349042551.exe" /f
REG: reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" /v "C:\\Users\\MEDIAM~1\\AppData\\Local\\Temp\\tmp57755b9e\\elly.exe" /f

Hosts:
CMD: shutdown /r /f /t 2

End
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Microsoft Default Manager => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\BCSSync => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\IndexSearch => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ControlCenter4 => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\BrStsMon00 => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Updater => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\OfficeSyncProcess => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSPM => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\lollipop_01070755_2 => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Updater => Value deleted successfully.
HKU\Default\Software\Microsoft\Windows\CurrentVersion\Run\\TOSHIBA Online Product Information => Value deleted successfully.
HKU\Default User\Software\Microsoft\Windows\CurrentVersion\Run\\TOSHIBA Online Product Information => Value not found.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully.
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk => Moved successfully.
C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk not found.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully.
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{31C364F3-B160-47B4-9166-73B725E9E5BC} => Key deleted successfully.
HKCR\CLSID\{31C364F3-B160-47B4-9166-73B725E9E5BC} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully.
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7667868F-49C5-4FD8-AB84-47E83C3639E5} => Key deleted successfully.
HKCR\CLSID\{7667868F-49C5-4FD8-AB84-47E83C3639E5} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7FA6D6DA-F503-48DC-9540-5212D4F27FF1} => Key deleted successfully.
HKCR\CLSID\{7FA6D6DA-F503-48DC-9540-5212D4F27FF1} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CBCBE449-3AC9-4DAC-93EC-A96AE5111749} => Key deleted successfully.
HKCR\CLSID\{CBCBE449-3AC9-4DAC-93EC-A96AE5111749} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411891178} => Key deleted successfully.
HKCR\CLSID\{11111111-1111-1111-1111-110411891178} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93DBF2BB-A2B3-4683-A92E-57E60751F346} => Key deleted successfully.
HKCR\CLSID\{93DBF2BB-A2B3-4683-A92E-57E60751F346} => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93DBF2BB-A2B3-4683-A92E-57E60751F346} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{93DBF2BB-A2B3-4683-A92E-57E60751F346} => Key deleted successfully.
HKCR\PROTOCOLS\Handler\skype-ie-addon-data => Key deleted successfully.
HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => Key not found.
C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk => Should not be moved.
Firefox newtab deleted successfully.
Firefox DefaultSearchEngine deleted successfully.
Firefox SearchEngineOrder.3 deleted successfully.
Firefox SelectedSearchEngine deleted successfully.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
C:\Program Files (x86)\mozilla firefox\searchplugins\avg_igeared.xml => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\Extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\Extensions\support@websteroidsapp.com => Moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@WebexpEnhancedV1alpha2360.net => Value deleted successfully.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ff => Moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@flash-Enhancer.com => Value deleted successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Value was restored successfully.
CHR HomePage: hxxp://search.conduit.com/?ctid=CT33149 ... 108F&SSPV= ==> The Chrome "Settings" can be used to fix the entry.
CHR RestoreOnStartup: "hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP9C598A0B-21EA-43E6-80C2-CBEDFE22108F&SSPV=" ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchKeyword: conduit.search ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchProvider: Conduit Search ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchURL: http://search.conduit.com/Results.aspx? ... E22108F&q={searchTerms}&SSPV= ==> The Chrome "Settings" can be used to fix the entry.
C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\odnopkenikdonjcijkgpahfeamcodhlp => Moved successfully.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl => Key deleted successfully.
"C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\odnopkenikdonjcijkgpahfeamcodhlp => Key deleted successfully.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ch\WebexpEnhancedV1alpha2360.crx => Moved successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully.
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
InternetUpdater => Service deleted successfully.
Wpm => Service deleted successfully.
McComponentHostService => Service deleted successfully.
"C:\Program Files (x86)\McAfee Security Scan" => File/Directory not found.
C:\Users\mediamarkcruqius\AppData\Roaming\newnext.me\nengine.dll => Moved successfully.
"C:\PROGRA~2\SearchProtect" => File/Directory not found.
C:\ProgramData\WPM => Moved successfully.
C:\ProgramData\InternetUpdater => Moved successfully.

"C:\Users\mediamarkcruqius\AppData\Local\Lollipop" directory move:

C:\Users\mediamarkcruqius\AppData\Local\Lollipop\logo.ico => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2.bat => Moved successfully.
Could not move "C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2.dat" => Scheduled to move on reboot.
C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2.lpd => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2_cfg.lpd => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2_ps.lpd => Moved successfully.
Could not move "C:\Users\mediamarkcruqius\AppData\Local\Lollipop" directory. => Scheduled to move on reboot.

C:\ProgramData\Updater => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\43D0D494-7FCC-4165-98F7-37C3B7ADF6AE => Moved successfully.
C:\ProgramData\RHelpers => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop => Moved successfully.
C:\ProgramData\dxcmatg.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\1349035193.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\1349042551.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\1349055577.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\1349080472.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\dlLogic.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\drm_dyndata_7410004.dll => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\EnableExtDll.dll => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\fEBundle10_12_13.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\FlashPlayersetup__5047_i241433740_il3.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\LollipopInstaller_14633.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsa89CE.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsaB42B.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsb106F.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsb5C2.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsdA2BA.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsdA579.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsgB0F0.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsgE1D.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsl8700.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nslAE50.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsoAE42.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsoB101.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsq84AE.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsr12F0.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsr277.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nsr8DF.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nst9FBD.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\nstAB54.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\speedupmypc.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\SPSetup.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt1D44.tmp.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt36DD.tmp.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt3CC6.tmp.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt7CE.tmp.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\utt9BF3.tmp.exe => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Temp\uttBDDA.tmp.exe => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\DP1818-chromeinstaller.job => Moved successfully.
C:\Windows\Tasks\DP1818-codedownloader.job => Moved successfully.
C:\Windows\Tasks\DP1818-enabler.job => Moved successfully.
C:\Windows\Tasks\DP1818-firefoxinstaller.job => Moved successfully.
C:\Windows\Tasks\DP1818-updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-354615371-2128914143-2807093971-1000Core.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-354615371-2128914143-2807093971-1000UA.job => Moved successfully.

========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f =========

The operation completed successfully.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent" /f =========

The operation completed successfully.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration" /f =========

The operation completed successfully.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" /v "C:\\Windows\\SysWOW64\\msiexec.exe" /f =========

ERROR: The system was unable to find the specified registry key or value.


========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" /v "C:\\Windows\\SysWOW64\\svchost.exe" /f =========

ERROR: The system was unable to find the specified registry key or value.


========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" /v "C:\\Users\\MEDIAM~1\\AppData\\Local\\Temp\\1349042551.exe" /f =========

ERROR: The system was unable to find the specified registry key or value.


========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" /v "C:\\Users\\MEDIAM~1\\AppData\\Local\\Temp\\tmp57755b9e\\elly.exe" /f =========

ERROR: The system was unable to find the specified registry key or value.


========= End of Reg: =========

C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

========= shutdown /r /f /t 2 =========


========= End of CMD: =========


=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-01-08 10:54:06)<=

C:\Users\mediamarkcruqius\AppData\Local\Lollipop\lollipop_01070755_2.dat => Moved successfully.
C:\Users\mediamarkcruqius\AppData\Local\Lollipop => Moved successfully.

==== End of Fixlog ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Vyskakujici reklamy

#10 Příspěvek od vyosek »

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Ver
Návštěvník
Návštěvník
Příspěvky: 113
Registrován: 31 črc 2008 19:05

Re: Vyskakujici reklamy

#11 Příspěvek od Ver »

Rkill 2.6.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 01/08/2014 02:09:21 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* Security Center (wscsvc) is not Running.
Startup Type set to: Disabled

* Windows Update (wuauserv) is not Running.
Startup Type set to: Disabled

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 01/08/2014 02:10:04 PM
Execution time: 0 hours(s), 0 minute(s), and 43 seconds(s)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Vyskakujici reklamy

#12 Příspěvek od vyosek »

Pokracujte ComboFixem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Ver
Návštěvník
Návštěvník
Příspěvky: 113
Registrován: 31 črc 2008 19:05

Re: Vyskakujici reklamy

#13 Příspěvek od Ver »

ComboFix 14-01-08.01 - mediamarkcruqius 08-01-2014 14:14:45.3.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1033.18.3959.2443 [GMT 1:00]
Gestart vanuit: c:\users\mediamarkcruqius\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Nieuw herstelpunt werd aangemaakt
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\WebexpEnhancedV1
c:\program files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ie\WebexpEnhancedV1alpha2360.dll
c:\program files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\uninstall.exe
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_fafckphhinbbcdnnjllcbnkcgbegcoid_0
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_fafckphhinbbcdnnjllcbnkcgbegcoid_0\1
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\background.html
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\crossriderManifest.json
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\manifest.xml
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins.json
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\1_base.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\13_CrossriderAppUtils.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\14_CrossriderUtils.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\17_jQuery.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\177_crossriderDashboard.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\182_openUrl.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\183_tabsWrapper.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\19_CHAppAPIWrapper.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\21_debug.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\22_resources.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\28_initializer.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\4_jquery_1_7_1.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\47_resources_background.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\64_appApiMessage.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\72_appApiValidation.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\78_CrossriderInfo.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\80_CHPopupAppAPI.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\91_monetizationLoader.js.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\plugins\97_resourceApiWrapper.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\userCode\background.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\extensionData\userCode\extension.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\icons\actions\1.png
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\icons\icon128.png
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\icons\icon16.png
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\icons\icon48.png
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\api\chrome.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\api\cookie.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\api\message.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\api\pageAction.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\api\pageActionBG.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\background.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\app_api.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\bg_app_api.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\consts.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\cookie_store.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\crossriderAPI.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\delegate.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\events.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\extensionDataStore.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\installer.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\logFile.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\logging.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\onBGDocumentLoad.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\popupResource\newPopup.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\popupResource\popup.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\reports.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\storageWrapper.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\updateManager.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\util.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\lib\xhr.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\main.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\js\platformVersion.js
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\manifest.json
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fafckphhinbbcdnnjllcbnkcgbegcoid\1.26.5_0\popup.html
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fafckphhinbbcdnnjllcbnkcgbegcoid
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fafckphhinbbcdnnjllcbnkcgbegcoid\000003.log
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fafckphhinbbcdnnjllcbnkcgbegcoid\CURRENT
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fafckphhinbbcdnnjllcbnkcgbegcoid\LOCK
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fafckphhinbbcdnnjllcbnkcgbegcoid\LOG
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fafckphhinbbcdnnjllcbnkcgbegcoid\MANIFEST-000002
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fafckphhinbbcdnnjllcbnkcgbegcoid_0.localstorage-journal
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fafckphhinbbcdnnjllcbnkcgbegcoid_0.localstorage
c:\users\mediamarkcruqius\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\mediamarkcruqius\AppData\Roaming\Ewenyk
c:\users\mediamarkcruqius\AppData\Roaming\Ewenyk\yffupy.ycc
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome.manifest
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\asyncDB.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\background.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\browserAction.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\contextMenu.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\dbManager.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\dom_bg.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\fileManager.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\firefox.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\firefoxNotifications.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\firefoxOmnibox.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\message.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\pageAction.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\request.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\tabs.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\webRequest.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\api\windowsMessagingHandler.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\background.html
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\baseObject.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\browser.xul
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\addressBarChangeObserver.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\console.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\consts.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\delegate.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\extensionDataStore.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\folderIOWrapper.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\httpObserver.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\IDBWrapper.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\installer.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\logFile.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\prefs.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\progressListenerObserver.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\registry.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\reloadObserver.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\reports.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\requestObject.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\searchSettings.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\uninstallObserver.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\updateManager.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\utils.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\core\xhr.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\dialog.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\main.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\options.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\options.xul
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\platformVersion.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\chrome\content\search_dialog.xul
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\defaults\preferences\prefs.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\manifest.xml
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins.json
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\1_base.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\103_intext_5_m.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\13_CrossriderAppUtils.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\14_CrossriderUtils.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\16_FFAppAPIWrapper.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\17_jQuery.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\177_crossriderDashboard.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\182_openUrl.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\183_tabsWrapper.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\21_debug.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\22_resources.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\28_initializer.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\4_jquery_1_7_1.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\47_resources_background.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\64_appApiMessage.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\72_appApiValidation.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\78_CrossriderInfo.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\91_monetizationLoader.js.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\plugins\98_omniCommands.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\userCode\background.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\extensionData\userCode\extension.js
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\install.rdf
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\locale\en-US\translations.dtd
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\button1.png
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\button2.png
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\button3.png
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\button4.png
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\button5.png
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\crossrider_statusbar.png
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\icon128.png
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\icon16.png
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\icon24.png
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\icon48.png
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\panelarrow-up.png
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\popup.html
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\skin.css
c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\a3b1728f-d038-4a75-a59f-6b5923320790@9bfb4f95-ed11-4198-bb7d-7925a3125ffb.com\skin\update.css
c:\users\mediamarkcruqius\AppData\Roaming\Seraiq
c:\users\mediamarkcruqius\AppData\Roaming\Seraiq\iplyyw.exe
c:\windows\TEMP\._msige61\GoogleEarth.exe
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\alchemy\ogl\IGAttrs.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\alchemy\ogl\IGGfx.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\alchemy\ogl\IGSg.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\D3DCompiler_43.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\d3dx9_43.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\IGAttrs.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\IGGfx.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\IGSg.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\libEGL.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\libGLESv2.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\alchemy\optimizations\IGOptExtension.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\alchemyext.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\earthflashsol.exe
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\earthps.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\ge_expat.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\googleearth.exe
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\googleearth_free.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\gpsbabel.exe
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\icudt.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\IGAttrs.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\IGCore.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\IGExportCommon.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\IGGfx.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\IGMath.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\IGOpt.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\IGSg.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\IGUtils.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\imageformats\qgif4.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\imageformats\qjpeg4.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\Leap.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\msvcp100.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\msvcr100.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\Plugins\npgeinprocessplugin.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\QtCore4.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\QtGui4.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\QtNetwork4.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\QtWebKit4.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\client\wavdest.ax
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\alchemy\ogl\IGAttrs.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\alchemy\ogl\IGGfx.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\alchemy\ogl\IGSg.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\D3DCompiler_43.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\d3dx9_43.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\IGAttrs.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\IGGfx.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\IGSg.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\libEGL.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\libGLESv2.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\alchemy\optimizations\IGOptExtension.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\alchemyext.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\earthps.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\ge_expat.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\geplugin.exe
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\googleearth_free.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\icudt.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\IGAttrs.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\IGCore.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\IGExportCommon.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\IGGfx.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\IGMath.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\IGOpt.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\IGSg.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\IGUtils.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\imageformats\qgif4.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\imageformats\qjpeg4.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\Leap.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\msvcp100.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\msvcr100.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\npgeplugin.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\plugin_ax.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\QtCore4.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\QtGui4.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\QtNetwork4.dll
c:\windows\TEMP\._msige61\program files\Google\Google Earth\plugin\QtWebKit4.dll
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2013-12-08 to 2014-01-08 ))))))))))))))))))))))))))))))
.
.
2014-01-08 13:22 . 2014-01-08 13:22 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-01-08 13:22 . 2014-01-08 13:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-07 22:49 . 2014-01-08 09:54 -------- d-----w- C:\FRST
2014-01-07 13:28 . 2014-01-07 21:32 -------- d-----w- C:\AdwCleaner
2014-01-07 13:18 . 2014-01-07 13:18 -------- d-----w- c:\windows\ERUNT
2014-01-07 13:02 . 2014-01-07 13:02 -------- d-----w- C:\rsit
2014-01-07 12:53 . 2014-01-07 12:53 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2014-01-07 12:49 . 2014-01-07 12:49 -------- d-----w- c:\program files (x86)\Lightspark 0.5.3-git
2014-01-07 12:48 . 2014-01-07 12:55 -------- d-----w- c:\program files (x86)\AmiExt
2014-01-07 12:47 . 2014-01-07 12:48 -------- d-----w- c:\programdata\Websteroids
2014-01-07 12:47 . 2014-01-07 12:47 -------- d-----w- c:\users\mediamarkcruqius\.android
2014-01-07 12:47 . 2014-01-08 09:51 -------- d-----w- c:\users\mediamarkcruqius\AppData\Roaming\newnext.me
2014-01-07 12:47 . 2014-01-07 12:47 -------- d-----w- c:\users\mediamarkcruqius\AppData\Local\cache
2014-01-07 12:47 . 2014-01-07 12:49 -------- d-----w- c:\users\mediamarkcruqius\AppData\Local\Mobogenie
2014-01-07 12:47 . 2014-01-07 12:47 -------- d-----w- c:\users\mediamarkcruqius\AppData\Local\genienext
2014-01-07 12:45 . 2014-01-07 12:45 -------- d-----w- c:\users\mediamarkcruqius\AppData\Local\Programs
2014-01-07 12:44 . 2014-01-07 12:44 -------- d-----w- c:\program files\Conduit
2014-01-07 12:44 . 2014-01-07 12:44 -------- d-----w- c:\users\mediamarkcruqius\AppData\Roaming\ValueApps
2014-01-07 12:44 . 2014-01-07 12:44 -------- d-----w- c:\program files (x86)\DP1818
2014-01-07 07:55 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{552CA289-E0FD-49BE-BBF2-3CE0D569CDCE}\mpengine.dll
2013-12-25 08:13 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-12-17 08:13 . 2013-12-17 08:13 -------- d-----w- c:\windows\SysWow64\SearchProtect
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-13 20:36 . 2012-09-15 10:08 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-13 20:36 . 2011-11-21 12:33 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_Dlls"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"PaperPort PTD"="c:\program files (x86)\Nuance\PaperPort\pptd40nt.exe"
"PDF5 Registry Controller"=c:\program files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe
"PDFHook"=c:\program files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe
"PPort12reminder"="c:\program files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "c:\programdata\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
"RIMBBLaunchAgent.exe"=c:\program files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe;c:\program files (x86)\Browny02\BrYNSvc.exe [x]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x]
R3 netr7364;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr7364.sys;c:\windows\SYSNATIVE\DRIVERS\netr7364.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys;c:\windows\SYSNATIVE\drivers\ccdcmbox64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys;c:\windows\SYSNATIVE\drivers\ccdcmbx64.sys [x]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe;c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [x]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [x]
S2 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe;c:\program files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [x]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe;c:\program files\TOSHIBA\TECO\TecoService.exe [x]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys;c:\windows\SYSNATIVE\DRIVERS\TVALZFL.sys [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys;c:\windows\SYSNATIVE\drivers\CHDMI64.sys [x]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys;c:\windows\SYSNATIVE\DRIVERS\FwLnk.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys;c:\windows\SYSNATIVE\DRIVERS\pgeffect.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192se.sys [x]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-10 520760]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-21 2327952]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-02-11 1050072]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 1289704]
.
------- Bijkomende Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: E&xporteren naar Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MIF5BA~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-12-15 14:22; client@anonymox.net; c:\users\mediamarkcruqius\AppData\Roaming\Mozilla\Firefox\Profiles\3jrfjxl7.default\extensions\client@anonymox.net.xpi
FF - ExtSQL: 2013-12-25 09:15; ext@WebexpEnhancedV1alpha2360.net; c:\program files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ff
.
- - - - ORPHANS VERWIJDERD - - - -
.
BHO-{fd9425ac-8ec0-4faf-8f6c-3033cc2ddd26} - c:\program files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\ie\WebexpEnhancedV1alpha2360.dll
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe
HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
AddRemove-AVS Update Manager_is1 - c:\program files (x86)\AVS4YOU\AVSUpdateManager\unins000.exe
AddRemove-AVS4YOU Software Navigator_is1 - c:\program files (x86)\AVS4YOU\AVSSoftwareNavigator\unins000.exe
AddRemove-AVS4YOU Video Converter 7_is1 - c:\program files (x86)\AVS4YOU\AVSVideoConverter\unins000.exe
AddRemove-InternetUpdater - c:\programdata\InternetUpdater\uninstall.exe
AddRemove-McAfee Security Scan - c:\program files (x86)\McAfee Security Scan\uninstall.exe
AddRemove-Webexp Enhanced - c:\program files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha2360\uninstall.exe
AddRemove-WPM - c:\programdata\WPM\wprotectmanager.exe
AddRemove-{D54E3D9F-FEB8-4D2D-A138-B69A5C80080B} - c:\programdata\Updater\Uninstall.exe
AddRemove-lollipop_01070755_2 - c:\users\mediamarkcruqius\appdata\local\lollipop\lollipop_01070755_2.bat
AddRemove-ValueApps - c:\program files (x86)\Conduit\ValueApps\IE\uninstaller.exe
.
.
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_USERS\S-1-5-21-354615371-2128914143-2807093971-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
Voltooingstijd: 2014-01-08 14:25:02
ComboFix-quarantined-files.txt 2014-01-08 13:25
.
Pre-Run: 10.547.982.336 bytes free
Post-Run: 10.237.689.856 bytes free
.
- - End Of File - - 7E70115A0636733EF4E32B8A8DB8A78B

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Vyskakujici reklamy

#14 Příspěvek od vyosek »

:arrow: Vyyyborne, CF nam to tez docela procistil

:arrow: Zkuste nyni udelat AdwCleaner
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Ver
Návštěvník
Návštěvník
Příspěvky: 113
Registrován: 31 črc 2008 19:05

Re: Vyskakujici reklamy

#15 Příspěvek od Ver »

tak jsem to zkusila a stale se to seka na analyzing browsers....
i pres administratora i pres nouzovy rezim :roll:

Zamčeno