Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Sekání pc

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Sekání pc

#61 Příspěvek od Márty84 »

To je tezke, kdyz si to zavirujete znova jeste pred dokoncenim prvni kontroly. To pak muzem delat porad dokola :boxed:
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

kontez.
Návštěvník
Návštěvník
Příspěvky: 83
Registrován: 19 kvě 2014 13:53

Re: Sekání pc

#62 Příspěvek od kontez. »

Ja se na pc driv nedostal chodim na brigady jak je mozne ze se sama od sebe pusti instalace zrychleníi pc ? samosebou si myslim ze to byl virus protoze mi neco vytezuje pc nebude lepsi odpojit pc od netu po dobu leceni ?

kontez.
Návštěvník
Návštěvník
Příspěvky: 83
Registrován: 19 kvě 2014 13:53

Re: Sekání pc

#63 Příspěvek od kontez. »

zatim to naslo toto
Přílohy
Bez názvu.jpg
Bez názvu.jpg (82.03 KiB) Zobrazeno 2234 x

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Sekání pc

#64 Příspěvek od Márty84 »

No, hezke. Tohle tam ale samo nevplulo, tomu musel nekdo pomoct, stejne jako tomu Zrychleni pocitace. Ono je tezke s tim neco delat, kdyz si to tam zase dobrovolne instalujete :arcisit:
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

kontez.
Návštěvník
Návštěvník
Příspěvky: 83
Registrován: 19 kvě 2014 13:53

Re: Sekání pc

#65 Příspěvek od kontez. »

na pc byl mladsi bratr ja byl na pc naposledy 11.7 bracha rad hraje hry na 1000her atd... ty internetove hry mam pak vse odstranit pres MBM az dojede scan ?

kontez.
Návštěvník
Návštěvník
Příspěvky: 83
Registrován: 19 kvě 2014 13:53

Re: Sekání pc

#66 Příspěvek od kontez. »

Dobrý den včera jsem dal obnovení systému abych se zbavil aspon nejakym zpusobem toho nainstalovani zrychleni pc a zapnul rizeni uzivatelskych uctu abych predesel samovolne instalaci nezadouciho softwaru ale ted je tu tento problem ve spravci uloh ej videt pouze procesy spustene uzivatelem ale procesy spustene SYSTEMEM tam nejsou pujde to opravit? screen je zde
Přílohy
Bez názvu.jpg
Bez názvu.jpg (69.67 KiB) Zobrazeno 2228 x

kontez.
Návštěvník
Návštěvník
Příspěvky: 83
Registrován: 19 kvě 2014 13:53

Re: Sekání pc

#67 Příspěvek od kontez. »

zde je novy log z RSIT
Logfile of random's system information tool 1.10 (written by random/random)
Run by David at 2014-07-18 12:29:44
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 23 GB (33%) free of 70 GB
Total RAM: 2038 MB (38% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:31:21, on 18.7.2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16561)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\David\Downloads\RSIT.exe
C:\Program Files\trend micro\David.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN11459&g ... 50-407&t=4
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe

--
End of file - 3906 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default

prefs.js - "browser.startup.homepage" - "seznam.cz"
prefs.js - "keyword.URL" - "http://dts.search.ask.com/sr?src=ffb&gc ... PN11459&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\searchplugins\
Ask.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-10-31 4702208]
"Skytel"=C:\Windows\Skytel.exe [2007-10-11 1826816]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-03-11 951576]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-02-26 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-02-26 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-02-26 150552]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-10 1233920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKOSD2]
C:\Program Files\ATKOSD2\ATKOSD2.exe [2007-10-17 7737344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
c:\program files\synaptics\syntp\syntpenh.exe [2007-12-06 1029416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-02-26 210432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe]
"Debugger="tasklist.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-07-18 01:13:29 ----A---- C:\Windows\wininit.ini
2014-07-18 00:22:14 ----A---- C:\Users\David\AppData\Roaming\apachesrvin.vbs
2014-07-17 23:13:41 ----D---- C:\Program Files\VideoLAN
2014-07-17 22:35:03 ----D---- C:\rsit
2014-07-17 10:48:37 ----D---- C:\Users\David\AppData\Roaming\FirefoxToolbar
2014-07-16 12:15:56 ----D---- C:\Program Files\Seznam.cz
2014-07-16 12:14:14 ----D---- C:\Users\David\AppData\Roaming\Seznam.cz
2014-07-16 12:12:54 ----D---- C:\Program Files\PCDApp
2014-07-16 12:10:48 ----D---- C:\Program Files\Microsoft Silverlight
2014-07-14 00:59:40 ----A---- C:\Users\David\AppData\Roaming\sKUOCEI.exe
2014-07-13 20:57:52 ----D---- C:\_OTM
2014-07-13 15:28:25 ----D---- C:\Users\David\AppData\Roaming\vlc
2014-07-13 15:11:15 ----SHD---- C:\$RECYCLE.BIN
2014-07-13 14:55:02 ----D---- C:\Users\David\AppData\Roaming\uTorrent
2014-07-13 13:26:42 ----A---- C:\Users\David\AppData\Roaming\die.bat
2014-07-13 13:22:04 ----D---- C:\Users\David\AppData\Roaming\Macromedia
2014-07-13 13:22:03 ----D---- C:\Users\David\AppData\Roaming\Adobe
2014-07-13 13:01:09 ----A---- C:\Memory Cleaner.lnk
2014-07-13 13:01:05 ----D---- C:\Users\David\AppData\Roaming\KoshyJohn.com
2014-07-09 07:40:44 ----A---- C:\Windows\system32\win32k.sys
2014-07-09 07:40:43 ----A---- C:\Windows\system32\qedit.dll
2014-07-09 07:40:42 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-09 07:40:41 ----A---- C:\Windows\system32\vbscript.dll
2014-07-09 07:40:40 ----A---- C:\Windows\system32\wininet.dll
2014-07-09 07:40:40 ----A---- C:\Windows\system32\mshtmled.dll
2014-07-09 07:40:40 ----A---- C:\Windows\system32\jscript.dll
2014-07-09 07:40:40 ----A---- C:\Windows\system32\ieui.dll
2014-07-09 07:40:40 ----A---- C:\Windows\system32\dxtrans.dll
2014-07-09 07:40:40 ----A---- C:\Windows\system32\dxtmsft.dll
2014-07-09 07:40:39 ----A---- C:\Windows\system32\jscript9.dll
2014-07-09 07:40:37 ----A---- C:\Windows\system32\mshtml.dll
2014-07-09 07:40:20 ----A---- C:\Windows\system32\msfeedssync.exe
2014-07-09 07:40:20 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-07-09 07:40:20 ----A---- C:\Windows\system32\msfeeds.dll
2014-07-09 07:40:20 ----A---- C:\Windows\system32\jsproxy.dll
2014-07-09 07:40:19 ----A---- C:\Windows\system32\url.dll
2014-07-09 07:40:17 ----A---- C:\Windows\system32\ieUnatt.exe
2014-07-09 07:40:16 ----A---- C:\Windows\system32\iertutil.dll
2014-07-09 07:40:16 ----A---- C:\Windows\system32\ieframe.dll
2014-07-09 07:40:15 ----A---- C:\Windows\system32\urlmon.dll
2014-07-09 07:40:15 ----A---- C:\Windows\system32\mshta.exe
2014-07-08 19:38:27 ----D---- C:\Program Files\trend micro
2014-07-07 12:36:23 ----A---- C:\Windows\system32\drivers\mwac.sys
2014-07-07 12:36:22 ----D---- C:\Program Files\Malwarebytes Anti-Malware
2014-07-07 12:36:22 ----A---- C:\Windows\system32\drivers\mbam.sys
2014-07-04 14:32:34 ----D---- C:\Program Files\Defraggler
2014-07-01 20:35:22 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-07-01 20:34:55 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2014-07-01 17:38:43 ----D---- C:\Windows\temp
2014-06-30 17:48:21 ----A---- C:\Windows\system32\drivers\VBoxUSBMon.sys
2014-06-30 17:48:20 ----DC---- C:\Windows\system32\DRVSTORE
2014-06-29 19:43:21 ----D---- C:\Windows\erdnt
2014-06-25 22:41:24 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-06-25 22:39:46 ----D---- C:\Program Files\Common Files\Adobe
2014-06-25 22:39:46 ----D---- C:\Program Files\Adobe
2014-06-22 17:44:42 ----D---- C:\Fraps
2014-06-22 17:43:21 ----D---- C:\Program Files\Company
2014-06-22 17:41:43 ----D---- C:\Program Files\FRAPS plna verze 3.4.7

======List of files/folders modified in the last 1 month======

2014-07-18 12:18:03 ----A---- C:\Windows\system32\acovcnt.exe
2014-07-18 01:20:29 ----D---- C:\Windows\system32\catroot2
2014-07-18 01:19:04 ----RD---- C:\Program Files
2014-07-18 01:14:12 ----D---- C:\ProgramData
2014-07-18 01:13:29 ----D---- C:\Windows
2014-07-18 01:03:21 ----D---- C:\Windows\system32\wbem
2014-07-18 01:02:27 ----D---- C:\Windows\system32\config
2014-07-18 01:02:08 ----D---- C:\Windows\Tasks
2014-07-18 01:02:07 ----D---- C:\Windows\system32\spool
2014-07-18 01:02:07 ----D---- C:\Windows\system32\drivers\UMDF
2014-07-18 01:02:07 ----D---- C:\Windows\system32\drivers\etc
2014-07-18 01:02:07 ----D---- C:\Windows\system32\drivers
2014-07-18 01:02:07 ----D---- C:\Windows\system32\CodeIntegrity
2014-07-18 01:02:07 ----D---- C:\Windows\System32
2014-07-18 01:02:07 ----D---- C:\Windows\inf
2014-07-18 01:02:07 ----D---- C:\Program Files\P4G
2014-07-18 01:02:06 ----D---- C:\Windows\registration
2014-07-18 01:00:45 ----SHD---- C:\System Volume Information
2014-07-18 00:33:11 ----D---- C:\Windows\Prefetch
2014-07-18 00:30:39 ----D---- C:\Windows\schemas
2014-07-18 00:18:41 ----D---- C:\Windows\system32\Tasks
2014-07-16 12:11:40 ----SHD---- C:\Windows\Installer
2014-07-16 12:11:40 ----SD---- C:\ProgramData\Microsoft
2014-07-13 12:54:23 ----D---- C:\Windows\Debug
2014-07-11 19:33:12 ----SD---- C:\Users\David\AppData\Roaming\Microsoft
2014-07-10 19:52:29 ----D---- C:\Windows\PCHEALTH
2014-07-10 14:49:35 ----D---- C:\Program Files\Windows Journal
2014-07-10 14:49:31 ----D---- C:\Windows\system32\migration
2014-07-10 14:49:31 ----D---- C:\Program Files\Internet Explorer
2014-07-10 06:46:42 ----D---- C:\Windows\system32\catroot
2014-07-10 06:46:36 ----D---- C:\Windows\winsxs
2014-07-10 06:32:47 ----D---- C:\Windows\system32\MRT
2014-07-10 06:27:12 ----A---- C:\Windows\system32\mrt.exe
2014-07-06 00:27:53 ----D---- C:\Program Files\Google
2014-07-01 20:35:37 ----D---- C:\ProgramData\Malwarebytes
2014-07-01 17:34:33 ----A---- C:\Windows\system.ini
2014-07-01 17:29:55 ----D---- C:\Windows\AppPatch
2014-07-01 17:29:54 ----D---- C:\Program Files\Common Files
2014-06-30 18:10:28 ----D---- C:\Windows\SoftwareDistribution
2014-06-22 18:23:33 ----D---- C:\Windows\Microsoft.NET
2014-06-22 17:43:31 ----D---- C:\Windows\system32\Printing_Admin_Scripts
2014-06-22 17:41:46 ----D---- C:\Windows\system32\bitstreams

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2007-09-29 308248]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-01-25 231960]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-05-20 242240]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 20936]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-03-11 104264]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-08-08 45568]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2007-12-06 761856]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-10 22528]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-02-26 4569088]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-11-01 2011224]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2007-01-24 5632]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-05-12 23256]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-10 148992]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2007-07-13 50688]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-10 89088]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-12-06 196400]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2014-05-18 66560]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-05-12 51928]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2014-05-18 155136]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-02 94208]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-05-12 1809720]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 22216]
R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-03-11 279776]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2014-05-12 860472]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-06-11 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-09-11 770168]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Sekání pc

#68 Příspěvek od Márty84 »

Delate s tim pocitacem psi kusy, vidim to na brzky reinstal.

Kvuli zrychleni pocitace se nedava bod obnovy, da se toho zbavit docela snadno.

Nevidel jsem vypis nalezu MBAM, takze nevim, jestli bylo vsechno na odstraneni.

V logu je videt smejdy.


Takze repete.

Zacnete ADWCleanerem.

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.


:arrow: V tom spravci uloh zkuste zobrazit procesy vsech uzivatelu, jestli se nahodou neobjevi.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

kontez.
Návštěvník
Návštěvník
Příspěvky: 83
Registrován: 19 kvě 2014 13:53

Re: Sekání pc

#69 Příspěvek od kontez. »

MBAM sem nedokoncil vytizeni cpu bylo na 100% at sem vypnul cokoliv porad 100% tak jsem udelal obnovu obaval jsem se o pc nic jineho me nenapadlo v tom zpravci vas navod funguje akorad po vcypnuti a opetovnem zapnuti spravce to zas zmizi ty systemove ulohy a musim je zas rozkliknout ale to nevadi zde je log z adw

# AdwCleaner v3.216 - Report created 18/07/2014 at 22:56:03
# Updated 17/07/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : David - DAVID-PC
# Running from : C:\Users\David\Downloads\adwcleaner_3.216.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files\PCDApp
File Deleted : C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\searchplugins\Ask.xml
File Deleted : C:\Program Files\Mozilla Firefox\browser\searchplugins\Ask.xml

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Key Deleted : HKLM\Software\SafetyNut
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16561

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v30.0 (cs)

[ File : C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\prefs.js ]

Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("keyword.URL", "hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=101&systemid=488&v=a13350-407&apn_dtid=TCH001&apn_ptnrs=AG1&apn_uid=5952045487624962&o=APN11459&q=");

-\\ Google Chrome v35.0.1916.153

[ File : C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=101&systemid=488&v=a13350-407&apn_uid=5952045487624962&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
Deleted [Startup_urls] : hxxp://www.search.ask.com/?o=APN11459&gct=hp&d ... 50-407&t=4
Deleted [Homepage] : hxxp://www.search.ask.com/?o=APN11459&gct=hp&d ... 50-407&t=4

*************************

AdwCleaner[R3].txt - [5477 octets] - [18/07/2014 22:55:27]
AdwCleaner[S3].txt - [4883 octets] - [18/07/2014 22:56:03]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [4943 octets] ##########

jinak preji hezkou dovolenou

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Sekání pc

#70 Příspěvek od Márty84 »

:arrow: Zopakujte krok s ComboFixem http://forum.viry.cz/viewtopic.php?f=13 ... 0#p1329926

Pokud ho jeste v pc mate, smazte ho a stahnete novy!
kontez. píše:jinak preji hezkou dovolenou
Diky :worship: :)
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

kontez.
Návštěvník
Návštěvník
Příspěvky: 83
Registrován: 19 kvě 2014 13:53

Re: Sekání pc

#71 Příspěvek od kontez. »

Zde je log

ComboFix 14-07-21.01 - David 21.07.2014 17:21:47.5.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2038.990 [GMT 2:00]
Spuštěný z: c:\users\David\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\background.html
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\content.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\lsdb.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\manifest.json
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\vS3uh3S.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\vS3uh3S.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco
c:\users\David\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco
c:\users\David\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\background.html
c:\users\David\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\content.js
c:\users\David\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\lsdb.js
c:\users\David\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\manifest.json
c:\users\David\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\vS3uh3S.js
c:\users\David\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco
c:\users\David\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\background.html
c:\users\David\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\content.js
c:\users\David\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\lsdb.js
c:\users\David\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\manifest.json
c:\users\David\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\vS3uh3S.js
c:\users\David\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\background.html
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\content.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\lsdb.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\manifest.json
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\vS3uh3S.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco\2.1\vS3uh3S.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlgchppoafdakfnaloglllfkooghagco
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-21 do 2014-07-21 )))))))))))))))))))))))))))))))
.
.
2014-07-21 15:40 . 2014-07-21 15:40 -------- d-----w- c:\users\David\AppData\Local\temp
2014-07-21 12:25 . 2014-07-02 03:11 8217224 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{670D4B10-E832-42FB-B5CC-3BAAD2027B02}\mpengine.dll
2014-07-19 23:10 . 2014-07-02 03:11 8217224 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-07-18 20:53 . 2014-07-18 20:56 -------- d-----w- C:\AdwCleaner
2014-07-17 21:13 . 2014-07-17 21:13 -------- d-----w- c:\program files\VideoLAN
2014-07-17 20:35 . 2014-07-17 20:35 -------- d-----w- C:\rsit
2014-07-17 08:48 . 2014-07-17 08:48 -------- d-----w- c:\users\David\AppData\Roaming\FirefoxToolbar
2014-07-16 10:15 . 2014-07-17 22:23 -------- d-----w- c:\program files\Seznam.cz
2014-07-16 10:14 . 2014-07-17 22:23 -------- d-----w- c:\users\David\AppData\Roaming\Seznam.cz
2014-07-16 10:10 . 2014-07-16 10:10 -------- d-----w- c:\program files\Microsoft Silverlight
2014-07-13 18:57 . 2014-07-13 18:57 -------- d-----w- C:\_OTM
2014-07-13 13:28 . 2014-07-17 23:02 -------- d-----w- c:\users\David\AppData\Roaming\vlc
2014-07-13 12:55 . 2014-07-20 15:58 -------- d-----w- c:\users\David\AppData\Roaming\uTorrent
2014-07-13 11:26 . 2014-07-20 16:07 93 ----a-w- c:\users\David\AppData\Roaming\die.bat
2014-07-13 11:01 . 2014-07-13 11:01 -------- d-----w- c:\users\David\AppData\Roaming\KoshyJohn.com
2014-07-12 04:27 . 2014-04-23 09:50 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{28FD22C4-B4F9-4EF9-8CC5-EDCC1FB05C4A}\gapaengine.dll
2014-07-08 17:38 . 2014-07-18 10:31 -------- d-----w- c:\program files\trend micro
2014-07-07 10:36 . 2014-05-12 05:26 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-07-07 10:36 . 2014-07-07 10:36 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-07-07 10:36 . 2014-05-12 05:25 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-07-04 12:32 . 2014-07-04 12:32 -------- d-----w- c:\program files\Defraggler
2014-07-01 18:35 . 2014-07-21 12:06 110296 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-07-01 18:34 . 2014-05-12 05:25 74456 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-06-30 15:48 . 2014-05-16 13:24 104736 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2014-06-30 15:48 . 2014-06-30 15:52 -------- dc----w- c:\windows\system32\DRVSTORE
2014-06-25 20:41 . 2014-07-09 17:25 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-06-25 20:41 . 2014-07-09 17:25 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-06-25 20:39 . 2014-06-25 20:39 -------- d-----w- c:\program files\Common Files\Adobe
2014-06-22 15:44 . 2014-06-22 15:47 -------- d-----w- C:\Fraps
2014-06-22 15:43 . 2014-06-22 15:43 -------- d-----w- c:\program files\Company
2014-06-22 15:41 . 2014-06-22 15:44 -------- d-----w- c:\program files\FRAPS plna verze 3.4.7
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-20 19:38 . 2014-05-17 15:13 45056 ----a-w- c:\windows\system32\acovcnt.exe
2014-05-20 15:39 . 2014-05-20 15:39 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2014-05-20 15:06 . 2014-05-20 15:06 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-05-17 22:32 . 2014-05-17 22:32 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-05-17 22:32 . 2014-05-17 22:32 9728 ----a-w- c:\windows\system32\lsass.exe
2014-05-17 22:32 . 2014-05-17 22:32 72704 ----a-w- c:\windows\system32\secur32.dll
2014-05-17 22:32 . 2014-05-17 22:32 278528 ----a-w- c:\windows\system32\schannel.dll
2014-05-17 22:32 . 2014-05-17 22:32 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2014-05-17 22:30 . 2014-05-17 22:30 9728 ----a-w- c:\windows\system32\Wdfres.dll
2014-05-17 22:30 . 2014-05-17 22:30 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2014-05-17 22:30 . 2014-05-17 22:30 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\wdf01000.sys.mui
2014-05-17 22:30 . 2014-05-17 22:30 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-05-17 22:30 . 2014-05-17 22:30 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-05-17 22:30 . 2014-05-17 22:30 613888 ----a-w- c:\windows\system32\WUDFx.dll
2014-05-17 22:30 . 2014-05-17 22:30 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-05-17 22:30 . 2014-05-17 22:30 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2014-05-17 22:30 . 2014-05-17 22:30 16896 ----a-w- c:\windows\system32\winusb.dll
2014-05-17 22:30 . 2014-05-17 22:30 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-05-17 22:30 . 2014-05-17 22:30 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-05-17 22:28 . 2014-05-17 22:28 5120 ----a-w- c:\windows\system32\wmi.dll
2014-05-17 22:28 . 2014-05-17 22:28 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-05-17 17:38 . 2014-05-17 17:38 161792 ----a-w- c:\windows\system32\msls31.dll
2014-05-17 17:38 . 2014-05-17 17:38 86528 ----a-w- c:\windows\system32\iesysprep.dll
2014-05-17 17:38 . 2014-05-17 17:38 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-05-17 17:38 . 2014-05-17 17:38 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-05-17 17:38 . 2014-05-17 17:38 63488 ----a-w- c:\windows\system32\tdc.ocx
2014-05-17 17:38 . 2014-05-17 17:38 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-05-17 17:38 . 2014-05-17 17:38 74752 ----a-w- c:\windows\system32\iesetup.dll
2014-05-17 17:38 . 2014-05-17 17:38 367104 ----a-w- c:\windows\system32\html.iec
2014-05-17 17:38 . 2014-05-17 17:38 23552 ----a-w- c:\windows\system32\licmgr10.dll
2014-05-17 17:38 . 2014-05-17 17:38 152064 ----a-w- c:\windows\system32\wextract.exe
2014-05-17 17:38 . 2014-05-17 17:38 150528 ----a-w- c:\windows\system32\iexpress.exe
2014-05-17 17:38 . 2014-05-17 17:38 35840 ----a-w- c:\windows\system32\imgutil.dll
2014-05-17 17:38 . 2014-05-17 17:38 101888 ----a-w- c:\windows\system32\admparse.dll
2014-05-17 17:38 . 2014-05-17 17:38 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-05-17 17:37 . 2014-05-17 17:37 98816 ----a-w- c:\windows\system32\mfps.dll
2014-05-17 17:37 . 2014-05-17 17:37 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2014-05-17 17:37 . 2014-05-17 17:37 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2014-05-17 17:37 . 2014-05-17 17:37 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2014-05-17 17:37 . 2014-05-17 17:37 2873344 ----a-w- c:\windows\system32\mf.dll
2014-05-17 17:37 . 2014-05-17 17:37 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2014-05-17 17:37 . 2014-05-17 17:37 586240 ----a-w- c:\windows\system32\stobject.dll
2014-05-17 17:37 . 2014-05-17 17:37 209920 ----a-w- c:\windows\system32\mfplat.dll
2014-05-17 17:37 . 2014-05-17 17:37 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2014-05-17 17:37 . 2014-05-17 17:37 847360 ----a-w- c:\windows\system32\OpcServices.dll
2014-05-17 17:37 . 2014-05-17 17:37 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2014-05-17 17:37 . 2014-05-17 17:37 478720 ----a-w- c:\windows\system32\dxgi.dll
2014-05-17 17:37 . 2014-05-17 17:37 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2014-05-17 17:37 . 2014-05-17 17:37 258048 ----a-w- c:\windows\system32\winspool.drv
2014-05-17 17:37 . 2014-05-17 17:37 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2014-05-17 17:35 . 2014-05-17 17:35 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\dxgkrnl.sys.mui
2014-05-17 17:35 . 2014-05-17 17:35 519680 ----a-w- c:\windows\system32\d3d11.dll
2014-05-17 17:35 . 2014-05-17 17:35 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2014-05-17 17:35 . 2014-05-17 17:35 252928 ----a-w- c:\windows\system32\dxdiag.exe
2014-05-17 17:35 . 2014-05-17 17:35 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2014-05-17 17:35 . 2014-05-17 17:35 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2014-05-17 17:35 . 2014-05-17 17:35 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-05-17 17:35 . 2014-05-17 17:35 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-05-17 11:58 . 2014-05-17 11:58 319456 ----a-w- c:\windows\DIFxAPI.dll
2014-05-17 11:58 . 2014-05-17 11:58 315392 ----a-w- c:\windows\HideWin.exe
2014-04-26 16:01 . 2014-06-11 13:12 502784 ----a-w- c:\windows\system32\usp10.dll
2014-04-23 09:50 . 2014-05-19 12:26 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-31 4702208]
"Skytel"="Skytel.exe" [2007-10-11 1826816]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 951576]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-26 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-26 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-26 150552]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKOSD2]
2007-10-17 17:04 7737344 ----a-w- c:\program files\ATKOSD2\ATKOSD2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2007-12-06 10:12 1029416 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MBAMSWISSARMY
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-13 12:20 1091912 ----a-w- c:\program files\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-07-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-25 17:25]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\
FF - prefs.js: browser.startup.homepage - seznam.cz
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-10 - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-InstallShield_{D7E04009-B191-4E9D-9D2D-1BBE57BD8A42} - c:\program files\InstallShield Installation Information\{D7E04009-B191-4E9D-9D2D-1BBE57BD8A42}\setup.exe
AddRemove-{3912D529-02BC-4CA8-B5ED-0D0C20EB6003} - c:\program files\InstallShield Installation Information\{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}\setup.exe
AddRemove-{5C1DB4ED-E9B4-402D-BB14-D75D97D6C1A6} - c:\program files\InstallShield Installation Information\{5C1DB4ED-E9B4-402D-BB14-D75D97D6C1A6}\setup.exe
AddRemove-{83F73CB1-7705-49D1-9852-84D839CA2A45} - c:\program files\InstallShield Installation Information\{83F73CB1-7705-49D1-9852-84D839CA2A45}\setup.EXE
AddRemove-{8CFEBE9C-F29F-4C49-80E0-7106970F8734} - c:\program files\InstallShield Installation Information\{8CFEBE9C-F29F-4C49-80E0-7106970F8734}\setup.EXE
AddRemove-{AE46ABD3-D625-467F-B5A7-8D3FFF077F0D} - c:\program files\InstallShield Installation Information\{AE46ABD3-D625-467F-B5A7-8D3FFF077F0D}\setup.exe
AddRemove-{C0FC1C14-4824-4A73-87A6-9E888C9C3102} - c:\program files\InstallShield Installation Information\{C0FC1C14-4824-4A73-87A6-9E888C9C3102}\setup.EXE
AddRemove-{D3D54F3E-C5C3-443D-978F-87A72E5616E8} - c:\program files\InstallShield Installation Information\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}\setup.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-07-21 17:40
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Celkový čas: 2014-07-21 17:44:12
ComboFix-quarantined-files.txt 2014-07-21 15:44
.
Před spuštěním: Volných bajtů: 26 142 883 840
Po spuštění: Volných bajtů: 26 182 909 952
.
- - End Of File - - C05D606AE5CC626F6B1534602300BF03
5C616939100B85E558DA92B899A0FC36

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Sekání pc

#72 Příspěvek od Márty84 »

Je s pc momentalne nejaky problem?
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

kontez.
Návštěvník
Návštěvník
Příspěvky: 83
Registrován: 19 kvě 2014 13:53

Re: Sekání pc

#73 Příspěvek od kontez. »

Ano porad mi tam naskakuje pakygayness a dnes jsem hral GTA a najednou zacal hucet cpu tak jsem to vypnul a opet se instalovalo zrychleni pocitace i presto ze mam zapnute rizeni uzivatelskych uctu proste samo od sebe nejdrive se objevi u hodin sedive CD a na plose je to jako continue instalation a hned potom se instaluje to zrychleni pc nic stahovano nebylo

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Sekání pc

#74 Příspěvek od Márty84 »

To GTA je jiste legalni, bez pouziti cracku a torrentu, ze?

Vidim to na reinstal s formatem disku. Porad se to odnekud vraci a jelikoz jsou v pc cracky, muze to byt z nich. Cili tohle bude nejrychlejsi a nejjistejsi zpusob.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

kontez.
Návštěvník
Návštěvník
Příspěvky: 83
Registrován: 19 kvě 2014 13:53

Re: Sekání pc

#75 Příspěvek od kontez. »

GTA je stazene ale drive mi to problemy nedelalo drive jsem to stahnul dal na flash disk a driv jsem problemy nemel to az ted
zde je scan z MBAM ktery jsem udelal

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 22.7.2014
Čas skenování: 13:21:36
Protokol: 22.7.2014.txt
Správce: Ano

Verze: 2.00.2.1012
Databáze malwaru: v2014.07.22.03
Databáze rootkitů: v2014.07.17.01
Licence: Premium
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Self-protection: Vypnuto

OS: Windows Vista Service Pack 2
CPU: x86
Souborový systém: NTFS
Uživatel: David

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 443991
Uplynulý čas: 4 hod, 30 min, 37 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristics: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 1
PUP.Optional.Amonetize, C:\Windows\System32\netupdsrv.exe, 1640, , [e9a2ccd65d1ed36301438213b94847b9]

Moduly: 0
(No malicious items detected)

Klíče registru: 40
PUP.Optional.Amonetize, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ServiceUpdater, , [e9a2ccd65d1ed36301438213b94847b9],
PUP.Hacktool.NetFilter, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\nethfdrv, , [90fbc4defc7fc86eea586a2b5ba67a86],
PUP.Optional.Amonetize, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NetHttpService, , [8cffe5bd324944f2271cfb9ac33eb54b],
PUP.Optional.OffersWizard.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\inethnfd, , [7417aaf878039f970b568d4e8282ab55],
PUP.Optional.Downloader, HKLM\SOFTWARE\CLASSES\TYPELIB\{315155F4-B214-4F9E-9167-6438EA0459DB}, , [aedd5b47accf3402ea3e643ac839936d],
PUP.Optional.Downloader, HKLM\SOFTWARE\CLASSES\INTERFACE\{72FEA35F-29A1-4EB1-878F-EC6F7B09F720}, , [aedd5b47accf3402ea3e643ac839936d],
PUP.Optional.Amonetize, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}, , [5b302280e09b50e64ecb1c83d42d827e],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\HD-V1.9, , [6f1c2b77d1aae551a697e2ec946e5fa1],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0060548.BHO, , [206bbbe7572480b6081ff4d04fb3a957],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0060548.BHO.1, , [6a2102a0b8c359dddb4ca61ef80ae21e],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0060548.Sandbox, , [6d1ed1d16219eb4b74b3467ef50deb15],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0060548.Sandbox.1, , [0b80ddc5512ae551ae79972d5ea452ae],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE, , [a5e6f8aa2c4fd95d31aeae172fd38d73],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, , [e3a8841e7b00e45275b5f9e809f9ef11],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-3353992676-1699608881-1036909048-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\HD-V1.9, , [7d0e5250077496a08ab2a12def132bd5],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-3353992676-1699608881-1036909048-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HD-V1.9, , [9bf0a9f9cbb00333a299af1f4bb717e9],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3353992676-1699608881-1036909048-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CROSSRIDER, , [0a81b3eff08ba0964042877d64a0e61a],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3353992676-1699608881-1036909048-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, , [1d6e11911a615bdb88a3ac35f60c4ab6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3353992676-1699608881-1036909048-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\InfoHD-V1.8, , [c8c3940efc7f83b3eb71efdaa95918e8],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HD-V1.9, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611051148}, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644054448}, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655055548}, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666056648}, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611051148}, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220622052248}, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611051148}\INPROCSERVER32, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, , [a0eb81214a31bd79b39814ab28da4db3],

Hodnoty registru: 4
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE|path, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, , [a5e6f8aa2c4fd95d31aeae172fd38d73]
PUP.Optional.NetworkUpdate.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NETHTTPSERVICE|ImagePath, C:\Windows\system32\nethtsrv.exe, , [acdfedb56c0f3cfa953fe14143c19b65]
PUP.Optional.NetworkUpdate.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SERVICEUPDATER|ImagePath, C:\Windows\system32\netupdsrv.exe, , [98f3b3ef7209d16580551b072fd5da26]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3353992676-1699608881-1036909048-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CROSSRIDER|Verifier, df6dde6f1c17181bc9367ad3441ef51c, , [0a81b3eff08ba0964042877d64a0e61a]

Data registru: 0
(No malicious items detected)

Složky: 22
PUP.Optional.OffersWizard.A, C:\Program Files\Common Files\Config, , [1f6c21811764cb6b2f11eadcdf235ba5],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\defaults, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\defaults\preferences, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\userCode, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\locale, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\locale\en-US, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Download, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Install, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline\{53A313D0-A4A8-4143-B9CB-8D524B06173B}, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.A, C:\Users\David\AppData\Local\temp\comh.432812, , [ef9c188afc7faa8cf275615ec042817f],

Soubory: 201
PUP.Optional.Amonetize, C:\Windows\System32\netupdsrv.exe, , [e9a2ccd65d1ed36301438213b94847b9],
PUP.Hacktool.NetFilter, C:\Windows\System32\drivers\nethfdrv.sys, , [90fbc4defc7fc86eea586a2b5ba67a86],
PUP.Optional.Amonetize, C:\Windows\System32\nethtsrv.exe, , [8cffe5bd324944f2271cfb9ac33eb54b],
PUP.Optional.OffersWizard.A, C:\Program Files\Common Files\Config\uninstinethnfd.exe, , [7417aaf878039f970b568d4e8282ab55],
PUP.Optional.CrossRider.A, C:\Program Files\HD-V1.9\utils.exe, , [4e3d7b274536c86ed05b97b51be5a858],
PUP.Optional.Downloader, C:\Users\David\AppData\Local\temp\MediaPlayer__9219_i1074750402_il240.exe, , [aedd5b47accf3402ea3e643ac839936d],
PUP.Optional.Amonetize, C:\Users\David\AppData\Roaming\9808\a25946.exe, , [5b302280e09b50e64ecb1c83d42d827e],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-1, , [4f3ccad85e1d5cda5a803293d92914ec],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-10, , [a2e9663c03783df98e4c863ffc06ee12],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-11, , [8605257d2c4f96a07e5c883dfa08926e],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-2, , [3c4fc4debfbc4de9ca100fb646bcc838],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-3, , [88031a88e09b8aac8357e2e320e24eb2],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-4, , [6724cbd71269ed49dcfe398c699920e0],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-5, , [612adbc7d7a4b185d604dbeaca38748c],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-6, , [e1aae9b94635a78faf2b5b6a8f732bd5],
PUP.Optional.OffersWizard.A, C:\Program Files\Common Files\Config\ver.xml, , [1f6c21811764cb6b2f11eadcdf235ba5],
PUP.Optional.OffersWizard.A, C:\Program Files\Common Files\Config\data.xml, , [1f6c21811764cb6b2f11eadcdf235ba5],
PUP.Software.Updater, C:\Windows\Tasks\AmiUpdXp.job, , [5536980aaecd3006120439bcaf53d32d],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-1.job, , [117a089a5b20a0964a2169bb1be9ab55],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-10.job, , [94f7b0f2f4879d990b60f33137cd38c8],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-11.job, , [503b871b374472c43c2f131129db4eb2],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-2.job, , [7c0f8022b0cbbf77096229fb679d18e8],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-3.job, , [4942049e2a51eb4bd09b7ca8f1137f81],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-4.job, , [0e7d2280215ac67027445dc76a9afe02],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-5.job, , [c4c73a68e59652e48fdce14302028a76],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-6.job, , [5a31435fdd9ed2645a11cc582fd58d73],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-7.job, , [f992abf7ec8f1a1c98d3a87c877d50b0],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, , [78131d854833be78e39efc283dc7ec14],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, , [4d3e267c53289f972d55869e24e0f10f],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, , [ef9ce7bba9d2a690f78c071d36ce0ef2],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, , [0289e6bcf487df572a5ad54f45bf1fe1],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome.manifest, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\install.rdf, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\026b809dcf4b9ab2b8ffbdba26dc3619.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\4a2b43218f532a906e61eb9feb7e52aa.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\504ffbadb4e4998210c42e85b4de629e.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\7753d1fd3eaca1a6df668107e07f8d26.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\background.html, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\bbcd466e716c0e2159b2f8d1330f2919.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\browser.xul, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\dialog.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\ffCoreFilesIndex.txt, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\options.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\options.xul, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\search_dialog.xul, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\02b75e70ae8d4b5270f6ac3409dce65b.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\06c3f722a8e28bb0825994121bf39d51.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\1b1338a28719b876bb07f7fa07c5f5e5.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\1dea37cd3aeaa17d0a9bd52505d97a67.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\4822f9a6293b0a8461480429d021671d.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\62ec6878cf4e481d9685668a0d177b96.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\673e2724d6c9888d41925c539233c3f1.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\6ce7d6f57c48a76f0277bf83ca0a8ace.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\6d8e8d0490998b6ec1d33f17237a7e33.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\6e53f326c28a0da40adbeeb7172d9345.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\79f67e3ef9f720e12db571694825afa6.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\a326f25ad15097d617f2183ee6c7e9ba.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\b8d3004571f755a8f4df0dcf8e08183f.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\f0fafc89303101dac1a471e4699b068a.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\f41d57cff03143d8f3f37ccfd112d334.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\api\f9ad5125785f9c8416080b7b4e27f9c9.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\0440b1ae5b59190716bea2596702c623.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\0f092e0e31e29ddc23c1cf980b16f14a.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\169227780c5a001fa2075175a58f134a.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\16a15c51ec83f7d43e67fafffd695099.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\2b4dd5dc20eea78144e33d44b1867236.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\5b3e8129dccd18ebd9ff11af73bbdaba.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\65d7482bc9af3e7f72501ffae67e8910.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\6c7e8076ad0feaf1d7741e95f5a6eb6e.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\6ff3fbc6b06db9cc4b9396723a75c3b4.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\8409c9d61bac48160bfba515256b10eb.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\a234a09aaf9d5c4b1d461f145c0cad03.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\c39d11f6eac9a153ff98e1d592f3dfa0.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\c4f0da524c9250d79668aafd91b611d4.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\cee043c37fe00f92c198e04a02201fea.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\cf7f8fa0c97496ca4941a1a046e66fd5.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\d8241fe3a6b10166f61aee6e42a2534e.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\e1da87c320c9e0f922fd1c90e38155a1.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\f1b1aac60ef4c52d167dc8d6463d0e6e.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\f7ef09cf3c2204437a515ff4a4f757fc.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\fde99aad4bfcd157a6b78b9ec48ae3d4.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\chrome\content\core\installer.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\defaults\preferences\prefs.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\manifest.xml, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins.json, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\242.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\1.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\102.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\104.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\119.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\123.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\13.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\14.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\16.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\17.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\177.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\178.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\179.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\180.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\182.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\183.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\184.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\190.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\191.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\195.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\207.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\21.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\22.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\220.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\221.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\223.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\231.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\232.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\244.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\246.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\259.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\260.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\262.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\263.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\268.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\273.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\275.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\28.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\281.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\284.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\286.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\289.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\4.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\47.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\64.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\7.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\72.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\78.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\9.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\91.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\93.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\plugins\98.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\userCode\background.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\extensionData\userCode\extension.js, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\locale\en-US\translations.dtd, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\button1.png, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\button2.png, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\button3.png, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\button4.png, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\button5.png, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\crossrider_statusbar.png, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\icon128.png, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\icon16.png, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\icon24.png, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\icon48.png, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\panelarrow-up.png, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\popup.html, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\skin.css, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\extensions\d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com\skin\update.css, , [78133072502b49ed8e1f555525ddf60a],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\Interop.IWshRuntimeLibrary.dll, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\1293297481.mxaddon, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\360-60548.crx, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\60548.crx, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\60548.xpi, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\background.html, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\bgNova.html, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-2.exe, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-3.exe, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-4.exe, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f-5.exe, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\fc1cf36f-2969-44bf-b2bd-02d187ae3d2f.crx, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\Newtonsoft.Json.dll, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\Newtonsoft.Json.xml, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\SuperSocket.ClientEngine.Common.dll, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\SuperSocket.ClientEngine.Core.dll, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\SuperSocket.ClientEngine.Protocol.dll, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\Uninstall.exe, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\WebSocket4Net.dll, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\HD-V1.9-bg.exe, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\HD-V1.9-bho.dll, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\HD-V1.9-codedownloader.exe, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\HD-V1.9-nova.dll, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\HD-V1.9-novainstaller.exe, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.PlusHD.A, C:\Program Files\HD-V1.9\HD-V1.9.ico, , [d7b4f3afa1daf046c9b4b604a45e50b0],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psmachine.dll, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll, , [a0eb81214a31bd79b39814ab28da4db3],
PUP.Optional.GlobalUpdate.A, C:\Users\David\AppData\Local\temp\comh.432812\GoogleCrashHandler.exe, , [ef9c188afc7faa8cf275615ec042817f],
PUP.Optional.GlobalUpdate.A, C:\Users\David\AppData\Local\temp\comh.432812\GoogleUpdate.exe, , [ef9c188afc7faa8cf275615ec042817f],
PUP.Optional.GlobalUpdate.A, C:\Users\David\AppData\Local\temp\comh.432812\GoogleUpdateBroker.exe, , [ef9c188afc7faa8cf275615ec042817f],
PUP.Optional.GlobalUpdate.A, C:\Users\David\AppData\Local\temp\comh.432812\GoogleUpdateHelper.msi, , [ef9c188afc7faa8cf275615ec042817f],
PUP.Optional.GlobalUpdate.A, C:\Users\David\AppData\Local\temp\comh.432812\GoogleUpdateOnDemand.exe, , [ef9c188afc7faa8cf275615ec042817f],
PUP.Optional.GlobalUpdate.A, C:\Users\David\AppData\Local\temp\comh.432812\goopdate.dll, , [ef9c188afc7faa8cf275615ec042817f],
PUP.Optional.GlobalUpdate.A, C:\Users\David\AppData\Local\temp\comh.432812\goopdateres_en.dll, , [ef9c188afc7faa8cf275615ec042817f],
PUP.Optional.GlobalUpdate.A, C:\Users\David\AppData\Local\temp\comh.432812\npGoogleUpdate4.dll, , [ef9c188afc7faa8cf275615ec042817f],
PUP.Optional.GlobalUpdate.A, C:\Users\David\AppData\Local\temp\comh.432812\psmachine.dll, , [ef9c188afc7faa8cf275615ec042817f],
PUP.Optional.GlobalUpdate.A, C:\Users\David\AppData\Local\temp\comh.432812\psuser.dll, , [ef9c188afc7faa8cf275615ec042817f],
PUP.Optional.CrossRider.A, C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\qtqpxxi2.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.crossrider.bic", "1475dcb19a18baf98ca1bb369c3de912");), ,[3853c6dcdf9c79bd07af1cc0867ead53]

Fyzické sektory: 0
(No malicious items detected)


(end)

Zamčeno