Reklamy v prohlížeči. Nic nepomáhá. Win32.Downloader.gen
Napsal: 02 kvě 2014 07:54
Zdravím,
poslední cca měsíc mě trápí vir/malware či něco takového... Ve všech prohlížečích mi zobrazuje reklamu. Na každé stránce jí prostě někam nacpe a často mě po kliknutí na odkaz přesměruje někam jinam. Zároveň se objevuje reklama přímo v textu na stránce ( např. zvýraznění slova Kolo a po najetí přes slovo vyskočí reklama na horské kola... )
Zkoušel jsem pár různých antivirů, cleanerů apod... ale nic nepomohlo. Program Spybot - Search & Destroy však nalezl b]Win32.Downloader.gen[/b] a za boha ho nedokáže odstranit.
Doufal jsem, že problém dokážu vyřešit sám, ale po dvou dnech intenzivního zkoumání jsem to vzdal a rozhodl se požádat o pomoc tady. Zde na fóru jsem našel topic http://forum.viry.cz/viewtopic.php?f=13&t=129919 kde to někomu také našlo stejný soubor. Ale nezmiňuje se o tom, že by měl stejný problém jako já...
Na závěr bych jen rád dodal, že jsem použil program ComboFix. Ze začátku jsem váhal zda to stojí za ten risk. Kdykoliv jsem si o tom programu něco četl, tak všude bylo fakt milion varování, ale dneska jsem se rozhodl že ho vyzkouším. Byl jsem odhodlaný přeinstalovat winy kdyby se náhodou něco podělalo. ComboFix scanoval cca 5 min, resetoval PC a vyhodil log. Reklamy stále naskakují, horské kolo stále nechci a rád bych se toho zbavil.
Budu rád za jakoukoliv pomoc!
Přikládám logy z programů ComboFix, Junkware Removal Tool a AdwCleaner.
EDIT: Pro zodpovězení dotazů, které by se mohli objevit ještě doplním pár věcí. Všechny programy jsem spouštěl jako správce a antivir i firewall jsem vypnul. Spybota jsem odinstaloval, stejně tak všechny antiviry, cleanery apod... co jsem stahoval na vlastní pěst. Celkově jsem se snažil odinstalovat z PC všechno o co nemám zájem.
ComboFix
ComboFix 14-04-30.01 - Tom 02.05.2014 8:09.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.8153.6463 [GMT 2:00]
Spuštěný z: c:\users\Tom\Downloads\ComboFix.exe
AV: Ad-Aware Antivirus *Disabled/Outdated* {D87B6541-12A1-DAEA-0033-9B8057AAB996}
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
FW: Ad-Aware Firewall *Disabled* {E040E464-58CE-DBB2-2B6C-32B5A979FEED}
SP: Ad-Aware Antivirus *Disabled/Outdated* {631A84A5-349B-D564-3A83-A0F22C2DF32B}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\INSTALL.LOG
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\tWefVKfyHIf.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\icon48.png
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\QKDD4gF94.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\hOW.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\dH1iFErm.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\newtab.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\FBekp.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\tWefVKfyHIf.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\icon48.png
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\QKDD4gF94.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\hOW.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\dH1iFErm.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\newtab.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\FBekp.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\tWefVKfyHIf.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\icon48.png
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\QKDD4gF94.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\hOW.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\dH1iFErm.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\newtab.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\FBekp.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\manifest.json
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\background.html
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\content.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\lsdb.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\manifest.json
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\tWefVKfyHIf.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\background.html
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\content.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\icon48.png
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\lsdb.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\manifest.json
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\QKDD4gF94.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\background.html
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\content.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\hOW.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\lsdb.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\manifest.json
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\background.html
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\content.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\dH1iFErm.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\lsdb.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\manifest.json
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\newtab.html
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\background.html
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\content.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\FBekp.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\lsdb.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\manifest.json
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmdjbiceagbmomlmanlmfokhocllcfk
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmdjbiceagbmomlmanlmfokhocllcfk\3.2_0\background.html
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmdjbiceagbmomlmanlmfokhocllcfk\3.2_0\content.js
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmdjbiceagbmomlmanlmfokhocllcfk\3.2_0\lsdb.js
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmdjbiceagbmomlmanlmfokhocllcfk\3.2_0\manifest.json
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmdjbiceagbmomlmanlmfokhocllcfk\3.2_0\nXAaTet0VOD.js
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\background.html
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\content.js
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\dH1iFErm.js
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\lsdb.js
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\manifest.json
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\newtab.html
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_efmdjbiceagbmomlmanlmfokhocllcfk_0.localstorage-journal
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_efmdjbiceagbmomlmanlmfokhocllcfk_0.localstorage
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_idgcphbhapbeejlhjhplmmhfffgkbmnf_0.localstorage-journal
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_idgcphbhapbeejlhjhplmmhfffgkbmnf_0.localstorage
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Tom\AppData\Local\Temp\7zS4302\HPSLPSVC64.DLL
c:\windows\iun6002.exe
c:\windows\SysWow64\Core.dll
c:\windows\SysWow64\X86
D:\install.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_HPSLPSVC
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-04-02 do 2014-05-02 )))))))))))))))))))))))))))))))
.
.
2014-05-02 04:10 . 2014-05-02 04:10 1031560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8D93409F-B444-486C-889B-53F36AEA8807}\gapaengine.dll
2014-05-02 04:10 . 2014-04-16 10:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2BA2E002-3CC3-4E10-84E0-9BBFAE558D2D}\mpengine.dll
2014-04-30 14:25 . 2014-04-16 10:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-04-20 21:37 . 2014-04-20 21:37 -------- d-----w- c:\program files (x86)\Common Files\BitSpirit
2014-04-20 21:37 . 2014-04-20 21:37 -------- d-----w- c:\program files\BitSpirit
2014-04-16 12:39 . 2014-04-16 12:39 -------- d-sh--w- c:\users\Tom\AppData\Local\EmieUserList
2014-04-16 12:39 . 2014-04-16 12:39 -------- d-sh--w- c:\users\Tom\AppData\Local\EmieSiteList
2014-04-16 12:38 . 2014-04-16 12:38 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2014-04-14 15:58 . 2014-04-14 15:58 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2014-04-14 15:50 . 2014-04-14 15:50 -------- d-sh--w- c:\windows\ftpcache
2014-04-14 15:22 . 2014-04-14 15:22 -------- d-----w- c:\program files (x86)\MP4 Converter
2014-04-14 15:18 . 2014-04-14 15:18 -------- d-----w- c:\users\Tom\AppData\Roaming\Sony Creative Software Inc
2014-04-14 15:07 . 2014-04-08 20:51 169984 ----a-w- c:\windows\system32\xvid.ax
2014-04-14 15:07 . 2014-04-08 20:51 251392 ----a-w- c:\windows\system32\xvidvfw.dll
2014-04-14 15:07 . 2014-04-08 20:51 706048 ----a-w- c:\windows\system32\xvidcore.dll
2014-04-14 15:07 . 2014-04-08 20:50 147456 ----a-w- c:\windows\SysWow64\xvid.ax
2014-04-14 15:07 . 2014-04-08 20:50 235520 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2014-04-14 15:07 . 2014-04-08 20:50 632320 ----a-w- c:\windows\SysWow64\xvidcore.dll
2014-04-14 15:07 . 2014-04-14 15:07 -------- d-----w- c:\program files (x86)\Xvid
2014-04-14 15:02 . 2014-04-27 01:49 -------- d-----w- C:\shimmy
2014-04-14 14:45 . 2014-04-25 19:44 -------- d-----w- C:\Downloads
2014-04-14 14:44 . 2014-04-14 14:44 -------- d-----w- c:\users\Tom\AppData\Roaming\BitSpirit
2014-04-10 07:38 . 2014-04-10 07:38 -------- d-----w- c:\users\Tom\AppData\Local\CrashRpt
2014-04-10 07:38 . 2014-04-10 07:38 -------- d-----w- c:\programdata\RegClean
2014-04-10 07:35 . 2014-04-10 07:35 -------- d-----w- c:\users\Tom\AppData\Roaming\Lavasoft
2014-04-10 07:18 . 2014-04-10 07:36 -------- d-----w- C:\AdwCleaner
2014-04-10 07:13 . 2014-04-10 07:13 -------- d-----w- c:\windows\ERUNT
2014-04-09 19:06 . 2014-04-09 19:06 -------- d-----w- C:\foto
2014-04-09 16:03 . 2014-04-09 16:03 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
2014-04-09 16:03 . 2014-04-10 07:20 -------- d-----w- c:\program files (x86)\Spyware Terminator
2014-04-08 21:28 . 2014-04-08 21:39 -------- d-----w- c:\users\Tom\AppData\Roaming\My Battle for Middle-earth Files
2014-04-07 19:20 . 2014-04-07 19:21 -------- d-----w- C:\Minecraft mody
2014-04-05 12:20 . 2014-04-05 12:20 499712 ----a-w- c:\windows\SysWow64\phatk121016Pitcairnv1w256l4.bin
2014-04-04 12:51 . 2014-04-17 02:43 -------- d-----w- c:\users\Tom\AppData\Roaming\.minecraft
2014-04-03 18:13 . 2014-04-03 18:13 -------- d-----w- c:\users\Tom\AppData\Roaming\logs
2014-04-03 17:49 . 2014-04-05 21:19 -------- d-----w- C:\mc server
2014-04-03 17:02 . 2014-04-03 17:02 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-04-03 16:30 . 2014-04-03 16:30 -------- d-----w- c:\program files\Mozilla Firefox
2014-04-02 13:08 . 2014-04-02 13:08 -------- d-----w- c:\windows\jre
2014-04-02 13:08 . 2014-04-02 13:08 -------- d--h--w- c:\program files (x86)\Zero G Registry
2014-04-02 13:07 . 2014-04-02 13:07 -------- d--h--w- c:\users\Tom\InstallAnywhere
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-02 01:24 . 2013-08-08 17:35 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-05-02 01:24 . 2013-08-08 16:24 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-05-02 00:58 . 2013-08-08 16:24 281032 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-04-29 11:36 . 2013-06-30 13:55 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-04-29 11:36 . 2013-06-18 20:34 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-07 19:21 . 2014-04-07 19:21 33428759 ----a-w- C:\Minecraft mody.zip
2014-03-27 06:04 . 2013-06-17 12:18 30528 ----a-w- c:\windows\GVTDrv64.sys
2014-03-27 06:04 . 2013-06-17 12:18 25640 ----a-w- c:\windows\gdrv.sys
2014-03-20 18:17 . 2014-03-20 18:17 43520 ----a-w- c:\windows\SysWow64\CmdLineExt03.dll
2014-03-18 23:32 . 2013-06-17 12:44 90015360 ----a-w- c:\windows\system32\MRT.exe
2014-03-13 15:08 . 2014-03-13 15:08 25640 ----a-w- c:\windows\etdrv.sys
2014-03-11 07:52 . 2013-01-20 13:59 133928 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2014-03-04 09:17 . 2014-04-09 13:23 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-02-21 14:59 . 2013-07-17 10:03 1031560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-02-07 21:51 . 2014-02-07 21:51 260 ----a-w- c:\users\Tom\AppData\Roaming\Civ5Network.bin
2014-02-07 01:23 . 2014-03-14 12:06 3156480 ----a-w- c:\windows\system32\win32k.sys
2014-02-04 02:32 . 2014-03-14 12:06 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-02-04 02:32 . 2014-03-14 12:06 624128 ----a-w- c:\windows\system32\qedit.dll
2014-02-04 02:04 . 2014-03-14 12:06 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04 . 2014-03-14 12:06 509440 ----a-w- c:\windows\SysWow64\qedit.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{BA88EE03-E964-4232-E85D-0B2DC2503D4E}]
2014-01-31 00:13 427520 ----a-w- c:\programdata\BlocckUTuboeAd\4LgrQmtUV.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoogleChromeAutoLaunch_F6A43803F41C0EE8AA9068339E55A010"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2014-01-23 866584]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"GamingMouseEditor"="c:\program files (x86)\GamingMouseEditor\GamingMouseEditor\GamingMouseEditor.exe" [2012-08-17 3333120]
"Xvid"="c:\program files (x86)\Xvid\CheckUpdate.exe" [2011-01-17 8192]
"icq"="c:\users\Tom\AppData\Roaming\ICQM\icq.exe" [2013-06-17 28682088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-02-29 56088]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-03-28 642656]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Nástroj WD Drive Unlocker"="c:\program files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe" [2012-09-06 1688008]
"Nástroj WD Quick View"="c:\program files (x86)\Western Digital\WD Quick View\WDDMStatus.exe" [2012-09-19 5236664]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"MSStp"="c:\windows\inf\msstp.vbe" [2014-03-05 1584]
"mncvkyolaSrv"="c:\windows\system32\mncvkyola.vbe" [2014-03-05 7670]
.
c:\users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2013-10-29 36536]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
LOLRecorder.lnk - c:\program files\LOLReplay\LOLRecorder.exe -minimize [2013-9-13 526336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.141\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.141\McCHSvc.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys;c:\windows\SYSNATIVE\DRIVERS\nlndis.sys [x]
R3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys;c:\windows\SYSNATIVE\DRIVERS\nlndis.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TunngleService;TunngleService;d:\program files\Tunngle\TnglCtrl.exe;d:\program files\Tunngle\TnglCtrl.exe [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
S0 vsock;vSockets Driver;c:\windows\system32\drivers\vsock.sys;c:\windows\SYSNATIVE\drivers\vsock.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AllShare Framework DMS;AllShare Framework DMS;c:\program files\Samsung\AllShare Framework DMS\1.3.09\AllShareFrameworkManagerDMS.exe;c:\program files\Samsung\AllShare Framework DMS\1.3.09\AllShareFrameworkManagerDMS.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AVerRECentral;AVerRECentral;c:\program files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe;c:\program files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe [x]
S2 AVerUpdateServer;AVerUpdateServer;c:\program files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe;c:\program files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 LavasoftAdAwareService11;Ad-Aware Service 11;d:\program files\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe;d:\program files\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
S2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [x]
S2 WDBackup;WD Backup;c:\program files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe;c:\program files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [x]
S2 WDDriveService;WD Drive Manager;c:\program files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe;c:\program files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [x]
S2 WDRulesService;WD Rules;c:\program files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe;c:\program files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 AVer330;AVer330;c:\windows\system32\DRIVERS\AVer330.sys;c:\windows\SYSNATIVE\DRIVERS\AVer330.sys [x]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-28 18:03 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.102\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-05-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-30 11:36]
.
2014-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-17 12:31]
.
2014-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-17 12:31]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA88EE03-E964-4232-E85D-0B2DC2503D4E}]
2014-01-31 00:13 476160 ----a-w- c:\programdata\BlocckUTuboeAd\4LgrQmtUV.x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144]
"AdAwareTray"="d:\program files\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareTray.exe" [2014-01-23 4114264]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
mDefault_Page_URL = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - d:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: Stáhnout pomocí &BitSpiritu - c:\program files\BitSpirit\bsurl.htm
LSP: %windir%\system32\vsocklib.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
FF - ProfilePath - c:\users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\0ymbjrnc.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SpywareTerminatorShield - c:\program files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
HKLM-Run-SpywareTerminatorUpdater - c:\program files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
AddRemove-BattlEye for A2 - c:\hry\Steam\steamapps\common\Arma 2BattlEye\UnInstallBE.exe
AddRemove-Borderlands 2 - d:\hry\Borderlands 2\Uninstall.exe
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-FixMyRegistry - c:\program files (x86)\SmartTweak\FixMyRegistry\uninst.exe
AddRemove-Minecraft 1.7.2 1.00 - c:\users\Tom\AppData\Roaming\.minecraft\Uninstall.exe
AddRemove-strife - d:\hry\Strife\uninstall.exe
AddRemove-{abc8eea4-29fa-3932-9612-e2122d8a62d9}}_is1 - d:\hry\WarThunderDev\unins000.exe
AddRemove-BitMinter Client - c:\windows\system32\javaws.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3404850598-2521911625-2363163390-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:86,9f,65,bc,bc,21,6e,84,68,ee,16,9c,de,39,32,48,f6,23,02,12,52,8d,fc,
c0,bb,a5,9d,db,ec,fe,81,46,8d,14,c8,7d,c0,f7,b8,06,99,92,24,28,53,10,2d,95,\
"??"=hex:89,27,f1,57,ca,b0,af,4e,91,94,98,19,de,e3,45,7b
.
[HKEY_USERS\S-1-5-21-3404850598-2521911625-2363163390-1000\Software\SecuROM\License information*]
"datasecu"=hex:2a,72,87,64,e5,86,9a,11,91,dd,2f,a7,67,15,b7,53,df,50,1f,94,89,
20,1e,0d,3b,49,74,88,c0,0e,28,6c,08,25,4c,b1,d8,3e,c9,62,77,f7,3a,e6,16,4f,\
"rkeysecu"=hex:fb,2d,06,d9,39,bf,a8,2d,ce,8c,e4,da,eb,0e,16,56
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Samsung\AllShare Framework DMS\1.3.09\AllShareFrameworkDMS.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
d:\program files\Nero\Nero MediaHome 4\NMMediaServerService.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\vmnat.exe
c:\windows\SysWOW64\vmnetdhcp.exe
d:\program files\WMware Player\vmware-authd.exe
c:\program files\LOLReplay\LOLRecorder.exe
c:\windows\SysWOW64\WScript.exe
c:\program files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
.
**************************************************************************
.
Celkový čas: 2014-05-02 08:17:08 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-05-02 06:17
.
Před spuštěním: Volných bajtů: 11 068 588 032
Po spuštění: Volných bajtů: 11 435 642 880
.
- - End Of File - - A9A72F7CBC911EA6D5FF5BEFCB67694D
AdwCleaner
# AdwCleaner v3.205 - Report created 02/05/2014 at 08:36:02
# Updated 28/04/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Tom - TOM-PC
# Running from : C:\Users\Tom\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\smarttweak
Key Deleted : HKCU\Software\AppDataLow\Software\adawarebp
Key Deleted : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v28.0 (cs)
[ File : C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\0ymbjrnc.default\prefs.js ]
-\\ Google Chrome v32.0.1700.102
[ File : C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
Deleted [Search Provider] : hxxp://websearch.toolksearchbook.info/?l=1&q={searchTerms}&pid=1565&r=2014/01/21&hid=16959463485068646480&lg=EN&cc=CZ&unqvl=46
Deleted [Search Provider] : hxxp://anidb.net/perl-bin/animedb.pl?show=animelist&adb.search={searchTerms}&do.search=search
*************************
AdwCleaner[R0].txt - [6903 octets] - [10/04/2014 09:18:25]
AdwCleaner[R1].txt - [1257 octets] - [10/04/2014 09:36:16]
AdwCleaner[R2].txt - [1942 octets] - [02/05/2014 08:32:35]
AdwCleaner[S0].txt - [6603 octets] - [10/04/2014 09:19:17]
AdwCleaner[S1].txt - [1245 octets] - [10/04/2014 09:36:52]
AdwCleaner[S2].txt - [2149 octets] - [02/05/2014 08:36:02]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2209 octets] ##########
Junkware Removal Tool
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Tom on p 02.05.2014 at 8:37:41,05
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files (x86)\smarttweak"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p 02.05.2014 at 8:40:57,48
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
poslední cca měsíc mě trápí vir/malware či něco takového... Ve všech prohlížečích mi zobrazuje reklamu. Na každé stránce jí prostě někam nacpe a často mě po kliknutí na odkaz přesměruje někam jinam. Zároveň se objevuje reklama přímo v textu na stránce ( např. zvýraznění slova Kolo a po najetí přes slovo vyskočí reklama na horské kola... )
Zkoušel jsem pár různých antivirů, cleanerů apod... ale nic nepomohlo. Program Spybot - Search & Destroy však nalezl b]Win32.Downloader.gen[/b] a za boha ho nedokáže odstranit.
Doufal jsem, že problém dokážu vyřešit sám, ale po dvou dnech intenzivního zkoumání jsem to vzdal a rozhodl se požádat o pomoc tady. Zde na fóru jsem našel topic http://forum.viry.cz/viewtopic.php?f=13&t=129919 kde to někomu také našlo stejný soubor. Ale nezmiňuje se o tom, že by měl stejný problém jako já...
Na závěr bych jen rád dodal, že jsem použil program ComboFix. Ze začátku jsem váhal zda to stojí za ten risk. Kdykoliv jsem si o tom programu něco četl, tak všude bylo fakt milion varování, ale dneska jsem se rozhodl že ho vyzkouším. Byl jsem odhodlaný přeinstalovat winy kdyby se náhodou něco podělalo. ComboFix scanoval cca 5 min, resetoval PC a vyhodil log. Reklamy stále naskakují, horské kolo stále nechci a rád bych se toho zbavil.
Budu rád za jakoukoliv pomoc!
Přikládám logy z programů ComboFix, Junkware Removal Tool a AdwCleaner.
EDIT: Pro zodpovězení dotazů, které by se mohli objevit ještě doplním pár věcí. Všechny programy jsem spouštěl jako správce a antivir i firewall jsem vypnul. Spybota jsem odinstaloval, stejně tak všechny antiviry, cleanery apod... co jsem stahoval na vlastní pěst. Celkově jsem se snažil odinstalovat z PC všechno o co nemám zájem.
ComboFix
ComboFix 14-04-30.01 - Tom 02.05.2014 8:09.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.8153.6463 [GMT 2:00]
Spuštěný z: c:\users\Tom\Downloads\ComboFix.exe
AV: Ad-Aware Antivirus *Disabled/Outdated* {D87B6541-12A1-DAEA-0033-9B8057AAB996}
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
FW: Ad-Aware Firewall *Disabled* {E040E464-58CE-DBB2-2B6C-32B5A979FEED}
SP: Ad-Aware Antivirus *Disabled/Outdated* {631A84A5-349B-D564-3A83-A0F22C2DF32B}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\INSTALL.LOG
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\tWefVKfyHIf.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\icon48.png
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\QKDD4gF94.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\hOW.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\dH1iFErm.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\newtab.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\FBekp.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\tWefVKfyHIf.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\icon48.png
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\QKDD4gF94.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\hOW.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\dH1iFErm.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\newtab.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\FBekp.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\tWefVKfyHIf.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\icon48.png
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\QKDD4gF94.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\hOW.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\dH1iFErm.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\newtab.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\FBekp.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\manifest.json
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\background.html
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\content.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\lsdb.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\manifest.json
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlanpmhnkadmkfkgkdfppicfhkkggjll\1.0\tWefVKfyHIf.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\background.html
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\content.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\icon48.png
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\lsdb.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\manifest.json
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fekndhmgknpngldmldagggcjkaiabjml\1.1\QKDD4gF94.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\background.html
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\content.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\hOW.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\lsdb.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghcomfgcnglinfbmdacdbkpjogleejek\2.7\manifest.json
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\background.html
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\content.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\dH1iFErm.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\lsdb.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\manifest.json
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\newtab.html
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\background.html
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\content.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\FBekp.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\lsdb.js
c:\users\NeroMediaHomeUser.4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipopodflddngcbmefgnnmfggjpknepha\161\manifest.json
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmdjbiceagbmomlmanlmfokhocllcfk
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmdjbiceagbmomlmanlmfokhocllcfk\3.2_0\background.html
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmdjbiceagbmomlmanlmfokhocllcfk\3.2_0\content.js
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmdjbiceagbmomlmanlmfokhocllcfk\3.2_0\lsdb.js
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmdjbiceagbmomlmanlmfokhocllcfk\3.2_0\manifest.json
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmdjbiceagbmomlmanlmfokhocllcfk\3.2_0\nXAaTet0VOD.js
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\background.html
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\content.js
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\dH1iFErm.js
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\lsdb.js
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\manifest.json
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgcphbhapbeejlhjhplmmhfffgkbmnf\2.1\newtab.html
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_efmdjbiceagbmomlmanlmfokhocllcfk_0.localstorage-journal
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_efmdjbiceagbmomlmanlmfokhocllcfk_0.localstorage
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_idgcphbhapbeejlhjhplmmhfffgkbmnf_0.localstorage-journal
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_idgcphbhapbeejlhjhplmmhfffgkbmnf_0.localstorage
c:\users\Tom\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Tom\AppData\Local\Temp\7zS4302\HPSLPSVC64.DLL
c:\windows\iun6002.exe
c:\windows\SysWow64\Core.dll
c:\windows\SysWow64\X86
D:\install.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_HPSLPSVC
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-04-02 do 2014-05-02 )))))))))))))))))))))))))))))))
.
.
2014-05-02 04:10 . 2014-05-02 04:10 1031560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8D93409F-B444-486C-889B-53F36AEA8807}\gapaengine.dll
2014-05-02 04:10 . 2014-04-16 10:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2BA2E002-3CC3-4E10-84E0-9BBFAE558D2D}\mpengine.dll
2014-04-30 14:25 . 2014-04-16 10:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-04-20 21:37 . 2014-04-20 21:37 -------- d-----w- c:\program files (x86)\Common Files\BitSpirit
2014-04-20 21:37 . 2014-04-20 21:37 -------- d-----w- c:\program files\BitSpirit
2014-04-16 12:39 . 2014-04-16 12:39 -------- d-sh--w- c:\users\Tom\AppData\Local\EmieUserList
2014-04-16 12:39 . 2014-04-16 12:39 -------- d-sh--w- c:\users\Tom\AppData\Local\EmieSiteList
2014-04-16 12:38 . 2014-04-16 12:38 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2014-04-14 15:58 . 2014-04-14 15:58 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2014-04-14 15:50 . 2014-04-14 15:50 -------- d-sh--w- c:\windows\ftpcache
2014-04-14 15:22 . 2014-04-14 15:22 -------- d-----w- c:\program files (x86)\MP4 Converter
2014-04-14 15:18 . 2014-04-14 15:18 -------- d-----w- c:\users\Tom\AppData\Roaming\Sony Creative Software Inc
2014-04-14 15:07 . 2014-04-08 20:51 169984 ----a-w- c:\windows\system32\xvid.ax
2014-04-14 15:07 . 2014-04-08 20:51 251392 ----a-w- c:\windows\system32\xvidvfw.dll
2014-04-14 15:07 . 2014-04-08 20:51 706048 ----a-w- c:\windows\system32\xvidcore.dll
2014-04-14 15:07 . 2014-04-08 20:50 147456 ----a-w- c:\windows\SysWow64\xvid.ax
2014-04-14 15:07 . 2014-04-08 20:50 235520 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2014-04-14 15:07 . 2014-04-08 20:50 632320 ----a-w- c:\windows\SysWow64\xvidcore.dll
2014-04-14 15:07 . 2014-04-14 15:07 -------- d-----w- c:\program files (x86)\Xvid
2014-04-14 15:02 . 2014-04-27 01:49 -------- d-----w- C:\shimmy
2014-04-14 14:45 . 2014-04-25 19:44 -------- d-----w- C:\Downloads
2014-04-14 14:44 . 2014-04-14 14:44 -------- d-----w- c:\users\Tom\AppData\Roaming\BitSpirit
2014-04-10 07:38 . 2014-04-10 07:38 -------- d-----w- c:\users\Tom\AppData\Local\CrashRpt
2014-04-10 07:38 . 2014-04-10 07:38 -------- d-----w- c:\programdata\RegClean
2014-04-10 07:35 . 2014-04-10 07:35 -------- d-----w- c:\users\Tom\AppData\Roaming\Lavasoft
2014-04-10 07:18 . 2014-04-10 07:36 -------- d-----w- C:\AdwCleaner
2014-04-10 07:13 . 2014-04-10 07:13 -------- d-----w- c:\windows\ERUNT
2014-04-09 19:06 . 2014-04-09 19:06 -------- d-----w- C:\foto
2014-04-09 16:03 . 2014-04-09 16:03 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
2014-04-09 16:03 . 2014-04-10 07:20 -------- d-----w- c:\program files (x86)\Spyware Terminator
2014-04-08 21:28 . 2014-04-08 21:39 -------- d-----w- c:\users\Tom\AppData\Roaming\My Battle for Middle-earth Files
2014-04-07 19:20 . 2014-04-07 19:21 -------- d-----w- C:\Minecraft mody
2014-04-05 12:20 . 2014-04-05 12:20 499712 ----a-w- c:\windows\SysWow64\phatk121016Pitcairnv1w256l4.bin
2014-04-04 12:51 . 2014-04-17 02:43 -------- d-----w- c:\users\Tom\AppData\Roaming\.minecraft
2014-04-03 18:13 . 2014-04-03 18:13 -------- d-----w- c:\users\Tom\AppData\Roaming\logs
2014-04-03 17:49 . 2014-04-05 21:19 -------- d-----w- C:\mc server
2014-04-03 17:02 . 2014-04-03 17:02 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-04-03 16:30 . 2014-04-03 16:30 -------- d-----w- c:\program files\Mozilla Firefox
2014-04-02 13:08 . 2014-04-02 13:08 -------- d-----w- c:\windows\jre
2014-04-02 13:08 . 2014-04-02 13:08 -------- d--h--w- c:\program files (x86)\Zero G Registry
2014-04-02 13:07 . 2014-04-02 13:07 -------- d--h--w- c:\users\Tom\InstallAnywhere
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-02 01:24 . 2013-08-08 17:35 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-05-02 01:24 . 2013-08-08 16:24 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-05-02 00:58 . 2013-08-08 16:24 281032 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-04-29 11:36 . 2013-06-30 13:55 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-04-29 11:36 . 2013-06-18 20:34 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-07 19:21 . 2014-04-07 19:21 33428759 ----a-w- C:\Minecraft mody.zip
2014-03-27 06:04 . 2013-06-17 12:18 30528 ----a-w- c:\windows\GVTDrv64.sys
2014-03-27 06:04 . 2013-06-17 12:18 25640 ----a-w- c:\windows\gdrv.sys
2014-03-20 18:17 . 2014-03-20 18:17 43520 ----a-w- c:\windows\SysWow64\CmdLineExt03.dll
2014-03-18 23:32 . 2013-06-17 12:44 90015360 ----a-w- c:\windows\system32\MRT.exe
2014-03-13 15:08 . 2014-03-13 15:08 25640 ----a-w- c:\windows\etdrv.sys
2014-03-11 07:52 . 2013-01-20 13:59 133928 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2014-03-04 09:17 . 2014-04-09 13:23 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-02-21 14:59 . 2013-07-17 10:03 1031560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-02-07 21:51 . 2014-02-07 21:51 260 ----a-w- c:\users\Tom\AppData\Roaming\Civ5Network.bin
2014-02-07 01:23 . 2014-03-14 12:06 3156480 ----a-w- c:\windows\system32\win32k.sys
2014-02-04 02:32 . 2014-03-14 12:06 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-02-04 02:32 . 2014-03-14 12:06 624128 ----a-w- c:\windows\system32\qedit.dll
2014-02-04 02:04 . 2014-03-14 12:06 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04 . 2014-03-14 12:06 509440 ----a-w- c:\windows\SysWow64\qedit.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{BA88EE03-E964-4232-E85D-0B2DC2503D4E}]
2014-01-31 00:13 427520 ----a-w- c:\programdata\BlocckUTuboeAd\4LgrQmtUV.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoogleChromeAutoLaunch_F6A43803F41C0EE8AA9068339E55A010"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2014-01-23 866584]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"GamingMouseEditor"="c:\program files (x86)\GamingMouseEditor\GamingMouseEditor\GamingMouseEditor.exe" [2012-08-17 3333120]
"Xvid"="c:\program files (x86)\Xvid\CheckUpdate.exe" [2011-01-17 8192]
"icq"="c:\users\Tom\AppData\Roaming\ICQM\icq.exe" [2013-06-17 28682088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-02-29 56088]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-03-28 642656]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Nástroj WD Drive Unlocker"="c:\program files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe" [2012-09-06 1688008]
"Nástroj WD Quick View"="c:\program files (x86)\Western Digital\WD Quick View\WDDMStatus.exe" [2012-09-19 5236664]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"MSStp"="c:\windows\inf\msstp.vbe" [2014-03-05 1584]
"mncvkyolaSrv"="c:\windows\system32\mncvkyola.vbe" [2014-03-05 7670]
.
c:\users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2013-10-29 36536]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
LOLRecorder.lnk - c:\program files\LOLReplay\LOLRecorder.exe -minimize [2013-9-13 526336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.141\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.141\McCHSvc.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys;c:\windows\SYSNATIVE\DRIVERS\nlndis.sys [x]
R3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys;c:\windows\SYSNATIVE\DRIVERS\nlndis.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TunngleService;TunngleService;d:\program files\Tunngle\TnglCtrl.exe;d:\program files\Tunngle\TnglCtrl.exe [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
S0 vsock;vSockets Driver;c:\windows\system32\drivers\vsock.sys;c:\windows\SYSNATIVE\drivers\vsock.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AllShare Framework DMS;AllShare Framework DMS;c:\program files\Samsung\AllShare Framework DMS\1.3.09\AllShareFrameworkManagerDMS.exe;c:\program files\Samsung\AllShare Framework DMS\1.3.09\AllShareFrameworkManagerDMS.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AVerRECentral;AVerRECentral;c:\program files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe;c:\program files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe [x]
S2 AVerUpdateServer;AVerUpdateServer;c:\program files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe;c:\program files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 LavasoftAdAwareService11;Ad-Aware Service 11;d:\program files\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe;d:\program files\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
S2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [x]
S2 WDBackup;WD Backup;c:\program files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe;c:\program files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [x]
S2 WDDriveService;WD Drive Manager;c:\program files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe;c:\program files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [x]
S2 WDRulesService;WD Rules;c:\program files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe;c:\program files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 AVer330;AVer330;c:\windows\system32\DRIVERS\AVer330.sys;c:\windows\SYSNATIVE\DRIVERS\AVer330.sys [x]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-28 18:03 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.102\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-05-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-30 11:36]
.
2014-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-17 12:31]
.
2014-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-17 12:31]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA88EE03-E964-4232-E85D-0B2DC2503D4E}]
2014-01-31 00:13 476160 ----a-w- c:\programdata\BlocckUTuboeAd\4LgrQmtUV.x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144]
"AdAwareTray"="d:\program files\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareTray.exe" [2014-01-23 4114264]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
mDefault_Page_URL = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - d:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: Stáhnout pomocí &BitSpiritu - c:\program files\BitSpirit\bsurl.htm
LSP: %windir%\system32\vsocklib.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
FF - ProfilePath - c:\users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\0ymbjrnc.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SpywareTerminatorShield - c:\program files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
HKLM-Run-SpywareTerminatorUpdater - c:\program files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
AddRemove-BattlEye for A2 - c:\hry\Steam\steamapps\common\Arma 2BattlEye\UnInstallBE.exe
AddRemove-Borderlands 2 - d:\hry\Borderlands 2\Uninstall.exe
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-FixMyRegistry - c:\program files (x86)\SmartTweak\FixMyRegistry\uninst.exe
AddRemove-Minecraft 1.7.2 1.00 - c:\users\Tom\AppData\Roaming\.minecraft\Uninstall.exe
AddRemove-strife - d:\hry\Strife\uninstall.exe
AddRemove-{abc8eea4-29fa-3932-9612-e2122d8a62d9}}_is1 - d:\hry\WarThunderDev\unins000.exe
AddRemove-BitMinter Client - c:\windows\system32\javaws.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3404850598-2521911625-2363163390-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:86,9f,65,bc,bc,21,6e,84,68,ee,16,9c,de,39,32,48,f6,23,02,12,52,8d,fc,
c0,bb,a5,9d,db,ec,fe,81,46,8d,14,c8,7d,c0,f7,b8,06,99,92,24,28,53,10,2d,95,\
"??"=hex:89,27,f1,57,ca,b0,af,4e,91,94,98,19,de,e3,45,7b
.
[HKEY_USERS\S-1-5-21-3404850598-2521911625-2363163390-1000\Software\SecuROM\License information*]
"datasecu"=hex:2a,72,87,64,e5,86,9a,11,91,dd,2f,a7,67,15,b7,53,df,50,1f,94,89,
20,1e,0d,3b,49,74,88,c0,0e,28,6c,08,25,4c,b1,d8,3e,c9,62,77,f7,3a,e6,16,4f,\
"rkeysecu"=hex:fb,2d,06,d9,39,bf,a8,2d,ce,8c,e4,da,eb,0e,16,56
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Samsung\AllShare Framework DMS\1.3.09\AllShareFrameworkDMS.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
d:\program files\Nero\Nero MediaHome 4\NMMediaServerService.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\vmnat.exe
c:\windows\SysWOW64\vmnetdhcp.exe
d:\program files\WMware Player\vmware-authd.exe
c:\program files\LOLReplay\LOLRecorder.exe
c:\windows\SysWOW64\WScript.exe
c:\program files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
.
**************************************************************************
.
Celkový čas: 2014-05-02 08:17:08 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-05-02 06:17
.
Před spuštěním: Volných bajtů: 11 068 588 032
Po spuštění: Volných bajtů: 11 435 642 880
.
- - End Of File - - A9A72F7CBC911EA6D5FF5BEFCB67694D
AdwCleaner
# AdwCleaner v3.205 - Report created 02/05/2014 at 08:36:02
# Updated 28/04/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Tom - TOM-PC
# Running from : C:\Users\Tom\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\smarttweak
Key Deleted : HKCU\Software\AppDataLow\Software\adawarebp
Key Deleted : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v28.0 (cs)
[ File : C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\0ymbjrnc.default\prefs.js ]
-\\ Google Chrome v32.0.1700.102
[ File : C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
Deleted [Search Provider] : hxxp://websearch.toolksearchbook.info/?l=1&q={searchTerms}&pid=1565&r=2014/01/21&hid=16959463485068646480&lg=EN&cc=CZ&unqvl=46
Deleted [Search Provider] : hxxp://anidb.net/perl-bin/animedb.pl?show=animelist&adb.search={searchTerms}&do.search=search
*************************
AdwCleaner[R0].txt - [6903 octets] - [10/04/2014 09:18:25]
AdwCleaner[R1].txt - [1257 octets] - [10/04/2014 09:36:16]
AdwCleaner[R2].txt - [1942 octets] - [02/05/2014 08:32:35]
AdwCleaner[S0].txt - [6603 octets] - [10/04/2014 09:19:17]
AdwCleaner[S1].txt - [1245 octets] - [10/04/2014 09:36:52]
AdwCleaner[S2].txt - [2149 octets] - [02/05/2014 08:36:02]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2209 octets] ##########
Junkware Removal Tool
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Tom on p 02.05.2014 at 8:37:41,05
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files (x86)\smarttweak"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p 02.05.2014 at 8:40:57,48
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~