Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

preventivka / zahadne moc vyuzivanie ramky

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
dex73r
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 13 srp 2011 10:07

preventivka / zahadne moc vyuzivanie ramky

#1 Příspěvek od dex73r »

zdravím, postrehol som jaksi nezvyčajné využívanie ramky a spomalene načítavanie systému windows, počítač je herne zameraný a má 1 rok, vpodstate všetko jedny s najnovších súčiastok, hardwarovo to byt nemoze cize rad by som skontroloval soft stranku :)

RSIT:

Logfile of random's system information tool 1.08 (written by random/random)
Run by Spravca at 2014-06-28 19:08:09
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 152 GB (32%) free of 477 GB
Total RAM: 8189 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:08:12, on 28. 6. 2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Garena Plus\ggdllhost.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\MKJogo\MKLOL\MK.exe
C:\Program Files (x86)\Bloody4\Bloody4\Bloody4.exe
C:\Program Files (x86)\puush\puush.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\PROGRA~2\Raptr\raptr.exe
C:\PROGRA~2\Raptr\raptr_im.exe
C:\GAMES\League of Legends\RADS\system\rads_user_kernel.exe
C:\GAMES\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.211\deploy\LoLLauncher.exe
C:\GAMES\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.98\deploy\LolClient.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Spravca.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Microsoft Web Test Recorder 12.0 Helper - {432dd630-7e03-4c97-9d62-b99f52df4fc2} - C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: FlashGetBHO - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\Spravca\AppData\Roaming\FlashGetBHO\FlashGetBHO.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [MKLOL] "C:\Program Files (x86)\MKJogo\MKLOL\MK.exe" -auto
O4 - HKCU\..\Run: [Bloody2] "C:\Program Files (x86)\Bloody4\Bloody4\Bloody4.exe" Minimum
O4 - HKCU\..\Run: [puush] C:\Program Files (x86)\puush\puush.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Spravca\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Google Update] "C:\Users\Spravca\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: AutorunsDisabled
O8 - Extra context menu item: Download all links by FlashGet3 - C:\Program Files (x86)\FlashGet Network\FlashGet 3\BHO\fdgetallurl.htm
O8 - Extra context menu item: Download all videos by FlashGet3 - C:\Program Files (x86)\FlashGet Network\FlashGet 3\BHO\fdgetallflvurl.htm
O8 - Extra context menu item: Download by FlashGet3 - C:\Program Files (x86)\FlashGet Network\FlashGet 3\BHO\fdgeturl.htm
O8 - Extra context menu item: Download current video by FlashGet3 - C:\Program Files (x86)\FlashGet Network\FlashGet 3\BHO\fdgetflvurl.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: WSISAllmytubechrome - (no CLSID) - (no file)
O18 - Filter: AutorunsDisabled - (no CLSID) - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: @%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000 (c2wts) - Unknown owner - C:\Program Files (x86)\Windows Identity Foundation\v3.5\c2wtshost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - C:\Users\Spravca\Downloads\xampp-win32-1.7.7-VC9\xampp\filezillaftp\filezillaserver.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files (x86)\WinPcap\rpcapd.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: SoftEther VPN Client (SEVPNCLIENT) - SoftEther VPN Project at University of Tsukuba, Japan. - C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13488 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\Sandboxie\SbieSvc.exe"
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe" /service
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 0b0cd3cd-90d5-4349-81d6-c43e67a747fa 1
\??\C:\Windows\system32\conhost.exe "-15181377-160402138-151535066300127214-846228860-1916735838-146221439698164514
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
"taskhost.exe"
\??\C:\Windows\system32\conhost.exe "1064040782-2062417215114921244913682178471123139000286025390831637136-552119875
taskeng.exe {8EFE9354-49DC-4075-BB10-526237CCB294}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Garena Plus\ggdllhost.exe" "C:\Program Files (x86)\Garena Plus\ggspawn.dll",rundll_entry
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
WLIDSvcM.exe 3016
"C:\Program Files (x86)\MKJogo\MKLOL\MK.exe" -auto
"C:\Program Files (x86)\Bloody4\Bloody4\Bloody4.exe" Minimum
"C:\Program Files (x86)\puush\puush.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\PROGRA~2\Raptr\raptr.exe" --log_to_file --from_stub --startup
raptr_im.exe
"C:\GAMES\League of Legends\RADS\system\rads_user_kernel.exe" updateandrun lol_launcher LoLLauncher.exe
LoLLauncher.exe
"C:\Program Files (x86)\Raptr\raptr_ep64.exe"
"C:/GAMES/League of Legends/RADS/projects/lol_air_client/releases/0.0.1.98/deploy/LolClient.exe" -runtime .\ -nodebug META-INF\AIR\application.xml .\ -- 8393
"taskhost.exe"
"C:\Windows\System32\taskmgr.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-b2f14404-d691-4637-abd9-d98abbd0d15a -SystemEventPortName:HostProcess-d71600b2-b0e0-4d54-ae83-dd0315b51d76 -IoCancelEventPortName:HostProcess-0021da6f-a307-4796-ae0b-4423e89e0ab1 -NonStateChangingEventPortName:HostProcess-35dbe768-c2b2-46df-bb1a-1fdfde2bbbd4 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:4343238b-6d3c-453e-972d-e997dc06be9d -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6116.0.773333621\177730499" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,15,39 --gpu-vendor-id=0x10de --gpu-device-id=0x11c0 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.3523 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.1.1686314636\898414288" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.2.1151322329\1691440451" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.3.1279492898\616320333" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.4.33158240\732329826" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/StandardR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.6.151228841\1018665137" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/StandardR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.7.85524365\2099139982" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/StandardR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.8.345757288\1690657752" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/StandardR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.9.1267679209\456224044" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/StandardR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.10.1412548262\1652825864" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll" --lang=sk --channel="6116.11.1074125539\930410636" /prefetch:-390060480
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/StandardR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.14.2029350479\442877218" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/StandardR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.16.243544675\618279153" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/StandardR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.17.997683658\625988868" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/StandardR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.18.427884915\1667651381" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe35_ Global\UsGthrCtrlFltPipeMssGthrPipe35 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/StandardR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="6116.20.91757697\433828730" /prefetch:673131151
"c:\program files\windows defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey C51B9D61-1B21-A276-AE43-38BED887A46D -Reinvoke
"C:\Users\Spravca\Downloads\RSITx64 (1).exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-144053010-3787646527-420655005-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-144053010-3787646527-420655005-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore1ceedc418d475d7.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA1cf4ca01724a1df.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA1cf8b2bd9c707d.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-144053010-3787646527-420655005-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-144053010-3787646527-420655005-1000UA1cf8c48b749628.job
C:\Windows\tasks\update-S-1-5-21-144053010-3787646527-420655005-1000.job
C:\Windows\tasks\update-sys.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-17 551840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-03-21 6270336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-17 209824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2013-10-08 515848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{432dd630-7e03-4c97-9d62-b99f52df4fc2}]
Microsoft Web Test Recorder 12.0 Helper - C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2013-08-27 71432]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-18 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05 339872]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-03-21 4502400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0}]
FlashGetBHO - C:\Users\Spravca\AppData\Roaming\FlashGetBHO\FlashGetBHO.dll [2012-11-01 149168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-12-18 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05 339872]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2013-10-08 448776]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05 339872]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-10-17 13307496]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2012-11-26 6325936]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-04-02 2201032]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-04-02 1225920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MKLOL"=C:\Program Files (x86)\MKJogo\MKLOL\MK.exe [2014-06-05 1227976]
"Bloody2"=C:\Program Files (x86)\Bloody4\Bloody4\Bloody4.exe [2013-08-30 11895808]
"puush"=C:\Program Files (x86)\puush\puush.exe [2013-12-28 567880]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-05-08 21444224]
"Raptr"=C:\PROGRA~2\Raptr\raptrstub.exe [2014-05-15 55360]
"uTorrent"=C:\Users\Spravca\AppData\Roaming\uTorrent\uTorrent.exe [2014-06-23 1271376]
"Google Update"=C:\Users\Spravca\AppData\Local\Google\Update\GoogleUpdate.exe [2014-04-07 116648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2011-09-05 2904984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [2011-09-05 36760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent]
C:\Program Files (x86)\BlueStacks\HD-Agent.exe [2013-12-20 807696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dargon]
C:\Dargon\DargonD.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DelaypluginInstall]
C:\ProgramData\iSkysoft\iTube Studio\DelayPluginI.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dxtory Update Checker 2.0]
C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM]
C:\Program Files (x86)\Origin\Origin.exe [2014-06-22 3595608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Spravca\AppData\Local\Google\Update\GoogleUpdate.exe [2014-04-07 116648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iSkysoft Helper Compact.exe]
C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2014-06-23 3816272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\puush]
C:\Program Files (x86)\puush\puush.exe [2013-12-28 567880]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
C:\Program Files\Sandboxie\SbieCtrl.exe [2012-08-25 765200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShadowPlay]
C:\Windows\system32\nvspcap64.dll [2014-04-02 1225920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoftEther VPN Client UI Helper]
C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [2014-03-10 4298808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]
C:\Users\Spravca\AppData\Roaming\Spotify\Spotify.exe [2014-04-11 6087224]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]
C:\Users\Spravca\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-04-11 1171000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files (x86)\uTorrent\uTorrent.exe [2012-11-15 968592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GIGABYTE OC_GURU.lnk]
C:\PROGRA~2\GIGABYTE\GIGABY~1\OC_GURU.exe [2014-03-31 23318528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^LOLRecorder.lnk]
C:\PROGRA~2\LOLREP~1\LOLREC~1.EXE [2013-12-11 526848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SoftEther VPN Client Manager Startup.lnk]
C:\PROGRA~1\SOFTET~1\VPNCMG~1.EXE [2014-03-10 4489784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Spravca^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk]
C:\Users\Spravca\AppData\Local\Facebook\MESSEN~1\214814~1.0\FACEBO~1.EXE [2013-03-07 248240]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
""= []
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2014-01-17 421888]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2014-06-23 3816272]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AutorunsDisabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HideSCAHealth"=1
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"

======List of files/folders created in the last 1 months======

2014-06-25 09:23:00 ----A---- C:\Windows\system32\wups2.dll
2014-06-25 09:23:00 ----A---- C:\Windows\system32\wucltux.dll
2014-06-25 09:23:00 ----A---- C:\Windows\system32\wuaueng.dll
2014-06-25 09:23:00 ----A---- C:\Windows\system32\wuauclt.exe
2014-06-25 09:22:52 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-06-25 09:22:52 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-06-25 09:22:52 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-06-25 09:22:52 ----A---- C:\Windows\system32\wups.dll
2014-06-25 09:22:52 ----A---- C:\Windows\system32\wudriver.dll
2014-06-25 09:22:52 ----A---- C:\Windows\system32\wuapi.dll
2014-06-25 09:22:12 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-06-25 09:22:12 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-06-25 09:22:12 ----A---- C:\Windows\system32\wuwebv.dll
2014-06-25 09:22:12 ----A---- C:\Windows\system32\wuapp.exe
2014-06-24 19:06:36 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2014-06-22 21:08:42 ----D---- C:\Program Files (x86)\ReflexiveArcade
2014-06-20 22:22:51 ----D---- C:\Users\Spravca\AppData\Roaming\NoNameScript
2014-06-19 20:24:43 ----D---- C:\Windows\SYSWOW64\GPBAK
2014-06-19 20:24:43 ----A---- C:\Windows\SYSWOW64\gpedit.msc
2014-06-19 20:24:43 ----A---- C:\Windows\SYSWOW64\appmgr.dll
2014-06-19 20:24:37 ----A---- C:\Windows\unins000.exe
2014-06-15 08:39:21 ----D---- C:\Users\Spravca\AppData\Roaming\Apple Computer
2014-06-14 23:59:03 ----D---- C:\ProgramData\Apple Computer
2014-06-14 23:59:03 ----D---- C:\Program Files (x86)\QuickTime
2014-06-14 23:58:01 ----D---- C:\ProgramData\Apple
2014-06-14 23:58:01 ----D---- C:\Program Files (x86)\Apple Software Update
2014-06-12 14:29:52 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-06-12 14:29:52 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-06-12 14:29:52 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-06-12 14:29:52 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-06-12 14:29:52 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-06-12 14:29:52 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-06-12 14:29:51 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-06-12 14:29:51 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-06-12 14:29:51 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-06-12 14:29:51 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 14:29:50 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-06-12 14:29:50 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-06-12 14:29:50 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-06-12 14:29:50 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-06-12 14:29:50 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-06-12 14:29:50 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-06-12 14:29:50 ----A---- C:\Windows\system32\urlmon.dll
2014-06-12 14:29:50 ----A---- C:\Windows\system32\msfeeds.dll
2014-06-12 14:29:50 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-06-12 14:29:50 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-06-12 14:29:50 ----A---- C:\Windows\system32\dxtmsft.dll
2014-06-12 14:29:49 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-06-12 14:29:49 ----A---- C:\Windows\system32\iesetup.dll
2014-06-12 14:29:49 ----A---- C:\Windows\system32\ie4uinit.exe
2014-06-12 14:29:48 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-06-12 14:29:48 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-06-12 14:29:48 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-06-12 14:29:48 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-06-12 14:29:48 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-06-12 14:29:48 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-06-12 14:29:48 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-06-12 14:29:48 ----A---- C:\Windows\system32\jsproxy.dll
2014-06-12 14:29:48 ----A---- C:\Windows\system32\iertutil.dll
2014-06-12 14:29:48 ----A---- C:\Windows\system32\iernonce.dll
2014-06-12 14:29:47 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-06-12 14:29:47 ----A---- C:\Windows\system32\mshtmled.dll
2014-06-12 14:29:47 ----A---- C:\Windows\system32\ieUnatt.exe
2014-06-12 14:29:47 ----A---- C:\Windows\system32\ieui.dll
2014-06-12 14:29:47 ----A---- C:\Windows\system32\ieframe.dll
2014-06-12 14:29:47 ----A---- C:\Windows\system32\dxtrans.dll
2014-06-12 14:29:46 ----A---- C:\Windows\system32\wininet.dll
2014-06-12 14:29:46 ----A---- C:\Windows\system32\vbscript.dll
2014-06-12 14:29:46 ----A---- C:\Windows\system32\msrating.dll
2014-06-12 14:29:46 ----A---- C:\Windows\system32\jscript9diag.dll
2014-06-12 14:29:46 ----A---- C:\Windows\system32\jscript9.dll
2014-06-12 14:29:46 ----A---- C:\Windows\system32\ieapfltr.dll
2014-06-12 14:29:45 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-12 14:29:45 ----A---- C:\Windows\system32\mshtml.dll
2014-06-12 14:28:02 ----A---- C:\Windows\SYSWOW64\usp10.dll
2014-06-12 14:28:02 ----A---- C:\Windows\system32\usp10.dll
2014-06-12 14:28:01 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-06-12 14:28:01 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-06-12 14:27:59 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2014-06-12 14:27:59 ----A---- C:\Windows\system32\msxml6.dll
2014-06-12 14:27:59 ----A---- C:\Windows\system32\msxml3.dll
2014-06-12 14:27:58 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2014-06-12 14:27:58 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-06-12 14:27:58 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-06-12 14:27:58 ----A---- C:\Windows\system32\msxml6r.dll
2014-06-12 14:27:58 ----A---- C:\Windows\system32\msxml3r.dll
2014-06-12 14:22:56 ----A---- C:\Windows\system32\aepdu.dll
2014-06-12 14:22:56 ----A---- C:\Windows\system32\aeinv.dll
2014-06-11 17:55:29 ----D---- C:\Program Files (x86)\Garena Plus
2014-06-10 17:05:22 ----D---- C:\Program Files (x86)\MediaHuman
2014-06-10 17:02:03 ----D---- C:\Program Files\WinPcap
2014-06-10 17:01:51 ----D---- C:\ProgramData\Freemake
2014-06-10 17:01:41 ----D---- C:\Program Files (x86)\Freemake
2014-06-10 14:24:15 ----D---- C:\TMPIk
2014-06-02 16:54:30 ----D---- C:\Program Files\Common Files\iSkysoft
2014-06-02 16:54:19 ----A---- C:\Windows\system32\drivers\VirtualAudio.sys
2014-06-02 16:54:12 ----D---- C:\ProgramData\iSkysoft iTube Studio
2014-06-02 16:54:11 ----D---- C:\ProgramData\iSkysoft Application Common Data
2014-06-02 16:54:11 ----D---- C:\Program Files (x86)\iSkysoft
2014-06-02 13:37:49 ----D---- C:\Program Files (x86)\4KDownload
2014-06-02 07:02:27 ----D---- C:\ProgramData\IDM
2014-06-02 07:02:26 ----D---- C:\Users\Spravca\AppData\Roaming\DMCache
2014-06-02 06:58:35 ----D---- C:\Users\Spravca\AppData\Roaming\DVDVideoSoft
2014-06-01 15:30:57 ----D---- C:\Users\Spravca\AppData\Roaming\library_dir
2014-06-01 15:30:44 ----D---- C:\Users\Spravca\AppData\Roaming\Raptr
2014-06-01 15:30:44 ----D---- C:\Program Files (x86)\Raptr
2014-05-31 15:52:01 ----D---- C:\plugdj
2014-05-31 15:48:21 ----D---- C:\Users\Spravca\AppData\Roaming\npm-cache
2014-05-31 15:48:21 ----D---- C:\Users\Spravca\AppData\Roaming\npm
2014-05-31 15:46:49 ----D---- C:\Program Files\nodejs
2014-05-30 15:12:19 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2014-05-30 15:06:45 ----D---- C:\ProgramData\EA Logs
2014-05-30 15:06:45 ----D---- C:\ProgramData\EA Core
2014-05-30 06:21:46 ----D---- C:\Program Files (x86)\Origin Games
2014-05-30 06:20:54 ----D---- C:\Users\Spravca\AppData\Roaming\Origin
2014-05-30 06:17:56 ----D---- C:\ProgramData\Origin
2014-05-30 06:17:54 ----D---- C:\ProgramData\Electronic Arts
2014-05-30 06:17:53 ----D---- C:\Program Files (x86)\Origin

======List of files/folders modified in the last 1 months======

2014-06-28 19:08:12 ----D---- C:\Windows\Prefetch
2014-06-28 19:08:11 ----D---- C:\Windows\temp
2014-06-28 19:08:10 ----D---- C:\Program Files\trend micro
2014-06-28 19:07:01 ----D---- C:\Program Files\SoftEther VPN Client
2014-06-28 19:03:14 ----D---- C:\Users\Spravca\AppData\Roaming\Skype
2014-06-28 19:02:57 ----D---- C:\Users\Spravca\AppData\Roaming\uTorrent
2014-06-28 18:52:07 ----D---- C:\Users\Spravca\AppData\Roaming\TS3Client
2014-06-28 18:51:45 ----D---- C:\Program Files (x86)\Steam
2014-06-28 11:16:23 ----D---- C:\Windows\system32\config
2014-06-28 11:01:42 ----D---- C:\Windows\system32\Tasks
2014-06-28 11:01:11 ----D---- C:\ProgramData\NVIDIA
2014-06-28 03:12:02 ----D---- C:\ProgramData\PMB Files
2014-06-27 12:43:12 ----D---- C:\Users\Spravca\AppData\Roaming\.minecraft
2014-06-27 08:28:46 ----D---- C:\Windows\rescache
2014-06-26 09:10:11 ----D---- C:\Windows\winsxs
2014-06-26 09:09:20 ----D---- C:\Windows\SYSWOW64\sk-SK
2014-06-26 09:09:20 ----D---- C:\Windows\SysWOW64
2014-06-26 09:09:20 ----D---- C:\Windows\system32\sk-SK
2014-06-26 09:09:20 ----D---- C:\Windows\System32
2014-06-25 09:27:12 ----SHD---- C:\System Volume Information
2014-06-25 09:23:07 ----D---- C:\Windows\system32\catroot
2014-06-24 19:07:21 ----SHD---- C:\Windows\Installer
2014-06-24 19:06:36 ----RD---- C:\Program Files (x86)
2014-06-24 12:47:47 ----D---- C:\TeamSpeak 3 Client
2014-06-24 06:03:28 ----D---- C:\Windows\system32\catroot2
2014-06-23 17:49:13 ----D---- C:\ProgramData\GarenaMessenger
2014-06-23 17:49:12 ----D---- C:\Users\Spravca\AppData\Roaming\GarenaPlus
2014-06-23 06:18:56 ----D---- C:\Program Files (x86)\uTorrent
2014-06-22 21:08:54 ----D---- C:\GAMES
2014-06-22 17:38:00 ----D---- C:\Windows\inf
2014-06-22 17:38:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-06-22 13:04:01 ----D---- C:\Program Files (x86)\OBS
2014-06-20 22:23:32 ----D---- C:\Program Files (x86)\mIRC
2014-06-20 22:23:02 ----D---- C:\Users\Spravca\AppData\Roaming\mIRC
2014-06-20 15:54:05 ----D---- C:\Users\Spravca\AppData\Roaming\vlc
2014-06-20 07:25:27 ----D---- C:\Windows\Tasks
2014-06-19 20:32:13 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2014-06-19 20:28:12 ----HD---- C:\Windows\system32\GroupPolicy
2014-06-19 20:24:37 ----D---- C:\Windows
2014-06-19 20:17:33 ----D---- C:\Windows\PolicyDefinitions
2014-06-15 15:41:57 ----SD---- C:\Users\Spravca\AppData\Roaming\Microsoft
2014-06-14 23:59:45 ----D---- C:\Program Files\Internet Explorer
2014-06-14 23:59:03 ----D---- C:\ProgramData
2014-06-14 23:58:11 ----D---- C:\Program Files (x86)\Common Files
2014-06-13 06:10:07 ----D---- C:\Windows\system32\drivers
2014-06-13 06:10:05 ----D---- C:\Windows\SYSWOW64\en-US
2014-06-13 06:10:04 ----D---- C:\Windows\system32\en-US
2014-06-13 06:10:04 ----D---- C:\Program Files (x86)\Internet Explorer
2014-06-13 06:09:59 ----D---- C:\Windows\system32\DriverStore
2014-06-13 00:38:52 ----D---- C:\Windows\system32\MRT
2014-06-13 00:36:31 ----A---- C:\Windows\system32\MRT.exe
2014-06-13 00:36:25 ----D---- C:\ProgramData\Microsoft Help
2014-06-13 00:34:49 ----SD---- C:\Windows\system32\CompatTel
2014-06-10 17:02:03 ----RD---- C:\Program Files
2014-06-10 17:01:23 ----RSD---- C:\Windows\assembly
2014-06-10 16:57:13 ----A---- C:\Windows\Sandboxie.ini
2014-06-09 15:24:53 ----D---- C:\Users\Spravca\AppData\Roaming\Mozilla
2014-06-09 11:56:55 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-06-09 11:56:54 ----RD---- C:\Program Files (x86)\Skype
2014-06-09 11:56:47 ----D---- C:\ProgramData\Skype
2014-06-04 19:38:11 ----D---- C:\Users\Spravca\AppData\Roaming\Spotify
2014-06-02 21:08:32 ----D---- C:\LOLHT Configs v2
2014-06-02 21:03:49 ----D---- C:\Program Files (x86)\XZONE REACTOR Application
2014-06-02 17:17:20 ----D---- C:\Windows\pss
2014-06-02 16:54:30 ----D---- C:\Program Files\Common Files
2014-06-01 12:41:48 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2014-05-31 18:29:12 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2014-05-31 17:56:12 ----D---- C:\Users\Spravca\AppData\Roaming\TeamViewer
2014-05-29 23:16:33 ----D---- C:\Windows\system32\drivers\etc

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2012-11-28 57904]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2011-11-02 21616]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2012-10-08 211344]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2012-10-08 149592]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2012-10-08 59440]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2012-08-24 126944]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2013-09-06 238352]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2013-09-06 119056]
R2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2013-12-20 114448]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2012-10-08 189208]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2013-04-30 72216]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2011-02-11 35344]
R3 AR9271;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athuwx.sys [2011-07-28 2224160]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver; C:\Windows\System32\Drivers\EtronHub3.sys [2011-07-29 56960]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver; C:\Windows\System32\Drivers\EtronXHCI.sys [2011-07-29 79104]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM); C:\Windows\system32\DRIVERS\vrtaucbl.sys [2014-01-11 108960]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-10-18 2957544]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2013-04-30 11552]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2012-12-14 24176]
R3 Neo_VPN;VPN Client Device Driver - VPN; C:\Windows\system32\DRIVERS\Neo_0062.sys [2014-03-10 28768]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2013-11-28 197408]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-03-21 40392]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-08-23 565352]
R3 SbieDrv;SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [2012-08-25 202632]
R3 SEE;SoftEther Ethernet Layer Driver; C:\Windows\system32\drivers\see.sys [2014-03-10 38240]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2013-09-06 131856]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2013-09-06 146704]
S2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys []
S3 GPCIDrv;GPCIDrv; \??\C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [2014-01-08 14376]
S3 PBDOWNFORCE_SERVICE;PBDOWNFORCE_SERVICE; \??\C:\Users\Spravca\Downloads\Hacking\------------------ Cs 1.6 --------------\PBDownForce v0.2\PBDownForce v0.2\PBDownforce.sys [2006-05-13 20480]
S3 PBDOWNFORCE_TEST_SERVICE;PBDOWNFORCE_TEST_SERVICE; \??\C:\Users\Spravca\Downloads\Hacking\------------------ Cs 1.6 --------------\PBDownForce0.2BETA\Test.sys [2006-05-13 10240]
S3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976]
S3 tap0901;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-02-08 36736]
S3 taphss6;Anchorfree HSS VPN Adapter; C:\Windows\system32\DRIVERS\taphss6.sys [2013-01-10 42184]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S4 ALSysIO;ALSysIO; \??\C:\Users\Spravca\AppData\Local\Temp\ALSysIO64.sys []
S4 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S4 cpuz136;cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys []
S4 FairplayKD;FairplayKD; \??\C:\ProgramData\MTA San Andreas All\1.3\temp\FairplayKD.sys []
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []
S4 vmci;VMware VMCI Bus Driver; C:\Windows\system32\DRIVERS\vmci.sys []
S4 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [2013-12-20 385808]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-04-11 1390720]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-04-11 1764992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2012-11-26 1329304]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2014-06-23 2524496]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [2014-04-15 377616]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-04-02 1615192]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-04-02 20541216]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-03-04 922968]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-05-31 76888]
R2 SbieSvc;Sandboxie Service; C:\Program Files\Sandboxie\SbieSvc.exe [2012-08-25 123664]
R2 SEVPNCLIENT;SoftEther VPN Client; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [2014-03-10 4298808]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-03-04 411936]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-04-25 5024576]
R2 wlidsvc;Windows Live ID Sign-in Assistant; c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files (x86)\BlueStacks\HD-Service.exe [2013-12-20 402192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-14 116648]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 c2wts;@%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [2010-02-03 15768]
S3 FileZilla Server;FileZilla Server FTP server; C:\Users\Spravca\Downloads\xampp-win32-1.7.7-VC9\xampp\filezillaftp\filezillaserver.exe []
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [2013-08-22 142336]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-14 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-05-30 111616]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files (x86)\WinPcap\rpcapd.exe -d -f C:\Program Files (x86)\WinPcap\rpcapd.ini []
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-01-27 571816]
S3 SwitchBoard;Adobe SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2013-08-22 119808]
S3 TunngleService;TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2013-08-16 757144]
S3 VsEtwService120;Visual Studio ETW Event Collection Service; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [2013-10-05 87728]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-11-14 1255736]
S4 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S4 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-05-03 115608]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [2007-12-13 447784]
S4 Secunia PSI Agent;Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [2012-11-26 1225312]
S4 Secunia Update Agent;Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [2012-11-26 659040]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka / zahadne moc vyuzivanie ramky

#2 Příspěvek od Márty84 »

Zdravim :)

:???: Vidim tam MBAM. Nasel neco pri kompletni kontrole?

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

dex73r
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 13 srp 2011 10:07

Re: preventivka / zahadne moc vyuzivanie ramky

#3 Příspěvek od dex73r »

# AdwCleaner v3.213 - Report created 29/06/2014 at 00:42:48
# Updated 23/06/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Spravca - SPRAVCA-PC
# Running from : C:\Users\Spravca\Downloads\adwcleaner_3.213.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\Skillbrains
Folder Deleted : C:\Users\Spravca\AppData\Local\Skillbrains
File Deleted : C:\Windows\Tasks\update-sys.job
File Deleted : C:\Windows\System32\Tasks\update-sys

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\Spravca\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\e394472a2df76cd2\[DefaultBox] Winamp.lnk

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2974C985-8151-4DE5-B23C-B875F0A8522F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E69D4A59-73DE-4E38-9FB3-740EC4D9060D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2974C985-8151-4DE5-B23C-B875F0A8522F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\anchorfree
Key Deleted : HKCU\Software\SkillBrains
Key Deleted : HKLM\Software\SkillBrains
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IM

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17126


-\\ Mozilla Firefox v20.0.1 (en-US)

[ File : C:\Users\Spravca\AppData\Roaming\Mozilla\Firefox\Profiles\gdha1i0b.default\prefs.js ]


-\\ Google Chrome v35.0.1916.153

[ File : C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Extension] : klaecimjlbpfompicealiiifcdjnkbpn

*************************

AdwCleaner[R0].txt - [2566 octets] - [29/06/2014 00:40:28]
AdwCleaner[S0].txt - [2373 octets] - [29/06/2014 00:42:48]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2433 octets] ##########


MBAM si teraz robí srandu, nechce sa mi ani spustiť :roll:

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka / zahadne moc vyuzivanie ramky

#4 Příspěvek od Márty84 »

dex73r píše:MBAM si teraz robí srandu, nechce sa mi ani spustiť :roll:
:arrow: Odinstalujte jej a pouzijte jejich cistic http://www.malwarebytes.org/mbam-clean.exe

:arrow: Pak stahnete a nainstalujte aktualni verzi a provedte novou kontrolu podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=29&t=137928
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

dex73r
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 13 srp 2011 10:07

Re: preventivka / zahadne moc vyuzivanie ramky

#5 Příspěvek od dex73r »

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 1. 7. 2014
Scan Time: 17:52:45
Logfile: dasd.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.07.01.05
Rootkit Database: v2014.07.01.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Spravca

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 444663
Time Elapsed: 13 min, 44 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 12
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\content_scripts, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\reg_syntax, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\_metadata, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],

Files: 182
RiskWare.Tool.CK, C:\Users\Spravca\Documents\celestial.bin, Quarantined, [16432e6cc1ba7fb7a2cbc688fb059967],
PUP.HackTool.Agent, C:\Users\Spravca\Downloads\dirupd1+13tr.rar, Quarantined, [b3a6d3c74c2f44f25f6cb4099f61e51b],
Backdoor.MSIL.P, C:\Users\Spravca\Downloads\BoG-v5.rar, Quarantined, [ff5a68320873c076abc92e5ce41c7c84],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cplklnmnlbnpmjogncfgfijoopmnlemp_0.localstorage, Quarantined, [233667335f1c999daeb58b2e8280629e],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cplklnmnlbnpmjogncfgfijoopmnlemp_0.localstorage-journal, Quarantined, [5108b5e5a9d2f2441a498930907203fd],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\AlertFoxLoginDialog.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\AlertFoxLoginDialog.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\AsyncFileIO.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\badge.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\beforePlay.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\beforePlay.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\bg.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\bg.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\browse.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\browse.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\communicator.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\context.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\extractDialog.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\extractDialog.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\fileView.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\fileView.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\folderView.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\folderView.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\loginDialog.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\loginDialog.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\macroView.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\macroView.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\manifest.json, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\mktree.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\mplayer.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\mrecorder.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\nm_connector.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\npimr.dll, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\options.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\options.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\panel.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\panel.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\passwordDialog.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\passwordDialog.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\rijndael.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\sandbox.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\sandbox.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\SOAPClient.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\treeView.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\treeView.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\utils.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\version.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\content_scripts\bookmarks_handler.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\content_scripts\connector.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\content_scripts\player.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\content_scripts\recorder.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\content_scripts\si_listener.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editor.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editor.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\saveAsDialog.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\saveAsDialog.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\imacro.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\imacro.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\imacro.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\license_apache.txt, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\license_bsd.txt, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\license_lgpl.txt, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\autocompletion.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\edit_area.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\edit_area.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\edit_area_functions.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\edit_area_loader.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\elements_functions.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\highlight.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\keyboard.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\manage_area.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\regexp.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\reg_syntax.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\resize_area.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\search_replace.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\template.html, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\autocompletion.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\close.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\fullscreen.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\go_to_line.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\help.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\highlight.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\load.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\move.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\newdocument.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\opacity.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\processing.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\redo.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\reset_highlight.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\save.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\search.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\smooth_selection.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\spacer.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\statusbar_resize.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\undo.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\images\word_wrap.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\bg.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\cs.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\de.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\dk.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\en.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\eo.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\es.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\fi.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\fr.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\hr.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\it.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\ja.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\mk.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\nl.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\pl.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\pt.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\ru.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\sk.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\langs\zh.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\reg_syntax\imacro.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\editor\editarea\edit_area\reg_syntax\js.js, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\Address.csv, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\ArchivePage.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\Eval.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\Extract.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\ExtractAndFill.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\ExtractRelative.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\ExtractTable.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\ExtractURL.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\FillForm-XPath.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\FillForm.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\Frame.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\Loop-Csv-2-Web.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\Open6Tabs.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\Profiler.xsl, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\SaveAs.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\SlideShow.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\Stopwatch.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\samples\TagPosition.iim, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\folder-up.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\AlertFoxLoginDialog.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\beforePlay.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\browse.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\browse.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\cancel.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\capture.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\close.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\common.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\disk.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\edit-disabled.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\edit.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\editor.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\extractDialog.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\folder-index.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\folderClosed.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\folderOpen.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\help.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\imglog.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\lock.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\loginDialog.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\logo128.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\logo16.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\logo19.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\logo24.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\logo38.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\logo48.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\loop-disabled.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\loop.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\macroView.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\mycomputer.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\ok.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\options.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\panel.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\passwordDialog.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\pause.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\play-disabled.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\play.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\record.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\save.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\saveas.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\saveAsDialog.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\settings.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\stop.png, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\treeView.css, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\skin\waiting_16x16.gif, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.5_0\_metadata\verified_contents.json, Quarantined, [0752c4d6314aac8aaad35e48e022c53b],

Physical Sectors: 0
(No malicious items detected)


(end)



všetko som to rovno aj smazal, poznam všetko čo tam je okrem toho chromu

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka / zahadne moc vyuzivanie ramky

#6 Příspěvek od Márty84 »

Fajn, restartujte pc a zopakujte test, at vime, ze se to nevraci. Ale tentokrat test nastavte podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=29&t=137928 , at prostoura cele disky. Napiste vysledek testu a podle nej zvolim dalsi postup.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

dex73r
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 13 srp 2011 10:07

Re: preventivka / zahadne moc vyuzivanie ramky

#7 Příspěvek od dex73r »

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 2. 7. 2014
Scan Time: 13:31:17
Logfile: dasd.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.07.02.03
Rootkit Database: v2014.07.01.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Spravca

Scan Type: Custom Scan
Result: Completed
Objects Scanned: 2143206
Time Elapsed: 6 hr, 3 min, 16 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 12
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\content_scripts, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\reg_syntax, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\_metadata, Quarantined, [16417228f982b18522e17f28ef132dd3],

Files: 91
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\AlertFoxLoginDialog.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\AlertFoxLoginDialog.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\AsyncFileIO.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\badge.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\beforePlay.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\beforePlay.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\bg.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\bg.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\browse.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\browse.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\communicator.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\context.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\extractDialog.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\extractDialog.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\fileView.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\fileView.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\folderView.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\folderView.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\loginDialog.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\loginDialog.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\macroView.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\macroView.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\manifest.json, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\mktree.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\mplayer.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\mrecorder.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\nm_connector.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\npimr.dll, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\options.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\options.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\panel.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\panel.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\passwordDialog.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\passwordDialog.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\rijndael.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\sandbox.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\sandbox.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\SOAPClient.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\treeView.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\treeView.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\utils.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\version.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\content_scripts\bookmarks_handler.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\content_scripts\connector.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\content_scripts\player.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\content_scripts\recorder.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\content_scripts\si_listener.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editor.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editor.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\saveAsDialog.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\saveAsDialog.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\imacro.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\imacro.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\imacro.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\license_apache.txt, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\license_bsd.txt, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\license_lgpl.txt, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\autocompletion.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\edit_area.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\edit_area.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\edit_area_functions.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\edit_area_loader.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\elements_functions.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\highlight.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\keyboard.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\manage_area.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\regexp.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\reg_syntax.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\resize_area.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\search_replace.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\template.html, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\autocompletion.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\close.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\fullscreen.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\go_to_line.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\help.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\highlight.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\load.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\move.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\newdocument.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\opacity.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\processing.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\redo.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\reset_highlight.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\save.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\search.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\smooth_selection.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\spacer.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\statusbar_resize.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\undo.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\images\word_wrap.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\bg.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\cs.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\de.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\dk.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\en.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\eo.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\es.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\fi.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\fr.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\hr.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\it.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\ja.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\mk.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\nl.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\pl.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\pt.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\ru.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\sk.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\langs\zh.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\reg_syntax\imacro.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\editor\editarea\edit_area\reg_syntax\js.js, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\Address.csv, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\ArchivePage.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\Eval.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\Extract.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\ExtractAndFill.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\ExtractRelative.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\ExtractTable.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\ExtractURL.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\FillForm-XPath.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\FillForm.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\Frame.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\Loop-Csv-2-Web.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\Open6Tabs.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\Profiler.xsl, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\SaveAs.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\SlideShow.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\Stopwatch.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\samples\TagPosition.iim, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\folder-up.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\AlertFoxLoginDialog.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\beforePlay.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\browse.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\browse.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\cancel.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\capture.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\close.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\common.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\disk.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\edit-disabled.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\edit.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\editor.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\extractDialog.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\folder-index.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\folderClosed.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\folderOpen.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\help.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\imglog.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\lock.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\loginDialog.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\logo128.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\logo16.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\logo19.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\logo24.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\logo38.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\logo48.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\loop-disabled.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\loop.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\macroView.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\mycomputer.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\ok.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\options.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\panel.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\passwordDialog.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\pause.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\play-disabled.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\play.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\record.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\save.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\saveas.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\saveAsDialog.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\settings.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\stop.png, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\treeView.css, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\skin\waiting_16x16.gif, Quarantined, [16417228f982b18522e17f28ef132dd3],
PUP.Optional.BestBuy.A, C:\Users\Spravca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\_metadata\verified_contents.json, Quarantined, [16417228f982b18522e17f28ef132dd3],

Physical Sectors: 0
(No malicious items detected)


(end)

:cry:

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka / zahadne moc vyuzivanie ramky

#8 Příspěvek od Márty84 »

:!: Postupujte presne v tomto poradi.
1) Odinstalujte kompletne Chrome (pokud nechcete prijit o zalozky, zazalohujte si je pomoci http://www.stahuj.centrum.cz/internet_a ... me-backup/ )
2) Vymazte/Vypnete vytvareni bodu obnovy http://forum.viry.cz/viewtopic.php?f=46&t=47040 , ale nerestartujte pc.
3) Resratujte pc
4) Udelejte novy test s MBAM a dejte sem vysledky.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

dex73r
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 13 srp 2011 10:07

Re: preventivka / zahadne moc vyuzivanie ramky

#9 Příspěvek od dex73r »

ako prve namňa vyskočilo http://puu.sh/9UpVi/d4955cc93f.jpg :???: idem pokračovať..

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka / zahadne moc vyuzivanie ramky

#10 Příspěvek od Márty84 »

No, mozna ten program nefunguje. Kazdopadne chrome je prolezly a bez odinstalace se te haveti nezbavite.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

dex73r
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 13 srp 2011 10:07

Re: preventivka / zahadne moc vyuzivanie ramky

#11 Příspěvek od dex73r »

dal som skenovať custom scanom c:/Users/Spravca/AppData - hneď je tu výsledok

dex73r
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 13 srp 2011 10:07

Re: preventivka / zahadne moc vyuzivanie ramky

#12 Příspěvek od dex73r »

Malwarebytes Anti-Malware
http://www.malwarebytes.org

Scan Date: 3. 7. 2014
Scan Time: 14:42:41
Logfile: dasd.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.07.03.02
Rootkit Database: v2014.07.01.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Spravca

Scan Type: Custom Scan
Result: Completed
Objects Scanned: 477252
Time Elapsed: 27 min, 20 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 2
Trojan.Agent, C:\Users\Spravca\AppData\Local\Temp\install.exe, , [ce502d6e1665cc6aba6ce4f8b849c53b],
Trojan.Genome, C:\Users\Spravca\AppData\Local\Temp\$inst\17.tmp, , [fd21c7d4f18a79bd06a77a6ade2320e0],

Physical Sectors: 0
(No malicious items detected)


(end)

install.exe https://www.virustotal.com/sk/file/9774 ... 404399851/
17.tmp https://www.virustotal.com/sk/file/0a05 ... 404399926/

nerobil som žiadnu akciu, čakam na radu :roll:

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka / zahadne moc vyuzivanie ramky

#13 Příspěvek od Márty84 »

:arrow: Nalezy samozrejme smazat.

Je zajimave, ze ty nejznamejsi antiviry na virustotal mlci :-D Ale ono hodne zalezi na nastaveni a tam to asi maji v tom tovarnim, kde ta citlivost neni tak velka.



:!: Pokud nemate, zazalohujte si radeji dulezita data (fotky, dokumenty, atd.) :!:

:!: Nepouzivejte ComboFix bez predchozi domluvy! Je to poruseni pravidel fora a ztratite tim narok na pomoc!

:arrow: Stahnete ComboFix http://download.bleepingcomputer.com/sUBs/ComboFix.exe a ulozte ho na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Kliknete na ComboFix pravym mysidlem a levym na Spustit jako spravce
Odsouhlaste licencni podminky a nechte program pracovat. Jestli vam nabidne instalaci Konzoly pro zotaveni, souhlaste.
Po dobu skenu nic nespoustejte, nikam neklikejte.
Po dokonceni skenovani (muze dojit i k restartu pc) by se mel vytvorit log, ktery bude umisteny zde C:\ComboFix.txt
Jeho obsah sem zkopirujte

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni ruznych programu bude hlasena chyba, staci restartovat pc a bude to v poradku
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

dex73r
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 13 srp 2011 10:07

Re: preventivka / zahadne moc vyuzivanie ramky

#14 Příspěvek od dex73r »

ComboFix 14-07-03.01 - Spravca . 07. 2014 20:06:22.3.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.8189.6214 [GMT 2:00]
Running from: c:\users\Spravca\Downloads\ComboFix.exe
AV: ESET Smart Security 6.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 6.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files (x86)\Java\jre7\bin\jp2ssv.dll
C:\text.txt
c:\users\Spravca\AppData\Roaming\mIRC\logs\status.log
c:\users\Spravca\AppData\Roaming\technic-launcher.jar
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\wpcap.dll
c:\windows\TEMP\VPN_8614\48616C33.dll
c:\windows\TEMP\VPN_8614\B7091C83.dll
c:\windows\XSxS
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_npf
.
.
((((((((((((((((((((((((( Files Created from 2014-06-03 to 2014-07-03 )))))))))))))))))))))))))))))))
.
.
2014-07-03 18:20 . 2014-07-03 18:20 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-07-03 18:20 . 2014-07-03 18:20 -------- d-----w- c:\users\Dex\AppData\Local\temp
2014-07-03 18:20 . 2014-07-03 18:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-07-03 00:57 . 2014-07-03 01:02 -------- d-----w- c:\users\Spravca\AppData\Roaming\Google Chrome Backup
2014-07-03 00:57 . 2014-07-03 00:57 -------- d-----w- c:\program files (x86)\Google Chrome Backup
2014-07-01 15:50 . 2014-07-03 18:25 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-07-01 15:50 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-07-01 15:50 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-07-01 15:50 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-07-01 15:50 . 2014-07-01 15:50 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-07-01 15:50 . 2014-07-01 15:50 -------- d-----w- c:\programdata\Malwarebytes
2014-07-01 09:14 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{465E4E9D-2EC8-4299-9FA2-048AC8566688}\mpengine.dll
2014-07-01 01:13 . 2014-07-02 21:02 -------- d-----w- c:\users\Spravca\AppData\Roaming\GameCompanion
2014-06-28 22:40 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-06-28 22:40 . 2014-06-28 22:43 -------- d-----w- C:\AdwCleaner
2014-06-25 07:23 . 2014-05-14 16:23 44512 ----a-w- c:\windows\system32\wups2.dll
2014-06-25 07:23 . 2014-05-14 16:23 58336 ----a-w- c:\windows\system32\wuauclt.exe
2014-06-25 07:23 . 2014-05-14 16:23 2477536 ----a-w- c:\windows\system32\wuaueng.dll
2014-06-25 07:23 . 2014-05-14 16:21 2620928 ----a-w- c:\windows\system32\wucltux.dll
2014-06-25 07:22 . 2014-05-14 16:23 38880 ----a-w- c:\windows\system32\wups.dll
2014-06-25 07:22 . 2014-05-14 16:23 36320 ----a-w- c:\windows\SysWow64\wups.dll
2014-06-25 07:22 . 2014-05-14 16:23 700384 ----a-w- c:\windows\system32\wuapi.dll
2014-06-25 07:22 . 2014-05-14 16:23 581600 ----a-w- c:\windows\SysWow64\wuapi.dll
2014-06-25 07:22 . 2014-05-14 16:20 97792 ----a-w- c:\windows\system32\wudriver.dll
2014-06-25 07:22 . 2014-05-14 16:17 92672 ----a-w- c:\windows\SysWow64\wudriver.dll
2014-06-25 07:22 . 2014-05-14 07:23 198600 ----a-w- c:\windows\system32\wuwebv.dll
2014-06-25 07:22 . 2014-05-14 07:23 179656 ----a-w- c:\windows\SysWow64\wuwebv.dll
2014-06-25 07:22 . 2014-05-14 07:20 36864 ----a-w- c:\windows\system32\wuapp.exe
2014-06-25 07:22 . 2014-05-14 07:17 33792 ----a-w- c:\windows\SysWow64\wuapp.exe
2014-06-24 17:06 . 2014-06-24 17:06 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2014-06-22 19:08 . 2014-06-22 19:08 -------- d-----w- c:\program files (x86)\ReflexiveArcade
2014-06-20 20:22 . 2014-06-20 21:00 -------- d-----w- c:\users\Spravca\AppData\Roaming\NoNameScript
2014-06-19 18:32 . 2014-06-19 18:32 -------- d-----w- c:\users\Spravca\AppData\Local\MediaHuman
2014-06-19 18:24 . 2014-06-19 18:24 -------- d-----w- c:\windows\SysWow64\GPBAK
2014-06-19 18:24 . 2008-04-14 00:11 295936 ----a-w- c:\windows\SysWow64\appmgr.dll
2014-06-19 18:24 . 2014-06-19 18:24 707354 ----a-w- c:\windows\unins000.exe
2014-06-15 06:39 . 2014-06-15 06:39 -------- d-----w- c:\users\Spravca\AppData\Roaming\Apple Computer
2014-06-14 21:59 . 2014-06-14 21:59 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2014-06-14 21:59 . 2014-06-14 21:59 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2014-06-14 21:59 . 2014-06-14 21:59 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2014-06-14 21:59 . 2014-06-14 21:59 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2014-06-14 21:59 . 2014-06-14 21:59 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2014-06-14 21:59 . 2014-06-14 21:59 -------- d-----w- c:\program files (x86)\QuickTime
2014-06-14 21:59 . 2014-06-14 21:59 -------- d-----w- c:\programdata\Apple Computer
2014-06-14 21:58 . 2014-06-14 21:58 -------- d-----w- c:\program files (x86)\Common Files\Apple
2014-06-14 21:58 . 2014-06-14 21:58 -------- d-----w- c:\users\Spravca\AppData\Local\Apple
2014-06-14 21:58 . 2014-06-14 21:58 -------- d-----w- c:\programdata\Apple
2014-06-14 21:58 . 2014-06-14 21:58 -------- d-----w- c:\program files (x86)\Apple Software Update
2014-06-14 19:50 . 2014-06-14 19:50 -------- d-----w- c:\users\Spravca\AppData\Local\Sidas_Script_Manager
2014-06-12 12:28 . 2014-04-25 02:34 801280 ----a-w- c:\windows\system32\usp10.dll
2014-06-12 12:28 . 2014-04-25 02:06 626688 ----a-w- c:\windows\SysWow64\usp10.dll
2014-06-12 12:28 . 2014-04-05 02:47 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-06-12 12:28 . 2014-04-05 02:47 288192 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2014-06-12 12:27 . 2014-03-26 14:44 2002432 ----a-w- c:\windows\system32\msxml6.dll
2014-06-12 12:27 . 2014-03-26 14:44 1882112 ----a-w- c:\windows\system32\msxml3.dll
2014-06-12 12:27 . 2014-03-26 14:27 1389056 ----a-w- c:\windows\SysWow64\msxml6.dll
2014-06-12 12:27 . 2014-03-26 14:41 2048 ----a-w- c:\windows\system32\msxml6r.dll
2014-06-12 12:27 . 2014-03-26 14:41 2048 ----a-w- c:\windows\system32\msxml3r.dll
2014-06-12 12:27 . 2014-03-26 14:27 1237504 ----a-w- c:\windows\SysWow64\msxml3.dll
2014-06-12 12:27 . 2014-03-26 14:25 2048 ----a-w- c:\windows\SysWow64\msxml6r.dll
2014-06-12 12:27 . 2014-03-26 14:25 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2014-06-12 12:22 . 2014-06-08 09:13 506368 ----a-w- c:\windows\system32\aepdu.dll
2014-06-12 12:22 . 2014-06-08 09:08 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-06-11 15:55 . 2014-06-11 15:55 -------- d-----w- c:\program files (x86)\Garena Plus
2014-06-10 15:05 . 2014-06-10 15:05 -------- d-----w- c:\program files (x86)\MediaHuman
2014-06-10 15:02 . 2014-06-10 15:02 -------- d-----w- c:\program files\WinPcap
2014-06-10 15:01 . 2014-06-10 15:09 -------- d-----w- c:\programdata\Freemake
2014-06-10 15:01 . 2014-06-10 15:07 -------- d-----w- c:\program files (x86)\Freemake
2014-06-10 12:24 . 2014-06-10 12:24 -------- d-----w- C:\TMPIk
2014-06-09 09:56 . 2014-06-09 09:56 -------- d-----w- c:\program files (x86)\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-12 22:36 . 2012-11-14 16:41 95414520 ----a-w- c:\windows\system32\MRT.exe
2014-06-01 10:41 . 2012-11-20 12:28 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-06-01 10:41 . 2012-11-20 12:26 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-06-01 08:52 . 2012-11-20 12:26 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-05-31 16:29 . 2012-11-20 12:26 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-04-12 02:22 . 2014-05-13 23:59 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-04-12 02:22 . 2014-05-13 23:59 155072 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 02:19 . 2014-05-13 23:59 29184 ----a-w- c:\windows\system32\sspisrv.dll
2014-04-12 02:19 . 2014-05-13 23:59 136192 ----a-w- c:\windows\system32\sspicli.dll
2014-04-12 02:19 . 2014-05-13 23:59 28160 ----a-w- c:\windows\system32\secur32.dll
2014-04-12 02:19 . 2014-05-13 23:59 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2014-04-12 02:19 . 2014-05-13 23:59 31232 ----a-w- c:\windows\system32\lsass.exe
2014-04-12 02:12 . 2014-05-13 23:59 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-04-12 02:10 . 2014-05-13 23:59 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2013-01-19 07:44 . 2013-01-19 07:44 2174976 ----a-w- c:\program files (x86)\Common Files\atimpenc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MKLOL"="c:\program files (x86)\MKJogo\MKLOL\MK.exe" [2014-06-05 1227976]
"Bloody2"="c:\program files (x86)\Bloody4\Bloody4\Bloody4.exe" [2013-08-30 11895808]
"puush"="c:\program files (x86)\puush\puush.exe" [2013-12-28 567880]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-05-08 21444224]
"Raptr"="c:\progra~2\Raptr\raptrstub.exe" [2014-05-14 55360]
"uTorrent"="c:\users\Spravca\AppData\Roaming\uTorrent\uTorrent.exe" [2014-07-03 1322832]
"GameCompanion"="c:\users\Spravca\AppData\Roaming\GameCompanion\GameCompanion.exe" [2013-10-12 484408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-01-17 421888]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-06-23 3816272]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled\
LOLRecorder.lnk - c:\program files (x86)\LOLReplay\LOLRecorder.exe -minimize [2013-12-11 526848]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
.
R2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 c2wts;Claims to Windows Token Service;c:\program files\Windows Identity Foundation\v3.5\c2wtshost.exe;c:\program files\Windows Identity Foundation\v3.5\c2wtshost.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 GPCIDrv;GPCIDrv;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 PBDOWNFORCE_SERVICE;PBDOWNFORCE_SERVICE;c:\users\Spravca\Downloads\Hacking\------------------ Cs 1.6 --------------\PBDownForce v0.2\PBDownForce v0.2\PBDownforce.sys;c:\users\Spravca\Downloads\Hacking\------------------ Cs 1.6 --------------\PBDownForce v0.2\PBDownForce v0.2\PBDownforce.sys [x]
R3 PBDOWNFORCE_TEST_SERVICE;PBDOWNFORCE_TEST_SERVICE;c:\users\Spravca\Downloads\Hacking\------------------ Cs 1.6 --------------\PBDownForce0.2BETA\Test.sys;c:\users\Spravca\Downloads\Hacking\------------------ Cs 1.6 --------------\PBDownForce0.2BETA\Test.sys [x]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf.sys [x]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe;c:\program files (x86)\Tunngle\TnglCtrl.exe [x]
R3 VsEtwService120;Visual Studio ETW Event Collection Service;c:\program files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe;c:\program files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WsAudio_Device;WsAudio_Device;c:\windows\system32\drivers\VirtualAudio.sys;c:\windows\SYSNATIVE\drivers\VirtualAudio.sys [x]
R4 ALSysIO;ALSysIO;c:\users\Spravca\AppData\Local\Temp\ALSysIO64.sys;c:\users\Spravca\AppData\Local\Temp\ALSysIO64.sys [x]
R4 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R4 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
R4 FairplayKD;FairplayKD;c:\programdata\MTA San Andreas All\1.3\temp\FairplayKD.sys;c:\programdata\MTA San Andreas All\1.3\temp\FairplayKD.sys [x]
R4 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe [x]
R4 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe;c:\program files (x86)\Secunia\PSI\sua.exe [x]
R4 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files (x86)\CyberLink\PowerDVD8\000.fcl;c:\program files (x86)\CyberLink\PowerDVD8\000.fcl [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 SEVPNCLIENT;SoftEther VPN Client;c:\program files\SoftEther VPN Client\vpnclient_x64.exe;c:\program files\SoftEther VPN Client\vpnclient_x64.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S3 AR9271;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athuwx.sys;c:\windows\SYSNATIVE\DRIVERS\athuwx.sys [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 Neo_VPN;VPN Client Device Driver - VPN;c:\windows\system32\DRIVERS\Neo_0062.sys;c:\windows\SYSNATIVE\DRIVERS\Neo_0062.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SEE;SoftEther Ethernet Layer Driver;c:\windows\system32\drivers\see.sys;c:\windows\SYSNATIVE\drivers\see.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MBAMSWISSARMY
.
Contents of the 'Scheduled Tasks' folder
.
2013-07-26 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-144053010-3787646527-420655005-1000Core.job
- c:\users\Spravca\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-04-22 20:19]
.
2013-07-26 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-144053010-3787646527-420655005-1000UA.job
- c:\users\Spravca\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-04-22 20:19]
.
2014-06-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-144053010-3787646527-420655005-1000Core.job
- c:\users\Spravca\AppData\Local\Google\Update\GoogleUpdate.exe [2014-04-07 15:13]
.
2014-07-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-144053010-3787646527-420655005-1000UA1cf8c48b749628.job
- c:\users\Spravca\AppData\Local\Google\Update\GoogleUpdate.exe [2014-04-07 15:13]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-11-26 6325936]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-04-02 2201032]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-04-02 1225920]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://google.sk/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Download all links by FlashGet3 - c:\program files (x86)\FlashGet Network\FlashGet 3\BHO\fdgetallurl.htm
IE: Download all videos by FlashGet3 - c:\program files (x86)\FlashGet Network\FlashGet 3\BHO\fdgetallflvurl.htm
IE: Download by FlashGet3 - c:\program files (x86)\FlashGet Network\FlashGet 3\BHO\fdgeturl.htm
IE: Download current video by FlashGet3 - c:\program files (x86)\FlashGet Network\FlashGet 3\BHO\fdgetflvurl.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM_Wow6432Node-ActiveSetup-{8A69D345-D564-463c-AFF1-A69D9E530F96} - c:\program files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe
AddRemove-Banished 1.0 - c:\games\Banished\Uninstall.exe
AddRemove-Dxtory2.0_is1 - c:\program files (x86)\Dxtory Software\Dxtory2.0\unins000.exe
AddRemove-FiveStories 1.00 - c:\games\FiveStories\Uninstall.exe
AddRemove-Super Hexagon_is1 - c:\games\Super Hexagon\unins000.exe
AddRemove-{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88} - c:\program files (x86)\InstallShield Installation Information\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD8\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\program files (x86)\Garena Plus\ggdllhost.exe
c:\progra~2\Raptr\raptr.exe
c:\progra~2\Raptr\raptr_im.exe
.
**************************************************************************
.
Completion time: 2014-07-03 20:42:07 - machine was rebooted
ComboFix-quarantined-files.txt 2014-07-03 18:41
ComboFix2.txt 2013-01-17 15:27
ComboFix3.txt 2013-01-16 17:57
.
Pre-Run: 152 121 376 768 bytes free
Post-Run: 151 911 092 224 bytes free
.
- - End Of File - - B0194863477E71138C2DD6183AAC937F
A36C5E4F47E84449FF07ED3517B43A31

:worship:

:???: môžem už nainštalovať chrome?

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka / zahadne moc vyuzivanie ramky

#15 Příspěvek od Márty84 »

:!: Presunte ComboFix na plochu, jinak to nebude fungovat!
:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

KillAll::

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MKLOL"=-
"Skype"=-
"uTorrent"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=-
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-
"SunJavaUpdateSched"=-

RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]

Driver::
SkypeUpdate
SwitchBoard
cpuz136
c2cautoupdatesvc
c2cpnrsvc

DDS::
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com

Reboot::
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev CFScript a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Pretahntete mysi tento vytvoreny textovy dokument nad ikonu ComboFix a pustte.
ComboFix by se mel spustit a vykonat prikazy.
Az skonci (muze dojit k restartu pc), mel by se objevit novy log, ten mi sem zase zkopirujte.

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni ruznych programu bude hlasena chyba, staci restartovat pc a bude to v poradku

dex73r píše: :???: môžem už nainštalovať chrome?
Ano
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno