Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

ShopperPro, JsDriver, vyskakovací okna

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
lucassman
Návštěvník
Návštěvník
Příspěvky: 114
Registrován: 21 úno 2009 14:04

ShopperPro, JsDriver, vyskakovací okna

#1 Příspěvek od lucassman »

Dobrý den,
dostal se mi do rukou počítač mých známých, který je totálně zpomalený a zasekaný vyskakovacími reklamami. Prosím o pomoc, v počítači by se doufám neměl vyskytovat žádný pirátský software. Děkuji

Zde log z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Kalkus at 2015-06-20 08:35:24
Microsoft Windows 8.1 s aplikací Bing
System drive C: has 425 GB (91%) free of 468 GB
Total RAM: 3979 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:35:26, on 20. 6. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Cinem Plus 2.4cV26.05\e0e1bc9b-45a9-4509-870a-a25c90106aca-10.exe
C:\PROGRA~2\YTDOWN~1\BrowserHelper.exe
C:\Program Files (x86)\ShopperPro\JSDriver\1.42.1.1875\jsdrv.exe
C:\Program Files (x86)\Dell Update\DellUpTray.exe
C:\Program Files (x86)\Opera\30.0.1835.59\opera.exe
C:\Program Files (x86)\Opera\30.0.1835.59\opera_crashreporter.exe
C:\Program Files (x86)\Opera\30.0.1835.59\opera.exe
C:\Program Files (x86)\Opera\30.0.1835.59\opera.exe
C:\Program Files (x86)\Opera\30.0.1835.59\opera.exe
C:\Program Files (x86)\YTDownloader\YTDownloader.exe
C:\Program Files (x86)\Opera\30.0.1835.59\opera.exe
C:\Program Files (x86)\Dell Backup and Recovery\COMPONENTS\DBRUPDATE\DBRUPD.EXE
C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE
C:\Program Files (x86)\Opera\30.0.1835.59\opera.exe
C:\Program Files\trend micro\Kalkus.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dell13.msn.com/?pc=DCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dell13.msn.com/?pc=DCJB
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: ShopperProBHO - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll
O4 - HKLM\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - HKLM\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.42.1.1875\jsdrv.exe
O4 - HKCU\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - HKCU\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.42.1.1875\jsdrv.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BrsHelper - Unknown owner - C:\PROGRA~2\YTDOWN~1\BROWSE~2.EXE
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Dell Customer Connect - Dell Inc. - C:\Program Files (x86)\Dell Customer Connect\OTBSurvey.exe
O23 - Service: Dell Data Vault (DellDataVault) - Dell Inc. - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
O23 - Service: Dell Data Vault Wizard (DellDataVaultWiz) - Dell Inc. - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
O23 - Service: Dell Digital Delivery Service (DellDigitalDelivery) - Dell Products, LP. - C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
O23 - Service: Dell Product Registration Manager (DellProdRegManager) - Aviata, Inc. - C:\Program Files (x86)\Dell Product Registration\regmgrsvc.exe
O23 - Service: Dell Update Service (DellUpdate) - Dell Inc. - C:\Program Files (x86)\Dell Update\DellUpService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: My Dell Client Framework - Dell Inc. - C:\Program Files (x86)\Dell\My Dell Client Framework\Dell.ClientFramework.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe
O23 - Service: SmdmF Service (SmdmFService) - Aztec Media Inc - C:\Program Files (x86)\Assets Manager\smdmf\SmdmFService.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: ShopperPro Update (SPBIUpd) - ShopperPro - C:\Program Files\Common Files\ShopperPro\spbiu.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Dell SupportAssist Agent (SupportAssistAgent) - Dell Inc. - C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update Air Globe - Unknown owner - C:\Program Files (x86)\Air Globe\updateAirGlobe.exe (file missing)
O23 - Service: Util Air Globe - Unknown owner - C:\Program Files (x86)\Air Globe\bin\utilAirGlobe.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8586 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SENDINPUT
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskhostex.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
taskeng.exe {6125EEFA-77C7-47C8-A1C2-7499A3C09F0D}
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
C:\PROGRA~2\YTDOWN~1\BROWSE~2.EXE
dashost.exe {e31b90fe-df3f-46e8-8755aa4facff834b}
"C:\Program Files (x86)\Cinem Plus 2.4cV26.05\e0e1bc9b-45a9-4509-870a-a25c90106aca-1-6.exe" /rawdata=Ry0rZGYEAPDAJ2ecm4R0mvcSZx2NMBsG+DO8z4l3ES0WejbqWew51bwTPWXRIyIuRVIPMzX9+Yo6NBsz6AX4++7HPfxy23tGv9lfJcwAa5edkXNGBuMVd5+oMTiiIkT9a/InEyTX3gb+F/b5EaHjPvaRrSUZtsbJoUANA0LhKZBwtpPoHu8uoeK4ka6bo46YjBDvAqi+WIaRd2f9NjnRO6TXpmiZaFS/8SVrNER6atUO1yMTtS88b8cxIGLLJd1o0FUMYKkAhGHxBi8kfmzq+5LG/KhDPB9ziqa8Wk7L+1dtULTi9GuudoAJy83+7i5bDPXiTF66fJyWYuW+HvbnMwOZ/u2Q1+Ky9/GlYeaumd3KaK1daN1/O4khASLKflFxSWAXfEbXCVkh7W7WeNgqa4xqtNev9s67N23w1H9PdUkfmymg7TV1X6JkrnMYYN1RDjpKxVW6tUFNWQ/Vy62Gnk1oBrMcdXI8DXzivSi6Yngmly5pN+LskmUvcWgMNJ3aVeGjC3XTQ36S1KmicJ82U+WQD3Uau/+7B0Joaaw22bE6sMsqgQq/pCtg3XcxJ+cjooXy7nHHWZPQsrrwiPyY82DrCgpANleLDXT5IgJwE5iBEYRSfSXpLozsNuwg10kXbhJ92n8UtOhrfDQ625fWV0BaSDxadmvxoeeRNDe58LWX910Ud+9SxWaPaUHCQTY8zQzZAoZFvmD3CEXxzT0sWj6EuHTMW0o9iOPh5aBdE7/6a3k+InJIgfw0G9fVQkOJdiWbYu8I2jW0db/16SYorzbQfdf5w8epP3GUYkPq2BS9wA4SKUr5tX1vwLHGzCE2XI4Mu/6U0FYvpBHRHW9G2pd4neApMYWV/+vPjE46AD0f8uglw+SJz6/3hPr4JHrJaLodECtBoV1fNqEF+dXX4DLupY2t2/R/7r9tHZ22IPwsSyLmZwCIKxuDVczABiXJZCOxI7Xk4wPEQVx01lqdk8Kdt45ww6M8CG7swxkd34/rbE2motkGb4fZpp4vGtSmWxMvVidqwdTjcFzDI7GILvx/e5Cyn75GmdA/Blxf6aizKkGC9PR5bkt2KZ9sUN8FckuAcp99rAZK8kzyaw8229lBXSOICFMJcXS3CRwJjcoh6M8pD3ZyNbRC9aViFpVnvbunV6OCVmwWlwjaer9CTrJwuvB4+6FDZ2fAaJ6Zv8qDL/fl56nDJVqiqpYgqImP9MMeTUat4aCOnZyfDfZBj/BkwrfZ0G83zzJwI5hX4g4GTS/mV7fgIIlEhQQLll5AmPi9vT/YF/8ymLUdT5TKYBb8ct8gPDRKVLtnbBRPnMGFJUuRY2MHU37cccS887k6rOtJhKVTLlXKG8zdKe6wtw==
taskeng.exe {030F231B-971D-48E4-B831-374FFA20483A}
"C:\Program Files (x86)\Cinem Plus 2.4cV26.05\e0e1bc9b-45a9-4509-870a-a25c90106aca-10.exe" /rawdata=kNElM+nBmIwqrtvcvEzYRthMcGs1LkQ3737O2mMx/ftk4ggQ9E9l1LH/8EbRUYWkmxScTGXvPlNInjVL877JhkVGclZMdmXXIX0q9F6x3iMPU+y+gUrVHd+AialPUUh0j6Mgb5AyBgnmtUNff3GolL+clvU8lcVln62YA+M2qDhCkbj5CpKjplkCXCuDctvOOhAzxN+U9ne38tLkSTW8gEzJ89AVAothUop1NgbHEHtK9shMi5EFuCNh8z1quEw4wdQfOK2WZgDTeCpkK1X6MbhH8vX3cjTP8WJaFiagMEo6zce9W/xu1/PpvSvtxhvClEoHhJriln5cRqMTxXhLxFDx1Khmfk7KjUofnc9zsSgcOH8cbbI/VxFTlR35yFuLy/q291Rewx40Y58hF0+wpA9g+v4kgckw6CLlyPpOdWeXDnLbsMEwMi+dOLyAt+1uH534egScuS0j8lhImssV49JfQYqPCKwPZ5UI6r25WlXnZz2iOFZuul0utNIaOtXimQdqUsAGTm9OI/+VcX/3psKgyDuS+QH8xIceXNVJVgIRogamk9ZYuT3voUlexlE8iSK/aT7AP//H7pR74hzozlRYvm8fD76tg4t10XpGk3kBXrGUFxdACudmPTkfYPc2mN9gZvZNzoI3CWfIHMJu8tnmUss1ruA8eQayiKJSFvVn368DdOhrcXv2eKxH/3Tj8QPMa5QiLU/q99nAIgnLmYV8axGin9Cc85TPeqF0KVfMVhr0eeIsc0mmeaFwKnWQTNq1XCJqXfYg3bpT0y1VAWlxCEWwjKKX6Iho81XvJ/kOJNAmXoPyxia0V6sML3bBhbqZt3vuWfo/RIRxd73acQ==
"C:\Program Files\Common Files\ShopperPro\spbiu.exe" /service
"C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe"

"C:\Program Files (x86)\Dell\My Dell Client Framework\Dell.ClientFramework.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\PROGRA~2\YTDOWN~1\BrowserHelper.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\wbem\wmiprvse.exe
igfxEM.exe
igfxHK.exe
igfxTray.exe

"C:\Program Files\Dell\QuickSet\quickset.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX4P1
"C:\Program Files\Realtek\Audio\HDA\WavesSvc64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /IM
"C:\Program Files (x86)\ShopperPro\JSDriver\1.42.1.1875\jsdrv.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\Dell Customer Connect\OTBSurvey.exe"
"C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe"
"C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe"
"C:\Program Files (x86)\Dell Update\DellUpService.exe"
/x /hideintroballoon /launchedbywindowsservice
"C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe"
"C:\Program Files\Dell\DellDataVault\DellDataVault.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Opera\30.0.1835.59\opera.exe" --ran-launcher
"C:\Program Files (x86)\Opera\30.0.1835.59\opera_crashreporter.exe" --ran-launcher --crash-reporter-parent-id=4304
"C:\Program Files (x86)\Opera\30.0.1835.59\opera.exe" --type=gpu-process --channel="4304.0.287125206\865424812" --crash-reporter-pid=2384 --enable-mse-h264-support --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,21,44 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3621 --crash-reporter-pid=2384 --enable-mse-h264-support --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Opera\30.0.1835.59\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-direct-npapi-requests --disable-win32k-renderer-lockdown --enable-deferred-image-decoding --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --crash-reporter-pid=2384 --enable-mse-h264-support --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4304 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4304.4.78661250\2086638591" /prefetch:673131151
"C:\Program Files (x86)\Opera\30.0.1835.59\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-direct-npapi-requests --disable-win32k-renderer-lockdown --enable-deferred-image-decoding --lang=cs --disable-client-side-phishing-detection --crash-reporter-pid=2384 --enable-mse-h264-support --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4304 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4304.6.529585524\1176103401" /prefetch:673131151
"C:\Program Files (x86)\YTDownloader\YTDownloader.exe"
"C:\Program Files (x86)\Opera\30.0.1835.59\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-direct-npapi-requests --disable-win32k-renderer-lockdown --enable-deferred-image-decoding --lang=cs --disable-client-side-phishing-detection --crash-reporter-pid=2384 --enable-mse-h264-support --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4304 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4304.10.781723178\1160576487" /prefetch:673131151
"C:\Program Files (x86)\Dell Backup and Recovery\COMPONENTS\DBRUPDATE\DBRUPD.EXE"
"C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE" C:\Users\Kalkus
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\Opera\30.0.1835.59\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-direct-npapi-requests --disable-win32k-renderer-lockdown --enable-deferred-image-decoding --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --crash-reporter-pid=2384 --enable-mse-h264-support --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4304 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4304.12.76934107\1262820209" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 564 568 576 65536 572

"C:\Windows\system32\NOTEPAD.EXE" C:\rsit\info.txt
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Kalkus\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\e0e1bc9b-45a9-4509-870a-a25c90106aca-1-6.job - C:\Program Files (x86)\Cinem Plus 2.4cV26.05\e0e1bc9b-45a9-4509-870a-a25c90106aca-1-6.exe /rawdata=Ry0rZGYEAPDAJ2ecm4R0mvcSZx2NMBsG+DO8z4l3ES0WejbqWew51bwTPWXRIyIuRVIPMzX9+Yo6NBsz6AX4++7HPfxy23tGv9lfJcwAa5edkXNGBuMVd5+oMTiiIkT9a/InEyTX3gb+F/b5EaHjPvaRrSUZtsbJoUANA0LhKZBwtpPoHu8uoeK4ka6bo46YjBDvAqi+WIaRd2f9NjnRO6TXpmiZaFS/8SVrNER6atUO1yMTtS88b8cxIGLLJd1o0FUMYKkAhGHxBi8kfmzq+5LG/KhDPB9ziqa8Wk7L+1dtULTi9GuudoAJy83+7i5bDPXiTF66fJyWYuW+HvbnMwOZ/u2Q1+Ky9/GlYeaumd3KaK1daN1/O4khASLKflFxSWAXfEbXCVkh7W7WeNgqa4xqtNev9s67N23w1H9PdUkfmymg7TV1X6JkrnMYYN1RDjpKxVW6tUFNWQ/Vy62Gnk1oBrMcdXI8DXzivSi6Yngmly5pN+LskmUvcWgMNJ3aVeGjC3XTQ36S1KmicJ82U+WQD3Uau/+7B0Joaaw22bE6sMsqgQq/pCtg3XcxJ+cjooXy7nHHWZPQsrrwiPyY82DrCgpANleLDXT5IgJwE5iBEYRSfSXpLozsNuwg10kXbhJ92n8UtOhrfDQ625fWV0BaSDxadmvxoeeRNDe58LWX910Ud+9SxWaPaUHCQTY8zQzZAoZFvmD3CEXxzT0sWj6EuHTMW0o9iOPh5aBdE7/6a3k+InJIgfw0G9fVQkOJdiWbYu8I2jW0db/16SYorzbQfdf5w8epP3GUYkPq2BS9wA4SKUr5tX1vwLHGzCE2XI4Mu/6U0FYvpBHRHW9G2pd4neApMYWV/+vPjE46AD0f8uglw+SJz6/3hPr4JHrJaLodECtBoV1fNqEF+dXX4DLupY2t2/R/7r9tHZ22IPwsSyLmZwCIKxuDVczABiXJZCOxI7Xk4wPEQVx01lqdk8Kdt45ww6M8CG7swxkd34/rbE2motkGb4fZpp4vGtSmWxMvVidqwdTjcFzDI7GILvx/e5Cyn75GmdA/Blxf6aizKkGC9PR5bkt2KZ9sUN8FckuAcp99rAZK8kzyaw8229lBXSOICFMJcXS3CRwJjcoh6M8pD3ZyNbRC9aViFpVnvbunV6OCVmwWlwjaer9CTrJwuvB4+6FDZ2fAaJ6Zv8qDL/fl56nDJVqiqpYgqImP9MMeTUat4aCOnZyfDfZBj/BkwrfZ0G83zzJwI5hX4g4GTS/mV7fgIIlEhQQLll5AmPi9vT/YF/8ymLUdT5TKYBb8ct8gPDRKVLtnbBRPnMGFJUuRY2MHU37cccS887k6rOtJhKVTLlXKG8zdKe6wtw==
C:\Windows\tasks\e0e1bc9b-45a9-4509-870a-a25c90106aca-1-7.job - C:\Program Files (x86)\Cinem Plus 2.4cV26.05\e0e1bc9b-45a9-4509-870a-a25c90106aca-1-7.exe /rawdata=k2YBKNuDgzoOwGXqWUFcEuWrxvShNzkH6J70sLo2sSCLIKe8Cf4RlKKTkAF6/KJTQ65n7SLQx2Rohst4vAwk/dLHUrfV3beNf3pBeH//opSaAjkP4wc2O4sRFOo9k1LlufbdAsbxYNiKrJpcgTTuFgUOXBg9BkPy+4Plaq8gsIF/YmK9YaE8nFPVjufH73QCi3lGrcyY/oLOtU7fSezMhV5XNbjvtlmL40iKkjFnNDj4sa8LgHsIiZsDiniMG0enzfNrY4Fmh41YjHeGt5kiprbLRxDZgSOjAzaeYjAtCPNDFzRNlTG8K7c943KlvvaVViqHJv0jru7VBtE8wqxonh0EbN2ywKGU1Hds3EpHRGmf0NMKA2kI0KXPm43L5NqRM+qj8s5EMGptI+M/sqkjN/P9e10sExnXVYfwVFOL1sEiXXnS+6KRWIQBB+aYDR9l7bYwHWyf7L4ag4PHNynbHn77d05yRqoACpNbUpwe3djAhQ2RzMkHT6XkwUGvzddfOG/LvUoRiw96H7h6HfILmEm4UyYq9qivBc4Z13kbJR/eHFCmIEpGOS3wbEcFQLrLVSJK+1MhsS5tPZxa5yVz6LtZGK1Fd3nvEIy3jGuU35VB6nuujPtTyUV6LQ35oh7ky5hOC3ra2pynxHuNlJ+1TwtFr0PfxRajYPD9tkGgKohpW7dhBNaOF0T6DwGo+W4lOqjST/mK6x3Zj41eEtB0C/naQ4aq5XmB1oAZhdArul5UmIqNMztMWRQCpIWyYkIP80U+AsFaJrVCM/WecRkI9cqwuK0z4lWfz12TAROaljodQs9kXiO1seL8OlMeZf2d7OB9DS1Llqz+y1LimrKbtBELqS3BiSXtUUwhWvr/pCrR8Phyn+7hS5LSWfHKQPAN8RTyyQ9ncK2VbA7O07UtkRHCeXuCcJAGZfgnYTvIFS6lXSqzXfz1LC0ydgyxtxgA+9GOu0c2UWW+1aGrGjuuQjxNJHU/SlRHQ5Zb3v2KApHXhcEr96yKvM5gIA9s3bKgUGT2ufj8DM6RRvK2dgZcIjqvVVb2w0O4b4dT3MoDyeT2xAqtHvJhZaVVuxWOwgeeXO1dWZqyzhqu8Dg4UTlGBoYSm8pPJxRkBX7JC9T4oxHPLYI9BdYUKvOBVk49EUoOUvOD9KKSH9WpgyrzQHk6t2IIkfZxS3OrJZboF98o8Rp1JioO0LZmY/2eMTY58pylQm4ilrrt4ZCuIRTTRJuNvqUSDWzKn00nDP7SuL/WqMOfZg6mNb7rWUhFD1Ny9S+f63slzQFMw0O/4PqEwCll7V+vHKb6Dih+o/VqclcZ0soovWUalIDyBqKuIjKjIM7IFrO1Ujnq+yL96dcy4H8hyQ==
C:\Windows\tasks\e0e1bc9b-45a9-4509-870a-a25c90106aca-10_user.job - C:\Program Files (x86)\Cinem Plus 2.4cV26.05\e0e1bc9b-45a9-4509-870a-a25c90106aca-10.exe /rawdata=kNElM+nBmIwqrtvcvEzYRthMcGs1LkQ3737O2mMx/ftk4ggQ9E9l1LH/8EbRUYWkmxScTGXvPlNInjVL877JhkVGclZMdmXXIX0q9F6x3iMPU+y+gUrVHd+AialPUUh0j6Mgb5AyBgnmtUNff3GolL+clvU8lcVln62YA+M2qDhCkbj5CpKjplkCXCuDctvOOhAzxN+U9ne38tLkSTW8gEzJ89AVAothUop1NgbHEHtK9shMi5EFuCNh8z1quEw4wdQfOK2WZgDTeCpkK1X6MbhH8vX3cjTP8WJaFiagMEo6zce9W/xu1/PpvSvtxhvClEoHhJriln5cRqMTxXhLxFDx1Khmfk7KjUofnc9zsSgcOH8cbbI/VxFTlR35yFuLy/q291Rewx40Y58hF0+wpA9g+v4kgckw6CLlyPpOdWeXDnLbsMEwMi+dOLyAt+1uH534egScuS0j8lhImssV49JfQYqPCKwPZ5UI6r25WlXnZz2iOFZuul0utNIaOtXimQdqUsAGTm9OI/+VcX/3psKgyDuS+QH8xIceXNVJVgIRogamk9ZYuT3voUlexlE8iSK/aT7AP//H7pR74hzozlRYvm8fD76tg4t10XpGk3kBXrGUFxdACudmPTkfYPc2mN9gZvZNzoI3CWfIHMJu8tnmUss1ruA8eQayiKJSFvVn368DdOhrcXv2eKxH/3Tj8QPMa5QiLU/q99nAIgnLmYV8axGin9Cc85TPeqF0KVfMVhr0eeIsc0mmeaFwKnWQTNq1XCJqXfYg3bpT0y1VAWlxCEWwjKKX6Iho81XvJ/kOJNAmXoPyxia0V6sML3bBhbqZt3vuWfo/RIRxd73acQ==
C:\Windows\tasks\e0e1bc9b-45a9-4509-870a-a25c90106aca-5.job - C:\Program Files (x86)\Cinem Plus 2.4cV26.05\e0e1bc9b-45a9-4509-870a-a25c90106aca-5.exe /rawdata=QaL6jjn202V+mU8C9OrC2M1h+jpWN4z3Aw7/5Qo/huIw899l7rNfxYtgZ9CNvn1sPiBEXWvPyn/apZvt2ggna545XHh8ezmupFZQXNpcE+1mad5/7BJFFkO1RiscdTZbVaxW3lJyQYfekKKxMJqdkTRbS8O+YiUl8CZN8Ok7zccuZNh18FKFExXVWoWXqhKLduS75isElDN+x+xNzjWwgBioKq02OZz7TGfpicgPtw0Pa80JpEV0vuXNWDtCAf1caM+xJQ3AJBuQy9j0NsvnWD4MbdRJtY4OYtagdvHz3ER4t5IzdDlzQ03Hc66YyfX0dD3SrMwOhiukCZymwrfYzpGsr9MicG6+pV8/wKOpR5cbXYJwkpS38jI9MZzjbGhN8vflfX65aJaaNQ1MUhCQNJneq4/ByYcwHyqWpGcb9PSBz1/YH7emBGDcxDTTUReKJyog04YX+BNVa2OaduGNiLyC948JyVI5r20yegOEG2/H7A+4U7v2nOdYma0HqTB3N6hlf2LAMlJqqzUgB/q77jfBMfSO3qQwJiJsfW6hi4N8lAZmUPYCv7K4LD2bQg2jHBQhUz2TSwI/iFBS+GaVuhPTLkiO1lvIl90XpDqaSqz3+cGCVALuo32nxJ66F3ucLf+oN4nbpSYn/GCUBknGZBO2tCOsLZ7WH6V+suZdj2sdvoksSBxkD02tsB3O15+RfDRR6uXz/dxkik7ncszhEzjUiTrlx1tQMq9MRYvl7p+U7UW5/y+L9AIzek6bZOaYb6Ruj4vMjUOsUz2iJ5tQ0QiQ3lTiuZVXjf5VfnE0G5187/Vjiky1xmWIKAB25fF4kvLT7+Rbn+dY6fgeo/uXbaqftI83kGZttl01PyGhc9nl0Jq+WJHN7MdIFgrfd8655imwaI/INwDh4jkLwM/AMJ44YC8t/+WstJCOb3K7K0fPXioFV1vtNLkmSCKFhUbKwJzvzl5KUHnHl7B4EdTtPW7m5NieZBHJyfgOtGNOQnJJ1Q3ILQJd+Y5iodrVdZ8+
C:\Windows\tasks\e0e1bc9b-45a9-4509-870a-a25c90106aca-5_user.job - C:\Program Files (x86)\Cinem Plus 2.4cV26.05\e0e1bc9b-45a9-4509-870a-a25c90106aca-5.exe /rawdata=QaL6jjn202V+mU8C9OrC2M1h+jpWN4z3Aw7/5Qo/huIw899l7rNfxYtgZ9CNvn1sPiBEXWvPyn/apZvt2ggna545XHh8ezmupFZQXNpcE+1mad5/7BJFFkO1RiscdTZbVaxW3lJyQYfekKKxMJqdkTRbS8O+YiUl8CZN8Ok7zccuZNh18FKFExXVWoWXqhKLduS75isElDN+x+xNzjWwgBioKq02OZz7TGfpicgPtw0Pa80JpEV0vuXNWDtCAf1caM+xJQ3AJBuQy9j0NsvnWD4MbdRJtY4OYtagdvHz3ER4t5IzdDlzQ03Hc66YyfX0dD3SrMwOhiukCZymwrfYzpGsr9MicG6+pV8/wKOpR5cbXYJwkpS38jI9MZzjbGhN8vflfX65aJaaNQ1MUhCQNJneq4/ByYcwHyqWpGcb9PSBz1/YH7emBGDcxDTTUReKJyog04YX+BNVa2OaduGNiLyC948JyVI5r20yegOEG2/H7A+4U7v2nOdYma0HqTB3N6hlf2LAMlJqqzUgB/q77jfBMfSO3qQwJiJsfW6hi4N8lAZmUPYCv7K4LD2bQg2jHBQhUz2TSwI/iFBS+GaVuhPTLkiO1lvIl90XpDqaSqz3+cGCVALuo32nxJ66F3ucLf+oN4nbpSYn/GCUBknGZBO2tCOsLZ7WH6V+suZdj2sdvoksSBxkD02tsB3O15+RfDRR6uXz/dxkik7ncszhEzjUiTrlx1tQMq9MRYvl7p+U7UW5/y+L9AIzek6bZOaYb6Ruj4vMjUOsUz2iJ5tQ0QiQ3lTiuZVXjf5VfnE0G5187/Vjiky1xmWIKAB25fF4kvLT7+Rbn+dY6fgeo/uXbbaIfvH7WCKsZoIrXaz/40/XuSddTArSGScq8ksdBAqhXCPWN/IPWGS7elPO1/on5C04q+z9JFNYFSGmNiPDM9+X3fprFZKdbVSuwN75u0fpxJMwNwxL8Hd0W+ejYHSb0MefVQL8nEzFd/qPbMVQmIp37s5IQZ0gAoBYewpvCFZ+
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
Shopper Pro - C:\ProgramData\ShopperPro\ShopperPro64.dll [2015-06-15 529840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
Shopper Pro - C:\ProgramData\ShopperPro\ShopperPro.dll [2015-06-15 444336]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickSet"=c:\Program Files\Dell\QuickSet\QuickSet.exe [2013-11-25 5776712]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2013-12-28 7506648]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-01-10 1374424]
"WavesSvc"=C:\Program Files\Realtek\Audio\HDA\WavesSvc64.exe [2013-12-31 285272]
"RtHDVBg_PushButton"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-01-10 1374424]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe [2015-05-20 1988528]
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.42.1.1875\jsdrv.exe [2015-06-15 3225088]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe [2015-05-20 1988528]
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.42.1.1875\jsdrv.exe [2015-06-15 3225088]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-06-20 08:34:21 ----D---- C:\Program Files\trend micro
2015-06-20 08:34:20 ----D---- C:\rsit
2015-06-20 08:08:52 ----A---- C:\Windows\system32\drivers\{399a0743-357c-44e5-9a46-bb7ce63a3062}w64.sys
2015-06-16 20:14:32 ----D---- C:\Program Files (x86)\Dell Digital Delivery
2015-06-16 18:42:46 ----D---- C:\Program Files\Common Files\ShopperPro
2015-06-16 18:31:59 ----A---- C:\Windows\system32\drivers\{8a41cfe2-3810-44a8-a83f-c58ba68c0bd4}w64.sys
2015-06-16 18:31:08 ----A---- C:\Windows\system32\drivers\{8a41cfe2-3810-44a8-a83f-c58ba68c0bd4}Gw64.sys
2015-06-16 18:28:21 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2015-06-16 18:28:21 ----A---- C:\Windows\system32\comctl32.dll
2015-06-16 18:28:07 ----A---- C:\Windows\system32\mshtml.dll
2015-06-16 18:28:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-06-16 18:28:01 ----A---- C:\Windows\system32\jscript9.dll
2015-06-16 18:28:00 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-06-16 18:28:00 ----A---- C:\Windows\system32\wininet.dll
2015-06-16 18:27:59 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-06-16 18:27:59 ----A---- C:\Windows\system32\ieframe.dll
2015-06-16 18:27:58 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-06-16 18:27:58 ----A---- C:\Windows\system32\iertutil.dll
2015-06-16 18:27:57 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-06-16 18:27:57 ----A---- C:\Windows\system32\urlmon.dll
2015-06-16 18:27:56 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-06-16 18:27:56 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-06-16 18:27:55 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-06-16 18:27:55 ----A---- C:\Windows\system32\vbscript.dll
2015-06-16 18:27:55 ----A---- C:\Windows\system32\actxprxy.dll
2015-06-16 18:27:54 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-06-16 18:27:54 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-06-16 18:27:54 ----A---- C:\Windows\system32\msfeeds.dll
2015-06-16 18:27:54 ----A---- C:\Windows\system32\jscript.dll
2015-06-16 18:27:53 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-06-16 18:27:53 ----A---- C:\Windows\system32\jscript9diag.dll
2015-06-16 18:27:53 ----A---- C:\Windows\system32\ieapfltr.dll
2015-06-16 18:27:52 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-06-16 18:27:52 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-06-16 18:27:52 ----A---- C:\Windows\system32\webcheck.dll
2015-06-16 18:27:52 ----A---- C:\Windows\system32\dxtrans.dll
2015-06-16 18:27:51 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-06-16 18:27:51 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2015-06-16 18:27:51 ----A---- C:\Windows\system32\mshtmled.dll
2015-06-16 18:27:51 ----A---- C:\Windows\system32\ieui.dll
2015-06-16 18:27:51 ----A---- C:\Windows\system32\iepeers.dll
2015-06-16 18:27:50 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2015-06-16 18:27:50 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-06-16 18:27:50 ----A---- C:\Windows\system32\inetcomm.dll
2015-06-16 18:27:50 ----A---- C:\Windows\system32\iedkcs32.dll
2015-06-16 18:27:36 ----A---- C:\Windows\system32\win32k.sys
2015-06-07 16:36:27 ----D---- C:\Program Files (x86)\Dell Customer Connect
2015-06-07 16:34:22 ----D---- C:\Program Files (x86)\Dell Update
2015-05-26 10:25:35 ----D---- C:\Program Files (x86)\Linkey
2015-05-26 10:25:27 ----A---- C:\Windows\system32\drivers\{bf34199a-d8d1-4010-b9b5-fa9597e3123a}Gw64.sys
2015-05-26 10:24:26 ----D---- C:\Program Files (x86)\Assets Manager
2015-05-26 10:24:18 ----D---- C:\ProgramData\smdmf
2015-05-26 10:24:02 ----D---- C:\Program Files (x86)\Air Globe
2015-05-26 10:22:57 ----D---- C:\ProgramData\ShopperPro
2015-05-26 10:21:53 ----D---- C:\Program Files (x86)\YTDownloader
2015-05-26 10:21:39 ----D---- C:\Program Files (x86)\ShopperPro
2015-05-26 10:19:13 ----D---- C:\Users\Kalkus\AppData\Roaming\Opera Software
2015-05-26 10:17:07 ----D---- C:\Program Files (x86)\Opera
2015-05-26 10:14:33 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-05-26 10:12:10 ----D---- C:\Program Files (x86)\globalUpdate
2015-05-26 10:10:58 ----D---- C:\Program Files (x86)\Cinem Plus 2.4cV26.05
2015-05-26 10:10:27 ----D---- C:\Program Files (x86)\Rockstar Games
2015-05-24 20:22:31 ----HDC---- C:\ProgramData\{6AACA38B-2810-4B47-BDEC-D7A1F38B1531}
2015-05-24 20:21:42 ----D---- C:\ProgramData\SupportAssistAgent
2015-05-24 19:23:44 ----D---- C:\ProgramData\PC-Doctor for Windows
2015-05-24 19:23:28 ----D---- C:\Program Files\Dell Support Center

======List of files/folders modified in the last 1 month======

2015-06-20 08:35:16 ----D---- C:\Windows\Prefetch
2015-06-20 08:34:21 ----RD---- C:\Program Files
2015-06-20 08:31:59 ----D---- C:\Windows\system32\sru
2015-06-20 08:29:51 ----D---- C:\Program Files (x86)\Dell Backup and Recovery
2015-06-20 08:28:00 ----D---- C:\Windows\system32\Tasks
2015-06-20 08:26:41 ----RD---- C:\Windows\System32
2015-06-20 08:26:41 ----D---- C:\Windows\Inf
2015-06-20 08:26:41 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-06-20 08:24:33 ----D---- C:\Windows\Temp
2015-06-20 08:18:32 ----RD---- C:\Program Files (x86)
2015-06-20 08:18:32 ----D---- C:\Windows\Tasks
2015-06-20 08:16:49 ----D---- C:\Windows\system32\wdi
2015-06-20 08:14:00 ----A---- C:\Windows\win.ini
2015-06-20 08:12:37 ----D---- C:\Windows\system32\catroot
2015-06-20 08:08:58 ----D---- C:\Windows\system32\DriverStore
2015-06-20 08:08:52 ----D---- C:\Windows\system32\drivers
2015-06-20 08:04:58 ----SHD---- C:\Windows\Installer
2015-06-17 18:22:22 ----D---- C:\Windows\system32\config
2015-06-16 20:33:26 ----D---- C:\Windows\Microsoft.NET
2015-06-16 20:26:32 ----HD---- C:\Program Files\WindowsApps
2015-06-16 20:26:20 ----D---- C:\Windows\AppReadiness
2015-06-16 20:12:06 ----HD---- C:\ProgramData
2015-06-16 20:12:03 ----D---- C:\Windows\WinSxS
2015-06-16 20:12:02 ----D---- C:\Windows\SysWOW64
2015-06-16 20:07:24 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-06-16 20:07:24 ----D---- C:\Program Files\Internet Explorer
2015-06-16 20:07:24 ----D---- C:\Program Files (x86)\Internet Explorer
2015-06-16 20:07:23 ----D---- C:\Windows\system32\cs-CZ
2015-06-16 20:07:23 ----D---- C:\Windows\PolicyDefinitions
2015-06-16 20:07:16 ----D---- C:\Windows\CbsTemp
2015-06-16 20:04:29 ----SHD---- C:\System Volume Information
2015-06-16 20:03:09 ----SHD---- C:\$Recycle.Bin
2015-06-16 18:42:46 ----D---- C:\Program Files\Common Files
2015-06-16 18:31:03 ----D---- C:\Windows\system32\GroupPolicy
2015-06-07 16:36:18 ----D---- C:\ProgramData\DELL
2015-06-03 18:18:09 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-05-26 10:22:42 ----D---- C:\Program Files\Common Files\System
2015-05-26 10:15:55 ----SD---- C:\ProgramData\Microsoft
2015-05-24 20:22:02 ----D---- C:\Program Files\Dell
2015-05-24 20:21:54 ----SD---- C:\Users\Kalkus\AppData\Roaming\Microsoft
2015-05-24 20:21:42 ----D---- C:\Program Files (x86)\Dell
2015-05-24 19:36:34 ----RSD---- C:\Windows\assembly

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Wof;Windows Overlay File System Filter Driver; C:\Windows\system32\drivers\Wof.sys [2014-10-20 157016]
R1 F06DEFF2-5B9C-490D-910F-35D3A9119622;F06DEFF2-5B9C-490D-910F-35D3A9119622; \??\C:\Program Files (x86)\Assets Manager\smdmf\x64\smdmfmgrc3.cfg [2015-04-15 46752]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-10-20 71680]
R2 sbmntr;SBMNTR; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [2015-05-20 58528]
R2 SPDRIVER_1.42.1.1875;SPDRIVER_1.42.1.1875; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.42.1.1875\jsdrv.sys [2015-06-15 52384]
R3 athr;@oem2.inf,%ATHR.Service.DispName%;Dell Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athwbx.sys [2013-09-11 3855872]
R3 DDDriver;DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [2015-02-26 23760]
R3 DellProf;DellProf; C:\Windows\system32\drivers\DellProf.sys [2015-02-26 23312]
R3 DellRbtn;@oem1.inf,%DellRbtn%;Airplane Mode Switch; C:\Windows\System32\drivers\DellRbtn.sys [2013-01-25 10752]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-05-22 3791872]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-01-10 3826776]
R3 IntcDAud;@oem145.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-05-22 450520]
R3 iwdbus;@oem148.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2014-05-07 27032]
R3 RSUSBVSTOR;@oem141.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUVStor.sys [2013-07-10 329944]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2014-02-20 31472]
R3 SPBIUpdd;ShopperPro UpdateD; \??\C:\Program Files\Common Files\ShopperPro\spbiw.sys [2015-06-15 41632]
R3 SynTP;@oem144.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2014-02-20 537328]
R3 TXEIx64;@oem142.inf,%TEE_SvcDesc%;Intel(R) Trusted Execution Engine Interface ; C:\Windows\System32\drivers\TXEIx64.sys [2014-01-15 88592]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-06-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2014-10-20 38912]
S3 AX88772;@netax88772.inf,%AX88772.DeviceDesc%;Adaptér ASIX AX88772 USB2.0 to Fast Ethernet Adapter; C:\Windows\system32\DRIVERS\ax88772.sys [2013-07-18 113864]
S3 intaud_WaveExtensible;@oem147.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2014-05-07 38296]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
R2 BrsHelper;BrsHelper; C:\PROGRA~2\YTDOWN~1\BROWSE~2.EXE [2015-05-20 112560]
R2 Dell Customer Connect;Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\OTBSurvey.exe [2015-04-09 145288]
R2 DellDataVault;Dell Data Vault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2015-02-26 2557136]
R2 DellDataVaultWiz;Dell Data Vault Wizard; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [2015-02-26 201936]
R2 DellDigitalDelivery;Dell Digital Delivery Service; C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2015-03-16 237448]
R2 DellUpdate;Dell Update Service; C:\Program Files (x86)\Dell Update\DellUpService.exe [2015-05-20 232152]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2014-05-22 315352]
R2 My Dell Client Framework;My Dell Client Framework; C:\Program Files (x86)\Dell\My Dell Client Framework\Dell.ClientFramework.exe [2014-01-10 168960]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2014-01-08 290520]
R2 SftService;SoftThinks Agent Service; C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe [2014-09-18 1924328]
R2 SPBIUpd;ShopperPro Update; C:\Program Files\Common Files\ShopperPro\spbiu.exe [2015-06-15 2346416]
R2 SupportAssistAgent;Dell SupportAssist Agent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [2015-04-10 19288]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-06-20 68608]
S2 SmdmFService;SmdmF Service; C:\Program Files (x86)\Assets Manager\smdmf\SmdmFService.exe [2015-04-15 3203840]
S2 Update Air Globe;Update Air Globe; C:\Program Files (x86)\Air Globe\updateAirGlobe.exe []
S2 Util Air Globe;Util Air Globe; C:\Program Files (x86)\Air Globe\bin\utilAirGlobe.exe []
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-05-22 279000]
S3 DellProdRegManager;Dell Product Registration Manager; C:\Program Files (x86)\Dell Product Registration\regmgrsvc.exe [2014-04-01 293440]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-06-20 68608]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [2013-12-24 887232]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: ShopperPro, JsDriver, vyskakovací okna

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Po spusteni probehne stazeni databaze
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

lucassman
Návštěvník
Návštěvník
Příspěvky: 114
Registrován: 21 úno 2009 14:04

Re: ShopperPro, JsDriver, vyskakovací okna

#3 Příspěvek od lucassman »

# AdwCleaner v4.206 - Log vytvořen 20/06/2015 v 09:01:24
# Aktualizováno 01/06/2015 by Xplode
# Databáze : 2015-06-17.1 [Server]
# Operační system : Windows 8.1 Connected (x64)
# Uživatelské jméno : Kalkus - KALKUSOVI
# Spuštěno z : C:\Users\Kalkus\Desktop\adwcleaner_4.206.exe
# Nastavení : Čištění

***** [ Služby ] *****

[#] Služba Smazáno : BrsHelper
[#] Služba Smazáno : globalUpdate
[#] Služba Smazáno : globalUpdatem
Služba Smazáno : sbmntr
[#] Služba Smazáno : SmdmFService
[#] Služba Smazáno : SPBIUpd
Služba Smazáno : SPBIUpdd
Služba Smazáno : {399a0743-357c-44e5-9a46-bb7ce63a3062}w64
Služba Smazáno : {8a41cfe2-3810-44a8-a83f-c58ba68c0bd4}Gw64
Služba Smazáno : {8a41cfe2-3810-44a8-a83f-c58ba68c0bd4}w64
Služba Smazáno : {bf34199a-d8d1-4010-b9b5-fa9597e3123a}Gw64
[#] Služba Smazáno : F06DEFF2-5B9C-490D-910F-35D3A9119622
Služba Smazáno : SPDRIVER_1.42.1.1875

***** [ Soubory / Složky ] *****

Složka Smazáno : C:\ProgramData\ShopperPro
Složka Smazáno : C:\ProgramData\smdmf
Složka Smazáno : C:\Users\Public\Documents\ShopperPro
Složka Smazáno : C:\Program Files (x86)\globalUpdate
Složka Smazáno : C:\Program Files (x86)\Linkey
Složka Smazáno : C:\Program Files (x86)\ShopperPro
Složka Smazáno : C:\Program Files (x86)\YTDownloader
Složka Smazáno : C:\Program Files (x86)\Assets Manager
Složka Smazáno : C:\Program Files (x86)\Air Globe
Složka Smazáno : C:\Program Files (x86)\Cinem Plus 2.4cV26.05
Složka Smazáno : C:\Users\Kalkus\AppData\Local\Temp\Air Globe
Složka Smazáno : C:\Program Files\Common Files\ShopperPro
Složka Smazáno : C:\Users\Kalkus\AppData\Local\globalUpdate
Složka Smazáno : C:\Users\Kalkus\AppData\Local\BrowserHelper
Složka Smazáno : C:\Users\Kalkus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YTDownloader
Soubor Smazáno : C:\Program Files\Common Files\System\SysMenu.dll
Soubor Smazáno : C:\Program Files\Common Files\System\SysMenu64.dll
Soubor Smazáno : C:\Windows\System32\drivers\{399a0743-357c-44e5-9a46-bb7ce63a3062}w64.sys
Soubor Smazáno : C:\Windows\System32\drivers\{8a41cfe2-3810-44a8-a83f-c58ba68c0bd4}Gw64.sys
Soubor Smazáno : C:\Windows\System32\drivers\{8a41cfe2-3810-44a8-a83f-c58ba68c0bd4}w64.sys
Soubor Smazáno : C:\Windows\System32\drivers\{bf34199a-d8d1-4010-b9b5-fa9597e3123a}Gw64.sys

***** [ Naplánované úlohy ] *****

Úloha Smazáno : globalUpdateUpdateTaskMachineCore
Úloha Smazáno : globalUpdateUpdateTaskMachineUA
Úloha Smazáno : ShopperPro
Úloha Smazáno : ShopperProJSUpd
Úloha Smazáno : SMupdate1
Úloha Smazáno : SPDriver
Úloha Smazáno : YTDownloader
Úloha Smazáno : YTDownloaderUpd
Úloha Smazáno : Microsoft\Windows\Multimedia\SMupdate3
Úloha Smazáno : Microsoft\Windows\Maintenance\SMupdate2
Úloha Smazáno : e0e1bc9b-45a9-4509-870a-a25c90106aca-1-6
Úloha Smazáno : e0e1bc9b-45a9-4509-870a-a25c90106aca-1-7
Úloha Smazáno : e0e1bc9b-45a9-4509-870a-a25c90106aca-10_user
Úloha Smazáno : e0e1bc9b-45a9-4509-870a-a25c90106aca-5
Úloha Smazáno : e0e1bc9b-45a9-4509-870a-a25c90106aca-5_user
Úloha Smazáno : SPBIW_UpdateTask_Time_313834383936303337312d23787845322a5b3434322d57
Úloha Smazáno : UNELEVATE_24962

***** [ Zástupci ] *****


***** [ Registry ] *****

Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO
Klíč Smazáno : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO.1
Hodnota Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SPDriver]
Klíč Smazáno : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Klíč Smazáno : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Hodnota Smazáno : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [YTDownloader]
Hodnota Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [YTDownloader]
Hodnota Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SPDriver]
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ShopperPro.exe
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\YTDownloader.exe
Klíč Smazáno : HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SysMenuExt
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\SysMenu.DLL
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe
Klíč Smazáno : HKLM\SYSTEM\CurrentControlSet\Control\Class\{0014298C-A9BA-440D-AAA8-AD12C7010EE5}
Klíč Smazáno : HKLM\SYSTEM\CurrentControlSet\Control\Class\{181A06EA-B82C-47DE-B851-E20FD0E1CC7D}
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Klíč Smazáno : HKCU\Software\GlobalUpdate
Klíč Smazáno : HKCU\Software\InstalledBrowserExtensions
Klíč Smazáno : HKCU\Software\ShopperPro
Klíč Smazáno : HKCU\Software\YTDownloader
Klíč Smazáno : HKCU\Software\YorkNewCin
Klíč Smazáno : HKCU\Software\HighDefAction
Klíč Smazáno : HKCU\Software\ArenaHD
Klíč Smazáno : HKCU\Software\Cinem Plus 2.4cV26.05
Klíč Smazáno : HKCU\Software\AppDataLow\Software\Crossrider
Klíč Smazáno : HKLM\SOFTWARE\GlobalUpdate
Klíč Smazáno : HKLM\SOFTWARE\InstalledBrowserExtensions
Klíč Smazáno : HKLM\SOFTWARE\ShopperPro
Klíč Smazáno : HKLM\SOFTWARE\SmdmF
Klíč Smazáno : HKLM\SOFTWARE\YTDownloader
Klíč Smazáno : HKLM\SOFTWARE\YorkNewCin
Klíč Smazáno : HKLM\SOFTWARE\HighDefAction
Klíč Smazáno : HKLM\SOFTWARE\ArenaHD
Klíč Smazáno : HKLM\SOFTWARE\Cinem Plus 2.4cV26.05
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YTDownloader
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Cinem Plus 2.4cV26.05
Klíč Smazáno : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Klíč Smazáno : [x64] HKLM\SOFTWARE\ShopperPro
Klíč Smazáno : [x64] HKLM\SOFTWARE\YTDownloader
Klíč Smazáno : [x64] HKLM\SOFTWARE\YorkNewCin
Klíč Smazáno : [x64] HKLM\SOFTWARE\HighDefAction
Klíč Smazáno : [x64] HKLM\SOFTWARE\ArenaHD
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\globalupdate.exe

***** [ Prohlížeče ] *****

-\\ Internet Explorer v11.0.9600.17840


-\\ Opera v30.0.1835.59


*************************

AdwCleaner[R0].txt - [13379 bytů] - [20/06/2015 08:57:55]
AdwCleaner[S0].txt - [12393 bytů] - [20/06/2015 09:01:24]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12452 bytů] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: ShopperPro, JsDriver, vyskakovací okna

#4 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět