Stránka 1 z 1

Prosím o kontrolu logu

Napsal: 30 zář 2015 19:38
od Peelie
Zdá sa, že mám v PC nejaké podivné súbory, tak pre istotu posielam log.



Logfile of random's system information tool 1.10 (written by random/random)
Run by Martin at 2015-09-30 20:35:44
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 27 GB (24%) free of 110 GB
Total RAM: 8154 MB (81% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:35:50, on 30. 9. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\C544AC00-1443634994-11E1-9478-5404A62F58BE\vnsi362.tmp
C:\Program Files\trend micro\Martin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/?type=hp&ts=1 ... xxz2aky9n1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oursurfing.com/?type=hp&ts=1 ... xxz2aky9n1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/?type=hp&ts=1 ... xxz2aky9n1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oursurfing.com/web/?type=ds& ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oursurfing.com/web/?type=ds& ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oursurfing.com/?type=hp&ts=1 ... xxz2aky9n1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\RunOnce: [Update] C:\Users\Martin\AppData\Roaming\VOPackage\VOPackage.exe /runonce
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ihpmServer - Unknown owner - C:\Program Files (x86)\RayDld\ihpmServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Firewall Touchpad (lukyquvu) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SSFK - TODO: <???> - C:\Program Files (x86)\SFK\SSFK.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 5784 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\RayDld\ihpmServer.exe"
taskeng.exe {C8895CD7-2FD1-4CD5-BB38-248C9F580958}
C:\Windows\SysWOW64\DllHost.exe /Processid:{FCC74B77-EC3E-4DD8-A80B-008A702075A9}
"C:\Program Files (x86)\C544AC00-1443634994-11E1-9478-5404A62F58BE\vnsi362.tmp" /qualify
"C:\Program Files (x86)\C544AC00-1443634994-11E1-9478-5404A62F58BE\knsyE06.tmpfs"
"C:\Program Files (x86)\SavePass 1.1\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-1-6.exe" /rawdata=KvIgkD+SwrCbfZGTQsJZaoX+ZlaKbhRwNLXpKOPR+uOPXuPZOAs3zXBUL93RU5Yq1QNudtTs3uYjEQXj0zWvw+uLZtluInHtffHdwL9+BVZf6i7DC2D3uDDWu6qzUS84M7Pj1wMfg4weexPXcF14/Qt5BxKcIZBg6OEsSlHHeTdUH3Ru48xPmD4mzW2m22C6BlwUkeklrorlrF8v3zaoP73Nn60c+hLFr7l/N5RF/GTwiLff55k5dnEr++23dnvaeFEEefKaHBO0FG+xRkDJvOoJ5GELjKnPOl9Z3lQPb4iPpmdc+6oJD9YeuE+gKkCVyWF2l4FcVKUwsJb3ZBfe1yBWuoGb9zHnEXBrEqkuAcSqjqe0XGGKRc6p00j7s++GqYody2LbdrxbADZ/2+XlapmTSl+adRLRn9WfVSxKE4zSYg9CZVGlgGnsOFbqp7qXHterdtuGCiqJr9TYGq0dAg3chE4II/SpeTlftwqOdDQOC/2MLzpgHpXDRYq/TOj9BR5QQ294yPpfjHGQziZQO8I/jYL7vNw8NPyIvbSCpHYSv7wbj8Mn9zgTy3z/UZ20i7aSiknUyIkby3+nDPN6z79jaNiAnFQibWzjgri4hIsVZp5rhQ4/FScmN7+C5v2AzQiPoWv52LaIfFRraA77XKmnTggR4br++U9EuPPxS0U5ojBfj8UggYTYBPt01IIfVT0DST00IjhWAt027gOk80b6Cr4JKSYBZ1Tdxw7Um5lXeXNlYA8+gpYELzjDbbDv/nlGoZNhGYFV4x+wU+P+NPwW2ba38+bbmsAX8WHwogv+2S7JSE0Kckw9WhemyZcjp8hP8cIdD7G/qOL3h+SIVZIIG+kRRcUUtmwZPMweiqVNAnoWdrn/aAu1MOIda9Y+DkjQpK2dP+Gr5HFYeNX1U5Vus5equTdsvA5kWFAHvO79QOFFXGMJduSC7R43EkpGm5do0Ef2DvLJ8zygsNFROYQ7pqu/qtqj7PgBA3uX0LoKMIU4svadWY1XIXjUScYwfI9c1Yowf3csfMX1WC8/04B4cvmr84v8j2ydL0RJyolR+IIn01+PZdM7nAovGGzSgtnk3NMT3Tzxo0519/C0tPVaxcg3UwY8oLQVuu4HcOUbO52BgKVJZ2KSc4OGv9kfC6CsuTlWJiXlnAOc2v/+FHtMC+c3SdaDlHqLvq8YAhgalptxpcI5espxM/Oil62ePKk2y3sBVP89nQEU5l+z5j5GpuAKvhXE2JzSnZ4sZpU9v9JARSahqQsCjWtkswHZMTszFRwjPuEgptcTMEdjFpQ9wH5bbdlGZbnLxHoMUEZmglueB7pn+53OmCuNo7e+BOBT/2pvhd8x6cQbnxfHsA==
"C:\Program Files\Concom\Concom.exe" /s iid=4931950 did=Missing sid= ref= id=5ac347dcb07d97f3849320e725d593ab4ecb5ec3991b2ee9bb52a2b13f03aadb
"C:\Program Files (x86)\CinemaPlus-3.2cV30.09\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-1-6.exe" /rawdata=deCoxqjIMDLpW9s+41F66mYzZ9cW9Xnfyb7e7Jkhlgzj2DHUXxvTyAuU6q+6QkHDujTAbVrymA7GKyCVJ2ZqPrEcajKnlG/xWM644kzOkG1LBTp8zx6f3Pt2L+vIOYJ8lWrf0ny/xiRUXCaZaLezH0FKMpsrFlxdv8v17+CsHxVO5mBnihg9PR6XPlFYxVQYoMH8d6n1yBbtAGtg08cbmzIrVEoF6o1hjlnd6KIIZ6XStGDw73f7R3RuldlQncRM3wd1AJ+WOw45tGgT7EXAFqRy23n09Lf9XKY8QcRPhoCA/r+D7krdspIEYI1tWPUZmY+9rVVBmdNOlpEk6wJXEAkQJHfkRgJxyTBz6OYPZ/NGZlNrJTrw9yncEiTd08QZ/xQXk32umcsXb7KBjmLLTlqToxVO9FEGiBK6BVyu8QHBg0FpOuJ9v2Uvwr5ZU6BsKj9YgT9xoxPqpuo4KGl3yIqInjhGi5OYrjuL7KkHpHYVc3rwd2W5WMXMmWFVYZiRR+DTlEW4wF1TVO9sbcj5TUm/WWZdRHyw/29C8MBIx6cwP8ToZm4RQPWOVZr+UYzHGfiu0Q6WE/J0uY4EBGKcsx+AoltGVtKpTrtGvUSCmTP5x/Cf4JsOn1eOtVKegc5Z1XPtNvs6ElJSJPTJl8zmYALWyYfzMU0IP22JOSmWHBEcyNVEEgnp1qF9URWNMtpBYlCfMTc93RdlQ9ycHGUR0dRnV6XVrKc38bLJxyfd2/HRN1OwCMwnJ6It+boKjaxALNTRCUElBguyVypTosyqFFnNFjW1SkxW58IYgsV9IMcXLGe0RfCn+JOn6U1ZSu5RCfTyJy4CoqUtXVcCx2msM2mxg4t9cXpFDvBV/h6WuwNb5vG7B/D1bPldNIkkDWHmhDJOiJ0YMUUlrGUShw5/TF9W3RcddIkVsmR6JHggbrdomXkHfnY64BEo3LR/H/rcDDGMQTHYNKq3jnzdwbylwnVM1xtgyL0yTvGktIPQnWfx8lTx/V5nzy8RZv09mOudvKL7aGMY6EoE6yiyoMPxVsU4VvXC6BfJ0JR1xbIuWGg4TlKWHZbd9N6ODnYestgk0qgF26mCqPWXFeblwStr/8HjY37w4QPDpJ/5cCCaJZ8FE/VNxcKXRLLFAhs6ZInzrv/ZGoAX28sl5SdXDaF6v9BSEdyl66K9lJIqIL6uXl1LJquIt9AqF+fkn/ZPHB4QsYtWDnsRxlcexMHiyB2w/FbJrGInYZ2QAc9ztwLt8h9VmcB/idffqhDRJh8rbakFLYTTjkjMz27QVqReIpBleg4f0rzfOkZLxebqCI8TM06AKM7GbW6j50PgiBQSqrw7Qxr7qNP4I3xovhVC41XdWg==
"C:\Program Files (x86)\GoHD\ebb06a68-202a-408c-971d-112055053eb5-1-6.exe" /rawdata=BGHonoevSdglMmGp+1P7nzSI494vV33cC7V/rngOXAEmKDoZBDO3f0+PW56jU4JY5WcMQ5LwUaZ3UIr9J4sSZ7XkVQOrkTZxtOGUWhc3Y70keiWzeZxv9ceU2F9gowV9GwVD/OsN4/V4ssZQ0nD85GtQ56jcI8VYO2IBJhmuiySOpjL6HwWrFg6CA4F+z+2IVEjBulsWc7330qh+GzqNALSmyWMfFY9WyZnpq01odqQ55WJW7AEggjSOuOpHxwKZR3eEiEhYiGgTF/gbmUlynFYllw99kABMdjp5gl0fWB5JS74zmgmUu5YsvmCFAW8sha1N8PuWhGrTweRo0K2Vq45/AVbmf14LFzoPgnI9XmXoMDP6YacmAmvsi5ckenHslCS0gsENz0uReIfmwkykoZrbRp12mkm7OGLabwXr5LmoMKr2Qx80c6ahWoMbDvRf4zWXNAM803kY7UHo1SOFnCJY3qXTioiaLrfyxd/IOhZZOHD4+NVpYG4jvOvrA98cCu0lasf5qXfcMUA+9J8shqnbCdKCqi2t1YOfCzgUSs/h0bP38cb7AexaNz7ClFA8SKj6gLGp1qsoRANysUI5TV/XSD2vkvyMxzCqV2zQNxzm0w3P5i+YSTfqhWjadma7kp7EdeMtNC6FW8prQoWZdzj3tp+d51BohItTQNcRFoaq0lqeZia8QfGnEijq0+zVJq7uKqTP7YVhSmg3r7Tl5u8M6n8M9DL1/ONwmo6fB8KQK3rMKZkCjR7zJTEP4CBwNIKfSUvqKeYoZ1uqWQpob+ZVMw684EeTY64WfA8/qLIth8d0o9ExZQPIQFKe+Bqav/ReZW2zbhz0YK5pJ850nYBjZYKtITnFvvfT22tq7ekZxqX0wTmdaOcj9eCqSQbwUq7pnNtVuPL5UdQ8ofPIdy7NTvZJVAk8gv2vlCWoQXXHstqBOD1ZDjfsQRwSzRER1Yj4dpCzRVSQCLvqtt8d3m7810xUD8MOzZImKsMZ43+GZnW4qLZqs9XukVKDLXwoWBpVPQaN8QRlDVgjoWPUdXxXB/LhqXM2RVIVT7wIps2ckrN3Q7540lnO1bzZc9G8YK1fL+AfMsxW/3umfBOj+Ht9/6kgHFW/SD9VKEOS0N5us2DRt8LkEm/SnXLEXwAGVVzE4JVwtN5cp6peujE1Quv+ozsHkU/jiekb95f8S3qnjrZRr2kkfTWbl+HkFopkw57b56+RlQR/jC8TiisyzIi0GXSxRtjIwPmesJ4JSkswGCo8y55XMOmczWNBAHY4U55msQrqLq9kldUvQpOUU/KjNzM0G4hBD5GGo9PKW1d8NZHfKa2jdOskPJSNlEiiV2eF+T9hdyFtit1MK/v5rw==
"C:\Program Files (x86)\SFK\SSFK.exe" -s

C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Martin\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-1-6.job - C:\Program Files (x86)\CinemaPlus-3.2cV30.09\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-1-6.exe /rawdata=deCoxqjIMDLpW9s+41F66mYzZ9cW9Xnfyb7e7Jkhlgzj2DHUXxvTyAuU6q+6QkHDujTAbVrymA7GKyCVJ2ZqPrEcajKnlG/xWM644kzOkG1LBTp8zx6f3Pt2L+vIOYJ8lWrf0ny/xiRUXCaZaLezH0FKMpsrFlxdv8v17+CsHxVO5mBnihg9PR6XPlFYxVQYoMH8d6n1yBbtAGtg08cbmzIrVEoF6o1hjlnd6KIIZ6XStGDw73f7R3RuldlQncRM3wd1AJ+WOw45tGgT7EXAFqRy23n09Lf9XKY8QcRPhoCA/r+D7krdspIEYI1tWPUZmY+9rVVBmdNOlpEk6wJXEAkQJHfkRgJxyTBz6OYPZ/NGZlNrJTrw9yncEiTd08QZ/xQXk32umcsXb7KBjmLLTlqToxVO9FEGiBK6BVyu8QHBg0FpOuJ9v2Uvwr5ZU6BsKj9YgT9xoxPqpuo4KGl3yIqInjhGi5OYrjuL7KkHpHYVc3rwd2W5WMXMmWFVYZiRR+DTlEW4wF1TVO9sbcj5TUm/WWZdRHyw/29C8MBIx6cwP8ToZm4RQPWOVZr+UYzHGfiu0Q6WE/J0uY4EBGKcsx+AoltGVtKpTrtGvUSCmTP5x/Cf4JsOn1eOtVKegc5Z1XPtNvs6ElJSJPTJl8zmYALWyYfzMU0IP22JOSmWHBEcyNVEEgnp1qF9URWNMtpBYlCfMTc93RdlQ9ycHGUR0dRnV6XVrKc38bLJxyfd2/HRN1OwCMwnJ6It+boKjaxALNTRCUElBguyVypTosyqFFnNFjW1SkxW58IYgsV9IMcXLGe0RfCn+JOn6U1ZSu5RCfTyJy4CoqUtXVcCx2msM2mxg4t9cXpFDvBV/h6WuwNb5vG7B/D1bPldNIkkDWHmhDJOiJ0YMUUlrGUShw5/TF9W3RcddIkVsmR6JHggbrdomXkHfnY64BEo3LR/H/rcDDGMQTHYNKq3jnzdwbylwnVM1xtgyL0yTvGktIPQnWfx8lTx/V5nzy8RZv09mOudvKL7aGMY6EoE6yiyoMPxVsU4VvXC6BfJ0JR1xbIuWGg4TlKWHZbd9N6ODnYestgk0qgF26mCqPWXFeblwStr/8HjY37w4QPDpJ/5cCCaJZ8FE/VNxcKXRLLFAhs6ZInzrv/ZGoAX28sl5SdXDaF6v9BSEdyl66K9lJIqIL6uXl04NPtlQvR2YXRPK8+XoHSJxpacPJRPV5y7aXd7eNpXVDUe2BXpsDuxq9jdYbobPevbouCd59NgilVqc/GosqIuFYwLipkCCxx9xd2kxIc+vj1aSgbSHPYbg5ugJODPWQDJtPE3QvyxAgUs+TP5P2Y6w2CEJqVnp2ufg8NNuhEXhA==
C:\Windows\tasks\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-1-7.job - C:\Program Files (x86)\CinemaPlus-3.2cV30.09\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-1-7.exe /rawdata=Tl/cmmxw2bzV34ZhPKszboLaPMT7tQrCOMQB5B3dcUwrHcHWXja2nCehZ/W7als2+8RAmPdBWxJOGfLPKXEKR2fFxjsGn3FhUP6O89JzrubvcQFhO2aGnCHK+j3EHh010Q3APHOd7TDj99aEEhxh077CIIGt1Q7vizTvjIGafzhG5LjFQXN1KsQVubPuqdmwXecdi3KcVn7SVo/ZTRILyIMLVu+IyvBgQrCj0yaNpq/GB6L1P4jhH9nZ9xFRr4e3Mc+jKcBazfJNIKD6C1vzzpmILRqjW0TVmGN1+KfTuC+fHjQ7GP/JLeih7SPEc9+XhQf0kTgVgpF69s2t+FaFfiYqUWo/ecA2/3wHA/0kqNJNJp3nNF/YLilQtqM7MvRbcdAbW30qiA0q+3GuLx6x9u/bYl3j9vHBSVq+satqm6bJh/0PivfBkqQd7/emIwZBWJNFr7jMESkyukNcr4lQQk0+cRGnXXlzBs+zYgpN9j2XfjQC3FG561XPdPmTyV3sHCj2mGsP26PumDgxWESPPnhskRmrOlxmvkFpr07F4n56uqGL1rpxzE49yUuR6HJ75542X3pXOrug2QTHtLm0h6xFNBYFRmuXExr1fAgZow6r+q1lt8YPlEPyFF2HZWSP0g0AhcIy7C310Nk60H8D4hL1rZGR2vSdVuhJKdiqJv1pj4FEVdrzu9Nas4XrsH6trj7x0UCdPp/adpcJzlVXMyCfI9+GU18iLAQS/4BG33z1lDan1ONdEmmi8rQYKwd0NApPD1sGTq3kkyW5PvSlg2CozJ4YXFv9FyE/sxRlbggMdgy5i3KP+rlXslI86Zsl2LUXyAQ23ZmJn/pY0OswWkBzF7DH4awt/YkjXN94kgdXD+SEbWD3pylC1eraNKqM+Qfka+wlx3Kb1J0Jyr8YdsBAB58MaB9S1em69NkJk6oay5HJczyHuyDNKptK+rTjT9pbVvn+uBa/y1TYEMFoQ+J/8uSSAJVCQEYGVEalwCLg10kJHDMDizLdfTeNx1veENXLlrq0F3JOpkAIe8XBA42t2/AbCEYiXa4O/RJCaDIWojNIZXOyZ8uOAP3mFXWdqmRSCr26KiWgBaq0SUhdHr6Yici2wHTb3bDoZJcQn1yBpVvc5c5trdZUXNycYYJmMx5rvvNtI2lgTLf60KcdIX6gjq6NKXU3Hc65smNMLApgAKLApwe98aYPPnG1c/J5Ok/RUY7DnpZio5PF0qqST/Da32SkEpcX5PPDnhkeYgTuS2ils9VRmQvAYiG1J6+tq4GxOLc6x60EgyNCtbAZzp4Dhcaisp0Ze8EPg3W9/EOgNnM6pMcoMkf0JpvHMsnU3cwCDyhWNMiWUwP6IN63iq1Zbl3xDDjEQWduG+/CgQfa2P3VtMN/6shzJkZ+Eqw9SE4F8CEv6y2r91u7UISKlBawVvRowkudNqsdjFjQfQ9L2YjN3Lopq6lLUknh9tkav381CkAVzsJ7Ol4wZRZfzfHzjOlTFBAUwUH57Wy8U6sLb0vHOKJ4OKQHzZvmsXKQ
C:\Windows\tasks\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-10_user.job - C:\Program Files (x86)\CinemaPlus-3.2cV30.09\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-10.exe /rawdata=KU3gWYfTZ7I0WEF9Msc8NU/btwVbWeiGYdgAWRU38Q3FTpxjXwlTvDyD2zl7XKFkmbmdCki15yC0V3XyDVZWq4lfUo43sYs9QYyfO+4CRVtJuDDOI8OlxSGRlBa/k28gd8yZDQggPEII6BDD1GZSZSwU4v2ETSPO+PYRNJaBH39OiJ7zjo9EfPE1cwdM6kZq/NvIzya7CUA0g499PQ7jvvhSXi4zI4plDvzO8uN680qSk5Fc5uW+afjxmQZ+cJC+VavZh4MnI/ThJATcYt2PPIKU1KabombTRfb0zYzBaLrCOAuWZustV6Fb5P1jjFl0Odgdpxk3tvK3z1MGOuykyMRHQ+6GG29JaDHAWElF8kbx2y1i7pencGKED4xQS5k6gja6Hgx5M9w+CZcEamR10Nmgbc01Ino/+Vbi7RYnIkoweRa5z7TkiUStEjtDcYabE9ZCJGveWXIXshAoBa0oBWsKdqcAEpV/3hdxCBLcmuQaikN7S8+iXLmembra7V0CmcpyeeSDb+pQoD3QCtG7GraulxJ3fEBGBadQ42czL29uZMKzmuRHU1aZ0r6oMYSk9cO+V3LlfGU4JuMJq3QLzoix2Due29VeabGjW0Ws4DhlFDHmuMM+W68Ykz3Qb0JlWpRlSnjvI2rcTK/n7KCH+vzal/73xkWrJIQM/7UDZPe7iLIbtDqgt/DmaPukpuQJbvDkF79Jr1Fz/2cNkudTc7dY/hQSAImM0s6M49c9h7SXTaXwT2l25P9RciNwQVa1w+5s1hyVrz8Wuscb6Z0luesF6XpViUTmQW7YZYt0hA7rwagP3S9qS8q0cfEHtem5jloWm+hXW51dzQY5lScA7Q==
C:\Windows\tasks\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-11.job - C:\Program Files (x86)\CinemaPlus-3.2cV30.09\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-11.exe /rawdata=cVaj0Yoj2lcQ8OB+9ak6q0uJu5zKwPLEbT9TXwFeGwW7s6126QxyU5Q0R2+0C0D+yKa5vT4fEV//jlKwoRIYvJJKkaApMGMDlJJn+Hy8fsIIXXd0mD4qiEN/fno0LXtMDukRj2eC9e+tiwzfVVBeYHqBrWgCzkEhJnVlyMJg/nSpjMDINhfxf7zyGrmlD75L2LVzAhO4u/OuYAbEsub9U/064vP54AYnzbqHH8Fgr8ZFQPSZ/P+00Bh1Zl5E7fNXdV/kixTF5Awrxo5hcE61P1GSGxjtPBray/DfHim4bkI5yAf6yYzmy4amHzFGqP/pWajw2/b7f4yNdPAevy2lOabG5z/MqqQ6s912GMcLFncJofNph3mSD7XOdIsT+DGlgQdPazf6E41RkYMv3OwDIcXzpyVdDrGLqVWOXrap30shh337ss9QtbePRcjPXLMnAa38olbTRN+ygSaMUJ6BIVfcu6u8P+AZcW2l/hsmxK4+hfnU4Q8a0YZiiXvF1/5Hmr6OvAEwxvThaouQbxfHkgzujPxMZCQR/Xke1YAehvJoMwEYaPzBixdXScGGnVAo3GGBkfDh4AcaXe3C2bY2bH+yYFNclcSKTM69peRAn0+Sz3tqvnnIyIVG5QEMX4i/6LKGtlqQx+NfFaPo7e5TmyyZuOeSHKIRp4YvdYS9qTO8CXbrh2MPfsNmno5+ThIwL2q+2Elk0tSBrBVvueh6mhepRI7RP50IrnNFuDN+Nb31WJB5jT4//azuib9AEvELmua0JUO5oSSgZqDrqAiZrTEDWyoqB0WnS7sYpEyciamhSvvVKHaL5kZ505CeX5bJ8cYwPEiZq4r6HqBvCI7VjaHGV57rZNxu8Ql01B3fz1Y2osVZ6xUgCVq5b0RNw1d/mVXDx0l6AXPSziXRhLoZZomh61zdP6G+9wtAhA/c+A8lkHSA6BvFYlZQhYzQP8HNTu/1rCx/VsIlooGfPMF3YwWt0uu0Yz6KX0iSlXGB6r+Cpb0QwiGSck2QV5FNgA9OfSJBQQmHjXCsp43j2JIiV2l527fl2GqA8ReGfFjlbLtUiMFBuzdmnIo3sTPplOP515rNB6mHl4wzTxmHO65CrQb0iNHw+ZHQcroW289IyPpx8WgRHT6VIWyRad+HXF5lvm8zW8Q3OeNKLULKLDVlrDjQcwPnezrulheQRG5J70J42uFwSsnYynF6aLnLhynF0m8Edxs9hGC6JdeyU6U9hvsmkxYIxhw567Xhc+a6p005vkMSqQlVwJXUoQUgSNm1N3XD+09nNYHa14/eSLbyiFxLrD7H1/8RsJn9eOmvE7k79+Z4kKu7Z+u7xyUoSUMNaU0RXaEP+FTUmQp0ZReyYRjpXHw7PVzr8yfBLQO5vtMqQ0zTQGagAhKWoseqtIp/ymklRxy8riy8UTf0YSfzFv1exBP76q50I9rx4z1cSuj9BG7a9HZQSXFw6urL2oIyvkJGWbqSqdtzXj/5f3EpCcBk9j4LXcdwS5BOZuki08FLcxIlnjBqtiqa92J7gnrwjINbVNWmCeOkHguartH2fd7G7QrRvqP82/Gu+G/XI/tk/aq8VDiog8cxDbSlX04uMPQ600TMmpxD69EPiwaLUnY7yysjLe13hP+fHbe7Zruks0yyL9CiZxC54AwTHlGB6XR46chG98+AmuBUBdeqP+HevlSAwElnL+tyOivA9VcxlOra9Zc/fIqIY/0AekDTNuWaBDKCOJfPl4VK4zvQ1HA1Z0C6UUfHEj3RIkNuMQYffuZuEgjGWL891R6+AwNWMj7IBd36ZEDLT1EEhmnFY29hqq2WZKZAlOqciRzSbrycmtQ2wd9x60gTDjiog8/+7qLpPi2eSIj32OVtKcHKgzp+kT/MtZtzBteB90Dl9khsKqBM/SYdQuccgPRbC32gT0MGZdHjk1NIQaFup2LMABMgwB/RYB7E30lABMrrNUtP37mzqpqbvSsFSajXo+h0YAPVHUAtWqchSxSUVUbmhyF7qELJb48FRleV1h9b5BK0HgLVY7NMt2LJK/OViK2SNhWKcYP/GnV9HtgvML+EW1tr67diWpAgw2z27RKpA3WOSLQQMtH8dCsKPpy/BulIkEjdJEy/5UajHWSXWnTQ2Aqhdo00p3MPt0wmh2Z9NnqfzJRf4t/VSCjsqBPFaNOq+K36N2mdVEEZED6WLZsd01vS/So0AIC6eQXENdLYhL1jq4WgPv04Fyqv0aATUxBpFtNx+T2BDSSD2T9UHO1S/nTL6XXFbNorj+OW1/Qu/rPCoCFNlkpx9MFupSc58rhGNgqPyzVSgDprbBtRsIg74JBKzQ5doFICCQbXYuk9Bc3/8m8pa6xtB739mHGshxSKM+LFsa1w/l3Vz0OFxQ8+Pw==
C:\Windows\tasks\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-5.job - C:\Program Files (x86)\CinemaPlus-3.2cV30.09\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-5.exe /rawdata=vv9/BJ+GY9IbkYiEeQt+zEJ1x2w1H1BybkRz+ikYGC0sO/5kr0qYQfy4sv+5d5L2gJeOJ2PLpzrABoWE2MVSrZDapuDIN7QkCPaj5Oh6tBbDaWlEHgJoKp39pO5zRt7J2LPJLrCWxQKgmBC4cekoBn8EYk/XQ2j2z5UYfHdgX1Oy9j/+8fXxcy92Ld+iBjw4xtVmwZ6OreiKeihB06znIUubJhFi4YyQERDqE+dKsTRdSHcPtqXe24ZuYA/gTeAkaWChL8DL1l2lHruO6hXf/5dHAVQ4cFxFwyq7RO4kUn/Aj3CuedMOoNftxiK0gCdmWXYX6bog2fAkcKMEUBBEXxZDN2i7k7NqLZDvoEzK14XGfz0K1di8EGoLfUe3uPQVSMwkmxnjDpcsbczwAND3+kXFooSxnOlEZek7l09R4cvPUr+AyXKy6z7/bhlDJNJSJzUMmkiyom0bW6tvXQlD1mf0n5AAF1MjOQpQwEljapzyGpEUzwKYc8FekUSYO6LmVJ3NQZxqt2eqTksKscashsZk2DYTDu2LVfsCqfP4yYK4kHaaHcxJUmZP/GPCyo8ylDmctN64FOAxHNHtA/M/34KVn1R7M/r/+U1RLrtKIlydub2sSCj7I+UEpfiEAVi2OSirptek5G1CT83Zhnx7qvrBapVz/INcL42HlpAJHG8CpIdIdrNa670LzjL1aHCF/MHJXTM/hTOVw55Pc17O4Tsyun9Hl0UtxnuAGbwj+beeNDCt6oChSSvTeSBpg41ZsAKDjWbEvIBiKT/EWm/9m4A+DuqqInkgkS7pteA21KSjvIcFfnflqNbj19mFkJ7cgYzjKai97/ofdxs40sYuCpoel/PDLiNUIMs+3skkr0vHTa6b3P2zKQK671jVlWmBMaAnqDEonlph54m2xLc1EQVUTAjwUgV67nyUWNG/K0zErVppVrNUXQWDG+DNwUZ57Oqr6qFtKmaQZ27jHLPKLF6UtmNWhE2j8ZEaMNnc/bqWx9rejsb1+v3O3/LLX+wl
C:\Windows\tasks\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-5_user.job - C:\Program Files (x86)\CinemaPlus-3.2cV30.09\29ffc21b-d8f2-4d5f-991e-086d6c54ce38-5.exe /rawdata=vv9/BJ+GY9IbkYiEeQt+zEJ1x2w1H1BybkRz+ikYGC0sO/5kr0qYQfy4sv+5d5L2gJeOJ2PLpzrABoWE2MVSrZDapuDIN7QkCPaj5Oh6tBbDaWlEHgJoKp39pO5zRt7J2LPJLrCWxQKgmBC4cekoBn8EYk/XQ2j2z5UYfHdgX1Oy9j/+8fXxcy92Ld+iBjw4xtVmwZ6OreiKeihB06znIUubJhFi4YyQERDqE+dKsTRdSHcPtqXe24ZuYA/gTeAkaWChL8DL1l2lHruO6hXf/5dHAVQ4cFxFwyq7RO4kUn/Aj3CuedMOoNftxiK0gCdmWXYX6bog2fAkcKMEUBBEXxZDN2i7k7NqLZDvoEzK14XGfz0K1di8EGoLfUe3uPQVSMwkmxnjDpcsbczwAND3+kXFooSxnOlEZek7l09R4cvPUr+AyXKy6z7/bhlDJNJSJzUMmkiyom0bW6tvXQlD1mf0n5AAF1MjOQpQwEljapzyGpEUzwKYc8FekUSYO6LmVJ3NQZxqt2eqTksKscashsZk2DYTDu2LVfsCqfP4yYK4kHaaHcxJUmZP/GPCyo8ylDmctN64FOAxHNHtA/M/34KVn1R7M/r/+U1RLrtKIlydub2sSCj7I+UEpfiEAVi2OSirptek5G1CT83Zhnx7qvrBapVz/INcL42HlpAJHG8CpIdIdrNa670LzjL1aHCF/MHJXTM/hTOVw55Pc17O4Tsyun9Hl0UtxnuAGbwj+beeNDCt6oChSSvTeSBpg41ZsAKDjWbEvIBiKT/EWm/9m4A+DuqqInkgkS7pteA21KSjvIcFfnflqNbj19mFkJ7cgYzjKai97/ofdxs40sYuCkn5pXplfCl6P4o90dPey+C+kCO3c/ct7YZout/d9KIjBj9c85FP+/s0eeIQtIZVKGMnVGdRjuPyr4P3SEmFFMN7pqurC1NSROcS0050zjcpveTVkY93SvUVJ7W8N2HmdWRasR48Ur9QdrLAg4PjI22SpQafwnqP20fHDYyTl9p1
C:\Windows\tasks\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-1-6.job - C:\Program Files (x86)\SavePass 1.1\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-1-6.exe /rawdata=KvIgkD+SwrCbfZGTQsJZaoX+ZlaKbhRwNLXpKOPR+uOPXuPZOAs3zXBUL93RU5Yq1QNudtTs3uYjEQXj0zWvw+uLZtluInHtffHdwL9+BVZf6i7DC2D3uDDWu6qzUS84M7Pj1wMfg4weexPXcF14/Qt5BxKcIZBg6OEsSlHHeTdUH3Ru48xPmD4mzW2m22C6BlwUkeklrorlrF8v3zaoP73Nn60c+hLFr7l/N5RF/GTwiLff55k5dnEr++23dnvaeFEEefKaHBO0FG+xRkDJvOoJ5GELjKnPOl9Z3lQPb4iPpmdc+6oJD9YeuE+gKkCVyWF2l4FcVKUwsJb3ZBfe1yBWuoGb9zHnEXBrEqkuAcSqjqe0XGGKRc6p00j7s++GqYody2LbdrxbADZ/2+XlapmTSl+adRLRn9WfVSxKE4zSYg9CZVGlgGnsOFbqp7qXHterdtuGCiqJr9TYGq0dAg3chE4II/SpeTlftwqOdDQOC/2MLzpgHpXDRYq/TOj9BR5QQ294yPpfjHGQziZQO8I/jYL7vNw8NPyIvbSCpHYSv7wbj8Mn9zgTy3z/UZ20i7aSiknUyIkby3+nDPN6z79jaNiAnFQibWzjgri4hIsVZp5rhQ4/FScmN7+C5v2AzQiPoWv52LaIfFRraA77XKmnTggR4br++U9EuPPxS0U5ojBfj8UggYTYBPt01IIfVT0DST00IjhWAt027gOk80b6Cr4JKSYBZ1Tdxw7Um5lXeXNlYA8+gpYELzjDbbDv/nlGoZNhGYFV4x+wU+P+NPwW2ba38+bbmsAX8WHwogv+2S7JSE0Kckw9WhemyZcjp8hP8cIdD7G/qOL3h+SIVZIIG+kRRcUUtmwZPMweiqVNAnoWdrn/aAu1MOIda9Y+DkjQpK2dP+Gr5HFYeNX1U5Vus5equTdsvA5kWFAHvO79QOFFXGMJduSC7R43EkpGm5do0Ef2DvLJ8zygsNFROYQ7pqu/qtqj7PgBA3uX0LoKMIU4svadWY1XIXjUScYwfI9c1Yowf3csfMX1WC8/04B4cvmr84v8j2ydL0RJyolR+IIn01+PZdM7nAovGGzSgtnk3NMT3Tzxo0519/C0tPVaxcg3UwY8oLQVuu4HcOUbO52BgKVJZ2KSc4OGv9kfC6CsuTlWJiXlnAOc2v/+FHtMC+c3SdaDlHqLvq8YAhikOCpFshvcJlQVH6sz3MstqywliEnsjyztT3mQIbZUlEfSChfpJ/62hMfpIdUNn0RfuF2x/886K9H/x0yPZFHGqG1zUQko9FnxSz6/E8u9p3v5McdlEt/euMPpepBhBNgnCRRDRjo/ULZs8U70Ris+CsGyHrB8nl+zQa+iAgkPRw==
C:\Windows\tasks\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-1-7.job - C:\Program Files (x86)\SavePass 1.1\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-1-7.exe /rawdata=pZ/Cl1lUygmovE205cFRbd1k3kKLPlxiz0lLQAN38fd9Wyv6Cl8DUPbmWfKkEBV6+qeQsz2IVDkzYKhQPNk6wzejBsiME9vPU9OdyhVKn8dHncYmntToLR75jjbIziREhpEOY+2kh5j31HSaodcYwHzG47ZTpLVAS0QBAwPUW0ymxuc/zKqkOrPddhjHCxZ3CaHzaYd5kg+1znSLE/gxpYEHT2s3+hONUZGDL9zsAyHF86clXQ6xi6lVjl62qd9LIYd9+7LPULW3j0XIz1yzJwGt/KJW00TfsoEmjFCegSFX3LurvD/gGXFtpf4bJsSuPoX51OEPGtGGYol7xdf+RxcOK0jXh5twA54kXnxqHCSF4/t3LbrOg3kvpjrMFGSqP3OEQeh2u6wkI45+dmkjQjnTfuUUTIyVhyBM9L9SWvELGxvhwmfXeII4uvyPLb+Qdaka+/QzUdtWk5a0VYPXv33g1f/Y3bBVeWUDl+irn+9H22/ksZbrDx9ss4JQnhOHXsom5sOLprGfdMWB0aht/y1kBVzEGNhLw9tHZaJYcNtiJ/HRk8gMhO0ZZUIzktTY/4+psb7CZ5Cw5P40vvam3ZPfDgvIYAHV6behI+4/X2XezMR1LbOaudroZdSXsJPrq2o4k+vK9AgZT6RD2AeWb7oM7usCZfkHnzFUrsul0aSw/yM80rvck5KyCziZVWWC7+pvadrcZ80B3oLBPhjIU+iO24aSS97iVP9RriHiZ+XFIZKANAUFuvquAzpm1QT+JoZqi1dDIaxFKAL4VNINamga0oX/UA2cSYmldZ5WNnuQvqAeRuExPGOMBz7kJ/gcduguWyJ4zchTaIm6YzWEz5HWSj5pybpVbHc5JU+7X/muy28TvMZjTblDrWqYr5WRR8BHtKDpk3897NoHbgt5+W1J1akNATghfC1ng7RIYM1rNlbh4qfqVRE77m5ySIZ5xEKsviBWOfr5rw7x4m9NCBzn/OjLSMZ//4WtS0gvZ/fPM08mXR7J/cOsoCvfiivjbdKbxpHbJjh5gFF9VflUC/cKjC5DirroVy/UzfbLmYP08xrfjpjO26lP6/ADE/8QIjbYO9mUmz/q2z5IzzzW3T49fD1eLtalW/jDXBs8irF0T6XawjQXGpUHr3ZbR+2PdmnEzUjD57K+FNVyIA2x3cyF9L9dGYElMkwgp7KNjQKPudzR+IE/ikNbK9ovkxq1f2+7cHUXJ1ZBdP0qOUeVVAg7ScJCZeTa5ov7mRjdvLHP3nYmMCexbOBtuMCVcZhJPX7d18f/n4GUlbsj8kpSYw1SJUrxubUtQv3UGa/3EiYKYOX2Sv3AnSjvZH0qbnMGJA/z4u7UotV5DAEVwoBGJrtaTr0qPKDscGPCMmUWp0UE2L0XRufb2CMBsMvNQRgWR3Ai8c0DqzXtgVUYzpNIsXjymeTVLY2oAAbxCN0TLtMDGZ1VhbVQkIxO8bubd43UPDlui4vDjnXaIdvWM9HTECeoJM2nBO3Bb7TVldVDw/r1ELHC75Js8ZJiAv8vhMuM
C:\Windows\tasks\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-10_user.job - C:\Program Files (x86)\SavePass 1.1\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-10.exe /rawdata=pbpwEOjtVFOcl4Ixf4I6QTnNinWXlaQ5D964074B2/sahhhgkUBTebjjEDxCosWiXLDsjkcDGhAQ+su2iUccdUvcukvadHPVpqTy/NOHRWAtI4rwO4p/6LcO6gBOq2l5nTUhoCoTjdXfplztgOugrBiqREgG7yh5KtfL3VQA4ohOiJ7zjo9EfPE1cwdM6kZq/NvIzya7CUA0g499PQ7jvvhSXi4zI4plDvzO8uN680qSk5Fc5uW+afjxmQZ+cJC+VavZh4MnI/ThJATcYt2PPIKU1KabombTRfb0zYzBaLrCOAuWZustV6Fb5P1jjFl0Odgdpxk3tvK3z1MGOuykyArJ8KT2uryZ7d2DhSi2H8VJcOZRoyz5dO6Qd+xVZ6VpLb6ZX07BYRB9pEtmxlglJr062q3aTXChkracJxBksixkQyLC6QTNFAGFcI6+VOnAxpg30bRy6H6kZ0Un0ddt/ZoDVxdgcxpaZ3TD29b29BHA7xVLzta/PnjXRxUxHHeXPyNBBxiAah99/tb53tfhxgr1E5lss5RX3Lz6+Z4Qw6rpNb4gNubn04F920/NyD30yplxLePaWsU03vito26uMyxcEdO7UtMDHyCWcWjQsY17w24jTeeLGzl58ET8PEBQQPbNmW31qwxKfDDUE6LHR0ghky8yvWtXdciWQyD6u01EVVrS4TG0dVMbTKn/5RCf7ke0MzV28huMjlXn3ouqc66eKlE4Bu3tx3NIrYAy321P8QwTpxhE9EkH3mDkN3ZMmG1CWNBvL1gZZplTCm+oU8ApQ86Lu/H1jeHHkppAkgOaq0v252aZUnijj0Rpv2sxh2npEIbgCnU3tVxWy3U2iw==
C:\Windows\tasks\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-11.job - C:\Program Files (x86)\SavePass 1.1\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-11.exe /rawdata=xIkh8sqQiqyM0heZWApF0swQpdTVVfPWsqcB5FW42jWYzhJpOj46M4PWSgYykih1KTQo/D/1BeW+kvlo5zfswBZKkSZAdcjV8dp92NSuVBQPCTLAPfTp+f07TWGo76YjVAGzkhO1qfnuKdVBZLTGb302jX19E2y0ZRXKu7t9oPEQMmuT+9AVSctOgVN88yVM4eVVmFHkXxSgJPYvcKhPqKn4wq5kjjK0oXfOgHQmiN9FbVLvlpbvsDOGVHFgu2kpW+33qNgW7/82m+DxEV4lvRrZcmqjGJudMFb6z9tFgAVWN74gyblXsFIgXIscn8x7qD71u0hkP3afYGFTHMouIU7mYGeKGD09Hpc+UVjFVBigwfx3qfXIFu0Aa2DTxxubMitUSgXqjWGOWd3ooghnpdK0YPDvd/tHdG6V2VCdxEzfB3UAn5Y7Djm0aBPsRcAWpHLbefT0t/1cpjxBxE+GgID+v4PuSt2ykgRgjW1Y9RmZj72tVUGZ006WkSTrAlcQvTUOp21taJMT6arAxvlAtLcP09fg4KHRVJVhsHO7EJXqt05IFw0bdUXp0os5mo+S6avNo6iLVwVxTSXlOyIA2jxHQZdxtQnTA8KXXOrg4IoXS/Q5V3HYtKRIh5uK9EJfHFLfS55mHJzUUc7IqU9t/7+n+9l6Wvi4RVTbSZnvksDAOicNabQiHUPjH7LCn1qAktHe6fvaZy0Meva8PLxSeo5ZU6otKdm9Wl5Op8jlBuSz2KnS76VH/RnzJr1V5S4DJvyFPEmdARl4CzDaeShqxH/pAHz1f4+5OVi4oowlMdw3PykvfWr/NpWbmOpZLFHOMcTadXt+Jf5b50pHqnxpXZ7apgABIe/2ysb+alMbgIf6LH1JhAsXotpGh+RSxc5JTKlyKzuhT3AjVxtoBgA2M4254P1XziKFpOygbkA3NyxhkVVd5xlJG+nPDD9Jg2YtxazGK0wf3G9e311uhafInIyHBa+ashD+BQOpDto8dllB3Ch+jeOmoKhXRFeWREOwq21OoIZtL3pZ8wL++hS4GCEtkWIIFdVjWM789oR9pG3BkZOmack288jO5dblSJso7q6Uy80mVlLVmwaMqA0AVhAaqhWu9qorXrLdIlFH/t08qAe5NDlq/PIvkREH12U/5P7Bp4JBHl36vl33jN72VCXCGW5c1UREUCuwrpmCvLm3Z3QHqn70/g7FXJFCVTtZaiDSN5v3dz38k0svlRuSyw//kfRZmMUWA17j7GWuwM1uv9yNhaxT58vF8a0Pb3Eui5mgVFlNTkjfIHl2ZC0nA0DgDrqeHEy1070UJ0A5MUDTVBT73Fv0Gtx4vsZ2kmz/2SYC2wCtmoFXqpcpXjwHX6YwUc+w7I1PgrI0HghltoRfOYjPDLtQDHnRKmjKPMK7xCWZWs1nveD1S2FMHj7C+2Mmmvmm+gm4Rc1n+HJuCU3x0vmour9KzJsO09gFXZigV/enalj6XJhFScMyk/0ctXBRw15gsLnyfUrqTkV/adD5hhWirQzFkurZ708TOM+VqdtaAcMFFnrhhnba+m7XSF034ClPp5eUZ50GCYxqYXAG0DaylrZxb/ZNVzQrl26N05ocFhHui+mCEtw1Eqz0NypcEpS6MPLd1qj3IeId155bRvhu2FVd1PNCJ9gJ2w9+BUUShzc17Q2cNf2pALqW6wFKpqMpcmqQl7TeVwMGtkxF7T9mxmCcgHQmrOrmXMSHaIzvmWB0YrJR5JcmiWr46+jjvoObnx6zCD3RhvHlazH1ViwsB9+HDFhhHBw97xknBWu6O6jeLaW6BZrdDLKO59Rsv3+kMuHU9pn3ScS6lbdDLDC9nFpluj7sSCJl/i/7f4Yw4O5yjblaEPRs9skCIaVU0EzrwouVueszxBXZdbQR88ZlT8MLI2hxDNEZxv+WEsJjHBxl/28zsEasf6YD6UT0Jp8biutRxHZDldgNSpssflhTK2br0v+PS+tHuOmDXufcDLRRRnKcwfiSWPw/hctDx+WvlMQrajgGW3/QMrCvDJWJ/JVZXz0r4LqKPMZFjKwkVEgTdsvzBzInASFmMLhrU4+raUJry8ZnReCoombBGpOUBjvzxnFjLY1RAIbakSy+VIAZIs6xbZmifBO/LMbFWz6Awu91U8VKjimzdgILfl1yfChQ4PfGX44UVYDgbqjFlcJHTBLh58Shh/DZuhn51pk7rwTRrL2T4xqNvcyF721Uzsvfsdkpz4mirK7xVd/SE09lLGPHojXn3gfdw2Yf/yXBKsCWd67MV3m0yuImGe1r+mvPyh5oV4LxW10JuqbdkHsF2Ogye5TY2WzFJQdq4y9s9fafqpE7J2WKucOFaHqKm5LAzdvSYx44nfv4DBP9atuKaKSYvuLAGcyKEQ==
C:\Windows\tasks\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-5.job - C:\Program Files (x86)\SavePass 1.1\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-5.exe /rawdata=babjtvrJi22sF/FOM6Opra9gzSGYPICmBmDAc0invjedDRiHFBj61m8W5d9Ko+LRFqAaXMgwWaDZBjDZ3HRVedWz+Acc3xDWTRAgN2NwJHLjxyvCBDqcnaG8ftsdTqqg/e76+d+Uahmk/H1pBmESRn+9Mxq/wc/9GWI+SF+4JmJZun7jAgOLkVIcfyP3NWQjFoCSyUOpRlw8JHTFzvVGJtmdZ9OhhWtj1QibOOrwCfa359JdKcILuxnwCGPbdpNB0j1v9mK70NZ6dmi89+AtIr0g7qxbyk7E1NWQ8EWS3bTctHm2OhnK9WEpa8lEQB3Wuv4302p4/lD8aYOzzVR7ZbuxuwfLvE8RUWjLuEBxlzxkqbxEyw0nRi6ljFASd3vCu88HMWG0N4Dwh1yBKi+tkB0nJ+3c7pdi9M6MdVXS8BLyAyzK0C8v4hv0Rn+l7P7C3U1r6o6tz7qrun75ueLlhEhgUiHsnPOlO8zvdryPCXc/ofruUC13rEirck+tt1PpX1k1L3lwASsn+A0lJjH56+tGMwxk6aVmWESWzB6KNB23pfqAJLzpAAwBJAsFPCkrNFgjStnhs8DL1MJ2u/DE/pU6aAxk4j9WKGHtSnjd0uicC5F9dpBaSaLHmdCULcMCJEYzl4NZSFzSoHCF4HMBB4gcEAricX+dg28EkJrfcFiPoQOj8EXbkYpASocMQd9cnHlSvdFi2sU0z9TWTvIYl1m4zmGmCzrmcPsTO/a+S9cN6GbcRt0smfviUcE9va5CHFRnPeACrvLwXMqoqGgWvi9DvjYgmEZc4inUrLRYJU3FLjDUhOrAQVWed3WGZcvS2m/ep8x/UK0mYkUib0yBhRLyxtQBHuCp184GIbWVwCqpDJWXdOjzdJxzs+6jWQZKo/ZDKNh8WZKK8GfjUYoYIhKLke7o3Z3r9TV3/zSYced++B6mHTHsjBZCBzKi30nypHQX8Z+VWF/7fuThk5CXaDs1gNltHg6phkdvI77xlGGNK7Scih8exHXWb7IEXDnI
C:\Windows\tasks\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-5_user.job - C:\Program Files (x86)\SavePass 1.1\5a6fbdd4-1650-49c0-a1b1-25f36a646e67-5.exe /rawdata=babjtvrJi22sF/FOM6Opra9gzSGYPICmBmDAc0invjedDRiHFBj61m8W5d9Ko+LRFqAaXMgwWaDZBjDZ3HRVedWz+Acc3xDWTRAgN2NwJHLjxyvCBDqcnaG8ftsdTqqg/e76+d+Uahmk/H1pBmESRn+9Mxq/wc/9GWI+SF+4JmJZun7jAgOLkVIcfyP3NWQjFoCSyUOpRlw8JHTFzvVGJtmdZ9OhhWtj1QibOOrwCfa359JdKcILuxnwCGPbdpNB0j1v9mK70NZ6dmi89+AtIr0g7qxbyk7E1NWQ8EWS3bTctHm2OhnK9WEpa8lEQB3Wuv4302p4/lD8aYOzzVR7ZbuxuwfLvE8RUWjLuEBxlzxkqbxEyw0nRi6ljFASd3vCu88HMWG0N4Dwh1yBKi+tkB0nJ+3c7pdi9M6MdVXS8BLyAyzK0C8v4hv0Rn+l7P7C3U1r6o6tz7qrun75ueLlhEhgUiHsnPOlO8zvdryPCXc/ofruUC13rEirck+tt1PpX1k1L3lwASsn+A0lJjH56+tGMwxk6aVmWESWzB6KNB23pfqAJLzpAAwBJAsFPCkrNFgjStnhs8DL1MJ2u/DE/pU6aAxk4j9WKGHtSnjd0uicC5F9dpBaSaLHmdCULcMCJEYzl4NZSFzSoHCF4HMBB4gcEAricX+dg28EkJrfcFiPoQOj8EXbkYpASocMQd9cnHlSvdFi2sU0z9TWTvIYl1m4zmGmCzrmcPsTO/a+S9cN6GbcRt0smfviUcE9va5CHFRnPeACrvLwXMqoqGgWvi9DvjYgmEZc4inUrLRYJU3FLjDUhOrAQVWed3WGZcvS2m/ep8x/UK0mYkUib0yBhVhUw79q2ZCBfH3SpME3i4C/Pp8KUIk5N2nilb8k9WhZLHvOG6OpXYgt2d8WFhjqfkLAtnqCzrMRQfAa9fjUdjJxOVj4QvUTLAXZB5LvNpQY0//XrewFbcVNoQkA0XfSALlFGA9m8cp140FXsmBc6e6IxlFcKFTIj2bk3s47iwn1
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\ebb06a68-202a-408c-971d-112055053eb5-1-6.job - C:\Program Files (x86)\GoHD\ebb06a68-202a-408c-971d-112055053eb5-1-6.exe /rawdata=BGHonoevSdglMmGp+1P7nzSI494vV33cC7V/rngOXAEmKDoZBDO3f0+PW56jU4JY5WcMQ5LwUaZ3UIr9J4sSZ7XkVQOrkTZxtOGUWhc3Y70keiWzeZxv9ceU2F9gowV9GwVD/OsN4/V4ssZQ0nD85GtQ56jcI8VYO2IBJhmuiySOpjL6HwWrFg6CA4F+z+2IVEjBulsWc7330qh+GzqNALSmyWMfFY9WyZnpq01odqQ55WJW7AEggjSOuOpHxwKZR3eEiEhYiGgTF/gbmUlynFYllw99kABMdjp5gl0fWB5JS74zmgmUu5YsvmCFAW8sha1N8PuWhGrTweRo0K2Vq45/AVbmf14LFzoPgnI9XmXoMDP6YacmAmvsi5ckenHslCS0gsENz0uReIfmwkykoZrbRp12mkm7OGLabwXr5LmoMKr2Qx80c6ahWoMbDvRf4zWXNAM803kY7UHo1SOFnCJY3qXTioiaLrfyxd/IOhZZOHD4+NVpYG4jvOvrA98cCu0lasf5qXfcMUA+9J8shqnbCdKCqi2t1YOfCzgUSs/h0bP38cb7AexaNz7ClFA8SKj6gLGp1qsoRANysUI5TV/XSD2vkvyMxzCqV2zQNxzm0w3P5i+YSTfqhWjadma7kp7EdeMtNC6FW8prQoWZdzj3tp+d51BohItTQNcRFoaq0lqeZia8QfGnEijq0+zVJq7uKqTP7YVhSmg3r7Tl5u8M6n8M9DL1/ONwmo6fB8KQK3rMKZkCjR7zJTEP4CBwNIKfSUvqKeYoZ1uqWQpob+ZVMw684EeTY64WfA8/qLIth8d0o9ExZQPIQFKe+Bqav/ReZW2zbhz0YK5pJ850nYBjZYKtITnFvvfT22tq7ekZxqX0wTmdaOcj9eCqSQbwUq7pnNtVuPL5UdQ8ofPIdy7NTvZJVAk8gv2vlCWoQXXHstqBOD1ZDjfsQRwSzRER1Yj4dpCzRVSQCLvqtt8d3m7810xUD8MOzZImKsMZ43+GZnW4qLZqs9XukVKDLXwoWBpVPQaN8QRlDVgjoWPUdXxXB/LhqXM2RVIVT7wIps2ckrN3Q7540lnO1bzZc9G8YK1fL+AfMsxW/3umfBOj+Ht9/6kgHFW/SD9VKEOS0N5us2DRt8LkEm/SnXLEXwAGVVzE4JVwtN5cp6peujE1Quv+ozsHkU/jiekb95f8S3pa3Mxkc/m1Dpyc2Uv96r42l7TeY5zjxdloYeU2+wJXsIH5cXEWp/LiZApWHQ8otxiFjKxMrArdNN1SnAb4Ss6HEMLgvWsSWrfjoz1L0J5aIAsTsx2teXDl8ZTZaTCAns/XDT7HBpUp4XHBWeR/ynj6eWGJ6+IG/jihJPfQFyRpSA==
C:\Windows\tasks\ebb06a68-202a-408c-971d-112055053eb5-1-7.job - C:\Program Files (x86)\GoHD\ebb06a68-202a-408c-971d-112055053eb5-1-7.exe /rawdata=tUTGZvEsX/EsDd/GHjwbFfU/2DX8v6Ady4XZEK3Ej0mF9CmaCNYPyYXyDMfiZAe1LouSsni4GQ9D0hHHVylAFc9SmvKgMLyRykVFnU7bZNgKMDj6+uu/pwFwX0tkln73kKCEUm0G2pz8DZL9/0ODOVwzsJBO3Hr7My7kE7a2gCuwEeiRriq4iF8SUQorkInqGDP26fHbuvwCkLc5XA3oe5ix1ZM8CAIt4BOT98yqaeQHG+wDHqMNYm1f3GPzzRA3uxN/5rGIzv/15Bee/BMaL1d+Cpk4iWy6UGwOJVmRoy+JQduE/xc7uDdWLhNq5xwCyWDm0WMKoomGTz0/4gK44BlK3gzYgIRq/qotvNv/ypCz0AnA3SI2Sb59Ab7NiKvvh0jlvIihUi6hUm6WkOmQuv2c8VqjNfCL92OCVwhAfbwnE6qBnyyvziI/ETD3rO0JGYm3bspFmwyCz2shTtUBnpYx4Qw5k5j7xADm9HmWME6pDnyuRZt8FuWSYexrDjRpIp1Sy0q2fxX4ZuUb0zw135EQUiRcvmewnopOue/Md2GuzHct6irwVR+fiRbVUMEBLtnyxjlZAYeD75yTysvDmtpDG91OEeR3O49PsLNhKavEtGvuqdRDYV267mUUVQcQMyPLJ0kQBnTItuGx98pbILP6AfhJQMAizviFWMGLHWB/W016P291k2ERQkFoFkF9E/SM9UOe4HleyhE94c0HM00EjxFxc5XHX+uN2WXhDuQ6j7t5Nb7REuDo8TswmDVuSjBv1e/44zdSkwaN5znYaLJ6nlYbX3FZ9aGNJM1IWgjBaKrQ8V01wE+E3lKDMNfr5htWLsRMFqmbGahmBn3S8z+hjBy38niW8xJdHHsHxcdx4CIWQM1doFhLSgFlrYivq0OwPsqhvZr5u0lsg+5vWOrfoILK4BqyGsKREcjAjrcvnd8VLUypdjtptj6v3LDEFFTjLSLBNaR00Nr9kkWIR3uXRYEIiH7fPSPTgUfBizwZhODkQD9de4QFcl5OgK2hNl0XIHkpL16C62JdTVZDn92Z78UgMvuIr7/3sez0USQq+o2TK/jKv+mOItnsRgkrNfUFuyRAb8eKGxXI5QYBCKnF+3p74wik8RGndOwQhSFtiv0cBL3KM2tKv4RWaY/17ARbjmDito3HqryVRNnW96FebYZOmdvPg/kyYw5A5J0olSy+GOf3GNbwZc+N/1BEntIif45WiUWb//PXTh0ldeb8fjiUuVNL8mH0rOhutaZAn4Jh9GngJxbAgus6HeGC9xq4yRE8Le4f9E4A6DENCoCpSNGN1TYVd9aVjps/nzYtx6MVlvBYZlW7TtAK/K8Th0zs/AZnJdr3s3SYPnxlXEbVi6NM6hqloWSrK7KXXZpkvN773kaq5UPKS8eeD4GkrXZGPRCtAFl4x11XhNoJ9eS4PGCg3sd6B6C9aqw1xUP+NE1FD/4bGRpQU3PIfpJ/NxvgIjGbAOXwAYGzzGguCepmK2egxcakdhwknnkUGAQmv3ruI0mH4vWMLbdmTDAL
C:\Windows\tasks\ebb06a68-202a-408c-971d-112055053eb5-10_user.job - C:\Program Files (x86)\GoHD\ebb06a68-202a-408c-971d-112055053eb5-10.exe /rawdata=fqiJ8uv3ce0nzs0KiYQTc/SqcsCN100xVdtc238jpQUfuEmcc15K0ouKHzJ2zfjMILLMg3pKg7iij0MyeqzKsL8zIYQ446vtjMwWuEYxGy0FEN6oUzFIySvKV1bxNdMFCfx8x9y8o85bC+JbeHAvsrPJLbGkOjI9QOjhdxS03TBOiJ7zjo9EfPE1cwdM6kZq/NvIzya7CUA0g499PQ7jvvhSXi4zI4plDvzO8uN680qSk5Fc5uW+afjxmQZ+cJC+VavZh4MnI/ThJATcYt2PPIKU1KabombTRfb0zYzBaLrCOAuWZustV6Fb5P1jjFl0Odgdpxk3tvK3z1MGOuykyBmBIS7pRoYtG43OdS32gphjWNc3yrSbOqeTqLQO7CWc/kageZDf4dqwn8Pj6h/IK93ikbzKR6Oj3LSHcOJT4c/BgxF3joM/D6o/u1y7AoTbiaJiewhD0EVuRupVo/fRD9KDr7FHEI4H41iiCt0fr5txBX4myT0emIhm0cEOPpOQwer84WRZaZl9GWRIHAXWj5K8HZVdD4a0T4uZdWhejTHc3AX0YRRXBCIiCKn0nzNOpYaLMTLLST03UYgqjAeH8aGCebRnwwTMVc7EK6mg9hcFHAU5Me6UmVkyKSvAXlL+4eK4So0OG2EUZuFLbRuK1ueUMK7QRUYpaPaPwagTXPexma9TF571NrsPHLRGCGiwiI3s4hPWNGTN016puys7vpIqc7uMjofwMPUnPuJq3soHgID5j8Uctvs/i2lFufviCuL6VKuSVv7zVD/RCIDdSJGYI2wyN+IdeUItL4ucGEAPZ6HunStz3psedum8+m16aufge4MCCZjTDAbX0eO0mw==
C:\Windows\tasks\ebb06a68-202a-408c-971d-112055053eb5-11.job - C:\Program Files (x86)\GoHD\ebb06a68-202a-408c-971d-112055053eb5-11.exe /rawdata=WbhnIBRXekwgNcW47zRAyb+k0oMew3xN3UhcW+w+X31/BCYRNIbVzcB45KyPTaUmj6kBNfusi7/4+osucTas5N9doVe4NEsoE9hKB4Y0l3q6hSAOxsIDgAuPMr4UXXXff8n1F3D/KBVmOAQtcPUzA3lVcK8UqA1kJWOhavaJwgik0+t2kWwj7MmG3SBYXY9dTrvCeinPeLAjEkBCGamb6ifEK6J2c8OUoQ7Cf/2okRQYt6edVBM0jR3zNj24ewMYvn+qfL2But1I3Xwu++gwLqtPUn8hW3ofMors4f6FyyoXwU2Fb2BHbQHvL9IgBq27wjYNcRCKBJhluAIkJXVuxgdivUSNNk1hckLK/Vi9y37gM+sPuOIp2X4nZghHhv12o092TilgS6vPhhnQX/juayE0KHVpzUCk2TZoIXu6HJcFIdbC/KflgThiSTcBH8mi3XDsPRAS6t9LLoLFnJDQ1ugkjyTV2Lh//9dyhFR/E9TMqjCAymn12+CMAorhB9/ZdQBPlVVTp1CwwdDA8LCLyLMb98wprxvCE+lwlpSlJFzSFWeulHery7G5u1VBDX7jlIs+6IvEL/U5OcB7bDm8zaE8avcbrpVtpX5IK9MMhfzE7kN2DeoBrsbMreJ3ekzIeyDrgYeUy+KfqCBqP4y+VP+2OqAYbXWbFcaBARB5BMIXUeOv+L+r0KWqJmIQmlKJnMmUp7gRCIg1e9d9hR21+kA22rTCGnrr61UuY9V4YFTOPwhhwDBCDICbqFvciGRv8zBa36CMp/p/wSv+dHHwPuFwsuTaWnYDbnQm5QsxSpuGpD/K152jL+xDg66ZKHXLe5J7rXPfS9Sky4PMxIN+rpK8YFaZeC5/W/jtK7BpSyE+kx4oKvqoeCq9ahqlRPWqgkZMyC2CHTVtqTjbW8z/Yjs2BjqwubkMEcZPq2XbjbKO3PxSQV+fxKf0LwqXQjcxhqGD4ZDzFj/FnCmc5cUSz9Y2V39BJRCcCyNKGrCwVyAhyME8+Iu5ChWUcJ6rB8G9Fv5NXvc16NddcG7mRTHeIwer6XJ7Aqut4/vPP0SM0dGmbc2sh+FEH66GePfzHPrODPxgv/Ngjh31FjVH96pem5Gf2xpG4hLSE4qvz/LSbMV4cE+qWbCIlySvZriOGq4B+r2ALy1S9FPX3s5qYcewXFp3rBYpNFuIEiSjAmTRp/V18m/KYURJo+ESIC1opCmYg75BFfRWbThJO7yDjxzAYkA0i6eDJCXDUWAhdfFEltBsi75qL2jten6xfybfEo/o+vIaoCpsLCu6mdSYGstxFTUipPR0AqKszNnaVk4Af005qa9dTiGRXQG9/oc4wzPpj6JEhkH6oI6WX3BgG1VX2cDo1UPLWFgGJ1NLBQyHS4EV96m+dMiMiW28JqBM7VI83OQsYehPwSOOJEeGGCOs2+jQuoOe46NVWGoxr1xGmL9tysgyo6MAb3LLDAfdCYnWfxq1BAUDfo83STPJuPqIuSNQQ8CJdbIBzXaQcNYP9buzRY1yNKQVsJcmiz+3cMVRAuGJC0NJMMpAdzr+8EdHAunqArvIugVJjbY6Vssnh1LKlcKOvcPK9qcgyO3JkjPWe61L7CGUDdxfwRUl6Qb+qcbtHj0a94SJa7Q+gJsVTCvDt7wAKt3Ajz8hH9AB2+nVvpqpYLnEmknPvL0Dblu0C7mok51B7cy/OAveO0tgqSeGWiPUV4+i60IssFQlZhqPF3HYIHqX+NB/sYeB4EFSf+MkuDiyOc1o0rbbWtu/Euh0ilNgy6+L5C6/maqYarwDyTyf15CU6GDv3pk+2cyS+1B8lIewBz1nDPHqCWJ9nqq7z+OzGEN7PH/IyL93IxbyeRthsMzcl/D+eEedAKRDtZSZoEv7W2g2taxAdrtXwoeCnQvOdTf2P+UC1O12DZBHNNHV1V1nR8KHcRwQQOpZCyn8fliAxh/3OZ1ZEMqFEb3hZkCUQYSkesfnvMqn5ca+kBmg4HVxbwqFP7BT3uAUSJyQJviVEtz0sW/U1YwthILKi7Qcf4gbTtAJmGF/mKjGLNZabmwbStuqC90FpJKzetVkOfzOZH3iqbVWXV7pDbQU4OU/XHY+taLrSOTKsA275jlwpfjbfr+hc7+3vGD7+XQcsLc1LVkn+Qd3TQ8Zo5k44IqjyuCZiisOAYUF29/Aa6vwn5F9RARZhRC34TloeuHq6NSKgLiWOvjpZfCJ51i8R4r3KxM2FTAO/4EGTQKLRJeADGuwCf0BGjFfgJ5AWr4sFiXA3wszhG722deLOWqroOJt5O5tQeqT50izAAPaEpW0mjYZtIZa1V0A9p/GuSk5yHseE7y+4ud8UNpcIE6Z1jIJkazXNp7ilmeh8b6WmjtGXk2wyb3YYHCIJw/m9w==
C:\Windows\tasks\ebb06a68-202a-408c-971d-112055053eb5-5.job - C:\Program Files (x86)\GoHD\ebb06a68-202a-408c-971d-112055053eb5-5.exe /rawdata=OFhBSk7F37rLI4+3/BT39hxY5YhexywwaLQM5jw+X2n1TrzjLBXkzWnhdAisM/pe+P4H4n7AnztOfS3lAvUbHdTmOjFEYanOIwk5bLjCc8llpdR3bDEY2f/U8cgKL0SmybfKGVn0ydeQHT8xRsPLRVj5VoXGc4Twdhoh2zXb9g+0dg1SdZ3F82MTyHSUda+5Uo9OxPkDklscbsXBPM7+BldKGjkcBVhmghmVrVrALOG1xz8XSmtROgKnVKVYE7UUh8lVLjLl1NWCxElTBkNBM76C33hOJMvHrZoWIT1Dq1tFWyu2iWYKlQaketZyB0T7F9S3Pp3DNgB/dZTjdJQqDqZxSypLlxxKFKuk/VSZcNh6xydESooUorBg5+PVTbYs7yZBklcGy8eMvh2HbpqVLlU67HIXbicaSddty/iSwqJM6S+tZEhapFtxYk+cD6XBu0iaJHgqIqVtd8VOhPvV9HPByiellT7EvrqYjaMKDrErBNpQIx9gU1b+UYrkUe0+ASy5T5PXsOojCyCz8ap3muPbGWPwU9LnXi2pzjgdiznBP0BWk2J/y+Ta33H4ODZ3JyD6kal17u9jQC+spKf926sEAF2LVdcH0bcIATsp/m34VdONQckFjtyBZQQjfUzcNvuDElvMjSQbGCMFIYqOD4g0/u3ZlYLNDuYOzA0LD9G2QCRfbxeXC+Bt2tCmuh5vtf0ZDE9T/vYDmESfSFWplhN+AiOEG2n+V1+nPdbO15SrnG+lQc603/ia7nm8U3fI5ckpB4D17ulx1lOTx0b4PQ/pRN24r9e3N3QWGn+ix3rL9Vt8eYp7IqxPOyFWW/YqgrufiID/pi+OZxrg7rb3LlGZRZyecK+0HxPSDO3ze2iW0jGqlbkvzq8aBsNpbKuhs9Ic+iZAVZ431jeGI+BJ4H8TUAtWJHz9aR0WpmdbyT/w58jOZ81HEWL70G8lEWKLU21D0zW4aMlnkO2rQ0AYi7GAIhfXUraeRXspdmshF+dA8LZW+KJTyVKbjiIQtwz2
C:\Windows\tasks\ebb06a68-202a-408c-971d-112055053eb5-5_user.job - C:\Program Files (x86)\GoHD\ebb06a68-202a-408c-971d-112055053eb5-5.exe /rawdata=OFhBSk7F37rLI4+3/BT39hxY5YhexywwaLQM5jw+X2n1TrzjLBXkzWnhdAisM/pe+P4H4n7AnztOfS3lAvUbHdTmOjFEYanOIwk5bLjCc8llpdR3bDEY2f/U8cgKL0SmybfKGVn0ydeQHT8xRsPLRVj5VoXGc4Twdhoh2zXb9g+0dg1SdZ3F82MTyHSUda+5Uo9OxPkDklscbsXBPM7+BldKGjkcBVhmghmVrVrALOG1xz8XSmtROgKnVKVYE7UUh8lVLjLl1NWCxElTBkNBM76C33hOJMvHrZoWIT1Dq1tFWyu2iWYKlQaketZyB0T7F9S3Pp3DNgB/dZTjdJQqDqZxSypLlxxKFKuk/VSZcNh6xydESooUorBg5+PVTbYs7yZBklcGy8eMvh2HbpqVLlU67HIXbicaSddty/iSwqJM6S+tZEhapFtxYk+cD6XBu0iaJHgqIqVtd8VOhPvV9HPByiellT7EvrqYjaMKDrErBNpQIx9gU1b+UYrkUe0+ASy5T5PXsOojCyCz8ap3muPbGWPwU9LnXi2pzjgdiznBP0BWk2J/y+Ta33H4ODZ3JyD6kal17u9jQC+spKf926sEAF2LVdcH0bcIATsp/m34VdONQckFjtyBZQQjfUzcNvuDElvMjSQbGCMFIYqOD4g0/u3ZlYLNDuYOzA0LD9G2QCRfbxeXC+Bt2tCmuh5vtf0ZDE9T/vYDmESfSFWplhN+AiOEG2n+V1+nPdbO15SrnG+lQc603/ia7nm8U3fI5ckpB4D17ulx1lOTx0b4PQ/pRN24r9e3N3QWGn+ix3rL9Vt8eYp7IqxPOyFWW/YqgrufiID/pi+OZxrg7rb3LqsDtRn9DHV88h1Qim4kYymwZHxCGnRkm60krXhHW0/dcEB8QH1TEKHmOaRRUiawVCs7oNz6A5Pzs0jfeufy6TMKKQ3nKj5EftqCRH8RrDwOZRFYmtxr7W/SctRgq0bpSXQqLSUZ24Rls7r8dCpkN2ht6RurvS+V/OgcjL3cgCAJ
C:\Windows\tasks\Wise Care 365.job - D:\PROGRAMY\Wise Care 365 12\WiseTray.exe -StartTray
C:\Windows\tasks\Wise Turbo Checker.job - D:\PROGRAMY\Wise Care 365 12\WiseTurbo.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-07-28 767176]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"Update"=C:\Users\Martin\AppData\Roaming\VOPackage\VOPackage.exe [2015-09-30 1083464]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2015-09-30 20:35:44 ----D---- C:\rsit
2015-09-30 20:35:44 ----D---- C:\Program Files\trend micro
2015-09-30 20:14:33 ----D---- C:\Users\Martin\AppData\Roaming\mystartsearch
2015-09-30 20:14:33 ----D---- C:\ProgramData\2WdsManPro2
2015-09-30 20:09:45 ----D---- C:\Program Files (x86)\ESET
2015-09-30 20:06:55 ----D---- C:\Program Files (x86)\GoHD
2015-09-30 20:06:32 ----D---- C:\ProgramData\Systweak
2015-09-30 20:06:31 ----D---- C:\Program Files (x86)\ASP
2015-09-30 20:06:11 ----D---- C:\Program Files (x86)\RCP
2015-09-30 20:06:10 ----D---- C:\Users\Martin\AppData\Roaming\systweak
2015-09-30 19:55:22 ----SHD---- C:\Users\Martin\AppData\Roaming\AnyProtectEx
2015-09-30 19:55:22 ----D---- C:\Program Files (x86)\AnyProtectEx
2015-09-30 19:54:31 ----D---- C:\Program Files (x86)\SFK
2015-09-30 19:54:31 ----D---- C:\Program Files (x86)\CinemaPlus-3.2cV30.09
2015-09-30 19:54:20 ----D---- C:\Users\Martin\AppData\Roaming\istartsurf
2015-09-30 19:54:20 ----D---- C:\ProgramData\iWdsManProi
2015-09-30 19:54:20 ----A---- C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-09-30 19:54:10 ----D---- C:\Program Files (x86)\gmsd_ra_005010102
2015-09-30 19:53:52 ----D---- C:\Program Files (x86)\MyBrowser
2015-09-30 19:53:46 ----A---- C:\task.vbs
2015-09-30 19:44:12 ----D---- C:\Program Files\Concom
2015-09-30 19:43:25 ----D---- C:\Program Files (x86)\SavePass 1.1
2015-09-30 19:43:14 ----D---- C:\Users\Martin\AppData\Roaming\VOPackage
2015-09-30 19:43:14 ----D---- C:\Program Files (x86)\C544AC00-1443634994-11E1-9478-5404A62F58BE
2015-09-30 19:40:02 ----A---- C:\AVScanner.ini
2015-09-30 19:38:51 ----D---- C:\Program Files (x86)\Crossbrowse
2015-09-30 19:38:00 ----D---- C:\Program Files (x86)\McAfee Security Scan
2015-09-30 19:37:59 ----D---- C:\ProgramData\McAfee
2015-09-30 19:37:34 ----D---- C:\Program Files (x86)\globalUpdate
2015-09-30 19:37:30 ----D---- C:\Program Files (x86)\CinemaP-1.9cV30.09
2015-09-30 19:35:52 ----D---- C:\Program Files (x86)\RayDld
2015-09-30 19:35:34 ----D---- C:\Users\Martin\AppData\Roaming\oursurfing
2015-09-30 19:31:00 ----D---- C:\Program Files (x86)\SeaMonkey
2015-09-29 16:22:26 ----D---- C:\Program Files (x86)\Netease
2015-09-29 14:38:57 ----D---- C:\Program Files (x86)\GUM767A.tmp
2015-09-28 18:32:55 ----D---- C:\ProgramData\Mozilla
2015-09-28 18:32:54 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-09-28 17:55:29 ----D---- C:\Program Files (x86)\GUM799A.tmp
2015-09-28 17:42:32 ----D---- C:\Program Files (x86)\GUM9F91.tmp
2015-09-03 10:08:51 ----A---- C:\Windows\system32\FNTCACHE.DAT
2015-09-02 13:46:04 ----A---- C:\Windows\WiseHDInfo64.dll

======List of files/folders modified in the last 1 month======

2015-09-30 20:35:45 ----D---- C:\Windows\Temp
2015-09-30 20:35:44 ----RD---- C:\Program Files
2015-09-30 20:31:34 ----D---- C:\Windows\System32
2015-09-30 20:30:11 ----D---- C:\Windows\system32\Tasks
2015-09-30 20:30:10 ----D---- C:\Windows\Tasks
2015-09-30 20:15:24 ----D---- C:\Windows\SysWOW64
2015-09-30 20:14:33 ----D---- C:\ProgramData
2015-09-30 20:09:45 ----RD---- C:\Program Files (x86)
2015-09-30 20:07:18 ----SHD---- C:\Windows\Installer
2015-09-30 20:07:18 ----D---- C:\Program Files (x86)\Common Files
2015-09-30 20:07:18 ----D---- C:\Config.Msi
2015-09-30 19:43:36 ----D---- C:\Windows\system32\drivers\etc
2015-09-30 19:37:58 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-09-30 19:32:43 ----D---- C:\Users\Martin\AppData\Roaming\Spotify
2015-09-30 19:31:04 ----D---- C:\Users\Martin\AppData\Roaming\Mozilla
2015-09-30 18:51:46 ----D---- C:\Program Files (x86)\Opera
2015-09-30 12:39:37 ----D---- C:\Windows\inf
2015-09-30 12:39:37 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-09-30 12:35:09 ----D---- C:\Program Files (x86)\Google
2015-09-23 19:39:17 ----D---- C:\Windows\system32\config
2015-09-23 19:02:39 ----SHD---- C:\System Volume Information
2015-09-17 14:20:49 ----D---- C:\Users\Martin\AppData\Roaming\vlc
2015-09-09 11:01:13 ----D---- C:\Windows
2015-09-03 15:46:08 ----D---- C:\Program Files (x86)\Portable
2015-09-03 12:24:15 ----D---- C:\Windows\Prefetch
2015-09-03 10:12:08 ----D---- C:\Windows\SoftwareDistribution
2015-09-03 10:08:58 ----D---- C:\Windows\debug
2015-09-02 13:52:07 ----D---- C:\Windows\system32\catroot2
2015-09-02 13:52:07 ----D---- C:\Windows\Downloaded Program Files

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2012-04-22 213888]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2012-04-22 60416]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-07-29 21622784]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-07-29 665088]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2010-01-05 1847296]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2015-07-15 96256]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-03 31232]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2012-04-22 18432]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2012-04-22 95232]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WiseHDInfo;WiseHDInfo; \??\C:\Windows\WiseHDInfo64.dll [2015-09-02 14800]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-07-29 246784]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-07-28 344064]
R2 ihpmServer;ihpmServer; C:\Program Files (x86)\RayDld\ihpmServer.exe [2015-09-25 268520]
R2 lukyquvu;Firewall Touchpad; C:\Program Files (x86)\C544AC00-1443634994-11E1-9478-5404A62F58BE\knsyE06.tmpfs [2015-09-30 792576]
R2 SSFK;SSFK; C:\Program Files (x86)\SFK\SSFK.exe [2015-09-30 458400]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-09-30 269000]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-08 569024]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]

-----------------EOF-----------------

Re: Prosím o kontrolu logu

Napsal: 30 zář 2015 19:42
od vyosek
Zdravim :)

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Po spusteni probehne stazeni databaze
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner[C?].txt, ten sem vlozte

Re: Prosím o kontrolu logu

Napsal: 30 zář 2015 19:55
od Peelie
# AdwCleaner v5.009 - Logfile created 30/09/2015 at 20:52:23
# Updated 27/09/2015 by Xplode
# Database : 2015-09-30.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Martin - MARTIN-PC
# Running from : C:\Users\Martin\Desktop\adwcleaner_5.009.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : SSFK
[-] Service Deleted : ihpmServer
[!] Service Not Deleted : Concom
[-] Service Deleted : lukyquvu

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files\Concom
[-] Folder Deleted : C:\Program Files (x86)\AnyProtectEx
[-] Folder Deleted : C:\Program Files (x86)\ASP
[-] Folder Deleted : C:\Program Files (x86)\globalUpdate
[-] Folder Deleted : C:\Program Files (x86)\RCP
[-] Folder Deleted : C:\Program Files (x86)\GoHD
[-] Folder Deleted : C:\Program Files (x86)\SavePass 1.1
[-] Folder Deleted : C:\Program Files (x86)\Crossbrowse
[-] Folder Deleted : C:\Program Files (x86)\SFK
[-] Folder Deleted : C:\Program Files (x86)\RayDld
[!] Folder Not Deleted : C:\Program Files (x86)\SavePass 1.1
[-] Folder Deleted : C:\Program Files (x86)\C544AC00-1443634994-11E1-9478-5404A62F58BE
[-] Folder Deleted : C:\Program Files (x86)\CinemaP-1.9cV30.09
[-] Folder Deleted : C:\Program Files (x86)\CinemaPlus-3.2cV30.09
[!] Folder Not Deleted : C:\Program Files (x86)\Crossbrowse
[!] Folder Not Deleted : C:\Program Files (x86)\GoHD
[-] Folder Deleted : C:\Program Files (x86)\MyBrowser
[!] Folder Not Deleted : C:\Program Files (x86)\SavePass 1.1
[-] Folder Deleted : C:\Program Files (x86)\gmsd_ra_005010102
[-] Folder Deleted : C:\ProgramData\Systweak
[-] Folder Deleted : C:\ProgramData\2WdsManPro2
[-] Folder Deleted : C:\ProgramData\iWdsManProi
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossbrowse
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System~Protector
[!] Folder Not Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossbrowse
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyBrowser
[-] Folder Deleted : C:\Users\Martin\AppData\Local\globalUpdate
[-] Folder Deleted : C:\Users\Martin\AppData\Local\Systweak
[-] Folder Deleted : C:\Users\Martin\AppData\Local\Crossbrowse
[!] Folder Not Deleted : C:\Users\Martin\AppData\Local\Crossbrowse
[-] Folder Deleted : C:\Users\Martin\AppData\Local\MyBrowser
[-] Folder Deleted : C:\Users\Martin\AppData\Local\gmsd_ra_005010102
[-] Folder Deleted : C:\Users\Martin\AppData\Local\C544AC00-1443642244-11E1-9478-5404A62F58BE
[-] Folder Deleted : C:\Users\Martin\AppData\Roaming\AnyProtectEx
[-] Folder Deleted : C:\Users\Martin\AppData\Roaming\istartsurf
[-] Folder Deleted : C:\Users\Martin\AppData\Roaming\Systweak
[-] Folder Deleted : C:\Users\Martin\AppData\Roaming\VOPackage
[-] Folder Deleted : C:\Users\Martin\AppData\Roaming\mystartsearch
[-] Folder Deleted : C:\Users\Martin\AppData\Roaming\oursurfing
[-] Folder Deleted : C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage

***** [ Files ] *****

[-] File Deleted : C:\Users\Martin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\crossbrowse.lnk
[-] File Deleted : C:\Users\Martin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\MyBrowser.lnk
[-] File Deleted : C:\Windows\Sysnative\drivers\bd0001.sys

***** [ Shortcuts ] *****

[-] Shortcut Disinfected : C:\Users\Public\Desktop\Opera.lnk
[-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[-] Shortcut Disinfected : C:\Users\Martin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk

***** [ Scheduled tasks ] *****

[-] Task Deleted : ASP
[-] Task Deleted : RegClean Pro
[-] Task Deleted : amiupdaterExd
[-] Task Deleted : amiupdaterExi
[-] Task Deleted : Advanced System~Protector
[-] Task Deleted : Advanced System~Protector_startup
[-] Task Deleted : 29ffc21b-d8f2-4d5f-991e-086d6c54ce38-1-6
[-] Task Deleted : 29ffc21b-d8f2-4d5f-991e-086d6c54ce38-1-7
[-] Task Deleted : 29ffc21b-d8f2-4d5f-991e-086d6c54ce38-10_user
[-] Task Deleted : 29ffc21b-d8f2-4d5f-991e-086d6c54ce38-11
[-] Task Deleted : 29ffc21b-d8f2-4d5f-991e-086d6c54ce38-5
[-] Task Deleted : 29ffc21b-d8f2-4d5f-991e-086d6c54ce38-5_user
[-] Task Deleted : 5a6fbdd4-1650-49c0-a1b1-25f36a646e67-1-6
[-] Task Deleted : 5a6fbdd4-1650-49c0-a1b1-25f36a646e67-1-7
[-] Task Deleted : 5a6fbdd4-1650-49c0-a1b1-25f36a646e67-10_user
[-] Task Deleted : 5a6fbdd4-1650-49c0-a1b1-25f36a646e67-11
[-] Task Deleted : 5a6fbdd4-1650-49c0-a1b1-25f36a646e67-5
[-] Task Deleted : 5a6fbdd4-1650-49c0-a1b1-25f36a646e67-5_user
[-] Task Deleted : ebb06a68-202a-408c-971d-112055053eb5-1-6
[-] Task Deleted : ebb06a68-202a-408c-971d-112055053eb5-1-7
[-] Task Deleted : ebb06a68-202a-408c-971d-112055053eb5-10_user
[-] Task Deleted : ebb06a68-202a-408c-971d-112055053eb5-11
[-] Task Deleted : ebb06a68-202a-408c-971d-112055053eb5-5
[-] Task Deleted : ebb06a68-202a-408c-971d-112055053eb5-5_user
[-] Task Deleted : 29ffc21b-d8f2-4d5f-991e-086d6c54ce38-1-6
[-] Task Deleted : 29ffc21b-d8f2-4d5f-991e-086d6c54ce38-1-7
[-] Task Deleted : 29ffc21b-d8f2-4d5f-991e-086d6c54ce38-10_user
[-] Task Deleted : 29ffc21b-d8f2-4d5f-991e-086d6c54ce38-11
[-] Task Deleted : 29ffc21b-d8f2-4d5f-991e-086d6c54ce38-5
[-] Task Deleted : 29ffc21b-d8f2-4d5f-991e-086d6c54ce38-5_user
[-] Task Deleted : 5a6fbdd4-1650-49c0-a1b1-25f36a646e67-1-6
[-] Task Deleted : 5a6fbdd4-1650-49c0-a1b1-25f36a646e67-1-7
[-] Task Deleted : 5a6fbdd4-1650-49c0-a1b1-25f36a646e67-10_user
[-] Task Deleted : 5a6fbdd4-1650-49c0-a1b1-25f36a646e67-11
[-] Task Deleted : 5a6fbdd4-1650-49c0-a1b1-25f36a646e67-5
[-] Task Deleted : 5a6fbdd4-1650-49c0-a1b1-25f36a646e67-5_user
[-] Task Deleted : ebb06a68-202a-408c-971d-112055053eb5-1-6
[-] Task Deleted : ebb06a68-202a-408c-971d-112055053eb5-1-7
[-] Task Deleted : ebb06a68-202a-408c-971d-112055053eb5-10_user
[-] Task Deleted : ebb06a68-202a-408c-971d-112055053eb5-11
[-] Task Deleted : ebb06a68-202a-408c-971d-112055053eb5-5
[-] Task Deleted : ebb06a68-202a-408c-971d-112055053eb5-5_user
[-] Task Deleted : Adobe Flash Player Updater

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
[-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
[-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Mediaplayer\Shiminclusionlist\crossbrowse.exe
[-] Key Deleted : HKLM\SOFTWARE\Classes\CRSBRWSHTML
[-] Key Deleted : HKLM\SOFTWARE\Clients\StartMenuInternet\Crossbrowse
[-] Value Deleted : HKLM\SOFTWARE\Classes\.htm\OpenWithProgids [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\Classes\.html\OpenWithProgids [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\RegisteredApplications [Crossbrowse]
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe
[-] Value Deleted : HKLM\SOFTWARE\Classes\.xht\OpenWithProgIDs [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\Classes\.webp\OpenWithProgIDs [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\Classes\.shtml\OpenWithProgIDs [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\RegisteredApplications [MyBrowser]
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\mybrowser.exe
[-] Key Deleted : HKLM\SOFTWARE\Clients\StartMenuInternet\MyBrowser
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{7D3C47ED-E0BE-4940-9DDA-A7A097AEBD88}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B0660298-91AA-421F-BF0D-BFF6BB8BF3AE}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{50F4150A-48B2-417A-BE4C-C83F580FB904}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}]
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
[-] Key Deleted : HKCU\Software\AnyProtect
[-] Key Deleted : HKCU\Software\GlobalUpdate
[-] Key Deleted : HKCU\Software\InstalledBrowserExtensions
[-] Key Deleted : HKCU\Software\SavePass 1.1
[-] Key Deleted : HKCU\Software\systweak
[-] Key Deleted : HKCU\Software\Tutorials
[-] Key Deleted : HKCU\Software\TutoTag
[-] Key Deleted : HKCU\Software\GoHD
[-] Key Deleted : HKCU\Software\CrossBrowser
[-] Key Deleted : HKCU\Software\Crossbrowse
[-] Key Deleted : HKCU\Software\YorkNewCin
[-] Key Deleted : HKCU\Software\HighDefAction
[-] Key Deleted : HKCU\Software\ArenaHD
[-] Key Deleted : HKCU\Software\OB
[-] Key Deleted : HKCU\Software\WEBAPP
[!] Key Not Deleted : HKCU\Software\SavePass 1.1
[!] Key Not Deleted : HKCU\Software\SavePass 1.1
[-] Key Deleted : HKCU\Software\CinemaPlus-3.2cV30.09
[!] Key Not Deleted : HKCU\Software\Crossbrowse
[!] Key Not Deleted : HKCU\Software\GoHD
[-] Key Deleted : HKCU\Software\MyBrowser
[!] Key Not Deleted : HKCU\Software\SavePass 1.1
[-] Key Deleted : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
[-] Key Deleted : HKLM\SOFTWARE\AppDataLow\SOFTWARE\Crossrider
[-] Key Deleted : HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
[-] Key Deleted : HKLM\SOFTWARE\GlobalUpdate
[-] Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Key Deleted : HKLM\SOFTWARE\SavePass 1.1
[-] Key Deleted : HKLM\SOFTWARE\systweak
[-] Key Deleted : HKLM\SOFTWARE\Tutorials
[-] Key Deleted : HKLM\SOFTWARE\GoHD
[-] Key Deleted : HKLM\SOFTWARE\GAMESDESKTOP
[-] Key Deleted : HKLM\SOFTWARE\Crossbrowse
[-] Key Deleted : HKLM\SOFTWARE\YorkNewCin
[-] Key Deleted : HKLM\SOFTWARE\HighDefAction
[-] Key Deleted : HKLM\SOFTWARE\oursurfingSoftware
[-] Key Deleted : HKLM\SOFTWARE\ArenaHD
[-] Key Deleted : HKLM\SOFTWARE\downchecker
[-] Key Deleted : HKLM\SOFTWARE\WdsManPro
[-] Key Deleted : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Key Deleted : HKLM\SOFTWARE\RayDld
[-] Key Deleted : HKLM\SOFTWARE\ihpmserver
[!] Key Not Deleted : HKLM\SOFTWARE\SavePass 1.1
[!] Key Not Deleted : HKLM\SOFTWARE\SavePass 1.1
[-] Key Deleted : HKLM\SOFTWARE\CinemaPlus-3.2cV30.09
[!] Key Not Deleted : HKLM\SOFTWARE\Crossbrowse
[!] Key Not Deleted : HKLM\SOFTWARE\GoHD
[-] Key Deleted : HKLM\SOFTWARE\MyBrowser
[!] Key Not Deleted : HKLM\SOFTWARE\SavePass 1.1
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean-Pro_is1
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SavePass 1.1
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdater
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoHD
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Crossbrowse
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SU
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\oursurfing
[!] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SavePass 1.1
[!] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SavePass 1.1
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaPlus-3.2cV30.09
[!] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Crossbrowse
[!] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoHD
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyBrowser
[!] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SavePass 1.1
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_ra_005010102_is1
[!] Key Not Deleted : [x64] HKCU\Software\AnyProtect
[!] Key Not Deleted : [x64] HKCU\Software\GlobalUpdate
[!] Key Not Deleted : [x64] HKCU\Software\InstalledBrowserExtensions
[!] Key Not Deleted : [x64] HKCU\Software\SavePass 1.1
[!] Key Not Deleted : [x64] HKCU\Software\systweak
[!] Key Not Deleted : [x64] HKCU\Software\Tutorials
[!] Key Not Deleted : [x64] HKCU\Software\TutoTag
[!] Key Not Deleted : [x64] HKCU\Software\GoHD
[!] Key Not Deleted : [x64] HKCU\Software\CrossBrowser
[!] Key Not Deleted : [x64] HKCU\Software\Crossbrowse
[!] Key Not Deleted : [x64] HKCU\Software\YorkNewCin
[!] Key Not Deleted : [x64] HKCU\Software\HighDefAction
[!] Key Not Deleted : [x64] HKCU\Software\ArenaHD
[!] Key Not Deleted : [x64] HKCU\Software\OB
[!] Key Not Deleted : [x64] HKCU\Software\WEBAPP
[!] Key Not Deleted : [x64] HKCU\Software\SavePass 1.1
[!] Key Not Deleted : [x64] HKCU\Software\SavePass 1.1
[!] Key Not Deleted : [x64] HKCU\Software\CinemaPlus-3.2cV30.09
[!] Key Not Deleted : [x64] HKCU\Software\Crossbrowse
[!] Key Not Deleted : [x64] HKCU\Software\GoHD
[!] Key Not Deleted : [x64] HKCU\Software\MyBrowser
[!] Key Not Deleted : [x64] HKCU\Software\SavePass 1.1
[-] Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Key Deleted : [x64] HKLM\SOFTWARE\YorkNewCin
[-] Key Deleted : [x64] HKLM\SOFTWARE\HighDefAction
[-] Key Deleted : [x64] HKLM\SOFTWARE\ArenaHD
[-] Key Deleted : [x64] HKLM\SOFTWARE\downchecker
[!] Key Not Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
[!] Key Not Deleted : HKU\S-1-5-21-515885200-768628804-3900138106-1000\Software\AppDataLow\Software\Crossrider
[!] Key Not Deleted : HKU\S-1-5-18\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GLOBALUPDATE.EXE
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
[-] Data Restored : HKU\S-1-5-21-515885200-768628804-3900138106-1000\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKU\S-1-5-21-515885200-768628804-3900138106-1000\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[!] Key Not Deleted : HKU\S-1-5-21-515885200-768628804-3900138106-1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data Restored : HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command []
[-] Data Restored : HKLM\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command []

***** [ Web browsers ] *****


*************************

:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [23365 bytes] ##########

Re: Prosím o kontrolu logu

Napsal: 30 zář 2015 21:15
od vyosek
:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: Prosím o kontrolu logu

Napsal: 30 zář 2015 21:36
od Peelie
Zoek.exe v5.0.0.1 Updated 30-09-2015
Tool run by Martin on st 30. 09. 2015 at 22:20:20,80.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Martin\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

30. 9. 2015 22:21:26 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\GUM767A.tmp deleted successfully
C:\PROGRA~2\GUM799A.tmp deleted successfully
C:\PROGRA~2\GUM9F91.tmp deleted successfully
C:\Users\Martin\AppData\Local\AAF6B80D-57C6-4E1B-A87-4797EA17A06D deleted successfully
C:\Users\Martin\AppData\Local\D781AE73-5D32-4233-AC1A-C1ED8B7BAB6 deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\ef26py92.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");

Added to C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\ef26py92.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Martin\AppData\Roaming\Mozilla\SeaMonkey\Profiles\ii5mfmc2.default\prefs.js:

Added to C:\Users\Martin\AppData\Roaming\Mozilla\SeaMonkey\Profiles\ii5mfmc2.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\PROGRA~2\GUM767A.tmp not found
C:\PROGRA~2\GUM799A.tmp not found
C:\PROGRA~2\GUM9F91.tmp not found
C:\Users\Martin\AppData\Local\7806 deleted
C:\task.vbs deleted
C:\PROGRA~3\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat deleted
C:\Users\Martin\AppData\Local\nscC67D.tmp deleted
C:\Users\Martin\AppData\Local\Planetlux.exe.config deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\ef26py92.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\SeaMonkey\Profiles\ii5mfmc2.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\SeaMonkey\Profiles\ii5mfmc2.default
- DOM - %ProfilePath%\extensions\inspector@mozilla.org
- ChatZilla - %ProfilePath%\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
- JavaScript Debugger - %ProfilePath%\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi

==== Firefox Plugins ======================


==== Chromium Look ======================


SavePass 1.1 - Martin\AppData\Roaming\Opera Software\Opera Stable\Extensions\akaelkiagnbfcccfnmbimdbplecgbikh
GoHD - Martin\AppData\Roaming\Opera Software\Opera Stable\Extensions\fijhlnmmmgflacagjecncpmpnhjieggk
CinemaPlus-3.2cV30.09 - Martin\AppData\Roaming\Opera Software\Opera Stable\Extensions\papbadoldddalgcjcicnikcfenodpghp

==== Chromium Fix ======================

C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage-journal deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage-journal deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Extensions\akaelkiagnbfcccfnmbimdbplecgbikh deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Local Storage\chrome-extension_akaelkiagnbfcccfnmbimdbplecgbikh_0.localstorage deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Local Storage\chrome-extension_akaelkiagnbfcccfnmbimdbplecgbikh_0.localstorage-journal deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\databases\chrome-extension_akaelkiagnbfcccfnmbimdbplecgbikh_0 deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Local Extension Settings\akaelkiagnbfcccfnmbimdbplecgbikh deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Extensions\fijhlnmmmgflacagjecncpmpnhjieggk deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Local Storage\chrome-extension_fijhlnmmmgflacagjecncpmpnhjieggk_0.localstorage deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Local Storage\chrome-extension_fijhlnmmmgflacagjecncpmpnhjieggk_0.localstorage-journal deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\databases\chrome-extension_fijhlnmmmgflacagjecncpmpnhjieggk_0 deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Local Extension Settings\fijhlnmmmgflacagjecncpmpnhjieggk deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Extensions\papbadoldddalgcjcicnikcfenodpghp deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Local Storage\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0.localstorage deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Local Storage\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0.localstorage-journal deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\databases\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0 deleted successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Local Extension Settings\papbadoldddalgcjcicnikcfenodpghp deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Web Data was reset successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Web Data-journal was reset successfully
C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Web Data.too_new was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~9338DF9D_is1 deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Martin\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Martin\AppData\Local\Mozilla\Firefox\Profiles\ef26py92.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Martin\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=166 folders=40 4397951 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Martin\AppData\Local\Temp will be emptied at reboot
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Martin\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted

==== EOF on st 30. 09. 2015 at 22:34:15,18 ======================

Re: Prosím o kontrolu logu

Napsal: 30 zář 2015 21:46
od vyosek

Re: Prosím o kontrolu logu

Napsal: 30 zář 2015 22:05
od Peelie
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:30-09-2015
Ran by Martin (administrator) on MARTIN-PC (30-09-2015 23:00:13)
Running from C:\Users\Martin\Desktop
Loaded Profiles: Martin (Available Profiles: Martin)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 9 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Spotify Ltd) C:\Users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(forum.viry.cz) C:\Users\Martin\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-07-28] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-515885200-768628804-3900138106-1000\...\Run: [Spotify Web Helper] => C:\Users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2025016 2015-09-30] (Spotify Ltd)
HKU\S-1-5-21-515885200-768628804-3900138106-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{B5844788-BED4-4849-99BF-940E9B612EC4}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-515885200-768628804-3900138106-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-515885200-768628804-3900138106-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-21-515885200-768628804-3900138106-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}

FireFox:
========
FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\ef26py92.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-30] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-30] ()
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-14]
CHR Extension: (Google Drive) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-09-14]
CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-29]
CHR Extension: (Google Search) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-29]
CHR Extension: (Google Docs Offline) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-29]
CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-29]

Opera:
=======
OPR Extension: (Adblock Plus) - C:\Users\Martin\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2015-09-30]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-07-28] (Advanced Micro Devices, Inc.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2012-04-22] (Microsoft Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 WiseHDInfo; C:\Windows\WiseHDInfo64.dll [14800 2015-09-02] (wisecleaner.com)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-30 23:00 - 2015-09-30 23:00 - 00006829 _____ C:\Users\Martin\Desktop\FRST.txt
2015-09-30 23:00 - 2015-09-30 23:00 - 00000000 ____D C:\FRST
2015-09-30 22:54 - 2015-09-30 22:54 - 00112640 _____ (forum.viry.cz) C:\Users\Martin\Desktop\FRSTLauncher.exe
2015-09-30 22:53 - 2015-09-30 22:53 - 02192384 _____ (Farbar) C:\Users\Martin\Desktop\FRST64.exe
2015-09-30 22:31 - 2015-09-30 22:20 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-09-30 22:21 - 2015-09-30 22:34 - 00012976 _____ C:\zoek-results.log
2015-09-30 22:20 - 2015-09-30 22:30 - 00000000 ____D C:\zoek_backup
2015-09-30 22:19 - 2015-09-30 22:19 - 01309184 _____ C:\Users\Martin\Desktop\zoek.exe
2015-09-30 21:17 - 2015-09-30 21:40 - 00000000 ____D C:\Users\Martin\AppData\Local\Spotify
2015-09-30 21:17 - 2015-09-30 21:17 - 00001772 _____ C:\Users\Martin\Desktop\Spotify.lnk
2015-09-30 21:17 - 2015-09-30 21:17 - 00001758 _____ C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-09-30 21:16 - 2015-09-30 21:16 - 00147616 _____ (Spotify Ltd) C:\Users\Martin\Downloads\SpotifySetup.exe
2015-09-30 21:07 - 2015-09-30 21:07 - 31772280 _____ (网易公司) C:\Users\Martin\Downloads\cloudmusicsetup_1_9_1[105579].exe
2015-09-30 20:51 - 2015-09-30 20:52 - 00000000 ____D C:\AdwCleaner
2015-09-30 20:49 - 2015-09-30 20:49 - 01670656 _____ C:\Users\Martin\Desktop\adwcleaner_5.009.exe
2015-09-30 20:35 - 2015-09-30 20:35 - 00000000 ____D C:\rsit
2015-09-30 20:35 - 2015-09-30 20:35 - 00000000 ____D C:\Program Files\trend micro
2015-09-30 20:33 - 2015-09-30 20:33 - 01222144 _____ C:\Users\Martin\Downloads\RSITx64.exe
2015-09-30 20:09 - 2015-09-30 20:09 - 02870984 _____ (ESET) C:\Users\Martin\Downloads\esetsmartinstaller_enu.exe
2015-09-30 19:52 - 2015-09-30 19:52 - 00004294 _____ C:\Windows\System32\Tasks\D781AE73-5D32-4233-AC1A-C1ED8B7BAB6
2015-09-30 19:43 - 2015-09-30 19:40 - 00000027 _____ C:\Windows\system32\Drivers\etc\hp.bak
2015-09-30 19:40 - 2015-09-30 19:38 - 00000030 _____ C:\AVScanner.ini
2015-09-30 19:38 - 2015-09-30 19:38 - 00004202 _____ C:\Windows\System32\Tasks\AAF6B80D-57C6-4E1B-A87-4797EA17A06D
2015-09-30 19:37 - 2015-09-30 20:06 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-09-30 19:37 - 2015-09-30 19:37 - 00000000 ____D C:\ProgramData\McAfee
2015-09-30 19:31 - 2015-09-30 21:05 - 00000000 ____D C:\Program Files (x86)\SeaMonkey
2015-09-30 19:30 - 2015-09-30 19:30 - 25660700 _____ C:\Users\Martin\Downloads\SeaMonkey Setup 2.23.exe
2015-09-29 16:22 - 2015-09-29 16:22 - 00000000 ____D C:\Program Files (x86)\Netease
2015-09-28 18:40 - 2015-09-30 20:52 - 00000994 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-09-28 18:40 - 2015-09-30 20:52 - 00000982 _____ C:\Users\Public\Desktop\Opera.lnk
2015-09-28 18:40 - 2015-09-30 18:51 - 00003844 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1443458430
2015-09-28 18:37 - 2015-09-28 18:40 - 32627432 _____ (Opera Software) C:\Users\Martin\Downloads\Opera.v28.0.1750.40(1).exe
2015-09-28 18:32 - 2015-09-28 18:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-09-28 18:32 - 2015-09-28 18:32 - 00000000 ____D C:\ProgramData\Mozilla
2015-09-23 20:22 - 2015-09-23 20:22 - 00610088 _____ C:\Users\Martin\Downloads\--php the title();--__14846_i1671427698.rar
2015-09-09 11:01 - 2015-09-30 22:33 - 00024450 _____ C:\Windows\PFRO.log
2015-09-03 10:11 - 2015-09-30 22:37 - 00146169 _____ C:\Windows\WindowsUpdate.log
2015-09-03 10:10 - 2015-09-03 10:10 - 00107608 _____ C:\Users\Martin\AppData\Local\GDIPFONTCACHEV1.DAT
2015-09-03 10:09 - 2015-09-30 22:34 - 00002520 _____ C:\Windows\setupact.log
2015-09-03 10:09 - 2015-09-03 10:09 - 00000000 _____ C:\Windows\setuperr.log
2015-09-03 10:08 - 2015-09-03 10:09 - 00412504 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-02 13:53 - 2015-09-30 22:34 - 00000350 _____ C:\Windows\Tasks\Wise Care 365.job
2015-09-02 13:53 - 2015-09-02 13:53 - 00002778 _____ C:\Windows\System32\Tasks\Wise Care 365
2015-09-02 13:47 - 2015-09-30 13:00 - 00000378 _____ C:\Windows\Tasks\Wise Turbo Checker.job
2015-09-02 13:47 - 2015-09-02 13:53 - 00003048 _____ C:\Windows\System32\Tasks\Wise Turbo Checker
2015-09-02 13:46 - 2015-09-02 13:46 - 00014800 _____ (wisecleaner.com) C:\Windows\WiseHDInfo64.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-30 22:41 - 2009-07-14 06:45 - 00021392 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-30 22:41 - 2009-07-14 06:45 - 00021392 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-30 22:38 - 2009-07-14 07:13 - 00785302 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-30 22:34 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-30 21:22 - 2014-08-16 20:49 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Spotify
2015-09-30 20:53 - 2014-07-28 18:43 - 00001443 _____ C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-09-30 20:53 - 2014-07-28 18:43 - 00001409 _____ C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-09-30 20:53 - 2009-07-14 06:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-09-30 19:37 - 2014-07-29 13:15 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-09-30 19:37 - 2014-07-29 13:15 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-09-30 19:37 - 2014-07-29 13:14 - 00000000 ____D C:\Users\Martin\AppData\Local\Adobe
2015-09-30 19:31 - 2015-03-20 12:56 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Mozilla
2015-09-30 19:31 - 2015-03-20 12:56 - 00000000 ____D C:\Users\Martin\AppData\Local\Mozilla
2015-09-30 18:51 - 2014-07-28 18:51 - 00000000 ____D C:\Program Files (x86)\Opera
2015-09-30 12:35 - 2015-01-27 13:23 - 00000000 ____D C:\Program Files (x86)\Google
2015-09-17 14:20 - 2014-08-23 21:09 - 00000000 ____D C:\Users\Martin\AppData\Roaming\vlc
2015-09-11 16:38 - 2009-07-14 07:08 - 00032526 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-09-03 15:46 - 2014-11-26 18:23 - 00000000 ____D C:\Program Files (x86)\Portable

==================== Files in the root of some directories =======

2015-07-25 16:15 - 2015-07-25 16:15 - 0007605 _____ () C:\Users\Martin\AppData\Local\Resmon.ResmonCfg
2015-06-16 17:54 - 2015-06-16 17:54 - 0000000 _____ () C:\Users\Martin\AppData\Local\Temp.dat

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-09-22 21:57

==================== End of FRST.txt ============================



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:107.32 GB) (Free:28.23 GB) NTFS
Drive d: () (Fixed) (Total:358.34 GB) (Free:346.42 GB) NTFS

Available physical RAM: 6970.63 MB
Total physical RAM: 8154.46 MB
Percentage of memory in use: 14%

==================== MBR and Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: A4C80B1C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=107.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=358.3 GB) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Wise Care 365.job => D:\PROGRAMY\Wise Care 365 12\WiseTray.exe
Task: C:\Windows\Tasks\Wise Turbo Checker.job => D:\PROGRAMY\Wise Care 365 12\WiseTurbo.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Martin\Desktop" je 5 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Re: Prosím o kontrolu logu

Napsal: 30 zář 2015 22:26
od Peelie
Ospravedlňujem sa, prídem zajtra. Zatiaľ vďaka.

Re: Prosím o kontrolu logu

Napsal: 01 říj 2015 11:15
od Peelie
Mám tie veci na ploche.

Re: Prosím o kontrolu logu

Napsal: 05 říj 2015 11:44
od vyosek
:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-515885200-768628804-3900138106-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearch
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhome
    HKU\S-1-5-21-515885200-768628804-3900138106-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearch
    
    2015-09-30 23:00 - 2015-09-30 23:00 - 00006829 _____ C:\Users\Martin\Desktop\FRST.txt
    2015-09-30 22:54 - 2015-09-30 22:54 - 00112640 _____ (forum.viry.cz) C:\Users\Martin\Desktop\FRSTLauncher.exe
    2015-09-30 22:31 - 2015-09-30 22:20 - 00024064 _____ C:\Windows\zoek-delete.exe
    2015-09-30 22:21 - 2015-09-30 22:34 - 00012976 _____ C:\zoek-results.log
    2015-09-30 22:20 - 2015-09-30 22:30 - 00000000 ____D C:\zoek_backup
    2015-09-30 22:19 - 2015-09-30 22:19 - 01309184 _____ C:\Users\Martin\Desktop\zoek.exe
    2015-09-30 21:07 - 2015-09-30 21:07 - 31772280 _____ (网易公司) C:\Users\Martin\Downloads\cloudmusicsetup_1_9_1[105579].exe
    2015-09-30 20:51 - 2015-09-30 20:52 - 00000000 ____D C:\AdwCleaner
    2015-09-30 20:49 - 2015-09-30 20:49 - 01670656 _____ C:\Users\Martin\Desktop\adwcleaner_5.009.exe
    2015-09-30 20:35 - 2015-09-30 20:35 - 00000000 ____D C:\rsit
    2015-09-30 20:35 - 2015-09-30 20:35 - 00000000 ____D C:\Program Files\trend micro
    2015-09-30 20:33 - 2015-09-30 20:33 - 01222144 _____ C:\Users\Martin\Downloads\RSITx64.exe
    2015-09-30 20:09 - 2015-09-30 20:09 - 02870984 _____ (ESET) C:\Users\Martin\Downloads\esetsmartinstaller_enu.exe
    
    Task: C:\Windows\Tasks\Wise Care 365.job => D:\PROGRAMY\Wise Care 365 12\WiseTray.exe
    Task: C:\Windows\Tasks\Wise Turbo Checker.job => D:\PROGRAMY\Wise Care 365 12\WiseTurbo.exe
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt