Stránka 1 z 2

jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedia.A"

Napsal: 23 říj 2017 10:09
od Xipco_CZ
Zdarvim, na domacim PC mne po spusteni prohlizece Google Chrome vyskakuje jiz par dni nize uvedena hlaska

Obrázek

V karantene mam jeden odkaz a v protokolu pak spousty hlaseni jako toto

Obrázek

Mam Windows 7 Professional, Google Chrome, Firefox, ESET Smart Security 10.
Hlaska vyskakuje jen v pri pusteni Chrome. Pri pusteni Firefox a IE to nedela.

Muzete mne prosim pomoci s odstranenim "kuikdelivery.com" a "JS/Adware.AztecMedia.A" z Google Chrome a PC?
Dekuji

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 23 říj 2017 10:13
od JaRon
ahoj,
na uvod to vycisti s ADWCleanerom - log sem

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 23 říj 2017 10:37
od Xipco_CZ
log po vycisteni AdwCleaner je zde:
# AdwCleaner 7.0.3.1 - Logfile created on Mon Oct 23 09:30:49 2017
# Updated on 2017/29/09 by Malwarebytes
# Running on Windows 7 Professional (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

No malicious registry entries deleted.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [952 B] - [2017/10/23 9:29:11]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 23 říj 2017 10:40
od JaRon

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 23 říj 2017 11:18
od Xipco_CZ
log po pouziti zoek je zde:
Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by max on po 23.10.2017 at 11:53:09,68.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode No Internet Access Detected
Launched: D:\!Users\max\Desktop\zoek.exe [Scan all users] [Script inserted]

===== Runcheck 11:54:22,74 =====

--- Create Environment Variables 11:54:23,73
--- Create System Restore Point 11:54:42,97
--- Checking Input 11:54:50,86
--- Reset Hosts File 11:54:57,40
--- AU AppData Check 11:54:57,87
--- Remove From Windows Installer 11:55:00,35
--- Empty Folders Check 11:55:57,18
--- Registry HKLM Software Check 11:55:57,18
--- Quick Launch Shortcut Check 11:56:07,47
--- IE Startpage Check 11:56:09,99
--- Program Files DB Check 11:56:24,31
--- D:\!Users\Default\AppData\Roaming DB Check 11:57:02,73
--- D:\!Users\Default User\AppData\Roaming DB Check 11:57:02,73
--- D:\!Users\max\AppData\Roaming DB Check 11:57:02,73
--- D:\!Users\Default\AppData\Roaming DB Check 11:57:02,73
--- D:\!Users\DEFAUL~1\AppData\Roaming DB Check 11:57:02,73
--- D:\!Users\max\AppData\Roaming DB Check 11:57:02,73
--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 11:57:02,73
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 11:57:02,73
--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 11:57:02,73
--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 11:57:02,73
--- D:\!Users\max DB Check 11:59:44,24
--- C:\PROGRA~3 DB Check 11:59:58,23
--- D:\!Users\Default\AppData\Local DB Check 12:00:02,71
--- D:\!Users\Default User\AppData\Local DB Check 12:00:02,71
--- D:\!Users\max\AppData\Local DB Check 12:00:02,71
--- D:\!Users\Default\AppData\Local DB Check 12:00:02,71
--- D:\!Users\DEFAUL~1\AppData\Local DB Check 12:00:02,71
--- D:\!Users\max\AppData\Local DB Check 12:00:02,71
--- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 12:00:02,71
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 12:00:02,71
--- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 12:00:02,71
--- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 12:00:02,71
--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 12:01:54,09
--- DB Check 12:02:02,40
--- Tasks DB Check 12:02:36,88
--- Downloads DB Check 12:02:40,15
--- D:\!Users\max\AppData\LocalLow DB Check 12:02:43,59
--- D:\!Users\max\AppData\LocalLow DB Check 12:02:43,59
--- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 12:02:43,59
--- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 12:02:43,59
--- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 12:02:43,59
--- Tasks2 DB Check 12:03:25,45
--- Documents DB Check 12:03:50,52
--- D:\!Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\6ccs718m.default DB Check 12:04:00,61
--- C:\Users\Public\Desktop DB Check 12:04:02,55
--- D:\!Users\max\Desktop DB Check 12:04:06,23
--- Services DB Check 12:04:15,79
--- FF prefs.js DB Check 12:04:33,65
--- Emptyclsid 12:05:06,51
--- Del by CLSID 12:05:08,03
--- Delete Services 12:05:26,92
--- Firefox Fix 12:05:28,72
Akorat PC se nerestartovalo, a zoek zustal spusteny na plose s vyse uvedenym logem
Co tedy ted?

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 23 říj 2017 11:21
od JaRon
zoek sa zrejme zasekol, restartuj PC manualne a napis, ci po restarte je este problem :???:

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 23 říj 2017 11:29
od Xipco_CZ
Po restarte a spusteni Chrome opet vyskakuje hlaska z ESETu (blokace "kuikdelivery.com" - "JS/Adware.AztecaMedia.A").
Zadny log po zoek nezustal na plose ani v:
C:\zoek
C:\zoek_backup

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 23 říj 2017 12:36
od JaRon
zrejme este nedoslo k mazaniu a zamrzol
skus zopakovat akciu zoek v núdzovom rezime PC

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 23 říj 2017 15:51
od Xipco_CZ
Provedl jsem akci Zoek v nouzovem rezimu. Akce se pozastavila u "Firefox" a dalsich 30 minut neprobehla zadna zmena v okne i kdyz je Zoek aktivni.

Po pokusu zavrit Zoek, ten se restartoval. Tak jsem ho nechal jet. Opet se ale zastavil u "Firefox".
Tak jsem zkopiroval log z okna Zoek a ulozil si ho. Pak jsem restartoval PC.
Tady je ten log.
Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by max on po 23.10.2017 at 16:21:29,36.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Safe Mode NETWORK No Internet Access Detected
Launched: D:\!Users\max\Desktop\zoek.exe [Scan all users] [Script inserted]

===== Runcheck 16:22:09,83 =====

--- Create Environment Variables 16:22:10,48
--- Checking Input 16:22:30,61
--- Reset Hosts File 16:22:34,34
--- AU AppData Check 16:22:34,51
--- Remove From Windows Installer 16:22:36,08
--- Empty Folders Check 16:22:58,81
--- Registry HKLM Software Check 16:22:58,81
--- Quick Launch Shortcut Check 16:23:06,86
--- IE Startpage Check 16:23:07,88
--- Program Files DB Check 16:23:15,30
--- D:\!Users\Default\AppData\Roaming DB Check 16:23:45,97
--- D:\!Users\Default User\AppData\Roaming DB Check 16:23:45,97
--- D:\!Users\max\AppData\Roaming DB Check 16:23:45,97
--- D:\!Users\Default\AppData\Roaming DB Check 16:23:45,97
--- D:\!Users\DEFAUL~1\AppData\Roaming DB Check 16:23:45,97
--- D:\!Users\max\AppData\Roaming DB Check 16:23:45,97
--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 16:23:45,97
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 16:23:45,97
--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 16:23:45,97
--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 16:23:45,97
--- D:\!Users\max DB Check 16:25:58,82
--- C:\PROGRA~3 DB Check 16:26:10,55
--- D:\!Users\Default\AppData\Local DB Check 16:26:14,25
--- D:\!Users\Default User\AppData\Local DB Check 16:26:14,25
--- D:\!Users\max\AppData\Local DB Check 16:26:14,25
--- D:\!Users\Default\AppData\Local DB Check 16:26:14,25
--- D:\!Users\DEFAUL~1\AppData\Local DB Check 16:26:14,25
--- D:\!Users\max\AppData\Local DB Check 16:26:14,25
--- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 16:26:14,25
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 16:26:14,25
--- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 16:26:14,25
--- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 16:26:14,25
--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 16:27:46,46
--- DB Check 16:27:53,36
--- Tasks DB Check 16:28:27,38
--- Downloads DB Check 16:28:30,13
--- D:\!Users\max\AppData\LocalLow DB Check 16:28:32,98
--- D:\!Users\max\AppData\LocalLow DB Check 16:28:32,98
--- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 16:28:32,98
--- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 16:28:32,98
--- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 16:28:32,98
--- Tasks2 DB Check 16:29:07,63
--- Documents DB Check 16:29:28,77
--- D:\!Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\6ccs718m.default DB Check 16:29:37,13
--- C:\Users\Public\Desktop DB Check 16:29:38,75
--- D:\!Users\max\Desktop DB Check 16:29:41,78
--- Services DB Check 16:29:47,74
--- FF prefs.js DB Check 16:29:58,55
--- Emptyclsid 16:30:23,51
--- Del by CLSID 16:30:24,29
--- Delete Services 16:30:41,01
--- Firefox Fix 16:30:42,23

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 23 říj 2017 15:56
od JaRon
Vycisti PC s MBAM

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 24 říj 2017 09:19
od Xipco_CZ
Vycistil jsem PC pomoci MBAM. Pak jsem znovu provedl akci se Zoek.
Opet ale stejna situace. Zoek se pozastavil v logu u Firefox a nic se pak 40 minut nedelo. Tak jsem opet zkopiroval log (ktery uvadim nize) a PC natvrdo restartoval.
Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by max on po 23.10.2017 at 18:56:12,98.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode No Internet Access Detected
Launched: D:\!Users\max\Desktop\zoek.exe [Scan all users] [Script inserted]

===== Runcheck 18:56:39,33 =====

--- Create Environment Variables 18:56:40,93
--- Checking Input 18:57:08,35
--- Reset Hosts File 18:57:18,52
--- AU AppData Check 18:57:19,04
--- Remove From Windows Installer 18:57:22,50
--- Empty Folders Check 18:59:14,22
--- Registry HKLM Software Check 18:59:14,24
--- Quick Launch Shortcut Check 18:59:36,93
--- IE Startpage Check 18:59:41,98
--- Program Files DB Check 19:00:15,60
--- D:\!Users\Default\AppData\Roaming DB Check 19:01:09,61
--- D:\!Users\Default User\AppData\Roaming DB Check 19:01:09,61
--- D:\!Users\max\AppData\Roaming DB Check 19:01:09,61
--- D:\!Users\Default\AppData\Roaming DB Check 19:01:09,61
--- D:\!Users\DEFAUL~1\AppData\Roaming DB Check 19:01:09,61
--- D:\!Users\max\AppData\Roaming DB Check 19:01:09,61
--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 19:01:09,61
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 19:01:09,61
--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 19:01:09,61
--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 19:01:09,61
--- D:\!Users\max DB Check 19:04:55,69
--- C:\PROGRA~3 DB Check 19:05:15,14
--- D:\!Users\Default\AppData\Local DB Check 19:05:21,36
--- D:\!Users\Default User\AppData\Local DB Check 19:05:21,36
--- D:\!Users\max\AppData\Local DB Check 19:05:21,36
--- D:\!Users\Default\AppData\Local DB Check 19:05:21,36
--- D:\!Users\DEFAUL~1\AppData\Local DB Check 19:05:21,36
--- D:\!Users\max\AppData\Local DB Check 19:05:21,36
--- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 19:05:21,36
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 19:05:21,36
--- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 19:05:21,36
--- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 19:05:21,36
--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 19:08:00,56
--- DB Check 19:08:11,94
--- Tasks DB Check 19:08:49,31
--- Downloads DB Check 19:08:53,89
--- D:\!Users\max\AppData\LocalLow DB Check 19:08:58,71
--- D:\!Users\max\AppData\LocalLow DB Check 19:08:58,71
--- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 19:08:58,71
--- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 19:08:58,71
--- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 19:08:58,71
--- Tasks2 DB Check 19:09:57,09
--- Documents DB Check 19:10:31,82
--- D:\!Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\6ccs718m.default DB Check 19:10:45,97
--- C:\Users\Public\Desktop DB Check 19:10:48,71
--- D:\!Users\max\Desktop DB Check 19:10:53,81
--- Services DB Check 19:11:06,74
--- FF prefs.js DB Check 19:11:38,44
--- Emptyclsid 19:12:26,56
--- Del by CLSID 19:12:29,31
--- Delete Services 19:12:58,49
--- Firefox Fix 19:13:00,91
Hlaska z ESET (kuikdelivery.com" - "JS/Adware.AztecaMedia.A") pri spusteni Chrome stale pretrvava.
Co ted?

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 24 říj 2017 09:22
od JaRon

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 24 říj 2017 13:42
od Xipco_CZ
Zde je log z JRT:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Professional x64
Ran by max (Administrator) on Łt 24.10.2017 at 14:28:50,52
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 24

Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0G7AWQSL (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1MOXYM9W (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25GL4UPD (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6BG14RL (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D7XH0AP8 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NKA04NVF (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OQY5GH0E (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VLHC3BSK (Temporary Internet Files Folder)
Successfully deleted: D:\!Users\max\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0G7AWQSL (Temporary Internet Files Folder)
Successfully deleted: D:\!Users\max\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: D:\!Users\max\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1MOXYM9W (Temporary Internet Files Folder)
Successfully deleted: D:\!Users\max\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25GL4UPD (Temporary Internet Files Folder)
Successfully deleted: D:\!Users\max\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: D:\!Users\max\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6BG14RL (Temporary Internet Files Folder)
Successfully deleted: D:\!Users\max\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D7XH0AP8 (Temporary Internet Files Folder)
Successfully deleted: D:\!Users\max\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: D:\!Users\max\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: D:\!Users\max\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NKA04NVF (Temporary Internet Files Folder)
Successfully deleted: D:\!Users\max\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OQY5GH0E (Temporary Internet Files Folder)
Successfully deleted: D:\!Users\max\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VLHC3BSK (Temporary Internet Files Folder)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 24.10.2017 at 14:30:57,44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 24 říj 2017 13:57
od JaRon
skus teraz zoek s tymto scriptom:

Kód: Vybrat vše

autoclean;
resethosts;
emptyclsid;
IEdefaults;
CHRdefaults;
emptyIEcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;

Re: jak odstranit "kuikdelivery.com" - "JS/Adware.AztecaMedi

Napsal: 24 říj 2017 15:59
od Xipco_CZ
Nize je log ze Zoek (se scriptem). Opet ale stejna situace. Zoek se pozastavil v logu u Firefox a nic se pak 50 minut nedelo. Tak jsem opet zkopiroval log (ktery uvadim nize) a PC pak natvrdo restartoval.
Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by max on Łt 24.10.2017 at 15:12:57,84.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode No Internet Access Detected
Launched: D:\!Users\max\Desktop\zoek.exe [Scan all users] [Script inserted]

===== Runcheck 15:13:48,70 =====

--- Create Environment Variables 15:13:49,73
--- Checking Input 15:14:06,12
--- Reset Hosts File 15:14:12,40
--- AU AppData Check 15:14:12,72
--- Remove From Windows Installer 15:14:15,08
--- Empty Folders Check 15:15:12,50
--- Registry HKLM Software Check 15:15:12,50
--- Quick Launch Shortcut Check 15:15:23,03
--- IE Startpage Check 15:15:25,62
--- Program Files DB Check 15:15:43,61
--- D:\!Users\Default\AppData\Roaming DB Check 15:16:22,28
--- D:\!Users\Default User\AppData\Roaming DB Check 15:16:22,28
--- D:\!Users\max\AppData\Roaming DB Check 15:16:22,28
--- D:\!Users\Default\AppData\Roaming DB Check 15:16:22,28
--- D:\!Users\DEFAUL~1\AppData\Roaming DB Check 15:16:22,28
--- D:\!Users\max\AppData\Roaming DB Check 15:16:22,28
--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 15:16:22,28
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 15:16:22,28
--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 15:16:22,28
--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 15:16:22,28
--- D:\!Users\max DB Check 15:19:04,80
--- C:\PROGRA~3 DB Check 15:19:19,00
--- D:\!Users\Default\AppData\Local DB Check 15:19:23,52
--- D:\!Users\Default User\AppData\Local DB Check 15:19:23,52
--- D:\!Users\max\AppData\Local DB Check 15:19:23,52
--- D:\!Users\Default\AppData\Local DB Check 15:19:23,52
--- D:\!Users\DEFAUL~1\AppData\Local DB Check 15:19:23,52
--- D:\!Users\max\AppData\Local DB Check 15:19:23,52
--- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 15:19:23,52
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 15:19:23,52
--- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 15:19:23,52
--- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 15:19:23,52
--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 15:21:15,53
--- DB Check 15:21:23,88
--- Tasks DB Check 15:21:58,39
--- Downloads DB Check 15:22:01,73
--- D:\!Users\max\AppData\LocalLow DB Check 15:22:05,20
--- D:\!Users\max\AppData\LocalLow DB Check 15:22:05,20
--- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 15:22:05,20
--- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 15:22:05,20
--- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 15:22:05,20
--- Tasks2 DB Check 15:22:47,34
--- Documents DB Check 15:23:12,71
--- D:\!Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\6ccs718m.default DB Check 15:23:22,85
--- C:\Users\Public\Desktop DB Check 15:23:24,80
--- D:\!Users\max\Desktop DB Check 15:23:28,45
--- Services DB Check 15:23:38,07
--- FF prefs.js DB Check 15:23:55,96
--- Emptyclsid 15:24:29,10
--- Del by CLSID 15:24:30,63
--- Delete Services 15:24:50,78
--- Delete files\folders 15:24:52,73
--- Create Backups 15:24:53,61
--- Firefox Extensions 15:24:57,27
Co ted?