Hi,
prosim o kontrolu logu RSIT a pomoc s odtranenim domovske stranky Omiga-plus.com.
Jiz jsem ji odinstaloval nekolikrat z PC, nastavil si jinou domovskou stranku, ale po resetu PC jse me vzdy objevi Omiga-plus a nabizi me k instalaci a stahuje jine programy, ktere nechci. Zasilam prvni polovinu RSIT, je dost velky. Druhou zaslu na vyzadani
Pomuze me nekdo?
Log 1/2:
Logfile of random's system information tool 1.10 (written by random/random)
Run by new at 2014-07-10 12:53:51
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 68 GB (49%) free of 138 GB
Total RAM: 4055 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:53:58, on 10/07/2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16561)
Boot mode: Normal
Running processes:
C:\Users\new\AppData\Local\fst_gb_58\upfst_gb_58.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Users\new\AppData\Local\WeatherAlerts\DesktopWeatherAlertsApp.exe
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Tapety 2.12\Tapety.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\new.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hp& ... MEM66MEM66
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hp& ... MEM66MEM66
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hp& ... MEM66MEM66
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hp& ... MEM66MEM66
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre7\bin\jusched.exe"
O4 - HKLM\..\Run: [Nikon Message Center 2] "C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe" -s
O4 - HKLM\..\RunOnce: [upfst_gb_58.exe] C:\Users\new\AppData\Local\fst_gb_58\upfst_gb_58.exe -runonce
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [NBCore] "C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBCore.exe"
O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\new\AppData\Local\Apps\2.0\NGAPRWHV.TY8\7H7O4R4E.7H1\dell..tion_0f612f649c4a10af_0005.0008_a4204ff54ae5d3ac\DellSystemDetect.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: DesktopWeatherAlerts.lnk = new\AppData\Local\WeatherAlerts\DesktopWeatherAlertsApp.exe
O4 - Startup: MyPC Backup.lnk = C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
O4 - Startup: Tapety 2.12.lnk = C:\Program Files (x86)\Tapety 2.12\Tapety.exe
O4 - Startup: Weather Alerts.lnk = new\AppData\Local\WeatherAlerts\WeatherAlerts.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.dell.com
O20 - AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_54cb4575\AESTSr64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ask Update Service (APNMCP) - APN LLC. - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Computer Backup (MyPC Backup) (BackupStack) - Just Develop It - C:\Program Files (x86)\MyPC Backup\BackupStack.exe
O23 - Service: Bing Desktop Update service (BingDesktopUpdate) - Unknown owner - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VO Service component (servervo) - Unknown owner - C:\Users\new\AppData\Roaming\VOPackage\VOsrv.exe
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_54cb4575\STacSV64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Fuyu LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Marvell Yukon Service (yksvc) - Unknown owner - RUNDLL32.EXE (file missing)
--
End of file - 11103 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_54cb4575\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\Dell\DellDock\DockLogin.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\bcmwltry.exe
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\ProgramData\IePluginServices\PluginService.exe -service
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
C:\Windows\System32\spoolsv.exe
taskeng.exe {213205A8-1133-4178-9DCE-F5F19ECF6621}
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {A85AD82C-7644-4419-881E-31046EFEDF53}
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_54cb4575\AESTSr64.exe
"C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe"
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe"
"C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Users\new\AppData\Roaming\VOPackage\VOsrv.exe
"C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe /Embedding
RUNDLL32.EXE ykx64coinst,serviceStartProc
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\new\AppData\Local\fst_gb_58\upfst_gb_58.exe" -runhelper
"C:\Program Files\Windows Defender\MSASCui.exe" -hide
"C:\Program Files\DellTPad\Apoint.exe"
"C:\WINDOWS\System32\hkcmd.exe"
"C:\WINDOWS\System32\igfxpers.exe"
"C:\WINDOWS\System32\WLTRAY.EXE"
"C:\Program Files\Dell\QuickSet\quickset.exe"
"C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\WINDOWS\ehome\ehtray.exe"
"C:\Users\new\AppData\Local\Apps\2.0\NGAPRWHV.TY8\7H7O4R4E.7H1\dell..tion_0f612f649c4a10af_0005.0008_a4204ff54ae5d3ac\DellSystemDetect.exe"
"C:\Users\new\AppData\Local\WeatherAlerts\DesktopWeatherAlertsApp.exe"
"C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
"C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe"
C:\Windows\ehome\ehmsas.exe -Embedding
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Tapety 2.12\Tapety.exe"
"C:\Users\new\AppData\Local\WeatherAlerts\WeatherAlerts.exe" /restart
"C:\Program Files\DellTPad\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"Apntex.exe"
"C:\Program Files\DellTPad\HidFind.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" http://isearch.omiga-plus.com/?type=sc& ... MEM66MEM66
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe" /c
C:\Windows\servicing\TrustedInstaller.exe
"C:\Users\new\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-1.job - C:\Program Files (x86)\Browseri_Appe 1.2\Browseri_Appe 1.2-codedownloader.exe /UeuLarGr /IozUWAj=task /bWxHzEOQU='Browseri_Appe 1.2' /YouvQ=60346 /GxGEkGdF='001739' /bwNVCJ='verticals-' /cgEIxH='0' /HhOBSahH=4F9B8B2865DD46DEA6E4A78B89F00243IE /HzGgQ=decdc4bd733300b1031bd647f0f4f168 /EtTokA=1_34_07_01 /DztlDuNIk=1.34.7.1 /kLtYi=1404937782 /mCQxdm=http://stats.geninfocloud.com /NVznWIyV=http://errors.geninfocloud.com /WRsVTroBw=http://js.geninfocloud.com /NIFnc=ff /wBpTXGGWU='Browseri_Appe 1.2' /BIzTzKS=http://js.clientdemocloud.com /dOQoZTpw /RAKNfHriu='{"asw":[32770, 5, 2048]}' /FICrMaUw='http://update.geninfocloud.com/ie_code_ ... pdate.json' /IozUWAj='task' /LqSnvRn=''
C:\Windows\tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-10.job - C:\Program Files (x86)\Browseri_Appe 1.2\769db768-0d4c-4e61-b3c9-edbbc6fa9516-10.exe /bWxHzEOQU='Browseri_Appe 1.2' /YouvQ=60346 /GxGEkGdF='001739' /bwNVCJ='verticals-' /cgEIxH='0' /HhOBSahH=4F9B8B2865DD46DEA6E4A78B89F00243IE /HzGgQ=decdc4bd733300b1031bd647f0f4f168 /EtTokA=1_34_07_01 /kLtYi=1404937782 /mCQxdm=http://stats.geninfocloud.com /NVznWIyV=http://errors.geninfocloud.com /iLMVfvZB='Browseri_Appe 1.2' /wXgkYaqWn=1000 /TZtoqKZIK=93-0,102-0,104-0,178-288,179-288,180-288,223-288 /UTFJqVNap=http://logs.geninfocloud.com /IozUWAj='task' /LqSnvRn=''
C:\Windows\tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-11.job - C:\Program Files (x86)\Browseri_Appe 1.2\769db768-0d4c-4e61-b3c9-edbbc6fa9516-11.exe 001739 4F9B8B2865DD46DEA6E4A78B89F00243IE 60346 1404937782 93-0,102-0,104-0,178-288,179-288,180-288,223-288
C:\Windows\tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-2.job - C:\Program Files (x86)\Browseri_Appe 1.2\769db768-0d4c-4e61-b3c9-edbbc6fa9516-2.exe /VIzFfz /bWxHzEOQU='Browseri_Appe 1.2' /YouvQ=60346 /GxGEkGdF='001739' /bwNVCJ='verticals-' /cgEIxH='0' /HhOBSahH=4F9B8B2865DD46DEA6E4A78B89F00243IE /HzGgQ=decdc4bd733300b1031bd647f0f4f168 /EtTokA=1_34_07_01 /kLtYi=1404937782 /mCQxdm=http://stats.geninfocloud.com /NVznWIyV=http://errors.geninfocloud.com /URzNAkFz=11111111-1111-1111-1111-110611031146 /NIFnc=ff /FSoGcOi /dOQoZTpw /FICrMaUw='http://update.geninfocloud.com/ie_enabl ... pdate.json' /IozUWAj='task' /LqSnvRn=''
C:\Windows\tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-3.job - C:\Program Files (x86)\Browseri_Appe 1.2\769db768-0d4c-4e61-b3c9-edbbc6fa9516-3.exe /coHOII=t9QHPcw/ecfpiN4Yp/MV4ytGvql+taQ5jYHYYi4F63FFjHcIbbAkhzvThuyBvRIlwzPg6LLhh8SGj7TTf6Rrroy4pWM7aLvMXlm5HI6kru2iJOzrAZxwTNQoNMX/DVOhnUvsIXj7J3PEnuTpdV5lUDaVC1MP99EJmnx7h2QcKtCTXdbuOhc2xL8dWy4YdEQEPbnn69Y8U0518LBkD2qGXqk9QqD7+G3e3K1bIeDlk43601TfOBhwAUwv86SCaV9sL3fCYoHvjAwMrgw701phCyruNxXJKl152I7f5nwUlisLyVK2y8KjGnrCzdwM2Ut6DekchPRVBEC3nUlvEXUZZG8JDCq1ybAWzoPv4mXhYzch50F1uqPIcaS18mq7x/fmYueeoYT7N1a/JVkkDEbm//d0sHhV9KsejWh3sP8gbhV0h1DPe5Z2RCypgFz+40p7T2VlDeI0Afpy5E12LTyQ5VCLiHVUHqHnGmzedm+FvI3HN5QKef+z2MnojD0wW9LzQUi85ffUz6p45BnFSmcmUKliP8kwMVFv6Nv6i0R9WQxFhPoEmm4rWEnW1kJUstBgc9rkNV7lJ0GrcHumNJQwlHes8hWK5pO4zSLDSEFjhd6AFGimEgzqi+ypKoAAoGN6PhHNcPRbaObEkiWINn55B4Hr6BzBL17yZ6JUxCK81FRxEIH0a22Km9VF+llFDnaemixqCEfLxr38tFKjQrocqekE+i1/vvvuCpb+iZdezyk/mONeJB2QdhotE6BpuuyeSnH3hDHSTaxjHRqokWlrdwn7BPFrhnQDKl6Rzam/X2wrKtW6zpGSuaQGF5FLrHRqwU42zm3LDb+K5urEVKgqghnu++3R8AvlPI7ArPoX/54NOeG6OLPxkpywWI+xAD1g9i/pTbgTFBl4n5XkWNk6F4alL9SlJgjuUKTY7XTZXW3FdU0qZ+aFmmnVOb4gm/H7E4hmcuRKyeYcGHbILZhI19cjHuTiJ3ckQOimubkesN3Xrsat6AdmSbrmofYKrMIqVYoIj40CkjnA4yPpI2Hje0m9BHFYzrFjuWZqwzruDfAW0/iXUaJRzGxn0pWkUDl10Gyp2JqwVA600AF9oWo9q0yovjvOz9McOnuyEyDQLgetFSO4/g3Ahe+3kE+DzMJQjxRvrjtdGS/+keN7oj1r02A/iLtjvb51JH4QtFhFPoJR1QRvRg82zy/EDvH39xNrJVJ/5xrJonSFpLsDew7Koy8F66Dxyv0Y1d/pbAmp2t6v1QP4gRlZVkM27l6QEVwlWF0abEhYbEsJKiL/LTzUBcgBSEt3slQA9M+pf0ACwz9f39sFKEgOL+uwGXTYyGkxdR9sGisXn6bWggLaZMuRLw==
C:\Windows\tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-4.job - C:\Program Files (x86)\Browseri_Appe 1.2\769db768-0d4c-4e61-b3c9-edbbc6fa9516-4.exe /jexcSDbVp /bWxHzEOQU='Browseri_Appe 1.2' /tlAWqrBz='C:\Program Files (x86)\Browseri_Appe 1.2\60346.xpi' /YouvQ=60346 /GxGEkGdF='001739' /bwNVCJ='verticals-' /cgEIxH='0' /HhOBSahH=4F9B8B2865DD46DEA6E4A78B89F00243IE /HzGgQ=decdc4bd733300b1031bd647f0f4f168 /EtTokA=1_34_07_01 /DztlDuNIk=1.34.7.1 /kLtYi=1404937782 /mCQxdm=http://stats.geninfocloud.com /NVznWIyV=http://errors.geninfocloud.com /xpnGql=300 /dvLSqKj=b8c5ecce-0eab-4412-bbe6-6dac31ebfaec@d0bda10d-78c8-4ed2-a9ff-fe1bb21c38dd.com /XvRQPmiii=0.94 /JDSvTHxwk=ab8c5ecce0eab4412bbe66dac31ebfaecd0bda10d78c84ed2a9fffe1bb21c38ddcom60346 /UVpSNfBU=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /60346.rdf /iLMVfvZB='Browseri_Appe 1.2' /PSaPwDx='Enhancing browsing experience' /THnVrsj='app' /NIFnc=ff /RAKNfHriu='{"asw":[32770, 5, 2048]}' /dOQoZTpw /KfkqPV /DoLMSEb /FICrMaUw='http://update.geninfocloud.com/ff_agent ... pdate.json' /IozUWAj='task' /LqSnvRn=''
C:\Windows\tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-5.job - C:\Program Files (x86)\Browseri_Appe 1.2\769db768-0d4c-4e61-b3c9-edbbc6fa9516-5.exe /syLHENzgf /bWxHzEOQU='Browseri_Appe 1.2' /YouvQ=60346 /GxGEkGdF='001739' /bwNVCJ='verticals-' /cgEIxH='0' /HhOBSahH=4F9B8B2865DD46DEA6E4A78B89F00243IE /HzGgQ=decdc4bd733300b1031bd647f0f4f168 /EtTokA=1_34_07_01 /kLtYi=1404937782 /mCQxdm=http://stats.geninfocloud.com /NVznWIyV=http://errors.geninfocloud.com /cZnBzUXaI=http://ipgeoapi.com/ /rHITTcAJM=http://update.geninfocloud.com /lIRHj=2 /UTFJqVNap=http://logs.geninfocloud.com /FICrMaUw='http://update.geninfocloud.com/updater_ ... pdate.json' /IozUWAj='task' /LqSnvRn=''
C:\Windows\tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-5_user.job - C:\Program Files (x86)\Browseri_Appe 1.2\769db768-0d4c-4e61-b3c9-edbbc6fa9516-5.exe /syLHENzgf /bWxHzEOQU='Browseri_Appe 1.2' /YouvQ=60346 /GxGEkGdF='001739' /bwNVCJ='verticals-' /cgEIxH='0' /HhOBSahH=4F9B8B2865DD46DEA6E4A78B89F00243IE /HzGgQ=decdc4bd733300b1031bd647f0f4f168 /EtTokA=1_34_07_01 /kLtYi=1404937782 /mCQxdm=http://stats.geninfocloud.com /NVznWIyV=http://errors.geninfocloud.com /cZnBzUXaI=http://ipgeoapi.com/ /rHITTcAJM=http://update.geninfocloud.com /lIRHj=2 /UTFJqVNap=http://logs.geninfocloud.com /FICrMaUw='http://update.geninfocloud.com/updater_ ... pdate.json' /YjcoVcow /IozUWAj='task' /LqSnvRn=''
C:\Windows\tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-6.job - C:\Program Files (x86)\Browseri_Appe 1.2\Browseri_Appe 1.2-novainstaller.exe /DEgRQ /bWxHzEOQU='Browseri_Appe 1.2' /YouvQ=60346 /GxGEkGdF='001739' /bwNVCJ='verticals-' /cgEIxH='0' /HhOBSahH=4F9B8B2865DD46DEA6E4A78B89F00243IE /HzGgQ=decdc4bd733300b1031bd647f0f4f168 /EtTokA=1_34_07_01 /DztlDuNIk=1.34.7.1 /kLtYi=1404937782 /mCQxdm=http://stats.geninfocloud.com /NVznWIyV=http://errors.geninfocloud.com /WRsVTroBw=http://js.geninfocloud.com /NIFnc=ff /bdJjuhX /wBpTXGGWU=Browseri_Appe 1.2 /FGyBpWj='nova' /BIzTzKS=http://js.clientdemocloud.com /RAKNfHriu='{"asw":[32770, 5, 2048]}' /IozUWAj=task /FICrMaUw='http://update.geninfocloud.com/novacode ... pdate.json' /IozUWAj='task' /LqSnvRn=''
C:\Windows\tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-7.job - C:\Program Files (x86)\Browseri_Appe 1.2\Browseri_Appe 1.2-nova.exe /bWxHzEOQU='Browseri_Appe 1.2' /YouvQ=60346 /GxGEkGdF='001739' /bwNVCJ='verticals-' /cgEIxH='0' /HhOBSahH=4F9B8B2865DD46DEA6E4A78B89F00243IE /HzGgQ=decdc4bd733300b1031bd647f0f4f168 /EtTokA=1_34_07_01 /DztlDuNIk=1.34.7.1 /kLtYi=1404937782 /mCQxdm=http://stats.geninfocloud.com /NVznWIyV=http://errors.geninfocloud.com /WRsVTroBw=http://js.geninfocloud.com /NIFnc=ff /bdJjuhX /wBpTXGGWU=Browseri_Appe 1.2 /FGyBpWj='nova' /BIzTzKS=http://js.clientdemocloud.com /RAKNfHriu='{"asw":[32770, 5, 2048]}' /FICrMaUw='http://update.geninfocloud.com/novarun/ ... pdate.json' /IozUWAj='task' /LqSnvRn=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611031146}]
Browseri_Appe 1.2 - C:\Program Files (x86)\Browseri_Appe 1.2\Browseri_Appe 1.2-bho64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-02 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files (x86)\SupTab\SupTab.dll [2014-07-09 515464]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-02 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1584184]
"Apoint"=C:\Program Files\DellTPad\Apoint.exe [2009-03-31 305664]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-03-31 154648]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-03-31 227352]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-03-31 202264]
"Broadcom Wireless Manager UI"=C:\Windows\system32\WLTRAY.exe [2008-12-21 4119552]
"QuickSet"=C:\Program Files\Dell\QuickSet\QuickSet.exe [2009-03-27 2115664]
"IAAnotif"=C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [2008-06-15 178712]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2010-02-26 487424]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 138240]
"NBCore"=C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBCore.exe [2009-05-15 1590568]
"DellSystemDetect"=C:\Users\new\AppData\Local\Apps\2.0\NGAPRWHV.TY8\7H7O4R4E.7H1\dell..tion_0f612f649c4a10af_0005.0008_a4204ff54ae5d3ac\DellSystemDetect.exe [2014-06-23 262720]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Dell DataSafe Online"=C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe [2009-07-07 1779952]
"Microsoft Default Manager"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2009-04-24 250192]
"DellSupportCenter"=C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe /P DellSupportCenter []
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-02 4086432]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"BingDesktop"=C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey []
"SunJavaUpdateSched"=C:\Program Files (x86)\Java\jre7\bin\jusched.exe []
"Nikon Message Center 2"=C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [2011-10-30 571392]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"upfst_gb_58.exe"=C:\Users\new\AppData\Local\fst_gb_58\upfst_gb_58.exe [2014-07-04 3357176]
C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
DesktopWeatherAlerts.lnk - C:\Users\new\AppData\Local\WeatherAlerts\DesktopWeatherAlertsApp.exe
MyPC Backup.lnk - C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
Tapety 2.12.lnk - C:\Program Files (x86)\Tapety 2.12\Tapety.exe
Weather Alerts.lnk - C:\Users\new\AppData\Local\WeatherAlerts\WeatherAlerts.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~2\SupTab\SEARCH~2.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-03-31 230400]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-07-10 12:53:51 ----D---- C:\rsit
2014-07-09 22:18:25 ----A---- C:\Windows\system32\jscript9.dll
2014-07-09 22:18:24 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-07-09 22:18:24 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-07-09 22:18:24 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-07-09 22:18:24 ----A---- C:\Windows\SYSWOW64\jscript.dll
2014-07-09 22:18:24 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-07-09 22:18:24 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-07-09 22:18:23 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-07-09 22:18:23 ----A---- C:\Windows\system32\wininet.dll
2014-07-09 22:18:23 ----A---- C:\Windows\system32\jsproxy.dll
2014-07-09 22:18:23 ----A---- C:\Windows\system32\dxtrans.dll
2014-07-09 22:18:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-07-09 22:18:21 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-07-09 22:18:18 ----A---- C:\Windows\system32\vbscript.dll
2014-07-09 22:18:17 ----A---- C:\Windows\system32\mshtmled.dll
2014-07-09 22:18:17 ----A---- C:\Windows\system32\ieui.dll
2014-07-09 22:18:17 ----A---- C:\Windows\system32\dxtmsft.dll
2014-07-09 22:18:15 ----A---- C:\Windows\system32\jscript.dll
2014-07-09 22:18:14 ----A---- C:\Windows\system32\mshtml.dll
2014-07-09 22:18:12 ----A---- C:\Windows\SYSWOW64\mshta.exe
2014-07-09 22:18:12 ----A---- C:\Windows\system32\mshta.exe
2014-07-09 22:18:11 ----A---- C:\Windows\system32\ieUnatt.exe
2014-07-09 22:18:10 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-07-09 22:18:10 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-07-09 22:18:09 ----A---- C:\Windows\SYSWOW64\url.dll
2014-07-09 22:18:09 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2014-07-09 22:18:09 ----A---- C:\Windows\system32\urlmon.dll
2014-07-09 22:18:09 ----A---- C:\Windows\system32\iertutil.dll
2014-07-09 22:18:08 ----A---- C:\Windows\system32\msfeeds.dll
2014-07-09 22:18:07 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-07-09 22:18:07 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-07-09 22:18:07 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-07-09 22:18:07 ----A---- C:\Windows\system32\url.dll
2014-07-09 22:18:06 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-07-09 22:18:06 ----A---- C:\Windows\system32\ieframe.dll
2014-07-09 22:17:25 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-07-09 22:17:22 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2014-07-09 22:17:22 ----A---- C:\Windows\system32\msfeedssync.exe
2014-07-09 22:17:11 ----A---- C:\Windows\system32\win32k.sys
2014-07-09 22:15:44 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-07-09 22:15:44 ----A---- C:\Windows\system32\qedit.dll
2014-07-09 22:15:08 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-09 21:52:16 ----D---- C:\Program Files (x86)\fst_gb_60
2014-07-09 21:33:36 ----D---- C:\Users\new\AppData\Roaming\VOPackage
2014-07-09 21:32:44 ----D---- C:\ProgramData\IePluginServices
2014-07-09 21:32:00 ----D---- C:\Program Files (x86)\SupTab
2014-07-09 21:31:34 ----D---- C:\ProgramData\WindowsMangerProtect
2014-07-09 21:30:03 ----D---- C:\Program Files (x86)\globalUpdate
2014-07-09 21:29:57 ----D---- C:\Program Files (x86)\Browseri_Appe 1.2
2014-07-09 21:29:52 ----D---- C:\Program Files (x86)\MyPC Backup
2014-07-09 21:29:37 ----D---- C:\Program Files (x86)\fst_gb_58
2014-07-09 15:49:45 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2014-07-09 15:49:11 ----D---- C:\Windows\PCHEALTH
2014-07-09 15:47:49 ----D---- C:\ProgramData\Nikon
2014-07-09 15:46:54 ----D---- C:\Program Files\Microsoft Office
2014-07-09 15:45:24 ----RHD---- C:\MSOCache
2014-07-09 12:58:30 ----A---- C:\Windows\IsUninst.exe
2014-07-09 12:40:58 ----D---- C:\Program Files (x86)\ArcSoft
2014-07-09 12:40:28 ----D---- C:\Users\new\AppData\Roaming\ArcSoft
2014-07-09 12:39:00 ----D---- C:\Windows\Downloaded Installations
2014-07-09 12:38:30 ----H---- C:\ProgramData\PKP_DLes.DAT
2014-07-09 12:37:34 ----D---- C:\Program Files\Common Files\Nikon
2014-07-09 12:37:34 ----D---- C:\Program Files (x86)\Nikon
2014-07-09 12:37:33 ----D---- C:\Program Files\Nikon
2014-07-09 12:37:22 ----H---- C:\ProgramData\PKP_DLev.DAT
2014-07-09 12:37:22 ----H---- C:\ProgramData\PKP_DLet.DAT
2014-07-09 12:36:28 ----D---- C:\ProgramData\54F3DE4E-B7BA-4EBD-8B3B-385D272CC583
2014-07-09 12:34:51 ----H---- C:\ProgramData\PKP_DLeo.DAT
2014-07-09 12:34:51 ----D---- C:\ProgramData\Ultima_T15
2014-07-09 12:34:51 ----D---- C:\ProgramData\EnterNHelp
2014-07-07 12:02:00 ----D---- C:\a943c332cc4aaaf5f221
2014-07-07 12:01:55 ----A---- C:\Windows\SYSWOW64\tcpipcfg.dll
2014-07-07 12:01:55 ----A---- C:\Windows\SYSWOW64\netiougc.exe
2014-07-07 12:01:55 ----A---- C:\Windows\system32\tcpipcfg.dll
2014-07-07 12:01:55 ----A---- C:\Windows\system32\netiougc.exe
2014-07-07 11:53:58 ----A---- C:\Windows\system32\drivers\watchdog.sys
2014-07-05 12:04:00 ----D---- C:\Program Files (x86)\Tapety 2.12
2014-07-05 11:05:47 ----D---- C:\Users\new\AppData\Roaming\Oracle
2014-07-05 11:05:18 ----D---- C:\ProgramData\AskPartnerNetwork
2014-07-05 11:05:18 ----D---- C:\Program Files (x86)\AskPartnerNetwork
2014-07-05 11:05:10 ----D---- C:\Windows\Sun
2014-07-05 11:05:08 ----D---- C:\ProgramData\APN
2014-07-05 11:03:06 ----D---- C:\ProgramData\Sun
2014-07-05 11:02:43 ----A---- C:\Windows\SYSWOW64\javaws.exe
2014-07-05 11:02:24 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-07-05 11:02:24 ----A---- C:\Windows\SYSWOW64\javaw.exe
2014-07-05 11:02:24 ----A---- C:\Windows\SYSWOW64\java.exe
2014-07-04 10:56:42 ----D---- C:\ProgramData\Oracle
2014-07-02 15:31:17 ----A---- C:\Windows\avastSS.scr
2014-07-02 11:35:09 ----D---- C:\ProgramData\Big Fish
2014-07-02 11:34:09 ----D---- C:\BigFishCache
2014-07-01 19:38:02 ----D---- C:\history
2014-07-01 13:01:40 ----D---- C:\ProgramData\TEMP
2014-06-30 15:47:00 ----A---- C:\Windows\Irremote.ini
2014-06-30 13:49:18 ----D---- C:\ProgramData\MySearch
2014-06-30 13:49:18 ----D---- C:\Program Files (x86)\MySearch
2014-06-30 13:49:03 ----D---- C:\ProgramData\Wideblue installer
2014-06-30 13:47:50 ----D---- C:\ProgramData\1cbea09c991e06b6
2014-06-30 13:47:15 ----D---- C:\ProgramData\InstallMate
2014-06-30 11:52:27 ----D---- C:\Program Files (x86)\MSXML 4.0
2014-06-30 10:23:19 ----D---- C:\Users\new\AppData\Roaming\Nero
2014-06-30 10:16:47 ----D---- C:\ProgramData\Nero
2014-06-26 15:00:53 ----A---- C:\Windows\SYSWOW64\webservices.dll
2014-06-26 15:00:53 ----A---- C:\Windows\system32\webservices.dll
2014-06-26 09:35:05 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2014-06-26 09:35:05 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-06-26 09:35:05 ----A---- C:\Windows\system32\d3d10warp.dll
2014-06-26 09:35:04 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2014-06-26 09:35:04 ----A---- C:\Windows\SYSWOW64\d3d10.dll
2014-06-26 09:35:04 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2014-06-26 09:35:04 ----A---- C:\Windows\system32\DWrite.dll
2014-06-26 09:35:04 ----A---- C:\Windows\system32\d2d1.dll
2014-06-26 09:35:03 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2014-06-26 09:35:03 ----A---- C:\Windows\SYSWOW64\d3d10core.dll
2014-06-26 09:35:03 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2014-06-26 09:35:03 ----A---- C:\Windows\system32\FntCache.dll
2014-06-26 09:35:03 ----A---- C:\Windows\system32\d3d10level9.dll
2014-06-26 09:35:03 ----A---- C:\Windows\system32\d3d10core.dll
2014-06-26 09:35:03 ----A---- C:\Windows\system32\d3d10_1core.dll
2014-06-26 09:35:03 ----A---- C:\Windows\system32\d3d10_1.dll
2014-06-26 09:35:03 ----A---- C:\Windows\system32\d3d10.dll
2014-06-26 09:34:24 ----A---- C:\Windows\system32\XpsPrint.dll
2014-06-26 09:34:23 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2014-06-25 22:36:49 ----D---- C:\Windows\Migration
2014-06-25 20:08:36 ----D---- C:\Users\new\AppData\Roaming\0ad
2014-06-25 17:31:27 ----D---- C:\Team17
2014-06-25 17:09:07 ----A---- C:\Windows\game.ini
2014-06-25 16:08:04 ----D---- C:\Program Files (x86)\GameTop.com
2014-06-25 15:59:38 ----D---- C:\Program Files\Windows Portable Devices
2014-06-25 15:59:38 ----D---- C:\Program Files (x86)\Windows Portable Devices
2014-06-25 15:41:26 ----A---- C:\Windows\SYSWOW64\WPDShextAutoplay.exe
2014-06-25 15:41:26 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2014-06-25 15:41:25 ----A---- C:\Windows\system32\wpdbusenum.dll
2014-06-25 15:41:25 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
2014-06-25 15:41:10 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2014-06-25 15:41:09 ----A---- C:\Windows\SYSWOW64\WPDShServiceObj.dll
2014-06-25 15:41:09 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2014-06-25 15:41:09 ----A---- C:\Windows\SYSWOW64\PortableDeviceTypes.dll
2014-06-25 15:41:09 ----A---- C:\Windows\SYSWOW64\PortableDeviceConnectApi.dll
2014-06-25 15:41:09 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2014-06-25 15:41:09 ----A---- C:\Windows\system32\wpdshext.dll
2014-06-25 15:41:09 ----A---- C:\Windows\system32\wpd_ci.dll
2014-06-25 15:41:08 ----A---- C:\Windows\SYSWOW64\WPDSp.dll
2014-06-25 15:41:08 ----A---- C:\Windows\SYSWOW64\PortableDeviceWMDRM.dll
2014-06-25 15:41:08 ----A---- C:\Windows\SYSWOW64\PortableDeviceClassExtension.dll
2014-06-25 15:41:08 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2014-06-25 15:41:08 ----A---- C:\Windows\system32\WPDSp.dll
2014-06-25 15:41:08 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2014-06-25 15:41:08 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2014-06-25 15:41:08 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2014-06-25 15:41:08 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2014-06-25 15:13:53 ----D---- C:\Windows\SYSWOW64\spool
2014-06-25 15:12:04 ----N---- C:\Windows\system32\stapi64.dll
2014-06-25 14:57:04 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-06-25 14:52:28 ----D---- C:\4d96164ad5aedf959685c0418784
2014-06-25 14:09:51 ----A---- C:\Windows\system32\winusb.dll
2014-06-25 14:09:49 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2014-06-25 14:09:49 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2014-06-25 14:09:48 ----A---- C:\Windows\SYSWOW64\winusb.dll
2014-06-25 14:09:47 ----A---- C:\Windows\system32\WUDFSvc.dll
2014-06-25 14:09:47 ----A---- C:\Windows\system32\WUDFPlatform.dll
2014-06-25 14:09:40 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2014-06-25 14:09:39 ----A---- C:\Windows\system32\WUDFx.dll
2014-06-25 14:09:39 ----A---- C:\Windows\system32\WUDFHost.exe
2014-06-25 13:55:32 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-06-25 13:55:32 ----A---- C:\Windows\SYSWOW64\msls31.dll
2014-06-25 13:55:31 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2014-06-25 13:55:31 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2014-06-25 13:55:31 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2014-06-25 13:55:31 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2014-06-25 13:55:29 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-06-25 13:55:29 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-06-25 13:55:29 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-06-25 13:55:29 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2014-06-25 13:55:29 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2014-06-25 13:55:29 ----A---- C:\Windows\SYSWOW64\icardie.dll
2014-06-25 13:55:28 ----A---- C:\Windows\SYSWOW64\wextract.exe
2014-06-25 13:55:28 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2014-06-25 13:55:28 ----A---- C:\Windows\SYSWOW64\inseng.dll
2014-06-25 13:55:28 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2014-06-25 13:55:28 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-06-25 13:55:27 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2014-06-25 13:55:26 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2014-06-25 13:55:25 ----A---- C:\Windows\SYSWOW64\occache.dll
2014-06-25 13:55:25 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2014-06-25 13:55:25 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2014-06-25 13:55:25 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2014-06-25 13:55:25 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2014-06-25 13:55:25 ----A---- C:\Windows\SYSWOW64\advpack.dll
2014-06-25 13:55:25 ----A---- C:\Windows\SYSWOW64\admparse.dll
2014-06-25 13:55:24 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2014-06-25 13:55:24 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2014-06-25 13:55:22 ----A---- C:\Windows\system32\msls31.dll
2014-06-25 13:55:21 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2014-06-25 13:55:21 ----A---- C:\Windows\system32\msrating.dll
2014-06-25 13:55:21 ----A---- C:\Windows\system32\imgutil.dll
2014-06-25 13:55:21 ----A---- C:\Windows\system32\iepeers.dll
2014-06-25 13:55:21 ----A---- C:\Windows\system32\ieakui.dll
2014-06-25 13:55:21 ----A---- C:\Windows\system32\ieaksie.dll
2014-06-25 13:55:21 ----A---- C:\Windows\system32\advpack.dll
2014-06-25 13:55:21 ----A---- C:\Windows\system32\admparse.dll
2014-06-25 13:55:20 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2014-06-25 13:55:20 ----A---- C:\Windows\system32\mshtmler.dll
2014-06-25 13:55:20 ----A---- C:\Windows\system32\iesysprep.dll
2014-06-25 13:55:20 ----A---- C:\Windows\system32\ieakeng.dll
2014-06-25 13:55:20 ----A---- C:\Windows\system32\IEAdvpack.dll
2014-06-25 13:55:19 ----A---- C:\Windows\system32\iesetup.dll
2014-06-25 13:55:19 ----A---- C:\Windows\system32\iernonce.dll
2014-06-25 13:55:19 ----A---- C:\Windows\system32\ieapfltr.dll
2014-06-25 13:55:19 ----A---- C:\Windows\system32\ieapfltr.dat
2014-06-25 13:55:19 ----A---- C:\Windows\system32\ie4uinit.exe
2014-06-25 13:55:19 ----A---- C:\Windows\system32\icardie.dll
2014-06-25 13:55:18 ----A---- C:\Windows\system32\wextract.exe
2014-06-25 13:55:18 ----A---- C:\Windows\system32\webcheck.dll
2014-06-25 13:55:18 ----A---- C:\Windows\system32\licmgr10.dll
2014-06-25 13:55:18 ----A---- C:\Windows\system32\inseng.dll
2014-06-25 13:55:18 ----A---- C:\Windows\system32\iexpress.exe
2014-06-25 13:55:18 ----A---- C:\Windows\system32\iedkcs32.dll
2014-06-25 13:55:17 ----A---- C:\Windows\system32\pngfilt.dll
2014-06-25 13:55:17 ----A---- C:\Windows\system32\occache.dll
2014-06-25 13:52:07 ----A---- C:\Windows\SYSWOW64\MFHEAACdec.dll
2014-06-25 13:52:07 ----A---- C:\Windows\SYSWOW64\MFH264Dec.dll
2014-06-25 13:52:07 ----A---- C:\Windows\system32\MFHEAACdec.dll
2014-06-25 13:52:07 ----A---- C:\Windows\system32\MFH264Dec.dll
2014-06-25 13:52:06 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2014-06-25 13:52:06 ----A---- C:\Windows\SYSWOW64\mfmp4src.dll
2014-06-25 13:52:06 ----A---- C:\Windows\system32\mfreadwrite.dll
2014-06-25 13:52:06 ----A---- C:\Windows\system32\mfmp4src.dll
2014-06-25 13:52:05 ----A---- C:\Windows\SYSWOW64\mf.dll
2014-06-25 13:52:05 ----A---- C:\Windows\system32\mfps.dll
2014-06-25 13:52:05 ----A---- C:\Windows\system32\mfpmp.exe
2014-06-25 13:52:05 ----A---- C:\Windows\system32\mf.dll
2014-06-25 13:52:04 ----A---- C:\Windows\SYSWOW64\mfps.dll
2014-06-25 13:52:03 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2014-06-25 13:52:03 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2014-06-25 13:52:03 ----A---- C:\Windows\system32\shdocvw.dll
2014-06-25 13:52:03 ----A---- C:\Windows\system32\mfplat.dll
2014-06-25 13:52:02 ----A---- C:\Windows\SYSWOW64\stobject.dll
2014-06-25 13:52:02 ----A---- C:\Windows\system32\stobject.dll
2014-06-25 13:51:58 ----A---- C:\Windows\system32\XpsRasterService.dll
2014-06-25 13:51:55 ----A---- C:\Windows\SYSWOW64\OpcServices.dll
2014-06-25 13:51:55 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2014-06-25 13:51:55 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2014-06-25 13:51:55 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2014-06-25 13:51:55 ----A---- C:\Windows\system32\OpcServices.dll
2014-06-25 13:51:55 ----A---- C:\Windows\system32\dxgi.dll
2014-06-25 13:51:54 ----A---- C:\Windows\SYSWOW64\xpsservices.dll
2014-06-25 13:51:54 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2014-06-25 13:51:54 ----A---- C:\Windows\system32\xpsservices.dll
2014-06-25 13:48:16 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2014-06-25 13:48:16 ----A---- C:\Windows\SYSWOW64\dxdiagn.dll
2014-06-25 13:48:16 ----A---- C:\Windows\SYSWOW64\dxdiag.exe
2014-06-25 13:48:16 ----A---- C:\Windows\system32\WMPhoto.dll
2014-06-25 13:48:16 ----A---- C:\Windows\system32\dxdiagn.dll
2014-06-25 13:48:16 ----A---- C:\Windows\system32\dxdiag.exe
2014-06-25 13:48:14 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2014-06-25 13:48:14 ----A---- C:\Windows\system32\d3d11.dll
2014-06-25 13:48:13 ----A---- C:\Windows\SYSWOW64\WindowsCodecsExt.dll
2014-06-25 13:48:13 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2014-06-25 13:48:13 ----A---- C:\Windows\SYSWOW64\PhotoMetadataHandler.dll
2014-06-25 13:48:13 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2014-06-25 13:48:13 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-06-25 13:48:13 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2014-06-25 10:54:24 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-06-25 10:54:23 ----A---- C:\Windows\system32\ntdll.dll
2014-06-25 10:54:22 ----A---- C:\Windows\SYSWOW64\setup16.exe
2014-06-25 10:54:22 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2014-06-25 10:54:22 ----A---- C:\Windows\system32\wow64.dll
2014-06-25 10:54:22 ----A---- C:\Windows\system32\smss.exe
2014-06-25 10:54:22 ----A---- C:\Windows\system32\ntvdm64.dll
2014-06-25 10:54:22 ----A---- C:\Windows\system32\csrsrv.dll
2014-06-25 10:54:21 ----A---- C:\Windows\SYSWOW64\wow32.dll
2014-06-25 10:54:21 ----A---- C:\Windows\SYSWOW64\user.exe
2014-06-25 10:54:21 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2014-06-25 10:54:21 ----A---- C:\Windows\SYSWOW64\instnm.exe
2014-06-25 10:54:17 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2014-06-25 10:54:17 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-06-25 10:54:14 ----A---- C:\Windows\system32\shell32.dll
2014-06-25 10:54:10 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-06-25 10:54:07 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-06-25 10:54:05 ----A---- C:\Windows\system32\IKEEXT.DLL
2014-06-25 10:54:05 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2014-06-25 10:54:04 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2014-06-25 10:53:54 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2014-06-25 10:53:52 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2014-06-25 10:53:16 ----A---- C:\Windows\SYSWOW64\synceng.dll
2014-06-25 10:53:16 ----A---- C:\Windows\system32\synceng.dll
2014-06-25 10:53:15 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2014-06-25 10:53:15 ----A---- C:\Windows\system32\msvcrt.dll
2014-06-25 10:53:13 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-06-25 10:52:22 ----A---- C:\Windows\SYSWOW64\msshsq.dll
2014-06-25 10:52:22 ----A---- C:\Windows\system32\msshsq.dll
2014-06-25 10:52:21 ----A---- C:\Windows\system32\wer.dll
2014-06-25 10:52:20 ----A---- C:\Windows\SYSWOW64\wer.dll
2014-06-25 10:52:18 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-06-25 10:52:18 ----A---- C:\Windows\system32\cdd.dll
2014-06-25 10:52:12 ----A---- C:\Windows\SYSWOW64\certutil.exe
2014-06-25 10:52:12 ----A---- C:\Windows\system32\certutil.exe
2014-06-25 10:52:11 ----A---- C:\Windows\system32\certenc.dll
2014-06-25 10:52:10 ----A---- C:\Windows\SYSWOW64\certenc.dll
2014-06-25 10:51:56 ----A---- C:\Windows\system32\icaapi.dll
2014-06-25 10:51:56 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-06-25 10:51:43 ----A---- C:\Windows\system32\jnwmon.dll
2014-06-25 10:51:40 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-06-25 10:51:40 ----A---- C:\Windows\system32\ncrypt.dll
2014-06-25 10:51:37 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2014-06-25 10:51:36 ----A---- C:\Windows\system32\qdvd.dll
2014-06-25 10:51:29 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-06-25 10:51:29 ----A---- C:\Windows\system32\tzres.dll
2014-06-25 10:51:12 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2014-06-25 10:51:12 ----A---- C:\Windows\system32\cryptdlg.dll
2014-06-25 10:50:59 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2014-06-25 10:50:59 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-06-25 10:50:57 ----A---- C:\Windows\system32\rpcrt4.dll
2014-06-25 10:50:56 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-06-25 10:50:55 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2014-06-25 10:50:55 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2014-06-25 10:50:55 ----A---- C:\Windows\system32\atmlib.dll
2014-06-25 10:50:55 ----A---- C:\Windows\system32\atmfd.dll
2014-06-25 10:49:34 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2014-06-25 10:49:34 ----A---- C:\Windows\SYSWOW64\oleaccrc.dll
2014-06-25 10:49:34 ----A---- C:\Windows\system32\UIAutomationCore.dll
2014-06-25 10:49:34 ----A---- C:\Windows\system32\oleaccrc.dll
2014-06-25 10:49:33 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2014-06-25 10:49:33 ----A---- C:\Windows\system32\oleacc.dll
2014-06-25 10:49:32 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2014-06-25 10:49:32 ----A---- C:\Windows\system32\oleaut32.dll
2014-06-25 10:49:08 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2014-06-25 10:49:07 ----A---- C:\Windows\system32\xmllite.dll
2014-06-25 10:48:47 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2014-06-25 10:48:47 ----A---- C:\Windows\system32\winhttp.dll
2014-06-25 10:48:41 ----A---- C:\Windows\system32\winmm.dll
2014-06-25 10:48:41 ----A---- C:\Windows\system32\mciwave.dll
2014-06-25 10:48:41 ----A---- C:\Windows\system32\mciseq.dll
2014-06-25 10:48:40 ----A---- C:\Windows\SYSWOW64\winmm.dll
2014-06-25 10:48:40 ----A---- C:\Windows\SYSWOW64\mciseq.dll
2014-06-25 10:48:40 ----A---- C:\Windows\system32\mcicda.dll
2014-06-25 10:48:06 ----A---- C:\Windows\system32\crypt32.dll
2014-06-25 10:48:05 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2014-06-25 10:46:42 ----A---- C:\Windows\system32\drivers\hidparse.sys
2014-06-25 10:45:45 ----A---- C:\Windows\system32\drivers\volsnap.sys
2014-06-25 10:45:34 ----A---- C:\Windows\system32\usp10.dll
2014-06-25 10:45:33 ----A---- C:\Windows\SYSWOW64\usp10.dll
2014-06-25 10:45:29 ----A---- C:\Windows\system32\EncDec.dll
2014-06-25 10:45:28 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2014-06-25 10:44:31 ----A---- C:\Windows\system32\kernel32.dll
2014-06-25 10:44:30 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2014-06-25 10:44:24 ----A---- C:\Windows\system32\dpnet.dll
2014-06-25 10:44:24 ----A---- C:\Windows\system32\dpnathlp.dll
2014-06-25 10:44:23 ----A---- C:\Windows\SYSWOW64\dpnsvr.exe
2014-06-25 10:44:23 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2014-06-25 10:44:23 ----A---- C:\Windows\system32\dpnsvr.exe
2014-06-25 10:04:02 ----A---- C:\Windows\SYSWOW64\themeui.dll
2014-06-25 10:04:02 ----A---- C:\Windows\system32\themeui.dll
2014-06-25 10:03:28 ----A---- C:\Windows\system32\drivers\usb8023.sys
2014-06-25 10:03:25 ----A---- C:\Windows\SYSWOW64\wscript.exe
2014-06-25 10:03:25 ----A---- C:\Windows\system32\wscript.exe
2014-06-25 10:03:25 ----A---- C:\Windows\system32\scrrun.dll
2014-06-25 10:03:25 ----A---- C:\Windows\system32\cscript.exe
2014-06-25 10:03:24 ----A---- C:\Windows\SYSWOW64\wshcon.dll
2014-06-25 10:03:24 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2014-06-25 10:03:24 ----A---- C:\Windows\SYSWOW64\cscript.exe
2014-06-25 10:03:15 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-06-25 10:03:14 ----A---- C:\Windows\system32\lsasrv.dll
2014-06-25 10:03:13 ----A---- C:\Windows\system32\schannel.dll
2014-06-25 10:03:13 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-06-25 10:03:12 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-06-25 10:03:11 ----A---- C:\Windows\system32\secur32.dll
2014-06-25 10:03:11 ----A---- C:\Windows\system32\lsass.exe
2014-06-25 10:03:07 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-06-25 10:03:07 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-06-25 10:03:03 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-06-25 10:03:03 ----A---- C:\Windows\system32\gdi32.dll
2014-06-25 10:02:57 ----A---- C:\Windows\system32\wintrust.dll
2014-06-25 10:02:57 ----A---- C:\Windows\system32\cryptsvc.dll
2014-06-25 10:02:57 ----A---- C:\Windows\system32\cryptnet.dll
2014-06-25 10:02:56 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2014-06-25 10:02:56 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2014-06-25 10:02:56 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2014-06-25 10:02:40 ----A---- C:\Windows\system32\comctl32.dll
2014-06-25 10:02:39 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2014-06-25 10:02:37 ----A---- C:\Windows\SYSWOW64\shlwapi.dll
2014-06-25 10:02:37 ----A---- C:\Windows\system32\shlwapi.dll
2014-06-25 10:02:34 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2014-06-25 10:02:34 ----A---- C:\Windows\system32\imagehlp.dll
2014-06-25 10:02:32 ----A---- C:\Windows\system32\Wdfres.dll
2014-06-25 10:02:32 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2014-06-25 10:02:31 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2014-06-25 10:02:26 ----A---- C:\Windows\system32\localspl.dll
2014-06-25 10:02:25 ----A---- C:\Windows\SYSWOW64\localspl.dll
2014-06-25 10:02:10 ----A---- C:\Windows\system32\netapi32.dll
2014-06-25 10:02:09 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2014-06-25 10:02:07 ----A---- C:\Windows\system32\winsrv.dll
2014-06-25 10:02:03 ----A---- C:\Windows\SYSWOW64\quartz.dll
2014-06-25 10:02:03 ----A---- C:\Windows\system32\quartz.dll
2014-06-25 10:02:01 ----A---- C:\Windows\system32\msxml3.dll
2014-06-25 10:02:00 ----A---- C:\Windows\system32\msxml6.dll
2014-06-25 10:01:59 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2014-06-25 10:01:59 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-06-25 10:01:11 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-06-25 10:01:11 ----A---- C:\Windows\system32\packager.dll
2014-06-25 10:01:09 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2014-06-25 10:01:09 ----A---- C:\Windows\system32\drivers\usbport.sys
2014-06-25 10:01:09 ----A---- C:\Windows\system32\drivers\usbhub.sys
2014-06-25 10:01:09 ----A---- C:\Windows\system32\drivers\usbehci.sys
2014-06-25 10:01:09 ----A---- C:\Windows\system32\drivers\usbd.sys
2014-06-25 10:01:01 ----A---- C:\Windows\system32\SysFxUI.dll
2014-06-25 10:01:01 ----A---- C:\Windows\system32\drivers\portcls.sys
2014-06-25 10:01:01 ----A---- C:\Windows\system32\drivers\drmk.sys
2014-06-25 10:00:55 ----A---- C:\Windows\system32\drivers\partmgr.sys
2014-06-25 09:59:04 ----A---- C:\Windows\system32\mstscax.dll
2014-06-25 09:59:02 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-06-25 09:56:57 ----A---- C:\Windows\system32\psisdecd.dll
2014-06-25 09:56:55 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2014-06-25 09:56:22 ----A---- C:\Windows\system32\win32spl.dll
2014-06-25 09:56:20 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2014-06-25 09:56:20 ----A---- C:\Windows\SYSWOW64\printcom.dll
2014-06-25 08:36:06 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2014-06-25 08:36:05 ----A---- C:\Windows\system32\UIAnimation.dll
2014-06-25 08:35:58 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2014-06-25 08:35:58 ----A---- C:\Windows\system32\UIRibbonRes.dll
2014-06-25 08:35:57 ----A---- C:\Windows\system32\UIRibbon.dll
2014-06-25 08:35:56 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2014-06-25 08:35:44 ----A---- C:\Windows\SYSWOW64\wmi.dll
2014-06-25 08:35:44 ----A---- C:\Windows\system32\wmi.dll
2014-06-25 08:35:44 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2014-06-25 08:18:34 ----A---- C:\Windows\SYSWOW64\rdpencom.dll
2014-06-25 08:18:34 ----A---- C:\Windows\system32\rdpencom.dll
2014-06-25 07:50:20 ----A---- C:\Windows\system32\wups2.dll
2014-06-25 07:50:20 ----A---- C:\Windows\system32\wuauclt.exe
2014-06-25 07:50:19 ----A---- C:\Windows\system32\wucltux.dll
2014-06-25 07:50:18 ----A---- C:\Windows\system32\wuaueng.dll
2014-06-25 07:49:48 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-06-25 07:49:48 ----A---- C:\Windows\system32\wups.dll
2014-06-25 07:49:48 ----A---- C:\Windows\system32\wudriver.dll
2014-06-25 07:49:47 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-06-25 07:49:47 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-06-25 07:49:47 ----A---- C:\Windows\system32\wuapi.dll
2014-06-25 07:49:31 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-06-25 07:49:31 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-06-25 07:49:31 ----A---- C:\Windows\system32\wuwebv.dll
2014-06-25 07:49:31 ----A---- C:\Windows\system32\wuapp.exe
2014-06-24 11:25:18 ----D---- C:\ProgramData\McAfee Security Scan
2014-06-24 11:24:56 ----D---- C:\Program Files (x86)\McAfee Security Scan
2014-06-24 10:47:52 ----D---- C:\Windows\SYSWOW64\vi-VN
2014-06-24 10:47:52 ----D---- C:\Windows\SYSWOW64\eu-ES
2014-06-24 10:47:52 ----D---- C:\Windows\SYSWOW64\ca-ES
2014-06-24 10:47:51 ----D---- C:\Windows\system32\eu-ES
2014-06-24 10:47:51 ----D---- C:\Windows\system32\ca-ES
2014-06-24 10:47:50 ----D---- C:\Windows\system32\vi-VN
2014-06-24 09:03:34 ----D---- C:\Windows\system32\EventProviders
2014-06-23 22:56:23 ----D---- C:\Program Files (x86)\THQ
2014-06-23 16:11:40 ----A---- C:\Windows\SYSWOW64\CSVer.dll
2014-06-23 16:04:22 ----A---- C:\Windows\system32\drivers\stwrt64.sys
2014-06-23 16:04:20 ----A---- C:\Windows\system32\stcplx64.dll
2014-06-23 16:04:19 ----A---- C:\Windows\system32\st646272.dll
2014-06-23 16:04:16 ----A---- C:\Windows\SYSWOW64\ctapo32.dll
2014-06-23 16:04:14 ----D---- C:\Program Files\IDT
2014-06-23 14:24:28 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-06-23 13:39:51 ----D---- C:\ProgramData\PC-Doctor for Windows
2014-06-23 13:39:50 ----D---- C:\Program Files\Dell Support Center
2014-06-23 13:38:31 ----D---- C:\Program Files\My Dell
2014-06-23 13:35:01 ----D---- C:\Users\new\AppData\Roaming\PCDr
2014-06-23 13:34:58 ----D---- C:\temp
2014-06-23 13:07:04 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2014-06-23 13:07:04 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2014-06-23 13:07:04 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2014-06-23 13:07:04 ----A---- C:\Windows\system32\XAudio2_7.dll
2014-06-23 13:07:04 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2014-06-23 13:07:04 ----A---- C:\Windows\system32\xactengine3_7.dll
2014-06-23 13:07:03 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2014-06-23 13:07:03 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2014-06-23 13:07:02 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2014-06-23 13:07:02 ----A---- C:\Windows\system32\d3dcsx_43.dll
2014-06-23 13:06:57 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2014-06-23 13:06:57 ----A---- C:\Windows\system32\d3dx11_43.dll
2014-06-23 13:06:52 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2014-06-23 13:06:52 ----A---- C:\Windows\system32\d3dx10_43.dll
2014-06-23 13:06:51 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2014-06-23 13:06:51 ----A---- C:\Windows\system32\D3DX9_43.dll
2014-06-23 13:06:50 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2014-06-23 13:06:50 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2014-06-23 13:06:50 ----A---- C:\Windows\system32\XAudio2_6.dll
2014-06-23 13:06:50 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2014-06-23 13:06:41 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2014-06-23 13:06:41 ----A---- C:\Windows\system32\xactengine3_6.dll
2014-06-23 13:06:40 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2014-06-23 13:06:40 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2014-06-23 13:06:39 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2014-06-23 13:06:39 ----A---- C:\Windows\system32\XAudio2_5.dll
2014-06-23 13:06:38 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2014-06-23 13:06:38 ----A---- C:\Windows\system32\xactengine3_5.dll
2014-06-23 13:06:37 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2014-06-23 13:06:37 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2014-06-23 13:06:36 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2014-06-23 13:06:36 ----A---- C:\Windows\system32\d3dcsx_42.dll
2014-06-23 13:06:35 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2014-06-23 13:06:35 ----A---- C:\Windows\system32\d3dx11_42.dll
2014-06-23 13:06:34 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2014-06-23 13:06:34 ----A---- C:\Windows\system32\d3dx10_42.dll
2014-06-23 13:06:33 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2014-06-23 13:06:33 ----A---- C:\Windows\system32\D3DX9_42.dll
2014-06-23 13:06:24 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2014-06-23 13:06:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2014-06-23 13:06:24 ----A---- C:\Windows\system32\d3dx10_41.dll
2014-06-23 13:06:24 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2014-06-23 13:06:23 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2014-06-23 13:06:23 ----A---- C:\Windows\system32\D3DX9_41.dll
2014-06-23 13:06:22 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2014-06-23 13:06:22 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2014-06-23 13:06:22 ----A---- C:\Windows\system32\XAudio2_4.dll
2014-06-23 13:06:22 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2014-06-23 13:06:21 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2014-06-23 13:06:21 ----A---- C:\Windows\system32\xactengine3_4.dll
2014-06-23 13:06:20 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2014-06-23 13:06:20 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2014-06-23 13:06:15 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2014-06-23 13:06:15 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2014-06-23 13:06:15 ----A---- C:\Windows\system32\d3dx10_40.dll
2014-06-23 13:06:15 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2014-06-23 13:06:14 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2014-06-23 13:06:14 ----A---- C:\Windows\system32\D3DX9_40.dll
2014-06-23 13:06:12 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2014-06-23 13:06:12 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2014-06-23 13:06:12 ----A---- C:\Windows\system32\XAudio2_3.dll
2014-06-23 13:06:12 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2014-06-23 13:06:03 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2014-06-23 13:06:03 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2014-06-23 13:06:03 ----A---- C:\Windows\system32\xactengine3_3.dll
2014-06-23 13:06:03 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2014-06-23 13:06:02 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2014-06-23 13:06:02 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2014-06-23 13:06:01 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2014-06-23 13:06:01 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2014-06-23 13:06:01 ----A---- C:\Windows\system32\XAudio2_2.dll
2014-06-23 13:06:01 ----A---- C:\Windows\system32\xactengine3_2.dll
2014-06-23 13:06:00 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2014-06-23 13:06:00 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2014-06-23 13:06:00 ----A---- C:\Windows\system32\d3dx10_39.dll
2014-06-23 13:06:00 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2014-06-23 13:05:58 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2014-06-23 13:05:58 ----A---- C:\Windows\system32\D3DX9_39.dll
2014-06-23 13:05:57 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2014-06-23 13:05:57 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2014-06-23 13:05:57 ----A---- C:\Windows\system32\XAudio2_1.dll
2014-06-23 13:05:57 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2014-06-23 13:05:56 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2014-06-23 13:05:56 ----A---- C:\Windows\system32\xactengine3_1.dll
2014-06-23 13:05:55 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2014-06-23 13:05:55 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2014-06-23 13:05:40 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2014-06-23 13:05:40 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2014-06-23 13:05:40 ----A---- C:\Windows\system32\d3dx10_38.dll
2014-06-23 13:05:40 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2014-06-23 13:05:39 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2014-06-23 13:05:39 ----A---- C:\Windows\system32\D3DX9_38.dll
2014-06-23 13:05:38 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2014-06-23 13:05:38 ----A---- C:\Windows\system32\XAudio2_0.dll
2014-06-23 13:05:37 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2014-06-23 13:05:37 ----A---- C:\Windows\system32\xactengine3_0.dll
2014-06-23 13:05:36 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2014-06-23 13:05:36 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2014-06-23 13:05:35 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2014-06-23 13:05:35 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2014-06-23 13:05:35 ----A---- C:\Windows\system32\d3dx10_37.dll
2014-06-23 13:05:35 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2014-06-23 13:05:34 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2014-06-23 13:05:34 ----A---- C:\Windows\system32\D3DX9_37.dll
2014-06-23 13:05:33 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2014-06-23 13:05:33 ----A---- C:\Windows\system32\xactengine2_10.dll
2014-06-23 13:05:31 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2014-06-23 13:05:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2014-06-23 13:05:31 ----A---- C:\Windows\system32\d3dx10_36.dll
2014-06-23 13:05:31 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2014-06-23 13:05:29 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2014-06-23 13:05:29 ----A---- C:\Windows\system32\d3dx9_36.dll
2014-06-23 13:05:28 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2014-06-23 13:05:28 ----A---- C:\Windows\system32\xactengine2_9.dll
2014-06-23 13:05:27 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2014-06-23 13:05:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2014-06-23 13:05:27 ----A---- C:\Windows\system32\d3dx10_35.dll
2014-06-23 13:05:27 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2014-06-23 13:05:26 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2014-06-23 13:05:26 ----A---- C:\Windows\system32\d3dx9_35.dll
2014-06-23 13:05:25 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2014-06-23 13:05:25 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2014-06-23 13:05:25 ----A---- C:\Windows\system32\xactengine2_8.dll
2014-06-23 13:05:25 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2014-06-23 13:05:24 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2014-06-23 13:05:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2014-06-23 13:05:24 ----A---- C:\Windows\system32\d3dx10_34.dll
2014-06-23 13:05:24 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2014-06-23 13:05:22 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2014-06-23 13:05:22 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2014-06-23 13:05:22 ----A---- C:\Windows\system32\xinput1_3.dll
2014-06-23 13:05:22 ----A---- C:\Windows\system32\d3dx9_34.dll
2014-06-23 13:05:21 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2014-06-23 13:05:21 ----A---- C:\Windows\system32\xactengine2_7.dll
2014-06-23 13:05:19 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2014-06-23 13:05:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2014-06-23 13:05:19 ----A---- C:\Windows\system32\d3dx10_33.dll
2014-06-23 13:05:19 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2014-06-23 13:05:18 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2014-06-23 13:05:18 ----A---- C:\Windows\system32\d3dx9_33.dll
2014-06-23 13:05:17 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2014-06-23 13:05:17 ----A---- C:\Windows\system32\xactengine2_6.dll
2014-06-23 13:05:16 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2014-06-23 13:05:16 ----A---- C:\Windows\system32\xactengine2_5.dll
2014-06-23 13:05:15 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2014-06-23 13:05:15 ----A---- C:\Windows\system32\d3dx10.dll
2014-06-23 13:05:13 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2014-06-23 13:05:13 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2014-06-23 13:05:13 ----A---- C:\Windows\system32\xactengine2_4.dll
2014-06-23 13:05:13 ----A---- C:\Windows\system32\x3daudio1_1.dll
2014-06-23 13:04:42 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2014-06-23 13:04:42 ----A---- C:\Windows\system32\d3dx9_31.dll
2014-06-23 13:04:41 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2014-06-23 13:04:41 ----A---- C:\Windows\system32\xactengine2_3.dll
2014-06-23 13:04:40 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2014-06-23 13:04:40 ----A---- C:\Windows\system32\xinput1_2.dll
2014-06-23 13:04:38 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2014-06-23 13:04:38 ----A---- C:\Windows\system32\xactengine2_2.dll
2014-06-23 13:04:37 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2014-06-23 13:04:37 ----A---- C:\Windows\system32\xinput1_1.dll
2014-06-23 13:04:36 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2014-06-23 13:04:36 ----A---- C:\Windows\system32\xactengine2_1.dll
2014-06-23 13:04:32 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2014-06-23 13:04:32 ----A---- C:\Windows\system32\d3dx9_30.dll
2014-06-23 13:04:30 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2014-06-23 13:04:30 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2014-06-23 13:04:30 ----A---- C:\Windows\system32\xactengine2_0.dll
2014-06-23 13:04:30 ----A---- C:\Windows\system32\x3daudio1_0.dll
2014-06-23 13:04:29 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2014-06-23 13:04:29 ----A---- C:\Windows\system32\d3dx9_29.dll
2014-06-23 13:04:28 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2014-06-23 13:04:28 ----A---- C:\Windows\system32\d3dx9_28.dll
2014-06-23 13:04:26 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2014-06-23 13:04:26 ----A---- C:\Windows\system32\d3dx9_27.dll
2014-06-23 13:04:25 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2014-06-23 13:04:25 ----A---- C:\Windows\system32\d3dx9_26.dll
2014-06-23 13:04:24 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2014-06-23 13:04:24 ----A---- C:\Windows\system32\d3dx9_25.dll
2014-06-23 13:04:22 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2014-06-23 13:04:22 ----A---- C:\Windows\system32\d3dx9_24.dll
2014-06-23 13:01:27 ----D---- C:\Windows\SYSWOW64\directx
2014-06-23 12:00:41 ----A---- C:\Windows\dd_vcredistMSI420F.txt
2014-06-23 12:00:40 ----A---- C:\Windows\dd_vcredistUI420F.txt
2014-06-23 08:32:51 ----D---- C:\Windows\system32\MRT
2014-06-23 08:30:16 ----A---- C:\Windows\SYSWOW64\NlsLexicons0007.dll
2014-06-23 08:30:15 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2014-06-23 08:30:05 ----A---- C:\Windows\system32\SLCExt.dll
2014-06-23 08:30:04 ----A---- C:\Windows\system32\SLsvc.exe
2014-06-23 08:30:03 ----A---- C:\Windows\SYSWOW64\FunctionDiscoveryFolder.dll
2014-06-23 08:30:03 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2014-06-23 08:29:58 ----A---- C:\Windows\SYSWOW64\NlsLexicons0009.dll
2014-06-23 08:29:58 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2014-06-23 08:29:54 ----A---- C:\Windows\system32\xmlfilter.dll
2014-06-23 08:29:54 ----A---- C:\Windows\system32\msshooks.dll
2014-06-23 08:29:54 ----A---- C:\Windows\system32\msscntrs.dll
2014-06-23 08:29:53 ----A---- C:\Windows\system32\msstrc.dll
2014-06-23 08:29:53 ----A---- C:\Windows\system32\mssrch.dll
2014-06-23 08:29:52 ----A---- C:\Windows\SYSWOW64\SLCExt.dll
2014-06-23 08:29:46 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2014-06-23 08:29:42 ----A---- C:\Windows\SYSWOW64\WscEapPr.dll
2014-06-23 08:29:42 ----A---- C:\Windows\SYSWOW64\wcnwiz2.dll
2014-06-23 08:29:42 ----A---- C:\Windows\system32\WscEapPr.dll
2014-06-23 08:29:42 ----A---- C:\Windows\system32\wcnwiz2.dll
2014-06-23 08:29:41 ----A---- C:\Windows\system32\tquery.dll
2014-06-23 08:29:41 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2014-06-23 08:29:41 ----A---- C:\Windows\system32\icardagt.exe
2014-06-23 08:29:41 ----A---- C:\Windows\system32\drivers\hdaudbus.sys
2014-06-23 08:29:40 ----A---- C:\Windows\system32\imapi2fs.dll
2014-06-23 08:29:38 ----A---- C:\Windows\SYSWOW64\tquery.dll
2014-06-23 08:29:37 ----A---- C:\Windows\system32\sysmain.dll
2014-06-23 08:29:37 ----A---- C:\Windows\system32\msi.dll
2014-06-23 08:29:36 ----A---- C:\Windows\SYSWOW64\PresentationNative_v0300.dll
2014-06-23 08:29:32 ----A---- C:\Windows\system32\scavenge.dll
2014-06-23 08:29:31 ----A---- C:\Windows\system32\drivers\spsys.sys
2014-06-23 08:29:29 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-06-23 08:29:26 ----A---- C:\Windows\SYSWOW64\imapi2fs.dll
2014-06-23 08:29:24 ----A---- C:\Windows\system32\mmcndmgr.dll
2014-06-23 08:29:23 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-06-23 08:29:22 ----A---- C:\Windows\system32\p2psvc.dll
2014-06-23 08:29:21 ----A---- C:\Windows\system32\spreview.exe
2014-06-23 08:29:21 ----A---- C:\Windows\system32\spinstall.exe
2014-06-23 08:29:21 ----A---- C:\Windows\system32\mmc.exe
2014-06-23 08:29:21 ----A---- C:\Windows\system32\drmv2clt.dll
2014-06-23 08:29:21 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2014-06-23 08:29:19 ----A---- C:\Windows\system32\esent.dll
2014-06-23 08:29:18 ----A---- C:\Windows\SYSWOW64\spwizui.dll
2014-06-23 08:29:18 ----A---- C:\Windows\SYSWOW64\AuxiliaryDisplayCpl.dll
2014-06-23 08:29:18 ----A---- C:\Windows\system32\spwizui.dll
2014-06-23 08:29:18 ----A---- C:\Windows\system32\SearchIndexer.exe
2014-06-23 08:29:14 ----A---- C:\Windows\SYSWOW64\spreview.exe
2014-06-23 08:29:14 ----A---- C:\Windows\SYSWOW64\spinstall.exe
2014-06-23 08:29:13 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2014-06-23 08:29:13 ----A---- C:\Windows\system32\sdohlp.dll
2014-06-23 08:29:12 ----A---- C:\Windows\system32\dfsr.exe
2014-06-23 08:29:11 ----A---- C:\Windows\system32\mssvp.dll
2014-06-23 08:29:10 ----A---- C:\Windows\SYSWOW64\p2psvc.dll
2014-06-23 08:29:10 ----A---- C:\Windows\system32\MSMPEG2VDEC.DLL
2014-06-23 08:29:09 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2014-06-23 08:29:09 ----A---- C:\Windows\SYSWOW64\EhStorPwdMgr.dll
2014-06-23 08:29:09 ----A---- C:\Windows\SYSWOW64\EhStorAuthn.dll
2014-06-23 08:29:09 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2014-06-23 08:29:09 ----A---- C:\Windows\system32\EhStorAuthn.dll
2014-06-23 08:29:08 ----A---- C:\Windows\system32\mssphtb.dll
2014-06-23 08:29:08 ----A---- C:\Windows\system32\mssph.dll
2014-06-23 08:29:08 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2014-06-23 08:29:07 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2014-06-23 08:29:06 ----A---- C:\Windows\system32\imapi2.dll
2014-06-23 08:29:05 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2014-06-23 08:29:05 ----A---- C:\Windows\SYSWOW64\MSMPEG2VDEC.DLL
2014-06-23 08:29:05 ----A---- C:\Windows\system32\korwbrkr.dll
2014-06-23 08:29:04 ----A---- C:\Windows\SYSWOW64\mssph.dll
2014-06-23 08:29:04 ----A---- C:\Windows\SYSWOW64\imapi2.dll
2014-06-23 08:29:04 ----A---- C:\Windows\system32\Query.dll
2014-06-23 08:29:04 ----A---- C:\Windows\system32\IMJP10K.DLL
2014-06-23 08:29:03 ----A---- C:\Windows\SYSWOW64\sdohlp.dll
2014-06-23 08:29:03 ----A---- C:\Windows\system32\uDWM.dll
2014-06-23 08:29:02 ----A---- C:\Windows\SYSWOW64\esent.dll
2014-06-23 08:29:02 ----A---- C:\Windows\SYSWOW64\DevicePairing.dll
2014-06-23 08:29:02 ----A---- C:\Windows\system32\WinSAT.exe
2014-06-23 08:29:02 ----A---- C:\Windows\system32\DevicePairing.dll
2014-06-23 08:29:01 ----A---- C:\Windows\SYSWOW64\IMJP10K.DLL
2014-06-23 08:29:00 ----A---- C:\Windows\SYSWOW64\korwbrkr.dll
2014-06-23 08:29:00 ----A---- C:\Windows\system32\sperror.dll
2014-06-23 08:28:59 ----A---- C:\Windows\SYSWOW64\sperror.dll
2014-06-23 08:28:58 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
2014-06-23 08:28:58 ----A---- C:\Windows\system32\P2PGraph.dll
2014-06-23 08:28:57 ----A---- C:\Windows\SYSWOW64\SLC.dll
2014-06-23 08:28:55 ----A---- C:\Windows\SYSWOW64\msjet40.dll
2014-06-23 08:28:55 ----A---- C:\Windows\SYSWOW64\EhStorAPI.dll
2014-06-23 08:28:55 ----A---- C:\Windows\system32\IasMigPlugin.dll
2014-06-23 08:28:55 ----A---- C:\Windows\system32\EhStorAPI.dll
2014-06-23 08:28:54 ----A---- C:\Windows\system32\wevtsvc.dll
2014-06-23 08:28:54 ----A---- C:\Windows\system32\setupapi.dll
2014-06-23 08:28:54 ----A---- C:\Windows\system32\drivers\Storport.sys
2014-06-23 08:28:53 ----A---- C:\Windows\system32\drivers\ndis.sys
2014-06-23 08:28:52 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2014-06-23 08:28:52 ----A---- C:\Windows\system32\SearchFilterHost.exe
2014-06-23 08:28:52 ----A---- C:\Windows\system32\compcln.exe
2014-06-23 08:28:51 ----A---- C:\Windows\SYSWOW64\Query.dll
2014-06-23 08:28:51 ----A---- C:\Windows\system32\qmgr.dll
2014-06-23 08:28:50 ----A---- C:\Windows\SYSWOW64\EhStorShell.dll
2014-06-23 08:28:50 ----A---- C:\Windows\system32\srchadmin.dll
2014-06-23 08:28:50 ----A---- C:\Windows\system32\fdBth.dll
2014-06-23 08:28:50 ----A---- C:\Windows\system32\EhStorShell.dll
2014-06-23 08:28:48 ----A---- C:\Windows\SYSWOW64\user32.dll
2014-06-23 08:28:48 ----A---- C:\Windows\system32\infocardapi.dll
2014-06-23 08:28:47 ----A---- C:\Windows\SYSWOW64\P2PGraph.dll
2014-06-23 08:28:47 ----A---- C:\Windows\SYSWOW64\msexch40.dll
2014-06-23 08:28:47 ----A---- C:\Windows\system32\vssapi.dll
2014-06-23 08:28:47 ----A---- C:\Windows\system32\diagperf.dll
2014-06-23 08:28:47 ----A---- C:\Windows\system32\advapi32.dll
2014-06-23 08:28:46 ----A---- C:\Windows\SYSWOW64\IasMigReader.exe
2014-06-23 08:28:46 ----A---- C:\Windows\system32\rpcss.dll
2014-06-23 08:28:46 ----A---- C:\Windows\explorer.exe
2014-06-23 08:28:45 ----A---- C:\Windows\SYSWOW64\srchadmin.dll
2014-06-23 08:28:45 ----A---- C:\Windows\system32\mblctr.exe
2014-06-23 08:28:45 ----A---- C:\Windows\system32\CertEnroll.dll
2014-06-23 08:28:44 ----A---- C:\Windows\system32\VSSVC.exe
2014-06-23 08:28:42 ----A---- C:\Windows\SYSWOW64\mmc.exe
2014-06-23 08:28:42 ----A---- C:\Windows\SYSWOW64\DevicePairingWizard.exe
2014-06-23 08:28:42 ----A---- C:\Windows\system32\spoolss.dll
2014-06-23 08:28:42 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2014-06-23 08:28:42 ----A---- C:\Windows\system32\comsvcs.dll
2014-06-23 08:28:41 ----A---- C:\Windows\SYSWOW64\IasMigPlugin.dll
2014-06-23 08:28:41 ----A---- C:\Windows\system32\browseui.dll
2014-06-23 08:28:40 ----A---- C:\Windows\SYSWOW64\riched20.dll
2014-06-23 08:28:40 ----A---- C:\Windows\system32\d3d9.dll
2014-06-23 08:28:39 ----A---- C:\Windows\SYSWOW64\RacEngn.dll
2014-06-23 08:28:39 ----A---- C:\Windows\SYSWOW64\Magnify.exe
2014-06-23 08:28:39 ----A---- C:\Windows\SYSWOW64\fdBth.dll
2014-06-23 08:28:38 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2014-06-23 08:28:38 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2014-06-23 08:28:38 ----A---- C:\Windows\SYSWOW64\milcore.dll
2014-06-23 08:28:38 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2014-06-23 08:28:38 ----A---- C:\Windows\system32\drivers\netio.sys
2014-06-23 08:28:37 ----A---- C:\Windows\SYSWOW64\spoolss.dll
2014-06-23 08:28:37 ----A---- C:\Windows\SYSWOW64\NaturalLanguage6.dll
2014-06-23 08:28:37 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2014-06-23 08:28:37 ----A---- C:\Windows\system32\Magnify.exe
2014-06-23 08:28:37 ----A---- C:\Windows\system32\iasrecst.dll
2014-06-23 08:28:37 ----A---- C:\Windows\system32\dpapimig.exe
2014-06-23 08:28:37 ----A---- C:\Windows\system32\dbgeng.dll
2014-06-23 08:28:36 ----A---- C:\Windows\system32\eudcedit.exe
2014-06-23 08:28:36 ----A---- C:\Windows\system32\apds.dll
2014-06-23 08:28:35 ----A---- C:\Windows\SYSWOW64\Storprop.dll
2014-06-23 08:28:35 ----A---- C:\Windows\SYSWOW64\msvcp60.dll
2014-06-23 08:28:35 ----A---- C:\Windows\SYSWOW64\msjtes40.dll
2014-06-23 08:28:35 ----A---- C:\Windows\system32\slwmi.dll
2014-06-23 08:28:35 ----A---- C:\Windows\system32\msctf.dll
2014-06-23 08:28:35 ----A---- C:\Windows\system32\gpedit.dll
2014-06-23 08:28:35 ----A---- C:\Windows\system32\es.dll
2014-06-23 08:28:35 ----A---- C:\Windows\system32\comuid.dll
2014-06-23 08:28:35 ----A---- C:\Windows\system32\audiosrv.dll
2014-06-23 08:28:34 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-06-23 08:28:34 ----A---- C:\Windows\SYSWOW64\gpedit.dll
2014-06-23 08:28:34 ----A---- C:\Windows\system32\user32.dll
2014-06-23 08:28:34 ----A---- C:\Windows\system32\RacEngn.dll
2014-06-23 08:28:34 ----A---- C:\Windows\system32\ipsmsnap.dll
2014-06-23 08:28:34 ----A---- C:\Windows\system32\evr.dll
2014-06-23 08:28:33 ----A---- C:\Windows\SYSWOW64\mstext40.dll
2014-06-23 08:28:33 ----A---- C:\Windows\SYSWOW64\es.dll
2014-06-23 08:28:33 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2014-06-23 08:28:33 ----A---- C:\Windows\system32\wevtapi.dll
2014-06-23 08:28:33 ----A---- C:\Windows\system32\photowiz.dll
2014-06-23 08:28:33 ----A---- C:\Windows\system32\nlhtml.dll
2014-06-23 08:28:33 ----A---- C:\Windows\system32\drivers\fltMgr.sys
2014-06-23 08:28:32 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2014-06-23 08:28:32 ----A---- C:\Windows\SYSWOW64\msexcl40.dll
2014-06-23 08:28:32 ----A---- C:\Windows\system32\SLC.dll
2014-06-23 08:28:32 ----A---- C:\Windows\system32\PresentationSettings.exe
2014-06-23 08:28:32 ----A---- C:\Windows\system32\msihnd.dll
2014-06-23 08:28:32 ----A---- C:\Windows\system32\certcli.dll
2014-06-23 08:28:32 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2014-06-23 08:28:32 ----A---- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2014-06-23 08:28:31 ----A---- C:\Windows\SYSWOW64\slwmi.dll
2014-06-23 08:28:31 ----A---- C:\Windows\SYSWOW64\msxbde40.dll
2014-06-23 08:28:31 ----A---- C:\Windows\SYSWOW64\comsvcs.dll
2014-06-23 08:28:31 ----A---- C:\Windows\system32\wcnwiz.dll
2014-06-23 08:28:31 ----A---- C:\Windows\system32\WcnNetsh.dll
2014-06-23 08:28:30 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2014-06-23 08:28:30 ----A---- C:\Windows\SYSWOW64\DevicePairingProxy.dll
2014-06-23 08:28:30 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-06-23 08:28:30 ----A---- C:\Windows\system32\devmgr.dll
2014-06-23 08:28:30 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2014-06-23 08:28:29 ----A---- C:\Windows\system32\wcncsvc.dll
2014-06-23 08:28:29 ----A---- C:\Windows\system32\NetProjW.dll
2014-06-23 08:28:29 ----A---- C:\Windows\system32\msdtctm.dll
2014-06-23 08:28:29 ----A---- C:\Windows\system32\msctfp.dll
2014-06-23 08:28:29 ----A---- C:\Windows\system32\fdBthProxy.dll
2014-06-23 08:28:28 ----A---- C:\Windows\SYSWOW64\msrepl40.dll
2014-06-23 08:28:28 ----A---- C:\Windows\system32\msvcp60.dll
2014-06-23 08:28:28 ----A---- C:\Windows\system32\davclnt.dll
2014-06-23 08:28:27 ----A---- C:\Windows\SYSWOW64\propsys.dll
2014-06-23 08:28:27 ----A---- C:\Windows\SYSWOW64\newdev.dll
2014-06-23 08:28:27 ----A---- C:\Windows\system32\WebClnt.dll
2014-06-23 08:28:27 ----A---- C:\Windows\system32\w32time.dll
2014-06-23 08:28:27 ----A---- C:\Windows\system32\rsaenh.dll
2014-06-23 08:28:27 ----A---- C:\Windows\system32\drivers\Classpnp.sys
2014-06-23 08:28:26 ----A---- C:\Windows\SYSWOW64\iasrecst.dll
2014-06-23 08:28:26 ----A---- C:\Windows\system32\SLCommDlg.dll
2014-06-23 08:28:26 ----A---- C:\Windows\system32\gpsvc.dll
2014-06-23 08:28:26 ----A---- C:\Windows\system32\drivers\netbt.sys
2014-06-23 08:28:25 ----A---- C:\Windows\SYSWOW64\eudcedit.exe
2014-06-23 08:28:23 ----A---- C:\Windows\system32\msdtcprx.dll
2014-06-23 08:28:23 ----A---- C:\Windows\system32\certmgr.dll
2014-06-23 08:28:22 ----A---- C:\Windows\SYSWOW64\explorer.exe
2014-06-23 08:28:22 ----A---- C:\Windows\system32\umpnpmgr.dll
2014-06-23 08:28:21 ----A---- C:\Windows\SYSWOW64\setupapi.dll
2014-06-23 08:28:21 ----A---- C:\Windows\SYSWOW64\mspbde40.dll
2014-06-23 08:28:20 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2014-06-23 08:28:20 ----A---- C:\Windows\system32\PhotoScreensaver.scr
2014-06-23 08:28:20 ----A---- C:\Windows\system32\drivers\rdbss.sys
2014-06-23 08:28:19 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2014-06-23 08:28:19 ----A---- C:\Windows\system32\WMNetMgr.dll
2014-06-23 08:28:19 ----A---- C:\Windows\system32\swprv.dll
2014-06-23 08:28:19 ----A---- C:\Windows\system32\SLUI.exe
2014-06-23 08:28:19 ----A---- C:\Windows\system32\MPSSVC.dll
2014-06-23 08:28:18 ----A---- C:\Windows\SYSWOW64\msrd3x40.dll
2014-06-23 08:28:18 ----A---- C:\Windows\SYSWOW64\msltus40.dll
2014-06-23 08:28:18 ----A---- C:\Windows\system32\ci.dll
2014-06-23 08:28:17 ----A---- C:\Windows\SYSWOW64\wevtapi.dll
2014-06-23 08:28:17 ----A---- C:\Windows\SYSWOW64\browseui.dll
2014-06-23 08:28:17 ----A---- C:\Windows\system32\WMVSDECD.DLL
2014-06-23 08:28:17 ----A---- C:\Windows\system32\sqlsrv32.dll
2014-06-23 08:28:17 ----A---- C:\Windows\system32\samsrv.dll
2014-06-23 08:28:17 ----A---- C:\Windows\system32\ipsecsnp.dll
2014-06-23 08:28:17 ----A---- C:\Windows\system32\iassdo.dll
2014-06-23 08:28:16 ----A---- C:\Windows\SYSWOW64\photowiz.dll
2014-06-23 08:28:16 ----A---- C:\Windows\SYSWOW64\nlhtml.dll
2014-06-23 08:28:16 ----A---- C:\Windows\system32\wercon.exe
2014-06-23 08:28:15 ----A---- C:\Windows\system32\services.exe
2014-06-23 08:28:15 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosim o odstraneni + kontrola RSIT
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Prosim o odstraneni + kontrola RSIT
Zdravim
Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner


- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte

- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
Re: Prosim o odstraneni + kontrola RSIT
zdravim tady je
log ADW :# AdwCleaner v3.215 - Report created 10/07/2014 at 15:28:01
# Updated 09/07/2014 by Xplode
# Operating System : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Username : new - NEW-PC
# Running from : C:\Users\new\Desktop\adwcleaner_3.215.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
Service Deleted : IePluginServices
Service Deleted : servervo
***** [ Files / Folders ] *****
[!] Folder Deleted : C:\ProgramData\IePluginServices
[!] Folder Deleted : C:\ProgramData\WindowsMangerProtect
[!] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freesofttoday
[!] Folder Deleted : C:\Program Files (x86)\globalUpdate
[!] Folder Deleted : C:\Program Files (x86)\SupTab
[!] Folder Deleted : C:\Program Files (x86)\fst_gb_58
[!] Folder Deleted : C:\Program Files (x86)\fst_gb_60
[!] Folder Deleted : C:\Users\new\AppData\Local\globalUpdate
[!] Folder Deleted : C:\Users\new\AppData\Local\SearchProtect
[!] Folder Deleted : C:\Users\new\AppData\Local\WeatherAlerts
[!] Folder Deleted : C:\Users\new\AppData\Local\fst_gb_58
[!] Folder Deleted : C:\Users\new\AppData\Local\fst_gb_60
[!] Folder Deleted : C:\Users\new\AppData\Local\Temp\apn
[!] Folder Deleted : C:\Users\new\AppData\Roaming\VOPackage
[!] Folder Deleted : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
File Deleted : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DesktopWeatherAlerts.lnk
File Deleted : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
File Deleted : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Weather Alerts.lnk
File Deleted : C:\Users\new\Desktop\Continue VuuPC Installation.lnk
File Deleted : C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default\searchplugins\ask-search.xml
File Deleted : C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default\searchplugins\bingp.xml
File Deleted : C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx
File Deleted : C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-1.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-1
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-10.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-10
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-11.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-11
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-2.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-2
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-3.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-3
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-4.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-4
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-5.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-5
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-5_user.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-5_user
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-6.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-6
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-7.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-7
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611031146}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611031146}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKCU\Software\Tutorials
Key Deleted : HKCU\Software\TutoTag
Key Deleted : HKLM\Software\FreeSoftToday
Key Deleted : HKLM\Software\omiga-plusSoftware
Key Deleted : HKLM\Software\SupDp
Key Deleted : HKLM\Software\SupTab
Key Deleted : HKLM\Software\supWindowsMangerProtect
Key Deleted : HKLM\Software\supWPM
Key Deleted : HKLM\Software\SystemK
Key Deleted : HKLM\Software\Tutorials
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeSoftToday_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\fst_gb_60_is1
Key Deleted : [x64] HKLM\SOFTWARE\installedbrowserextensions
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~1.DLL
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16561
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v30.0 (cs)
[ File : C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default\prefs.js ]
Line Deleted : user_pref("browser.newtab.url", "hxxp://isearch.omiga-plus.com/newtab/?type=nt&ts=1404937789&from=tugs&uid=WDCXWD1600BEVT-75ZCT2_WD-WXR0E69MEM66MEM66");
Line Deleted : user_pref("browser.search.defaultenginename", "omiga-plus");
Line Deleted : user_pref("browser.search.selectedEngine", "omiga-plus");
Line Deleted : user_pref("extensions.0Xf.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net[...]
Line Deleted : user_pref("extensions.GnY.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net[...]
Line Deleted : user_pref("extensions.helperbar.DockingPositionDown", false);
Line Deleted : user_pref("extensions.helperbar.Visibility", false);
Line Deleted : user_pref("extensions.helperbar.keepAliveLastevent", "1404239165");
Line Deleted : user_pref("extensions.helperbar.lastExternalJsUpdate", "1404944644039");
Line Deleted : user_pref("extensions.toolbar_ORJ-V7C@apn.ask.com.install-event-fired", true);
-\\ Google Chrome v35.0.1916.153
[ File : C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1404937789&from=tugs&uid=WDCXWD1600BEVT-75ZCT2_WD-WXR0E69MEM66MEM66&q={searchTerms}
Deleted [Startup_urls] : hxxp://isearch.omiga-plus.com/?type=hppp&ts=1404992304&from=tugs&uid=WDCXWD1600BEVT-75ZCT2_WD-WXR0E69MEM66MEM66
Deleted [Homepage] : hxxp://isearch.omiga-plus.com/?type=hppp&ts=1404992304&from=tugs&uid=WDCXWD1600BEVT-75ZCT2_WD-WXR0E69MEM66MEM66
*************************
AdwCleaner[R0].txt - [1028 octets] - [22/06/2014 16:35:18]
AdwCleaner[R1].txt - [46280 octets] - [01/07/2014 18:42:54]
AdwCleaner[R2].txt - [13546 octets] - [10/07/2014 15:26:52]
AdwCleaner[S0].txt - [1094 octets] - [22/06/2014 16:36:44]
AdwCleaner[S1].txt - [40413 octets] - [01/07/2014 18:45:00]
AdwCleaner[S2].txt - [10755 octets] - [10/07/2014 15:28:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [10816 octets] ##########
a tady je log JRT:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows (TM) Vista Home Premium x64
Ran by new on 10/07/2014 at 15:11:37.33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Successfully stopped: [Service] backupstack
Successfully deleted: [Service] backupstack
Successfully stopped: [Service] APNMCP
Successfully deleted: [Service] APNMCP
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\speedupmypc
Successfully deleted: [Registry Key] "hkey_current_user\software\askpartnernetwork"
Successfully deleted: [Registry Key] "hkey_local_machine\software\askpartnernetwork"
~~~ Files
Successfully deleted: [File] "C:\end"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\big fish"
Successfully deleted: [Folder] "C:\ProgramData\mysearch"
Successfully deleted: [Folder] "C:\Program Files (x86)\mypc backup"
Successfully deleted: [Folder] "C:\Program Files (x86)\mysearch"
Successfully deleted: [Folder] "C:\Users\new\AppData\Roaming\microsoft\windows\start menu\programs\mypc backup"
Successfully deleted: [Folder] "C:\bigfishcache"
Successfully deleted: [Folder] "C:\ProgramData\AskPartnerNetwork"
Successfully deleted: [Folder] "C:\Program Files (x86)\askpartnernetwork"
~~~ FireFox
Successfully deleted: [File] C:\Users\new\AppData\Roaming\mozilla\firefox\profiles\80dz04l1.default\user.js
Successfully deleted the following from C:\Users\new\AppData\Roaming\mozilla\firefox\profiles\80dz04l1.default\prefs.js
user_pref("extensions.0Xf.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||u
user_pref("extensions.GnY.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||u
user_pref("extensions.GnY.url", "hxxp://homewebbnew.us/sync2/?q=hfZ9ofV9CShEAen0rTU9rShTB6lKDzt4okDctNtVh7n0rjnEqTrErjs9pda8tMFHhd9Fqda6rjaFrjs9rdaMDMlGojUMAe4Uojs6qTYHrjY7rdY
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.testingGaq.value", "%22hxxp%3A//extclickmedia-maynemyltf.netdna-ss
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.name", "Torntv V9.0");
user_pref("extensions.crossrider.bic", "1471d001ebd0b1a7d6de86558d7f2922");
user_pref("extensions.helperbar.SmartbarDisabled", false);
user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Emptied folder: C:\Users\new\AppData\Roaming\mozilla\firefox\profiles\80dz04l1.default\minidumps [9 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10/07/2014 at 15:25:34.50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
log ADW :# AdwCleaner v3.215 - Report created 10/07/2014 at 15:28:01
# Updated 09/07/2014 by Xplode
# Operating System : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Username : new - NEW-PC
# Running from : C:\Users\new\Desktop\adwcleaner_3.215.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
Service Deleted : IePluginServices
Service Deleted : servervo
***** [ Files / Folders ] *****
[!] Folder Deleted : C:\ProgramData\IePluginServices
[!] Folder Deleted : C:\ProgramData\WindowsMangerProtect
[!] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freesofttoday
[!] Folder Deleted : C:\Program Files (x86)\globalUpdate
[!] Folder Deleted : C:\Program Files (x86)\SupTab
[!] Folder Deleted : C:\Program Files (x86)\fst_gb_58
[!] Folder Deleted : C:\Program Files (x86)\fst_gb_60
[!] Folder Deleted : C:\Users\new\AppData\Local\globalUpdate
[!] Folder Deleted : C:\Users\new\AppData\Local\SearchProtect
[!] Folder Deleted : C:\Users\new\AppData\Local\WeatherAlerts
[!] Folder Deleted : C:\Users\new\AppData\Local\fst_gb_58
[!] Folder Deleted : C:\Users\new\AppData\Local\fst_gb_60
[!] Folder Deleted : C:\Users\new\AppData\Local\Temp\apn
[!] Folder Deleted : C:\Users\new\AppData\Roaming\VOPackage
[!] Folder Deleted : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
File Deleted : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DesktopWeatherAlerts.lnk
File Deleted : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
File Deleted : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Weather Alerts.lnk
File Deleted : C:\Users\new\Desktop\Continue VuuPC Installation.lnk
File Deleted : C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default\searchplugins\ask-search.xml
File Deleted : C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default\searchplugins\bingp.xml
File Deleted : C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx
File Deleted : C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-1.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-1
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-10.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-10
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-11.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-11
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-2.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-2
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-3.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-3
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-4.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-4
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-5.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-5
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-5_user.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-5_user
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-6.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-6
File Deleted : C:\Windows\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-7.job
File Deleted : C:\Windows\System32\Tasks\769db768-0d4c-4e61-b3c9-edbbc6fa9516-7
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\new\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611031146}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611031146}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKCU\Software\Tutorials
Key Deleted : HKCU\Software\TutoTag
Key Deleted : HKLM\Software\FreeSoftToday
Key Deleted : HKLM\Software\omiga-plusSoftware
Key Deleted : HKLM\Software\SupDp
Key Deleted : HKLM\Software\SupTab
Key Deleted : HKLM\Software\supWindowsMangerProtect
Key Deleted : HKLM\Software\supWPM
Key Deleted : HKLM\Software\SystemK
Key Deleted : HKLM\Software\Tutorials
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeSoftToday_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\fst_gb_60_is1
Key Deleted : [x64] HKLM\SOFTWARE\installedbrowserextensions
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~1.DLL
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16561
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v30.0 (cs)
[ File : C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default\prefs.js ]
Line Deleted : user_pref("browser.newtab.url", "hxxp://isearch.omiga-plus.com/newtab/?type=nt&ts=1404937789&from=tugs&uid=WDCXWD1600BEVT-75ZCT2_WD-WXR0E69MEM66MEM66");
Line Deleted : user_pref("browser.search.defaultenginename", "omiga-plus");
Line Deleted : user_pref("browser.search.selectedEngine", "omiga-plus");
Line Deleted : user_pref("extensions.0Xf.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net[...]
Line Deleted : user_pref("extensions.GnY.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net[...]
Line Deleted : user_pref("extensions.helperbar.DockingPositionDown", false);
Line Deleted : user_pref("extensions.helperbar.Visibility", false);
Line Deleted : user_pref("extensions.helperbar.keepAliveLastevent", "1404239165");
Line Deleted : user_pref("extensions.helperbar.lastExternalJsUpdate", "1404944644039");
Line Deleted : user_pref("extensions.toolbar_ORJ-V7C@apn.ask.com.install-event-fired", true);
-\\ Google Chrome v35.0.1916.153
[ File : C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1404937789&from=tugs&uid=WDCXWD1600BEVT-75ZCT2_WD-WXR0E69MEM66MEM66&q={searchTerms}
Deleted [Startup_urls] : hxxp://isearch.omiga-plus.com/?type=hppp&ts=1404992304&from=tugs&uid=WDCXWD1600BEVT-75ZCT2_WD-WXR0E69MEM66MEM66
Deleted [Homepage] : hxxp://isearch.omiga-plus.com/?type=hppp&ts=1404992304&from=tugs&uid=WDCXWD1600BEVT-75ZCT2_WD-WXR0E69MEM66MEM66
*************************
AdwCleaner[R0].txt - [1028 octets] - [22/06/2014 16:35:18]
AdwCleaner[R1].txt - [46280 octets] - [01/07/2014 18:42:54]
AdwCleaner[R2].txt - [13546 octets] - [10/07/2014 15:26:52]
AdwCleaner[S0].txt - [1094 octets] - [22/06/2014 16:36:44]
AdwCleaner[S1].txt - [40413 octets] - [01/07/2014 18:45:00]
AdwCleaner[S2].txt - [10755 octets] - [10/07/2014 15:28:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [10816 octets] ##########
a tady je log JRT:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows (TM) Vista Home Premium x64
Ran by new on 10/07/2014 at 15:11:37.33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Successfully stopped: [Service] backupstack
Successfully deleted: [Service] backupstack
Successfully stopped: [Service] APNMCP
Successfully deleted: [Service] APNMCP
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\speedupmypc
Successfully deleted: [Registry Key] "hkey_current_user\software\askpartnernetwork"
Successfully deleted: [Registry Key] "hkey_local_machine\software\askpartnernetwork"
~~~ Files
Successfully deleted: [File] "C:\end"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\big fish"
Successfully deleted: [Folder] "C:\ProgramData\mysearch"
Successfully deleted: [Folder] "C:\Program Files (x86)\mypc backup"
Successfully deleted: [Folder] "C:\Program Files (x86)\mysearch"
Successfully deleted: [Folder] "C:\Users\new\AppData\Roaming\microsoft\windows\start menu\programs\mypc backup"
Successfully deleted: [Folder] "C:\bigfishcache"
Successfully deleted: [Folder] "C:\ProgramData\AskPartnerNetwork"
Successfully deleted: [Folder] "C:\Program Files (x86)\askpartnernetwork"
~~~ FireFox
Successfully deleted: [File] C:\Users\new\AppData\Roaming\mozilla\firefox\profiles\80dz04l1.default\user.js
Successfully deleted the following from C:\Users\new\AppData\Roaming\mozilla\firefox\profiles\80dz04l1.default\prefs.js
user_pref("extensions.0Xf.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||u
user_pref("extensions.GnY.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||u
user_pref("extensions.GnY.url", "hxxp://homewebbnew.us/sync2/?q=hfZ9ofV9CShEAen0rTU9rShTB6lKDzt4okDctNtVh7n0rjnEqTrErjs9pda8tMFHhd9Fqda6rjaFrjs9rdaMDMlGojUMAe4Uojs6qTYHrjY7rdY
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.testingGaq.value", "%22hxxp%3A//extclickmedia-maynemyltf.netdna-ss
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.name", "Torntv V9.0");
user_pref("extensions.crossrider.bic", "1471d001ebd0b1a7d6de86558d7f2922");
user_pref("extensions.helperbar.SmartbarDisabled", false);
user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Emptied folder: C:\Users\new\AppData\Roaming\mozilla\firefox\profiles\80dz04l1.default\minidumps [9 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10/07/2014 at 15:25:34.50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Re: Prosim o odstraneni + kontrola RSIT

- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;
- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: Prosim o odstraneni + kontrola RSIT
tady je ten log;
Zoek.exe v5.0.0.0 Updated 05-July-2014
Tool run by new on 10/07/2014 at 15:56:35.50.
Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\new\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
10/07/2014 15:57:29 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1710971718-3430145923-3092330257-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DCB7100-DF86-4384-8842-8FA844297B3F} deleted successfully
HKEY_USERS\S-1-5-21-1710971718-3430145923-3092330257-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8DCB7100-DF86-4384-8842-8FA844297B3F} deleted successfully
HKEY_USERS\S-1-5-21-1710971718-3430145923-3092330257-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9} deleted successfully
HKEY_USERS\S-1-5-21-1710971718-3430145923-3092330257-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DBC80044-A445-435B-BC74-9C25C1C588A9} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8DCB7100-DF86-4384-8842-8FA844297B3F} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{DBC80044-A445-435B-BC74-9C25C1C588A9} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435B-BC74-9C25C1C588A9} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-1710971718-3430145923-3092330257-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.co.uk/");
user_pref("browser.search.defaultengine", "Yahoo! (Avast)");
user_pref("extensions.APN_TB.first-previous-keyword-url", "");
user_pref("extensions.ORJ-V7C.my-keyword-url", "\"\"");
user_pref("extensions.ORJ-V7C.previous-keyword-url", "\"\"");
user_pref("keyword.URL", "http://www.bing.com/search?FORM=BDT1DF& ... =070514&q=");
user_pref("browser.search.suggest.enabled", false);
user_pref("browser.search.useDBForOrder", "false");
Added to C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("extensions.APN_TB.first-previous-keyword-url", "");
user_pref("extensions.ORJ-V7C.my-keyword-url", "\"\"");
user_pref("extensions.ORJ-V7C.previous-keyword-url", "\"\"");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default
user.js not found
---- Lines a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390 removed from prefs.js ----
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.active", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.addressbar", "NA");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.addressbarenhanced", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.asyncdb.was_copied", "true");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.asyncdb_dbWasSet", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.asyncinternaldb.was_copied", "true");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.asyncinternaldb_dbWasSet", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.backgroundver", 5);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.certdomaininstaller", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.changeprevious", false);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.au.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.au.value", "%222014-7-1%22");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.cnt.expiration", "Fri Feb 01 2030 00:00:0
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.cnt.value", "%22GB%22");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.first_run.expiration", "Fri Feb 01 2030 0
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.first_run.value", "%221%22");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.install.expiration", "Fri Feb 01 2030 00:
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.install.value", "%222014-7-1%22");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.InstallationTime.value", "%221404209032%2
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.testingGaq.expiration", "Fri Feb 01 2030
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.description", "The must-have App extensions for
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.domain", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.enablesearch", false);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.homepage", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.iframe", false);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.InstallationThankYouPage", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.InstallationTime", 1404209032);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.__defualt_browser__.value", "%22ff%22
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb._installer_additional_info.expiration
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb._installer_additional_info.value", "%
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin__disable_bi_pixel
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin__disable_bi_pixel
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_last_executable_r
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_last_executable_r
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_appVer.value", "83");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_lastVersion.value", "2");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_nextCheck.expiration", "Tue
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_remote_resources.expiration
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_remote_resources.value", "%
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.lastDailyReport", "1404230994890");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.lastUpdate", "1404230994180");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.manifesturl", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.newtab", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.opensearch", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.pluginsurl", "http://js.democlientnet.com/plugin
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.pluginsversion", 75);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.publisher", "installdaddy");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.searchstatus", 0);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.setnewtab", false);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.thankyou", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.updateinterval", 360);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.ver", 83);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.apps", "51390");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.bic", "146f165dd1e70b0af3ba6765d40215a5");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.cid", 51390);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.firstrun", false);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.hadappinstalled", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.installationdate", 1404209323);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.installerAdditionalInfo", "{\"asw\":[32770, 5, 512]}")
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.modetype", "production");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.reportInstall", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.statsDailyCounter", 2);
---- Lines extensions.00c7XXS62R removed from prefs.js ----
user_pref("extensions.00c7XXS62R.epoch", "1404301881");
user_pref("extensions.00c7XXS62R.url", "http://safefacile.net/sync2/?q=hfZ9ofq7 ... jnEqHaFrjw
---- Lines extensions.0Xf removed from prefs.js ----
user_pref("extensions.0Xf.epoch", "1405077841");
user_pref("extensions.0Xf.url", "http://firsttshare.us/sync2/?q=hfZ9ofDS ... rjsHrjkMDM
---- Lines extensions.GnY removed from prefs.js ----
user_pref("extensions.GnY.epoch", "1405077842");
---- FireFox user.js and prefs.js backups ----
prefs_072014_1611_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\omiga-plus.xml deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\PROGRA~2\Browseri_Appe 1.2 deleted
C:\PROGRA~3\InstallMate deleted
C:\Users\new\AppData\Local\Local_Weather_LLC deleted
C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Weather Alerts deleted
C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\new\Searches deleted
C:\Windows\WININIT.INI deleted
"C:\Windows\Installer\2746c81.msi" deleted
"C:\Users\new\AppData\Roaming\PreferencePane" deleted
"C:\Users\new\AppData\Roaming\Printer Icons" deleted
"C:\Users\new\AppData\Roaming\Printers" deleted
"C:\Users\new\AppData\Roaming\Robot" deleted
"C:\ProgramData\PrintsService" deleted
"C:\ProgramData\Profiles" deleted
"C:\ProgramData\Project Templates" deleted
"C:\ProgramData\Sample Delay" deleted
"C:\ProgramData\Sampler Files" deleted
"C:\ProgramData\Sci-Fi" deleted
"C:\ProgramData\String Comparison" deleted
"C:\PROGRA~3\1cbea09c991e06b6\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.20140630134810" deleted
"C:\PROGRA~3\1cbea09c991e06b6\{993EA8F6-6E55-7E4E-39DE-5796E3226DB9}.20140630134750" deleted
"C:\PROGRA~3\1cbea09c991e06b6\{993EA8F6-6E55-7E4E-39DE-5796E3226DB9}.20140630134804" deleted
"C:\PROGRA~3\1cbea09c991e06b6\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}.20140630134816" deleted
"C:\PROGRA~3\1cbea09c991e06b6\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}.20140630134918" deleted
"C:\PROGRA~3\1cbea09c991e06b6" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [02/07/2014 15:31]
==== Firefox Extensions ======================
ProfilePath: C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default
- Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
- avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- ColorfulTabs - %ProfilePath%\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
- S3.Download Statusbar - %ProfilePath%\extensions\s3download@statusbar.xpi
- Quick Translator - %ProfilePath%\extensions\{5C655500-E712-41e7-9349-CE462F844B19}.xpi
- ImTranslator - %ProfilePath%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
- DownThemAll - %ProfilePath%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default
4390CCD3790F8D9C427C0C29590C62D7 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash
AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[02/07/2014 15:31]
saVE on - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng
MySearch - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
MySearch - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
saVE on - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng
MySearch - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
saVE on - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng
MySearch - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
MySearch - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
saVE on - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng
MySearch - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
saVE on - new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng
MySearch - new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
Google Voice Search Hotword (Beta) - new\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
avast Online Security - new\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Browseri_Appe 1.2 - new\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgdaeidiojbdgmnjnpmklilaodjlkbjp
saVE on - new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng
MySearch - new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
==== Chrome Fix ======================
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.fastsearchings.info_0.localstorage deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.fastsearchings.info_0.localstorage-journal deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_leenlgdlclmcghkjgalpkhilppcebdgj_0.localstorage deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_leenlgdlclmcghkjgalpkhilppcebdgj_0.localstorage-journal deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lkmofgnohbedopheiphabfhfjgkhfcgf_0.localstorage deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lkmofgnohbedopheiphabfhfjgkhfcgf_0.localstorage-journal deleted successfully
C:\Users\new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kgdaeidiojbdgmnjnpmklilaodjlkbjp deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgdaeidiojbdgmnjnpmklilaodjlkbjp deleted successfully
C:\Users\new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kgdaeidiojbdgmnjnpmklilaodjlkbjp deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kgdaeidiojbdgmnjnpmklilaodjlkbjp_0.localstorage deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kgdaeidiojbdgmnjnpmklilaodjlkbjp_0.localstorage-journal deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_kgdaeidiojbdgmnjnpmklilaodjlkbjp_0 deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kgdaeidiojbdgmnjnpmklilaodjlkbjp deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"Default"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://www.google.com"
"SearchAssistant"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{A73BABC1-F83A-46EB-9CA8-0D6C489E5E5E} Bing Url="http://www.bing.com/search?FORM=BDT3DF& ... -SearchBox"
==== Reset Google Chrome ======================
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F60730A4A66673047777F5728467D401 deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\17ec400e-1835-4e29-8f9e-387ab43678b2 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\new\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\new\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\new\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\new\AppData\Local\Mozilla\Firefox\Profiles\80dz04l1.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=249 folders=75 4689903 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\new\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\new\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\new\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
==== EOF on 10/07/2014 at 16:18:07.56 ======================
Zoek.exe v5.0.0.0 Updated 05-July-2014
Tool run by new on 10/07/2014 at 15:56:35.50.
Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\new\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
10/07/2014 15:57:29 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1710971718-3430145923-3092330257-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DCB7100-DF86-4384-8842-8FA844297B3F} deleted successfully
HKEY_USERS\S-1-5-21-1710971718-3430145923-3092330257-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8DCB7100-DF86-4384-8842-8FA844297B3F} deleted successfully
HKEY_USERS\S-1-5-21-1710971718-3430145923-3092330257-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9} deleted successfully
HKEY_USERS\S-1-5-21-1710971718-3430145923-3092330257-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DBC80044-A445-435B-BC74-9C25C1C588A9} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8DCB7100-DF86-4384-8842-8FA844297B3F} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{DBC80044-A445-435B-BC74-9C25C1C588A9} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435B-BC74-9C25C1C588A9} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-1710971718-3430145923-3092330257-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.co.uk/");
user_pref("browser.search.defaultengine", "Yahoo! (Avast)");
user_pref("extensions.APN_TB.first-previous-keyword-url", "");
user_pref("extensions.ORJ-V7C.my-keyword-url", "\"\"");
user_pref("extensions.ORJ-V7C.previous-keyword-url", "\"\"");
user_pref("keyword.URL", "http://www.bing.com/search?FORM=BDT1DF& ... =070514&q=");
user_pref("browser.search.suggest.enabled", false);
user_pref("browser.search.useDBForOrder", "false");
Added to C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("extensions.APN_TB.first-previous-keyword-url", "");
user_pref("extensions.ORJ-V7C.my-keyword-url", "\"\"");
user_pref("extensions.ORJ-V7C.previous-keyword-url", "\"\"");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default
user.js not found
---- Lines a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390 removed from prefs.js ----
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.active", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.addressbar", "NA");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.addressbarenhanced", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.asyncdb.was_copied", "true");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.asyncdb_dbWasSet", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.asyncinternaldb.was_copied", "true");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.asyncinternaldb_dbWasSet", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.backgroundver", 5);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.certdomaininstaller", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.changeprevious", false);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.au.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.au.value", "%222014-7-1%22");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.cnt.expiration", "Fri Feb 01 2030 00:00:0
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.cnt.value", "%22GB%22");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.first_run.expiration", "Fri Feb 01 2030 0
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.first_run.value", "%221%22");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.install.expiration", "Fri Feb 01 2030 00:
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.install.value", "%222014-7-1%22");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.InstallationTime.value", "%221404209032%2
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.cookie.testingGaq.expiration", "Fri Feb 01 2030
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.description", "The must-have App extensions for
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.domain", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.enablesearch", false);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.homepage", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.iframe", false);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.InstallationThankYouPage", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.InstallationTime", 1404209032);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.__defualt_browser__.value", "%22ff%22
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb._installer_additional_info.expiration
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb._installer_additional_info.value", "%
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin__disable_bi_pixel
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin__disable_bi_pixel
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_last_executable_r
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_last_executable_r
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_appVer.value", "83");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_lastVersion.value", "2");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_nextCheck.expiration", "Tue
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_remote_resources.expiration
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.Resources_remote_resources.value", "%
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.lastDailyReport", "1404230994890");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.lastUpdate", "1404230994180");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.manifesturl", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.newtab", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.opensearch", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.pluginsurl", "http://js.democlientnet.com/plugin
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.pluginsversion", 75);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.publisher", "installdaddy");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.searchstatus", 0);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.setnewtab", false);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.thankyou", "");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.updateinterval", 360);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.ver", 83);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.apps", "51390");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.bic", "146f165dd1e70b0af3ba6765d40215a5");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.cid", 51390);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.firstrun", false);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.hadappinstalled", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.installationdate", 1404209323);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.installerAdditionalInfo", "{\"asw\":[32770, 5, 512]}")
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.modetype", "production");
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.reportInstall", true);
user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.statsDailyCounter", 2);
---- Lines extensions.00c7XXS62R removed from prefs.js ----
user_pref("extensions.00c7XXS62R.epoch", "1404301881");
user_pref("extensions.00c7XXS62R.url", "http://safefacile.net/sync2/?q=hfZ9ofq7 ... jnEqHaFrjw
---- Lines extensions.0Xf removed from prefs.js ----
user_pref("extensions.0Xf.epoch", "1405077841");
user_pref("extensions.0Xf.url", "http://firsttshare.us/sync2/?q=hfZ9ofDS ... rjsHrjkMDM
---- Lines extensions.GnY removed from prefs.js ----
user_pref("extensions.GnY.epoch", "1405077842");
---- FireFox user.js and prefs.js backups ----
prefs_072014_1611_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\omiga-plus.xml deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\PROGRA~2\Browseri_Appe 1.2 deleted
C:\PROGRA~3\InstallMate deleted
C:\Users\new\AppData\Local\Local_Weather_LLC deleted
C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Weather Alerts deleted
C:\Users\new\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\new\Searches deleted
C:\Windows\WININIT.INI deleted
"C:\Windows\Installer\2746c81.msi" deleted
"C:\Users\new\AppData\Roaming\PreferencePane" deleted
"C:\Users\new\AppData\Roaming\Printer Icons" deleted
"C:\Users\new\AppData\Roaming\Printers" deleted
"C:\Users\new\AppData\Roaming\Robot" deleted
"C:\ProgramData\PrintsService" deleted
"C:\ProgramData\Profiles" deleted
"C:\ProgramData\Project Templates" deleted
"C:\ProgramData\Sample Delay" deleted
"C:\ProgramData\Sampler Files" deleted
"C:\ProgramData\Sci-Fi" deleted
"C:\ProgramData\String Comparison" deleted
"C:\PROGRA~3\1cbea09c991e06b6\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.20140630134810" deleted
"C:\PROGRA~3\1cbea09c991e06b6\{993EA8F6-6E55-7E4E-39DE-5796E3226DB9}.20140630134750" deleted
"C:\PROGRA~3\1cbea09c991e06b6\{993EA8F6-6E55-7E4E-39DE-5796E3226DB9}.20140630134804" deleted
"C:\PROGRA~3\1cbea09c991e06b6\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}.20140630134816" deleted
"C:\PROGRA~3\1cbea09c991e06b6\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}.20140630134918" deleted
"C:\PROGRA~3\1cbea09c991e06b6" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [02/07/2014 15:31]
==== Firefox Extensions ======================
ProfilePath: C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default
- Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
- avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- ColorfulTabs - %ProfilePath%\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
- S3.Download Statusbar - %ProfilePath%\extensions\s3download@statusbar.xpi
- Quick Translator - %ProfilePath%\extensions\{5C655500-E712-41e7-9349-CE462F844B19}.xpi
- ImTranslator - %ProfilePath%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
- DownThemAll - %ProfilePath%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\new\AppData\Roaming\Mozilla\Firefox\Profiles\80dz04l1.default
4390CCD3790F8D9C427C0C29590C62D7 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash
AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[02/07/2014 15:31]
saVE on - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng
MySearch - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
MySearch - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
saVE on - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng
MySearch - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
saVE on - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng
MySearch - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
MySearch - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
saVE on - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng
MySearch - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
saVE on - new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng
MySearch - new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
Google Voice Search Hotword (Beta) - new\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
avast Online Security - new\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Browseri_Appe 1.2 - new\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgdaeidiojbdgmnjnpmklilaodjlkbjp
saVE on - new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng
MySearch - new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj
User Agent Switcher - new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf
==== Chrome Fix ======================
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.fastsearchings.info_0.localstorage deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.fastsearchings.info_0.localstorage-journal deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ahefljkboneonffonakmbcaiidkomfng deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\leenlgdlclmcghkjgalpkhilppcebdgj deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_leenlgdlclmcghkjgalpkhilppcebdgj_0.localstorage deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_leenlgdlclmcghkjgalpkhilppcebdgj_0.localstorage-journal deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkmofgnohbedopheiphabfhfjgkhfcgf deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lkmofgnohbedopheiphabfhfjgkhfcgf_0.localstorage deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lkmofgnohbedopheiphabfhfjgkhfcgf_0.localstorage-journal deleted successfully
C:\Users\new\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kgdaeidiojbdgmnjnpmklilaodjlkbjp deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgdaeidiojbdgmnjnpmklilaodjlkbjp deleted successfully
C:\Users\new\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kgdaeidiojbdgmnjnpmklilaodjlkbjp deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kgdaeidiojbdgmnjnpmklilaodjlkbjp_0.localstorage deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kgdaeidiojbdgmnjnpmklilaodjlkbjp_0.localstorage-journal deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_kgdaeidiojbdgmnjnpmklilaodjlkbjp_0 deleted successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kgdaeidiojbdgmnjnpmklilaodjlkbjp deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"Default"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://www.google.com"
"SearchAssistant"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{A73BABC1-F83A-46EB-9CA8-0D6C489E5E5E} Bing Url="http://www.bing.com/search?FORM=BDT3DF& ... -SearchBox"
==== Reset Google Chrome ======================
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F60730A4A66673047777F5728467D401 deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\17ec400e-1835-4e29-8f9e-387ab43678b2 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\new\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\new\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\new\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\new\AppData\Local\Mozilla\Firefox\Profiles\80dz04l1.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\new\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=249 folders=75 4689903 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\new\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\new\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\new\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
==== EOF on 10/07/2014 at 16:18:07.56 ======================