Urgentní kontrola logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
roady
Level 2.5
Level 2.5
Příspěvky: 351
Registrován: červen 09
Pohlaví: Muž
Stav:
Offline
Kontakt:

Urgentní kontrola logu

Příspěvekod roady » 15 zář 2014 18:01

Ahoj, nevím na co jsem kliknul/nainstaloval, ale mám plný prohlížeč reklam. A po spuštění prohlížeče se otevře stránka "iStartSurf". A aby toho nebylo málo, mám tu program "Shopper-pro", který nejde odinstalovat.

HijackThis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:57:04, on 15.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe
C:\Users\roady\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe
E:\PROGRAMS\AVAST\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\roady\jagexcache\jagexlauncher\bin\JagexLauncher.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\roady\Downloads\HijackThis.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll
O2 - BHO: CrossriderApp0063317 - {11111111-1111-1111-1111-110611331117} - C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-bho.dll
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ShopperProBHO - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - (no file)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: YTAHelperBHO - {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} - C:\ProgramData\YTAHelper\YTAHelper.dll
O4 - HKLM\..\Run: [avast5] "E:\PROGRAMS\AVAST\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\roady\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\roady\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [GoobzoYouTubeAccelerator] "C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe" /startup
O4 - HKCU\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe
O4 - HKCU\..\Run: [EADM] "E:\PROGRAMS\Origin\Origin.exe" -AutoStart
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRAMS\OFFICE\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://E:\PROGRAMS\OFFICE\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - E:\PROGRAMS\AVAST\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - E:\PROGRAMS\AVAST\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - E:\PROGRAMS\AVAST\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: ShopperPro Update (SPBIUpd) - ShopperPro - C:\Program Files\Common Files\ShopperPro\spbiu.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Fuyu LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: YouTubeAcceleratorService - GOOBZO - C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe

--
End of file - 14869 bytes
KINGSTON 4GB RAM | nVIDIA GeForce GTX 560 | Intel Core2 Quad Q8400 @ 2.67GHz | LCPOWER 600W | Gigabyte GA-EP35-DS4 | SAMSUNG SpinPoint F3 1000Gb, Hitachi 500GB | W7

Reklama
Uživatelský avatar
roady
Level 2.5
Level 2.5
Příspěvky: 351
Registrován: červen 09
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Urgentní kontrola logu

Příspěvekod roady » 15 zář 2014 18:04

Tohle je ono.

► Zobrazit spoiler
KINGSTON 4GB RAM | nVIDIA GeForce GTX 560 | Intel Core2 Quad Q8400 @ 2.67GHz | LCPOWER 600W | Gigabyte GA-EP35-DS4 | SAMSUNG SpinPoint F3 1000Gb, Hitachi 500GB | W7

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43072
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Urgentní kontrola logu

Příspěvekod jaro3 » 15 zář 2014 18:48

Odinstaluj:
McAfee Security Scan

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
roady
Level 2.5
Level 2.5
Příspěvky: 351
Registrován: červen 09
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Urgentní kontrola logu

Příspěvekod roady » 15 zář 2014 19:51

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 15.9.2014
Scan Time: 19:40:03
Logfile: malw.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.09.15.09
Rootkit Database: v2014.09.15.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: roady

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 305806
Time Elapsed: 9 min, 41 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 8
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1712, , [5c99ad401c5f87af291e69fd59a8936d]
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1804, , [2ec72cc184f720161af6ac0618e958a8]
PUP.Optional.Goobzo, C:\Program Files\Common Files\ShopperPro\spbiu.exe, 2160, , [5c99c924562541f54882915926de39c7]
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-6.exe, 3872, , [e1147974c3b87db9be14fba9c63bcc34]
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe, 4444, , [cb2af6f7502b290dfbe9759142c1c739]
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\HpUI.exe, 1812, , [44b110dd6a11ef472dc6dc1333cf4db3]
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\Loader32.exe, 3716, , [44b110dd6a11ef472dc6dc1333cf4db3]
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\Loader64.exe, 3312, , [44b110dd6a11ef472dc6dc1333cf4db3]

Modules: 16
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\4a8cbc19-01c2-4922-b0dd-51cbff85fe3b.dll, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],

Registry Keys: 92
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, , [5c99ad401c5f87af291e69fd59a8936d],
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, , [2ec72cc184f720161af6ac0618e958a8],
PUP.Optional.WindowsProtectManger.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WindowsMangerProtect, , [2ec72cc184f720161af6ac0618e958a8],
PUP.Optional.Goobzo, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPBIUpd, , [5c99c924562541f54882915926de39c7],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611331117}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110611331117}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644334417}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655335517}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666336617}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655335517}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666336617}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644334417}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0063317.BHO.1, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611331117}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611331117}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0063317.BHO, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0063317.BHO, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0063317.BHO.1, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220622332217}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0063317.Sandbox.1, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0063317.Sandbox, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0063317.Sandbox, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0063317.Sandbox.1, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220622332217}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611331117}\INPROCSERVER32, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [60950ae347342c0a62fb36531be7af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [60950ae347342c0a62fb36531be7af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [60950ae347342c0a62fb36531be7af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [60950ae347342c0a62fb36531be7af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [60950ae347342c0a62fb36531be7af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [60950ae347342c0a62fb36531be7af51],
Trojan.Agent, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ShopperPro, , [2cc9f2fbc1ba2a0c66526121b0520bf5],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ShopperPro, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPDRIVER_1.37.0.193, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\3874, , [0ce9886576053ff7115965c1af54d030],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [6a8bca2317642f07d5db93c148bcbd43],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\ClickMovie1-Downloaderv10, , [dc19925bd0ab8caa24ea11f99172db25],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\ClickMovie1-Downloaderv10-nv, , [767ffcf1770487af7d91d931cd36649c],
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\istartsurfSoftware, , [4baa88655328979f5a4f18ecd72c42be],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, , [d42114d92c4f57dfce56670205ff4cb4],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, , [c035ca2386f5e94db82e4bb7f40fd729],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, , [11e4b5386318979f172d1af1ae556898],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\3874, , [9f568c613249d165501a0620758ef709],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [9a5b31bcccafea4ca0109aba0004e61a],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, , [cb2a4f9e611a191dcf7c5e0e0afac838],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, , [0ce901ec5526300690bc91db689c629e],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, , [02f3c429f586f93d8929d929847f7888],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, , [83729e4f52296ec8598cd1311de6b749],
PUP.Optional.1ClickMovieDownload.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\ClickMovie1-Downloaderv10, , [e213bd303e3d0432b45cf01afa09e818],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, , [f8fda34ad7a40f27b2b2fe4c857ffd03],
PUP.Optional.WebSearches.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SupHpUISoft, , [c2339855f784280eacf76e96748fd62a],
PUP.Optional.1ClickMovieDownload.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\ClickMovie1-Downloaderv10, , [28cd3faec0bb092dc14fec1e27dc817f],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [4ea742ab6d0e73c3acad1548fa0a20e0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\3874, , [c134db12abd05dd9ffd5ce30d82aa957],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\end, , [d61f8d6083f8989eb061b456f50e48b8],
PUP.Optional.Qone8, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [d81d539a48333ff7654a64f038cc2fd1],
PUP.Optional.Softonic.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [af4621cc94e749edde09859c4cb7fb05],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.Update3WebControl.4, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ClickMovie1-Downloaderv10, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.ShopperPro, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPBIUpdd, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\TYPELIB\{8FB1A663-2820-468B-95C4-5060A4C5F413}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\INTERFACE\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\INTERFACE\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{8FB1A663-2820-468B-95C4-5060A4C5F413}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\ShopperPro.ShopperProBHO.1, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\ShopperPro.ShopperProBHO, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperPro.ShopperProBHO, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperPro.ShopperProBHO.1, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\INPROCSERVER32, , [28cdea03f68589ad661212e6be44e020],

Registry Values: 5
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SPDriver, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe, , [cb2af6f7502b290dfbe9759142c1c739]
PUP.Optional.ShopperPro, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SPDriver, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe, , [cb2af6f7502b290dfbe9759142c1c739]
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, , [11e4b5386318979f172d1af1ae556898]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, , [02f3c429f586f93d8929d929847f7888]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, ild, , [83729e4f52296ec8598cd1311de6b749]

Registry Data: 12
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX),,[0ce95f8e86f5f343e5dedb1827dd639d]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}, Good: (www.google.com), Bad: (http://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}),,[b243f0fdec8f3402a71238bb7a8a7f81]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX, Good: (www.google.com), Bad: (http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX),,[03f258955a218caacbec15de6d97d828]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX, Good: (www.google.com), Bad: (http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX),,[678ebe2f2f4c6cca45761dd6699b768a]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[e41109e46a11dc5a31a337c7e51fd62a]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX),,[8d68618ceb903501eed5f4ff30d4fd03]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}, Good: (www.google.com), Bad: (http://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}),,[bd38b23bf685db5b4e6b866dc83cd42c]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX, Good: (www.google.com), Bad: (http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX),,[38bd826bf784eb4b863173804db76e92]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX, Good: (www.google.com), Bad: (http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX),,[b2435b923e3d6bcbc4f71bd8a361718f]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[6e87b23b255653e3449032cc2cd8a55b]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX, Good: (www.google.com), Bad: (http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX),,[d12411dcef8c0a2cf6c6658e84809070]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX, Good: (www.google.com), Bad: (http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX),,[8b6a717c235856e03088827112f2649c]

Folders: 46
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox\content, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, , [5d98a4496318c076a2c3af3832d01ee2],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, , [5d98a4496318c076a2c3af3832d01ee2],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, , [ee076885d2a9cd6928ad9257d32fc63a],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, , [ee076885d2a9cd6928ad9257d32fc63a],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, , [ee076885d2a9cd6928ad9257d32fc63a],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Install, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline\{0539AF68-A07F-4317-ADD9-5C0DD730F62A}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, C:\ProgramData\ShopperPro, , [28cdea03f68589ad661212e6be44e020],

Files: 172
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, , [5c99ad401c5f87af291e69fd59a8936d],
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, , [2ec72cc184f720161af6ac0618e958a8],
PUP.Optional.Goobzo, C:\Program Files\Common Files\ShopperPro\spbiu.exe, , [5c99c924562541f54882915926de39c7],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-6.exe, , [e1147974c3b87db9be14fba9c63bcc34],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-bho64.dll, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-bho.dll, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, , [60950ae347342c0a62fb36531be7af51],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-buttonutil.exe, , [38bd30bdb3c8989e03cfdaca936e738d],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-7.exe, , [f8fd9459512abf773d95a7fd27da9a66],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-bg.exe, , [a4518e5fa1daac8a7959931133ce2bd5],
PUP.Optional.CrossRider.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\utils.exe, , [d71eb33a1467fd3901442c19b34d5ea2],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-buttonutil64.exe, , [ba3b30bd7dfe92a407cb475d1fe228d8],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-codedownloader.exe, , [02f3cc21fe7d5bdb389a0b99857cef11],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-11.exe, , [6c89c22b4338ad89765c277d976a4fb1],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-2.exe, , [da1be508d6a5f3434290c6dedc259b65],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-3.exe, , [3abb23ca87f4e94d7c569f05956c46ba],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-4.exe, , [f9fc13daa5d67db969693470dc25a858],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-5.exe, , [40b5f9f46c0f211521b1eeb69d6420e0],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-64.exe, , [a055c32a0e6df73ff4de960e21e019e7],
Trojan.Agent, C:\Program Files (x86)\ShopperPro\SPRemove.exe, , [2cc9f2fbc1ba2a0c66526121b0520bf5],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, , [e1142fbe45360135d0f04550847d54ac],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, , [36bf698439429a9c9030cbcaec15e11f],
PUP.Optional.IEPluginService.A, C:\Program Files (x86)\SupTab\RSHP.exe, , [fcf9d61784f731058c62bebaca37df21],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, , [0ee7f1fcb9c292a4d0f0f3a28b76c23e],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, , [23d2c7260c6f8bab219f098c946d639d],
PUP.Optional.IePluginService.A, C:\Program Files (x86)\SupTab\SupIePluginServiceUpdate.exe, , [33c2e40912696bcb93b4c5a1df22b947],
PUP.Optional.ShopperPro, C:\Windows\System32\Tasks\SPBIW_UpdateTask_Time_3730353332363033382d3437415a556c2a3223346c41, , [4da8e10c22594ee8acb5d42ef50e936d],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\ShopperPro.exe, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\config.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\database1_0_0.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\manifest.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\ShopperPro.crx, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\ShopperPro.zip, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\ShopperPro64.dll, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\SPRemove.exe, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\Updater.exe, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox\chrome.manifest, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox\install.rdf, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox\content\overlay.js, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox\content\overlay.xul, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox\content\shopperpro_128.png, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\jsdrv.exe, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\jsdrv.sys, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\config.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\database1_0_0.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.sys, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189\config.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189\database1_0_0.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189\jsdrv.exe, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189\jsdrv.sys, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Windows\System32\Tasks\ShopperPro, , [ba3bd21bf8833006f8f755b1d42ff808],
PUP.Optional.ShopperPro, C:\Windows\System32\Tasks\ShopperProJSUpd, , [d61f9855e09b290d1bd55aacba4958a8],
PUP.Optional.ShopperPro, C:\Windows\System32\Tasks\SPDriver, , [06efb637ec8fb77f6d843bcb6a99916f],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-1, , [f9fc727b5a218ea83e01dc2f0cf702fe],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-11, , [579ed01dc7b44fe760dfe229ec17ff01],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-2, , [44b16e7f5e1d60d691ae858638cb4ab6],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-3, , [c03541ac2a51f83eab947a91f112c53b],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-4, , [fcf9a24bd5a6bd79d669a368af54a759],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-5, , [2cc9866716650d29ac9357b4b25109f7],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-5_user, , [fff6b13c5e1da78f86b92fdc46bd7f81],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-6, , [fdf843aa314a211581becf3cfd06c33d],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-7, , [55a08d603e3ddd5939060cff14ef41bf],
PUP.Optional.Superfish.A, C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, , [01f4d518cdae1d19fccd5ac00ff431cf],
PUP.Optional.Superfish.A, C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, , [1adb599473086fc704c5a2787c87f30d],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-1.job, , [83723eaf215acb6b6063f8710ff5f10f],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-11.job, , [11e4707dd1aa43f3f3d0d693897b1ae6],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-2.job, , [936216d70576be78dae98fdad82c56aa],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-3.job, , [19dc6885a0db56e0586bf871867ec23e],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-4.job, , [e2138e5f611a5adc576cc0a9dc28ad53],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-5.job, , [01f46f7eff7c063092316cfd1fe5857b],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-5_user.job, , [b144539a6b1047efa320d7928d779070],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-6.job, , [45b0b8353b40211519aad792e1235ea2],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-7.job, , [876eb6372754da5c22a1db8eb153956b],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, , [c92c27c6176406307a5f254423e18779],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, , [f7feb6374f2c37ff9c3ec0a9ae56c838],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, , [22d3b73696e5fc3ae3f8f079ee16f709],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, , [d12444a9eb903afca03c2c3d27dd4bb5],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, , [5d98a4496318c076a2c3af3832d01ee2],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-09-10[16-30-02-801].log, , [ee076885d2a9cd6928ad9257d32fc63a],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, , [ee076885d2a9cd6928ad9257d32fc63a],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\1293297481.mxaddon, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\4a8cbc19-01c2-4922-b0dd-51cbff85fe3b.crx, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\4a8cbc19-01c2-4922-b0dd-51cbff85fe3b.dll, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\background.html, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\be765c55-1ce5-466c-95f1-d787e4796026.dll, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\bgNova.html, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-buttonutil.dll, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3.crx, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3.xpi, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d59bd006-5c9f-4ee7-9632-369bd5ef4f89.crx, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\Uninstall.exe, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-buttonutil64.dll, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10.ico, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\HpUI.exe, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\Loader32.exe, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\Loader64.exe, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll64.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\bk_shadow.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\btn.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\close.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml.bak, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_box.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_check.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_bk.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_check.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit-ie8.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit2.0.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbia.exe, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbici32.dll, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbici64.dll, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbii64.exe, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbiw.sys, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, C:\ProgramData\ShopperPro\config.json, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, C:\ProgramData\ShopperPro\database1_0_0.json, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, C:\ProgramData\ShopperPro\ShopperPro64.dll, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, C:\ProgramData\ShopperPro\spbihe.js, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.IStartSurf.A, C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "startup_urls": [ "http://google.cz/", "http://www.istartsurf.com/?type=hp&ts=1410359370&from=ild&uid=HitachiXHDP725050GLA360_GEA534RJ1PX84A1PX84AX" ],), ,[15e0757896e5b284e9abdb55e025a858]

Physical Sectors: 0
(No malicious items detected)


(end)
KINGSTON 4GB RAM | nVIDIA GeForce GTX 560 | Intel Core2 Quad Q8400 @ 2.67GHz | LCPOWER 600W | Gigabyte GA-EP35-DS4 | SAMSUNG SpinPoint F3 1000Gb, Hitachi 500GB | W7

Uživatelský avatar
roady
Level 2.5
Level 2.5
Příspěvky: 351
Registrován: červen 09
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Urgentní kontrola logu

Příspěvekod roady » 15 zář 2014 19:51

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 15.9.2014
Scan Time: 19:40:03
Logfile: malw.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.09.15.09
Rootkit Database: v2014.09.15.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: roady

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 305806
Time Elapsed: 9 min, 41 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 8
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1712, , [5c99ad401c5f87af291e69fd59a8936d]
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1804, , [2ec72cc184f720161af6ac0618e958a8]
PUP.Optional.Goobzo, C:\Program Files\Common Files\ShopperPro\spbiu.exe, 2160, , [5c99c924562541f54882915926de39c7]
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-6.exe, 3872, , [e1147974c3b87db9be14fba9c63bcc34]
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe, 4444, , [cb2af6f7502b290dfbe9759142c1c739]
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\HpUI.exe, 1812, , [44b110dd6a11ef472dc6dc1333cf4db3]
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\Loader32.exe, 3716, , [44b110dd6a11ef472dc6dc1333cf4db3]
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\Loader64.exe, 3312, , [44b110dd6a11ef472dc6dc1333cf4db3]

Modules: 16
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\4a8cbc19-01c2-4922-b0dd-51cbff85fe3b.dll, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],

Registry Keys: 92
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, , [5c99ad401c5f87af291e69fd59a8936d],
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, , [2ec72cc184f720161af6ac0618e958a8],
PUP.Optional.WindowsProtectManger.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WindowsMangerProtect, , [2ec72cc184f720161af6ac0618e958a8],
PUP.Optional.Goobzo, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPBIUpd, , [5c99c924562541f54882915926de39c7],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611331117}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110611331117}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644334417}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655335517}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666336617}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655335517}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666336617}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644334417}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0063317.BHO.1, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611331117}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611331117}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0063317.BHO, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0063317.BHO, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0063317.BHO.1, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220622332217}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0063317.Sandbox.1, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0063317.Sandbox, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0063317.Sandbox, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0063317.Sandbox.1, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220622332217}, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611331117}\INPROCSERVER32, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [60950ae347342c0a62fb36531be7af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [60950ae347342c0a62fb36531be7af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [60950ae347342c0a62fb36531be7af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [60950ae347342c0a62fb36531be7af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [60950ae347342c0a62fb36531be7af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [60950ae347342c0a62fb36531be7af51],
Trojan.Agent, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ShopperPro, , [2cc9f2fbc1ba2a0c66526121b0520bf5],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ShopperPro, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPDRIVER_1.37.0.193, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\3874, , [0ce9886576053ff7115965c1af54d030],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [6a8bca2317642f07d5db93c148bcbd43],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\ClickMovie1-Downloaderv10, , [dc19925bd0ab8caa24ea11f99172db25],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\ClickMovie1-Downloaderv10-nv, , [767ffcf1770487af7d91d931cd36649c],
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\istartsurfSoftware, , [4baa88655328979f5a4f18ecd72c42be],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, , [d42114d92c4f57dfce56670205ff4cb4],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, , [c035ca2386f5e94db82e4bb7f40fd729],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, , [11e4b5386318979f172d1af1ae556898],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\3874, , [9f568c613249d165501a0620758ef709],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [9a5b31bcccafea4ca0109aba0004e61a],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, , [cb2a4f9e611a191dcf7c5e0e0afac838],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, , [0ce901ec5526300690bc91db689c629e],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, , [02f3c429f586f93d8929d929847f7888],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, , [83729e4f52296ec8598cd1311de6b749],
PUP.Optional.1ClickMovieDownload.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\ClickMovie1-Downloaderv10, , [e213bd303e3d0432b45cf01afa09e818],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, , [f8fda34ad7a40f27b2b2fe4c857ffd03],
PUP.Optional.WebSearches.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SupHpUISoft, , [c2339855f784280eacf76e96748fd62a],
PUP.Optional.1ClickMovieDownload.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\ClickMovie1-Downloaderv10, , [28cd3faec0bb092dc14fec1e27dc817f],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [4ea742ab6d0e73c3acad1548fa0a20e0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\3874, , [c134db12abd05dd9ffd5ce30d82aa957],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\end, , [d61f8d6083f8989eb061b456f50e48b8],
PUP.Optional.Qone8, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [d81d539a48333ff7654a64f038cc2fd1],
PUP.Optional.Softonic.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [af4621cc94e749edde09859c4cb7fb05],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.Update3WebControl.4, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ClickMovie1-Downloaderv10, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.ShopperPro, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPBIUpdd, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\TYPELIB\{8FB1A663-2820-468B-95C4-5060A4C5F413}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\INTERFACE\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\INTERFACE\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{8FB1A663-2820-468B-95C4-5060A4C5F413}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\ShopperPro.ShopperProBHO.1, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\ShopperPro.ShopperProBHO, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperPro.ShopperProBHO, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperPro.ShopperProBHO.1, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, HKLM\SOFTWARE\CLASSES\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\INPROCSERVER32, , [28cdea03f68589ad661212e6be44e020],

Registry Values: 5
PUP.Optional.ShopperPro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SPDriver, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe, , [cb2af6f7502b290dfbe9759142c1c739]
PUP.Optional.ShopperPro, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SPDriver, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe, , [cb2af6f7502b290dfbe9759142c1c739]
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, , [11e4b5386318979f172d1af1ae556898]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, , [02f3c429f586f93d8929d929847f7888]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, ild, , [83729e4f52296ec8598cd1311de6b749]

Registry Data: 12
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX),,[0ce95f8e86f5f343e5dedb1827dd639d]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}, Good: (www.google.com), Bad: (http://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}),,[b243f0fdec8f3402a71238bb7a8a7f81]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX, Good: (www.google.com), Bad: (http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX),,[03f258955a218caacbec15de6d97d828]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX, Good: (www.google.com), Bad: (http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX),,[678ebe2f2f4c6cca45761dd6699b768a]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[e41109e46a11dc5a31a337c7e51fd62a]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX),,[8d68618ceb903501eed5f4ff30d4fd03]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}, Good: (www.google.com), Bad: (http://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}),,[bd38b23bf685db5b4e6b866dc83cd42c]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX, Good: (www.google.com), Bad: (http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX),,[38bd826bf784eb4b863173804db76e92]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX, Good: (www.google.com), Bad: (http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX),,[b2435b923e3d6bcbc4f71bd8a361718f]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[6e87b23b255653e3449032cc2cd8a55b]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX, Good: (www.google.com), Bad: (http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX),,[d12411dcef8c0a2cf6c6658e84809070]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX, Good: (www.google.com), Bad: (http://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX),,[8b6a717c235856e03088827112f2649c]

Folders: 46
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox\content, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, , [5d98a4496318c076a2c3af3832d01ee2],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, , [5d98a4496318c076a2c3af3832d01ee2],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, , [ee076885d2a9cd6928ad9257d32fc63a],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, , [ee076885d2a9cd6928ad9257d32fc63a],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, , [ee076885d2a9cd6928ad9257d32fc63a],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Install, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline\{0539AF68-A07F-4317-ADD9-5C0DD730F62A}, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, C:\ProgramData\ShopperPro, , [28cdea03f68589ad661212e6be44e020],

Files: 172
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, , [5c99ad401c5f87af291e69fd59a8936d],
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, , [2ec72cc184f720161af6ac0618e958a8],
PUP.Optional.Goobzo, C:\Program Files\Common Files\ShopperPro\spbiu.exe, , [5c99c924562541f54882915926de39c7],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-6.exe, , [e1147974c3b87db9be14fba9c63bcc34],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-bho64.dll, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-bho.dll, , [8a6b9e4f5a2110268250851f966b7888],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, , [60950ae347342c0a62fb36531be7af51],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-buttonutil.exe, , [38bd30bdb3c8989e03cfdaca936e738d],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-7.exe, , [f8fd9459512abf773d95a7fd27da9a66],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-bg.exe, , [a4518e5fa1daac8a7959931133ce2bd5],
PUP.Optional.CrossRider.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\utils.exe, , [d71eb33a1467fd3901442c19b34d5ea2],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-buttonutil64.exe, , [ba3b30bd7dfe92a407cb475d1fe228d8],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-codedownloader.exe, , [02f3cc21fe7d5bdb389a0b99857cef11],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-11.exe, , [6c89c22b4338ad89765c277d976a4fb1],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-2.exe, , [da1be508d6a5f3434290c6dedc259b65],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-3.exe, , [3abb23ca87f4e94d7c569f05956c46ba],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-4.exe, , [f9fc13daa5d67db969693470dc25a858],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-5.exe, , [40b5f9f46c0f211521b1eeb69d6420e0],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3-64.exe, , [a055c32a0e6df73ff4de960e21e019e7],
Trojan.Agent, C:\Program Files (x86)\ShopperPro\SPRemove.exe, , [2cc9f2fbc1ba2a0c66526121b0520bf5],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, , [e1142fbe45360135d0f04550847d54ac],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, , [36bf698439429a9c9030cbcaec15e11f],
PUP.Optional.IEPluginService.A, C:\Program Files (x86)\SupTab\RSHP.exe, , [fcf9d61784f731058c62bebaca37df21],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, , [0ee7f1fcb9c292a4d0f0f3a28b76c23e],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, , [23d2c7260c6f8bab219f098c946d639d],
PUP.Optional.IePluginService.A, C:\Program Files (x86)\SupTab\SupIePluginServiceUpdate.exe, , [33c2e40912696bcb93b4c5a1df22b947],
PUP.Optional.ShopperPro, C:\Windows\System32\Tasks\SPBIW_UpdateTask_Time_3730353332363033382d3437415a556c2a3223346c41, , [4da8e10c22594ee8acb5d42ef50e936d],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\ShopperPro.exe, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\config.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\database1_0_0.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\manifest.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\ShopperPro.crx, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\ShopperPro.zip, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\ShopperPro64.dll, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\SPRemove.exe, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\Updater.exe, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox\chrome.manifest, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox\install.rdf, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox\content\overlay.js, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox\content\overlay.xul, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\FireFox\content\shopperpro_128.png, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\jsdrv.exe, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\jsdrv.sys, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\config.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\database1_0_0.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.sys, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189\config.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189\database1_0_0.json, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189\jsdrv.exe, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189\jsdrv.sys, , [cb2af6f7502b290dfbe9759142c1c739],
PUP.Optional.ShopperPro, C:\Windows\System32\Tasks\ShopperPro, , [ba3bd21bf8833006f8f755b1d42ff808],
PUP.Optional.ShopperPro, C:\Windows\System32\Tasks\ShopperProJSUpd, , [d61f9855e09b290d1bd55aacba4958a8],
PUP.Optional.ShopperPro, C:\Windows\System32\Tasks\SPDriver, , [06efb637ec8fb77f6d843bcb6a99916f],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-1, , [f9fc727b5a218ea83e01dc2f0cf702fe],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-11, , [579ed01dc7b44fe760dfe229ec17ff01],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-2, , [44b16e7f5e1d60d691ae858638cb4ab6],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-3, , [c03541ac2a51f83eab947a91f112c53b],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-4, , [fcf9a24bd5a6bd79d669a368af54a759],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-5, , [2cc9866716650d29ac9357b4b25109f7],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-5_user, , [fff6b13c5e1da78f86b92fdc46bd7f81],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-6, , [fdf843aa314a211581becf3cfd06c33d],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-7, , [55a08d603e3ddd5939060cff14ef41bf],
PUP.Optional.Superfish.A, C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, , [01f4d518cdae1d19fccd5ac00ff431cf],
PUP.Optional.Superfish.A, C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, , [1adb599473086fc704c5a2787c87f30d],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-1.job, , [83723eaf215acb6b6063f8710ff5f10f],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-11.job, , [11e4707dd1aa43f3f3d0d693897b1ae6],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-2.job, , [936216d70576be78dae98fdad82c56aa],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-3.job, , [19dc6885a0db56e0586bf871867ec23e],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-4.job, , [e2138e5f611a5adc576cc0a9dc28ad53],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-5.job, , [01f46f7eff7c063092316cfd1fe5857b],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-5_user.job, , [b144539a6b1047efa320d7928d779070],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-6.job, , [45b0b8353b40211519aad792e1235ea2],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d528dafa-994d-4025-9dd0-44dc506221a3-7.job, , [876eb6372754da5c22a1db8eb153956b],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, , [c92c27c6176406307a5f254423e18779],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, , [f7feb6374f2c37ff9c3ec0a9ae56c838],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, , [22d3b73696e5fc3ae3f8f079ee16f709],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, , [d12444a9eb903afca03c2c3d27dd4bb5],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, , [5d98a4496318c076a2c3af3832d01ee2],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-09-10[16-30-02-801].log, , [ee076885d2a9cd6928ad9257d32fc63a],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, , [ee076885d2a9cd6928ad9257d32fc63a],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll, , [63920ce1c9b289ad743938b33bc7dc24],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\1293297481.mxaddon, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\4a8cbc19-01c2-4922-b0dd-51cbff85fe3b.crx, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\4a8cbc19-01c2-4922-b0dd-51cbff85fe3b.dll, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\background.html, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\be765c55-1ce5-466c-95f1-d787e4796026.dll, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\bgNova.html, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-buttonutil.dll, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3.crx, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d528dafa-994d-4025-9dd0-44dc506221a3.xpi, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\d59bd006-5c9f-4ee7-9632-369bd5ef4f89.crx, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\Uninstall.exe, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10-buttonutil64.dll, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.1ClickMovieDownload.A, C:\Program Files (x86)\ClickMovie1-Downloaderv10\ClickMovie1-Downloaderv10.ico, , [8b6a43aa334868ce818f9954c93942be],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\HpUI.exe, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\Loader32.exe, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\Loader64.exe, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll64.dll, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\bk_shadow.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\btn.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\close.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml.bak, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_box.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_check.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_bk.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_check.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit-ie8.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit2.0.js, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, , [44b110dd6a11ef472dc6dc1333cf4db3],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbia.exe, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbici32.dll, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbici64.dll, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbii64.exe, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbiw.sys, , [9362628b9cdfc96d3bb2ce287e84e61a],
PUP.Optional.ShopperPro, C:\ProgramData\ShopperPro\config.json, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, C:\ProgramData\ShopperPro\database1_0_0.json, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, C:\ProgramData\ShopperPro\ShopperPro64.dll, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.ShopperPro, C:\ProgramData\ShopperPro\spbihe.js, , [28cdea03f68589ad661212e6be44e020],
PUP.Optional.IStartSurf.A, C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "startup_urls": [ "http://google.cz/", "http://www.istartsurf.com/?type=hp&ts=1410359370&from=ild&uid=HitachiXHDP725050GLA360_GEA534RJ1PX84A1PX84AX" ],), ,[15e0757896e5b284e9abdb55e025a858]

Physical Sectors: 0
(No malicious items detected)


(end)
KINGSTON 4GB RAM | nVIDIA GeForce GTX 560 | Intel Core2 Quad Q8400 @ 2.67GHz | LCPOWER 600W | Gigabyte GA-EP35-DS4 | SAMSUNG SpinPoint F3 1000Gb, Hitachi 500GB | W7

Uživatelský avatar
roady
Level 2.5
Level 2.5
Příspěvky: 351
Registrován: červen 09
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Urgentní kontrola logu

Příspěvekod roady » 15 zář 2014 19:51

# AdwCleaner v3.310 - Report created 15/09/2014 at 19:33:32
# Updated 12/09/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : roady - ROADY-PC
# Running from : C:\Users\roady\Downloads\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****

Service Found : globalUpdate
Service Found : globalUpdatem
Service Found : IePluginServices
Service Found : SPBIUpd
Service Found : SPBIUpdd
Service Found : WindowsMangerProtect
Service Found : YouTubeAcceleratorService

***** [ Files / Folders ] *****

File Found : C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Found : C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Folder Found : C:\Program Files (x86)\ClickMovie1-Downloaderv10
Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\Program Files (x86)\ShopperPro
Folder Found : C:\Program Files (x86)\SupTab
Folder Found : C:\Program Files (x86)\YouTube Accelerator
Folder Found : C:\Program Files (x86)\YTAHelper
Folder Found : C:\ProgramData\apn
Folder Found : C:\ProgramData\Goobzo
Folder Found : C:\ProgramData\IePluginServices
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
Folder Found : C:\ProgramData\ShopperPro
Folder Found : C:\ProgramData\WindowsMangerProtect
Folder Found : C:\ProgramData\YTAHelper
Folder Found : C:\Users\Public\Documents\Goobzo
Folder Found : C:\Users\Public\Documents\ShopperPro
Folder Found : C:\Users\Public\Documents\YTAHelper
Folder Found : C:\Users\roady\AppData\Local\cool_mirage
Folder Found : C:\Users\roady\AppData\Local\globalUpdate
Folder Found : C:\Users\roady\AppData\LocalLow\Goobzo

***** [ Scheduled Tasks ] *****

Task Found : globalUpdateUpdateTaskMachineCore
Task Found : globalUpdateUpdateTaskMachineUA
Task Found : ShopperPro
Task Found : ShopperProJSUpd
Task Found : SPDriver
Task Found : YTAHelper
Task Found : d528dafa-994d-4025-9dd0-44dc506221a3-1
Task Found : d528dafa-994d-4025-9dd0-44dc506221a3-11
Task Found : d528dafa-994d-4025-9dd0-44dc506221a3-2
Task Found : d528dafa-994d-4025-9dd0-44dc506221a3-3
Task Found : d528dafa-994d-4025-9dd0-44dc506221a3-4
Task Found : d528dafa-994d-4025-9dd0-44dc506221a3-5
Task Found : d528dafa-994d-4025-9dd0-44dc506221a3-5_user
Task Found : d528dafa-994d-4025-9dd0-44dc506221a3-6
Task Found : d528dafa-994d-4025-9dd0-44dc506221a3-7

***** [ Shortcuts ] *****

Shortcut Found : C:\Users\Public\Desktop\Google Chrome.lnk ( hxxp://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX )
Shortcut Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk ( hxxp://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX )
Shortcut Found : C:\Users\roady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( hxxp://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX )
Shortcut Found : C:\Users\roady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ( hxxp://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX )
Shortcut Found : C:\Users\roady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk ( hxxp://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX )
Shortcut Found : C:\Users\roady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( hxxp://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX )
Shortcut Found : C:\Users\roady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk ( hxxp://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX )

***** [ Registry ] *****

Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1 ... 84A1PX84AX
Key Found : HKCU\Software\1ClickDownload
Key Found : HKCU\Software\AppDataLow\Software\ClickMovie1-Downloaderv10
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\Goobzo
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Found : HKCU\Software\ShopperPro
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\SupHpUISoft
Key Found : [x64] HKCU\Software\1ClickDownload
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\Goobzo
Key Found : [x64] HKCU\Software\InstalledBrowserExtensions
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKCU\Software\ShopperPro
Key Found : [x64] HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\SupHpUISoft
Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\AppID\{3A188115-B81B-48F2-A958-F974C8F3F309}
Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Key Found : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Found : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\SMBarBroker.EXE
Key Found : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611331117}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622332217}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0063317.BHO
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0063317.BHO.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0063317.Sandbox
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0063317.Sandbox.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655335517}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666336617}
Key Found : HKLM\SOFTWARE\Classes\Interface\{78CE34FD-F6D4-4866-B79C-A37268D06A04}
Key Found : HKLM\SOFTWARE\Classes\Interface\{80904944-C726-4C7D-A452-3FFF2A882095}
Key Found : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO
Key Found : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO.1
Key Found : HKLM\SOFTWARE\Classes\SMBarBroker.SMBarDealer
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2D9B1B31-D034-4738-8F6E-40F0AFCC742C}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644334417}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644334417}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Found : HKLM\SOFTWARE\ClickMovie1-Downloaderv10
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\Goobzo
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\acaoakiamfeidcmgooclgeleejkbaecf
Key Found : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : HKLM\SOFTWARE\istartsurfSoftware
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611331117}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ClickMovie1-Downloaderv10
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowsMangerProtect
Key Found : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Found : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Found : HKLM\SOFTWARE\ShopperPro
Key Found : HKLM\SOFTWARE\SupDp
Key Found : HKLM\SOFTWARE\SupTab
Key Found : HKLM\SOFTWARE\supWindowsMangerProtect
Key Found : HKLM\SOFTWARE\supWPM
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611331117}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622332217}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655335517}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666336617}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{78CE34FD-F6D4-4866-B79C-A37268D06A04}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{80904944-C726-4C7D-A452-3FFF2A882095}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611331117}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Found : [x64] HKLM\SOFTWARE\ShopperPro
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [GoobzoYouTubeAccelerator]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SPDriver]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}

-\\ Google Chrome v37.0.2062.120

[ File : C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}
Found [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}
Found [Startup_urls] : hxxp://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX
Found [Extension] : acaoakiamfeidcmgooclgeleejkbaecf
Found [Extension] : bopakagnckmlgajfccecajhnimjiiedh

*************************

AdwCleaner[R0].txt - [18506 octets] - [15/09/2014 19:33:32]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [18567 octets] ##########
KINGSTON 4GB RAM | nVIDIA GeForce GTX 560 | Intel Core2 Quad Q8400 @ 2.67GHz | LCPOWER 600W | Gigabyte GA-EP35-DS4 | SAMSUNG SpinPoint F3 1000Gb, Hitachi 500GB | W7

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43072
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Urgentní kontrola logu

Příspěvekod jaro3 » 16 zář 2014 09:59

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
roady
Level 2.5
Level 2.5
Příspěvky: 351
Registrován: červen 09
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Urgentní kontrola logu

Příspěvekod roady » 16 zář 2014 11:28

# AdwCleaner v3.310 - Report created 16/09/2014 at 11:23:37
# Updated 12/09/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : roady - ROADY-PC
# Running from : C:\Users\roady\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
Service Deleted : IePluginServices
Service Deleted : SPBIUpd
[#] Service Deleted : SPBIUpdd
Service Deleted : WindowsMangerProtect
Service Deleted : YouTubeAcceleratorService

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\Goobzo
Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\ProgramData\ShopperPro
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\ProgramData\YTAHelper
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\ShopperPro
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Program Files (x86)\YouTube Accelerator
Folder Deleted : C:\Program Files (x86)\YTAHelper
Folder Deleted : C:\Program Files (x86)\ClickMovie1-Downloaderv10
Folder Deleted : C:\Users\Public\Documents\Goobzo
Folder Deleted : C:\Users\Public\Documents\ShopperPro
Folder Deleted : C:\Users\Public\Documents\YTAHelper
Folder Deleted : C:\Users\roady\AppData\Local\cool_mirage
Folder Deleted : C:\Users\roady\AppData\Local\globalUpdate
Folder Deleted : C:\Users\roady\AppData\LocalLow\Goobzo
File Deleted : C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal

***** [ Scheduled Tasks ] *****

Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : ShopperPro
Task Deleted : ShopperProJSUpd
Task Deleted : SPDriver
Task Deleted : YTAHelper
Task Deleted : d528dafa-994d-4025-9dd0-44dc506221a3-1
Task Deleted : d528dafa-994d-4025-9dd0-44dc506221a3-11
Task Deleted : d528dafa-994d-4025-9dd0-44dc506221a3-2
Task Deleted : d528dafa-994d-4025-9dd0-44dc506221a3-3
Task Deleted : d528dafa-994d-4025-9dd0-44dc506221a3-4
Task Deleted : d528dafa-994d-4025-9dd0-44dc506221a3-5
Task Deleted : d528dafa-994d-4025-9dd0-44dc506221a3-5_user
Task Deleted : d528dafa-994d-4025-9dd0-44dc506221a3-6
Task Deleted : d528dafa-994d-4025-9dd0-44dc506221a3-7

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\roady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\roady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\roady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\roady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\roady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\acaoakiamfeidcmgooclgeleejkbaecf
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [GoobzoYouTubeAccelerator]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\SMBarBroker.EXE
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO
Key Deleted : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO.1
Key Deleted : HKLM\SOFTWARE\Classes\SMBarBroker.SMBarDealer
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SPDriver]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0063317.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0063317.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0063317.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0063317.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3A188115-B81B-48F2-A958-F974C8F3F309}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611331117}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622332217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78CE34FD-F6D4-4866-B79C-A37268D06A04}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{80904944-C726-4C7D-A452-3FFF2A882095}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655335517}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666336617}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D9B1B31-D034-4738-8F6E-40F0AFCC742C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644334417}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611331117}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611331117}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622332217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{78CE34FD-F6D4-4866-B79C-A37268D06A04}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{80904944-C726-4C7D-A452-3FFF2A882095}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655335517}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666336617}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611331117}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Goobzo
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\ShopperPro
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\ClickMovie1-Downloaderv10
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\Goobzo
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\istartsurfSoftware
Key Deleted : HKLM\SOFTWARE\ShopperPro
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\supWPM
Key Deleted : HKLM\SOFTWARE\ClickMovie1-Downloaderv10
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ClickMovie1-Downloaderv10
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : [x64] HKLM\SOFTWARE\ShopperPro

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v37.0.2062.120

[ File : C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}
Deleted [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds& ... 1PX84AX&q={searchTerms}
Deleted [Startup_urls] : hxxp://www.istartsurf.com/?type=hp&ts=1 ... 84A1PX84AX
Deleted [Extension] : acaoakiamfeidcmgooclgeleejkbaecf
Deleted [Extension] : bopakagnckmlgajfccecajhnimjiiedh

*************************

AdwCleaner[R0].txt - [18760 octets] - [15/09/2014 19:33:32]
AdwCleaner[R1].txt - [18511 octets] - [16/09/2014 11:21:26]
AdwCleaner[S0].txt - [16462 octets] - [16/09/2014 11:23:37]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16523 octets] ##########
KINGSTON 4GB RAM | nVIDIA GeForce GTX 560 | Intel Core2 Quad Q8400 @ 2.67GHz | LCPOWER 600W | Gigabyte GA-EP35-DS4 | SAMSUNG SpinPoint F3 1000Gb, Hitachi 500GB | W7

Uživatelský avatar
roady
Level 2.5
Level 2.5
Příspěvky: 351
Registrován: červen 09
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Urgentní kontrola logu

Příspěvekod roady » 16 zář 2014 11:37

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x64
Ran by roady on Łt 16.09.2014 at 11:29:42,76
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CB9506DA-0AB4-4674-9B73-9064BBA5F5BE}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 16.09.2014 at 11:36:24,16
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
KINGSTON 4GB RAM | nVIDIA GeForce GTX 560 | Intel Core2 Quad Q8400 @ 2.67GHz | LCPOWER 600W | Gigabyte GA-EP35-DS4 | SAMSUNG SpinPoint F3 1000Gb, Hitachi 500GB | W7

Uživatelský avatar
roady
Level 2.5
Level 2.5
Příspěvky: 351
Registrován: červen 09
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Urgentní kontrola logu

Příspěvekod roady » 16 zář 2014 11:55

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 16.9.2014
Scan Time: 11:38:32
Logfile: 111.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.09.16.03
Rootkit Database: v2014.09.15.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: roady

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 305462
Time Elapsed: 8 min, 45 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 3
PUP.Optional.1ClickMovieDownload.A, HKLM\SOFTWARE\WOW6432NODE\ClickMovie1-Downloaderv10-nv, Quarantined, [87cc727c1e5d2115d3de967452b1f50b],
PUP.Optional.ShopperPro, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPDRIVER_1.37.0.193, Quarantined, [6ce7bd31e09b61d59a8dcf36a063d729],
PUP.Optional.1ClickMovieDownload.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\ClickMovie1-Downloaderv10, Quarantined, [c093bc32e99203336e4554b635cef010],

Registry Values: 1
PUP.Optional.ShopperPro, HKU\S-1-5-21-3149046002-180890714-1592814674-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SPDriver, C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe, Quarantined, [0251cd21ea9162d4ce583ec739cabb45]

Registry Data: 0
(No malicious items detected)

Folders: 1
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro, Quarantined, [b1a2ae40077437ffe57aaa4d788a19e7],

Files: 10
PUP.Optional.ShopperPro, C:\Windows\System32\Tasks\SPBIW_UpdateTask_Time_3730353332363033382d3437415a556c2a3223346c41, Quarantined, [391ab43adc9fac8a2fd516ed12f17c84],
PUP.Optional.Superfish.A, C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, Delete-on-Reboot, [42116985d9a290a6cd9f4fcc788b4fb1],
PUP.Optional.Superfish.A, C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, Quarantined, [91c2707e8af12c0afd6fca51847fb44c],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbia.exe, Quarantined, [b1a2ae40077437ffe57aaa4d788a19e7],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbici32.dll, Quarantined, [b1a2ae40077437ffe57aaa4d788a19e7],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbici64.dll, Quarantined, [b1a2ae40077437ffe57aaa4d788a19e7],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbii64.exe, Quarantined, [b1a2ae40077437ffe57aaa4d788a19e7],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbiu.exe, Quarantined, [b1a2ae40077437ffe57aaa4d788a19e7],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbiw.sys, Quarantined, [b1a2ae40077437ffe57aaa4d788a19e7],
PUP.Optional.IStartSurf.A, C:\Users\roady\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "startup_urls": [ "http://google.cz/", "http://www.istartsurf.com/?type=hp&ts=1410359370&from=ild&uid=HitachiXHDP725050GLA360_GEA534RJ1PX84A1PX84AX" ],), Replaced,[ada6c6283f3ce84ed4925ad79c699d63]

Physical Sectors: 0
(No malicious items detected)


(end)
KINGSTON 4GB RAM | nVIDIA GeForce GTX 560 | Intel Core2 Quad Q8400 @ 2.67GHz | LCPOWER 600W | Gigabyte GA-EP35-DS4 | SAMSUNG SpinPoint F3 1000Gb, Hitachi 500GB | W7

Uživatelský avatar
roady
Level 2.5
Level 2.5
Příspěvky: 351
Registrován: červen 09
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Urgentní kontrola logu

Příspěvekod roady » 16 zář 2014 12:13

RogueKiller V9.2.10.0 (x64) [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : roady [Práva správce]
Mód : Kontrola -- Datum : 09/16/2014 12:03:22

¤¤¤ Škodlivé procesy: : 3 ¤¤¤
[Suspicious.Path] szndesktop.exe -- C:\Users\roady\AppData\Roaming\Seznam.cz\bin\szndesktop.exe[7] -> SMAZÁNO [TermProc]
[Suspicious.Path] listicka-x64.exe -- C:\Users\roady\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe[7] -> SMAZÁNO [TermThr]
[Suspicious.Path] explorer.exe -- C:\Users\roady\AppData\Roaming\Seznam.cz\bin\8799libfoxloader-x64.dll[-] -> ODEBRÁNO

¤¤¤ ¤¤¤ Záznamy Registrů: : 12 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3149046002-180890714-1592814674-1001\Software\Microsoft\Windows\CurrentVersion\Run | cz.seznam.software.autoupdate : "C:\Users\roady\AppData\Roaming\Seznam.cz\szninstall.exe" -c -> NALEZENO
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3149046002-180890714-1592814674-1001\Software\Microsoft\Windows\CurrentVersion\Run | cz.seznam.software.szndesktop : "C:\Users\roady\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q -> NALEZENO
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3149046002-180890714-1592814674-1001\Software\Microsoft\Windows\CurrentVersion\Run | cz.seznam.software.autoupdate : "C:\Users\roady\AppData\Roaming\Seznam.cz\szninstall.exe" -c -> NALEZENO
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3149046002-180890714-1592814674-1001\Software\Microsoft\Windows\CurrentVersion\Run | cz.seznam.software.szndesktop : "C:\Users\roady\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q -> NALEZENO
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-3149046002-180890714-1592814674-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-3149046002-180890714-1592814674-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-3149046002-180890714-1592814674-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-3149046002-180890714-1592814674-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: NAHRÁNO) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HDP725050GLA360 ATA Device +++++
--- User ---
[MBR] 2148a229775f731697d306809d4a92c5
[BSP] 2e98d0607f5b07122474589ecd7c15c4 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 50000 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 102402048 | Size: 426936 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: SAMSUNG HD103SJ ATA Device +++++
--- User ---
[MBR] c79861213f9b92783867a8d7c6eca346
[BSP] 36271b1ed84c1ef95cbbc2991ed4cec3 : Windows Vista/7/8 MBR Code
Partition table:
1 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 2048 | Size: 953867 MB
User = LL1 ... OK
User = LL2 ... OK
KINGSTON 4GB RAM | nVIDIA GeForce GTX 560 | Intel Core2 Quad Q8400 @ 2.67GHz | LCPOWER 600W | Gigabyte GA-EP35-DS4 | SAMSUNG SpinPoint F3 1000Gb, Hitachi 500GB | W7

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Urgentní kontrola logu

Příspěvekod Orcus » 16 zář 2014 12:36

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka).
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva" a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

====================================================

Stáhni
Zoek.exe

a ulož si ho na plochu.
Zavři všechny ostatní programy, okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor, náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


Klikni na Run Script
Program provede sken, opravu, sken i oprava může trvat i více minut, je třeba posečkat do konce. Do okna neklikej!
rogram nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů, jinak se sám ukládá do:
C:\zoek-results.log
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 4 hosti