Prosím o kontrolu logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

winxclub
nováček
Příspěvky: 6
Registrován: září 16
Pohlaví: Žena
Stav:
Offline

Prosím o kontrolu logu

Příspěvekod winxclub » 24 zář 2016 13:46

Prosím o kontrolu logu, děkuji.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:34:06, on 24. 9. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)

FIREFOX: 49.0.1 (x86 cs)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Users\Acer\AppData\Local\Emotiplus\Emotiplus.exe
C:\PROGRA~2\Booking.com\BOOKIN~2.EXE
C:\Users\Acer\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://%66%65%65%64.%68%65%6C%70%65%72% ... vTwFJTe&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%68%65%6C%70%65%72% ... vTwFJTe&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%68%65%6C%70%65%72% ... vTwFJTe&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.globasearch.com/?serie=209&b ... NA9x96DYG2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nuesearch.com/search/?type=d ... UVTA5PT&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nuesearch.com/search/?type=d ... UVTA5PT&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.globasearch.com/?serie=209&b ... NA9x96DYG2
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%68%65%6C%70%65%72% ... vTwFJTe&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: True Key Helper - {0F4B8786-5502-4803-8EBC-F652A1153BB6} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll
O3 - Toolbar: True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [EmotiplusHelper] "C:\Users\Acer\AppData\Local\EmotiplusHelper\EmotiplusHelper.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Acer\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_22_0_0_209_pepper.exe -update pepperplugin
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
O4 - Startup: CurseClientStartup.ccip
O4 - Startup: Emotiplus.lnk = C:\Users\Acer\AppData\Local\Emotiplus\Emotiplus.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\siteadvisor\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\siteadvisor\mcieplg.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\ProgramData\Quoteex\Zathis.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Biometric and Context Agent Service (IntelBCAsvc) - Intel(R) Corporation - C:\Program Files\Intel\BCA\pabeSvc64.exe
O23 - Service: iSafeService - Unknown owner - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe (file missing)
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Launch Manager Service (LMSvc) - Acer Incorporate - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.376\McCHSvc.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: Intel Security True Key (TrueKey) - McAfee, Inc. - C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
O23 - Service: Intel Security True Key Scheduler (TrueKeyScheduler) - McAfee, Inc. - C:\Program Files\TrueKey\McTkSchedulerService.exe
O23 - Service: Intel Security True Key Helper Service (TrueKeyServiceHelper) - McAfee, Inc. - C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13341 bytes

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 25 zář 2016 09:44

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
http://www.geekstogo.com/forum/files/fi ... -oldtimer/
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Scan“
Po skenu klikni na „Logfile“ ,objeví se okno „Log Manager“ a pak poklepej na odpovídající log , který se otevře. ( jinak je uložen systémovem disku jako C:\AdwCleaner [C?].txt ), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na Uložit výsledky a vyber zkopírovat do schránky a vlož sem celý log.
-jinak se log nachází zde: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

winxclub
nováček
Příspěvky: 6
Registrován: září 16
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod winxclub » 09 lis 2016 15:40

# AdwCleaner v6.030 - Logfile created 09/11/2016 at 15:39:07
# Updated on 19/10/2016 by Malwarebytes
# Database : 2016-11-08.1 [Server]
# Operating System : Windows 8.1 (X64)
# Username : Acer - ACER-PC
# Running from : C:\Users\Acer\Desktop\AdwCleaner.exe
# Mode: Scan
# Support : https://www.malwarebytes.com/support



***** [ Services ] *****

Service Found: rtop
Service Found: ByteFenceService


***** [ Folders ] *****

Folder Found: C:\Users\Acer\AppData\Local\Kometa
Folder Found: C:\Users\Acer\AppData\Local\Mail.Ru
Folder Found: C:\Users\Acer\AppData\Local\Nichrome
Folder Found: C:\Users\Acer\AppData\Local\Orbitum
Folder Found: C:\Users\Acer\AppData\Local\torch
Folder Found: C:\Users\Acer\AppData\Local\Xpom
Folder Found: C:\Users\Acer\AppData\Local\fupdate
Folder Found: C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence
Folder Found: C:\Program Files\ByteFence
Folder Found: C:\ProgramData\ByteFence
Folder Found: C:\ProgramData\Mail.Ru
Folder Found: C:\ProgramData\Application Data\ByteFence
Folder Found: C:\ProgramData\Application Data\Mail.Ru
Folder Found: C:\Program Files (x86)\Mail.Ru
Folder Found: C:\Program Files (x86)\Common Files\freemake shared
Folder Found: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}
Folder Found: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\search@mail.ru
Folder Found: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\homepage@mail.ru
Folder Found: C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd
Folder Found: C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof


***** [ Files ] *****

File Found: C:\Users\Acer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk
File Found: C:\Users\Acer\Favorites\Mail.Ru.url
File Found: C:\Users\Acer\Favorites\Mail.Ru Агент - используй для общения!.url
File Found: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\searchplugins\GoSearch.xml
File Found: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\searchplugins\mailru.xml
File Found: C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ojlcebdkbpjdpiligkdbbkdkfjmchbfd_0.localstorage
File Found: C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ccfifbojenkenpkmnbnndeadpfdiffof_0.localstorage


***** [ DLL ] *****

No malicious DLLs found.


***** [ WMI ] *****

No malicious keys found.


***** [ Shortcuts ] *****

Shortcut infected: C:\Users\Acer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk ( url,FileProtocolHandler "hxxp://www.mail.ru/cnt/20775012?gp=811035" )


***** [ Scheduled Tasks ] *****

Task Found: ByteFence
Task Found: ByteFence Scan


***** [ Registry ] *****

Key Found: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\ByteFenceService
Key Found: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\ByteFenceService
Key Found: HKU\.DEFAULT\Software\Mail.Ru
Key Found: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\ByteFence
Key Found: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Media Get LLC
Key Found: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\PRODUCTSETUP
Key Found: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Mail.Ru
Key Found: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Ultimate-Discounter
Key Found: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\csastats
Key Found: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\AppDataLow\Software\Mail.Ru
Key Found: HKU\S-1-5-18\Software\Mail.Ru
Key Found: HKCU\Software\ByteFence
Key Found: HKCU\Software\Media Get LLC
Key Found: HKCU\Software\PRODUCTSETUP
Key Found: HKCU\Software\Mail.Ru
Key Found: HKCU\Software\Ultimate-Discounter
Key Found: HKCU\Software\csastats
Key Found: HKCU\Software\AppDataLow\Software\Mail.Ru
Key Found: HKLM\SOFTWARE\ByteFence
Key Found: HKLM\SOFTWARE\Mail.Ru
Key Found: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Key Found: [x64] HKCU\Software\ByteFence
Key Found: [x64] HKCU\Software\Media Get LLC
Key Found: [x64] HKCU\Software\PRODUCTSETUP
Key Found: [x64] HKCU\Software\Mail.Ru
Key Found: [x64] HKCU\Software\Ultimate-Discounter
Key Found: [x64] HKCU\Software\csastats
Key Found: [x64] HKCU\Software\AppDataLow\Software\Mail.Ru
Key Found: [x64] HKLM\SOFTWARE\ByteFence
Key Found: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3129290B-0B12-4FA9-B6FA-1E1A70E52929}
Key Found: HKLM\SOFTWARE\Classes\Installer\Features\B092921321B09AF46BAFE1A1075E9292
Key Found: HKLM\SOFTWARE\Classes\Installer\Products\B092921321B09AF46BAFE1A1075E9292
Key Found: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B092921321B09AF46BAFE1A1075E9292
Key Found: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B092921321B09AF46BAFE1A1075E9292
Key Found: [x64] HKLM\SOFTWARE\Classes\Installer\Features\B092921321B09AF46BAFE1A1075E9292
Key Found: [x64] HKLM\SOFTWARE\Classes\Installer\Products\B092921321B09AF46BAFE1A1075E9292
Data Found: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://granena.ru/?utm_content=31b5cebd ... &utm_term=
Data Found: HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://granena.ru/?utm_content=31b5cebd ... _d=2016101
Data Found: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://granena.ru/?utm_content=31b5cebd ... tm_d=20161
Data Found: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.nuesearch.com/search/?type=d ... OSHIBAXMQ0
Data Found: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.nuesearch.com/search/?type=d ... MQ01ABD075
Key Found: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Microsoft\Internet Explorer\SearchScopes\0633EE93-D776-472f-A0FF-E1416B8B2E3A
Key Found: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Microsoft\Internet Explorer\SearchScopes\{A06ED961-D98F-4CF9-A89B-80AB11DB149C}
Key Found: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
Key Found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\0633EE93-D776-472f-A0FF-E1416B8B2E3A
Key Found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A06ED961-D98F-4CF9-A89B-80AB11DB149C}
Key Found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\0633EE93-D776-472f-A0FF-E1416B8B2E3A
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A06ED961-D98F-4CF9-A89B-80AB11DB149C}
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
Key Found: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Found: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{060486CD-08C4-4200-B0CE-BDAC651AD413} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{2507E7FA-76EF-44B4-8211-141F612C41AE} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{46AC5AA6-2674-4DE1-8EF6-CB9A74B5D2B4} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{AD636DF0-4E91-4B69-9C77-B9120B52D8F5} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{C8882C40-2A2F-46E1-BFF2-C4B6F042A023} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{E50FA07D-656A-4FDE-930F-A8090CDFAEFB} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{EA2595C5-EBE1-4E14-B38C-D5CC6222F723} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{060486CD-08C4-4200-B0CE-BDAC651AD413} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{2507E7FA-76EF-44B4-8211-141F612C41AE} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{46AC5AA6-2674-4DE1-8EF6-CB9A74B5D2B4} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{AD636DF0-4E91-4B69-9C77-B9120B52D8F5} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{C8882C40-2A2F-46E1-BFF2-C4B6F042A023} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{E50FA07D-656A-4FDE-930F-A8090CDFAEFB} [NameServer] - 91.109.206.194,98.158.96.96
Data Found: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{EA2595C5-EBE1-4E14-B38C-D5CC6222F723} [NameServer] - 91.109.206.194,98.158.96.96
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\foxi69.tlscdn.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\hao123.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mpc.am
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\search.mpc.am
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\tlscdn.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.hao123.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\filmfanatic2.dl.myway.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\flightsearchapp.dl.myway.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\fromdoctopdf.dl.myway.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\hao123.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mpc.am
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\myway.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.mpc.am
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ttdetect.staticimgfarm.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\weatherblink.dl.myway.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.hao123.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\foxi69.tlscdn.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\hao123.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mpc.am
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\search.mpc.am
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\tlscdn.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.hao123.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\filmfanatic2.dl.myway.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\flightsearchapp.dl.myway.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\fromdoctopdf.dl.myway.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\hao123.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mpc.am
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\myway.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.mpc.am
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ttdetect.staticimgfarm.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\weatherblink.dl.myway.com
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.hao123.com
Key Found: HKLM\SOFTWARE\Classes\*\shell\ByteFence File Scan
Key Found: HKLM\SOFTWARE\Classes\Directory\shell\ByteFence Folder Scan
Key Found: HKLM\SOFTWARE\Google\Chrome\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj
Key Found: HKLM\SOFTWARE\Google\Chrome\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd
Key Found: HKLM\SOFTWARE\Google\Chrome\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof


***** [ Web browsers ] *****

Firefox pref Found: [C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\prefs.js] - "browser.search.defaultenginename" - "GoSearch"
Firefox pref Found: [C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\prefs.js] - "browser.search.selectedEngine" - "GoSearch"
Firefox pref Found: [C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\prefs.js] - "browser.startup.homepage" - "hxxps://mail.ru/cnt/11956636?fr=ffhp1.0.3&gp=800000"
Chrome pref Found: [C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - hxxp://granena.ru/?utm_content=31b5cebd ... 0B6FB2F8C2
Chrome pref Found: [C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - ccfifbojenkenpkmnbnndeadpfdiffof
Chrome pref Found: [C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - oelpkepjlgmehajehfeicfbjdiobdkfj
Chrome pref Found: [C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - ojlcebdkbpjdpiligkdbbkdkfjmchbfd
Chrome pref Found: [C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - hxxp://granena.ru/?utm_content=31b5cebd ... 90B6FB2F8C

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [1117 Bytes] - [27/05/2016 16:06:10]
C:\AdwCleaner\AdwCleaner[C2].txt - [16683 Bytes] - [12/10/2016 14:10:44]
C:\AdwCleaner\AdwCleaner[S1].txt - [15203 Bytes] - [27/05/2016 15:58:54]
C:\AdwCleaner\AdwCleaner[S2].txt - [15222 Bytes] - [12/10/2016 14:09:13]
C:\AdwCleaner\AdwCleaner[S3].txt - [16076 Bytes] - [09/11/2016 15:39:07]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [16150 Bytes] ##########

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 09 lis 2016 19:20

A Malwarebytes' Anti-Malware?

Avast
McAfee
jeden antivir odinstaluj.

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Scan“, po prohledání klikni na „ Clean

Program provede opravu, po automatickém restartu klikni na „Log Manager“ a pak poklepej na odpovídají log, (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

winxclub
nováček
Příspěvky: 6
Registrován: září 16
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod winxclub » 09 lis 2016 21:50

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 9. 11. 2016
Čas skenování: 21:23
Protokol: mbam.txt
Správce: Ano

Verze: 2.2.1.1043
Databáze malwaru: v2016.11.09.07
Databáze rootkitů: v2016.10.31.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto

OS: Windows 8.1
CPU: x64
Souborový systém: NTFS
Uživatel: Acer

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 326706
Uplynulý čas: 22 min, 40 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 1
Trojan.Dropper, C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe, 2728, , [2813615d78220c2ab7c16189a95b8779]

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 29
Trojan.Dropper, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rtop, , [2813615d78220c2ab7c16189a95b8779],
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{6DC6EE87-F3BB-40EB-BCEE-12F7D6E3EEDF}, , [2b10516dd1c9e84e61c882947b8ac63a],
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{959D527D-6C27-4879-A644-065526D6969C}, , [dc5f89358713cf679492b264c243d52b],
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, , [dc5f89358713cf679492b264c243d52b],
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, , [dc5f89358713cf679492b264c243d52b],
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, , [dc5f89358713cf679492b264c243d52b],
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{BAF87BD0-A924-4108-AFA5-A5FA720A2E86}, , [03382d91e1b9f83eab79ef2742c3dd23],
PUP.Optional.InstallMonster, HKLM\SOFTWARE\CLASSES\My Little Pony Hack Cheats Tool.DynamicNS, , [4cefb20ca3f7ff37e0446884ac58f10f],
PUP.Optional.InstallMonster, HKLM\SOFTWARE\WOW6432NODE\CLASSES\My Little Pony Hack Cheats Tool.DynamicNS, , [90ab506ea7f36dc910147d6fb94bae52],
PUP.Optional.InstallMonster, HKLM\SOFTWARE\CLASSES\WOW6432NODE\My Little Pony Hack Cheats Tool.DynamicNS, , [90ab506ea7f36dc910147d6fb94bae52],
PUP.Optional.NeuSearch.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [97a4526c6238da5c68a47c832cd7fe02],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E7E78F21-7E2A-4B13-A647-1FF05845C0FE}, , [b487ecd22a707db9c9b2c151be47e719],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\InternetSD, , [102b57675c3e4beb4337a66c72936d93],
PUP.Optional.StartPage.ShrtCln, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\PowerMonitor, , [7dbe8a343d5dfa3c20d9bf33c3401ae6],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WarThunder 01440, , [1427942a6634ae8894091cbaaf53d729],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WarThunder 05, , [40fbd1edfaa00036a7f622b460a2a15f],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WarThunder 0Sat0, , [4dee536b801ad3636b32bd1925dd3cc4],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WarThunder 0Sun0, , [3308f9c5623836009c01a03625ddd22e],
PUP.Optional.MorePowerfulCleaner, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\MPCDisabled, , [68d3ebd3603ac670d5858960ec175ba5],
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{3129290B-0B12-4FA9-B6FA-1E1A70E52929}, , [0b30e9d50694d660a22a2be9f11421df],
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}, , [69d2ba04495157dfd4c86e5bb1514bb5],
PUP.Optional.MorePowerfulCleaner, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\MPCDisabled, , [67d49e20eab06bcb75e5bb2edd26eb15],
PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{9CDC5B93-3DAC-4388-B9DA-55E30FB79C91}, , [102b04bad3c78bab08938d3cba48cd33],
PUP.Optional.InstallCore, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\csastats, , [b18ad0ee4d4d55e1d15abc3e2cd754ac],
PUP.Optional.UltimateDiscounter, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\Ultimate-Discounter, , [41fa6a54e3b780b619855396be45639d],
PUP.Optional.GlobalSearch.ShrtCln, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\0633EE93-D776-472F-A0FF-E1416B8B2E3A, , [9ba04678aeec1f17b763954424de58a8],
PUP.Optional.GoSearch, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{A06ED961-D98F-4CF9-A89B-80AB11DB149C}, , [3803506e2179f442258f44a24fb5e818],
PUP.Optional.ProductSetup, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\PRODUCTSETUP, , [4cefd0ee168426101986b5fbb152ee12],
PUP.Optional.StartPage, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\START PAGE, , [3efd5b63e4b645f1089e22d119ea5ea2],

Hodnoty registru: 16
PUP.Optional.Elex.SHHKRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{6710C780-E20E-4C49-A87D-321850ED3D7C}, , [d566734b2d6dd066a68bd7f94cb86997],
PUP.Optional.Elex.SHHKRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS|{6710C780-E20E-4C49-A87D-321850ED3D7C}, , [d566734b2d6dd066a68bd7f94cb86997],
PUP.Optional.NeuSearch.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, http://www.nuesearch.com/search/?type=d ... UVTA5PT&q={searchTerms}, , [97a4526c6238da5c68a47c832cd7fe02]
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E7E78F21-7E2A-4B13-A647-1FF05845C0FE}|Path, \InternetSD, , [b487ecd22a707db9c9b2c151be47e719]
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{3129290B-0B12-4FA9-B6FA-1E1A70E52929}|DisplayName, SlimCleaner Plus, , [0b30e9d50694d660a22a2be9f11421df]
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|hp, http://www.trotux.com/?z=8bf581d2e71d72 ... =ffsengext, , [69d2ba04495157dfd4c86e5bb1514bb5]
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|tab, http://www.trotux.com/?z=8bf581d2e71d72 ... =ffsengext, , [d368239b4456aa8ca1fb0abf46bc55ab]
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|sp, http://www.trotux.com/search/?q={searchTerms}&z=8bf581d2e71d72744c46fffgdzeq7m7b5q8t4wfbbz&from=opt&uid=TOSHIBAXMQ01ABD075_35UVTA5PTXX35UVTA5PT&type=sp, , [58e3209e0694e0560993b4152ed4946c]
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|surl, http://www.trotux.com/search/?&z=8bf581 ... type=sp&q=, , [e15a9925afeb8ea8dbc10fba60a2bd43]
PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{9CDC5B93-3DAC-4388-B9DA-55E30FB79C91}|DisplayName, trotux - Uninstall, , [102b04bad3c78bab08938d3cba48cd33]
PUP.Optional.GlobalSearch.ShrtCln, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\0633EE93-D776-472f-A0FF-E1416B8B2E3A|URL, http://www.globasearch.com/?serie=209&i ... YG2&b=3&q={searchTerms}, , [9ba04678aeec1f17b763954424de58a8]
PUP.Optional.GoSearch, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{A06ED961-D98F-4CF9-A89B-80AB11DB149C}|FaviconURL, http://go-search.ru/favicon.ico, , [3803506e2179f442258f44a24fb5e818]
PUP.Optional.GoSearch, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{A06ED961-D98F-4CF9-A89B-80AB11DB149C}|URL, http://go-search.ru/search?q={searchTerms}, , [6fcc8f2fb6e487af10a4796d6e960af6]
PUP.Optional.StartPage.Generic, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|uedsxobuia, explorer "http://granena.ru/?utm_source=uoua03n&utm_content=e739009bccd5f1e6d71a91bff5994529&utm_term=E63BD1FB7A121F890B6FB2F8C2A59667&utm_d=20161015", , [cc6f8539cfcb0d294e15b4151ae86898]
PUP.Optional.ProductSetup, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\PRODUCTSETUP|tb, 0U1S1H0G1O1D1O2Y, , [4cefd0ee168426101986b5fbb152ee12]
PUP.Optional.StartPage, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\START PAGE|Start Page, http://granena.ru/?utm_content=31b5cebd ... d=20161015, , [3efd5b63e4b645f1089e22d119ea5ea2]

Data registru: 3
PUP.Optional.NeuSearch.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.nuesearch.com/search/?type=d ... UVTA5PT&q={searchTerms}, Dobré: (www.google.com), Špatné: (http://www.nuesearch.com/search/?type=d ... UVTA5PT&q={searchTerms}),,[45f6b20cf1a9d75f26050079ec18b14f]
PUP.Optional.NeuSearch.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.nuesearch.com/search/?type=d ... UVTA5PT&q={searchTerms}, Dobré: (www.google.com), Špatné: (http://www.nuesearch.com/search/?type=d ... UVTA5PT&q={searchTerms}),,[8caf6559d1c9082eaa8147320103b34d]
PUP.Optional.StartPage, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://granena.ru/?utm_content=31b5cebd ... d=20161015, Dobré: (www.google.com), Špatné: (http://granena.ru/?utm_content=31b5cebd ... d=20161015),,[92a9c5f984167bbba4dea76385800ff1]

Složky: 65
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\alerter, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\background, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\common, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\content, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\images, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\ppapi, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata\yandex, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Local Storage, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\alerter, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\background, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\common, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\content, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\images, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\ppapi, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\_metadata, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\_metadata\yandex, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\alerter, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\background, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\common, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\images, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\plugins, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\alerter, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\background, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\common, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\content, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\images, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\ppapi, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata\yandex, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.Linkury.ACMB1, C:\Program Files (x86)\Common Files\Nimkix, , [a497a81638628bab72f38c10c63efa06],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\common, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\revert, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\settings, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\settings\common, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\settings\partner, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\_metadata, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\common, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\content_script, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\logo, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\newtab, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\revert, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\settings, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\settings\common, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\settings\partner, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\_metadata, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj, , [f546b80691092a0cd254c6d629db46ba],

Soubory: 130
Trojan.Dropper, C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe, , [2813615d78220c2ab7c16189a95b8779],
PUP.Optional.OpenCandy, C:\Users\Acer\Downloads\Cheat Engine 6.5.1 [1].exe, , [cb705a64891156e000eeb1dbcb36639d],
PUP.Optional.InstallCore, C:\Users\Acer\Downloads\Cheat Engine 6.5.1.exe, , [bb808a3479214aec40ba54414bb9f30d],
Adware.LoadMoney, C:\Users\Acer\AppData\Local\fupdate\trz8453.tmp, , [f843f8c669313cfa28a6f4252fd6ec14],
PUP.Optional.GoSearch, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\searchplugins\GoSearch.xml, , [84b7209eb5e5fd39bb72663e1de66997],
PUP.Optional.Elex, C:\Program Files (x86)\SSFK.exe, , [cf6ce0dee3b785b16980578eb94a53ad],
PUP.Optional.Linkury, C:\Users\Acer\AppData\Roaming\ApplicationHosting.dat, , [4bf02f8fd1c921156a91f3fb59aabe42],
PUP.Optional.Linkury, C:\Users\Acer\AppData\Roaming\md.xml, , [0833cef0fd9d42f4c5378965e81b46ba],
PUP.Optional.Linkury, C:\Users\Acer\AppData\Roaming\noah.dat, , [023996280a909b9b9e5fe00e2cd7b848],
PUP.Optional.Linkury, C:\Users\Acer\AppData\Roaming\uninstall_temp.ico, , [93a8ccf2bbdf57df7985717df21126da],
PUP.Optional.Linkury, C:\Users\Acer\AppData\Roaming\lobby.dat, , [310a4f6f3268f83ebccbc02f996aa15f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.mysearch.com_0.localstorage, , [ad8e714d207a06300df243ad21e26a96],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.mysearch.com_0.localstorage-journal, , [80bbffbf2179c27402fd48a8f60d3ec2],
PUP.Optional.Linkury.Gen, C:\Users\Acer\AppData\Roaming\Doubledax.tst, , [62d9cbf3a4f6d165d9d342bad52efa06],
PUP.Optional.Linkury.Gen, C:\Users\Acer\AppData\Roaming\U--Fresh.tst, , [f348e0de8e0ccd696d3f0cf045bec040],
PUP.Optional.StartPage, C:\Windows\System32\Tasks\InternetSD, , [0c2ff7c75b3fee4868113ed46d984eb2],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Preferences, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\manifest.json, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\alerter\block.html, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\alerter\block.js, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\background\background.js, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\background\blacklist.js, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\background\index.html, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\background\plugin.js, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\background\whitelist.js, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\common\common.js, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\content\content.js, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\images\icon_128.png, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\images\icon_48.png, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\ppapi\safe_surfing.nmf, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\ppapi\safe_surfing_arm.nexe, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\ppapi\safe_surfing_x86_32.nexe, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\ppapi\safe_surfing_x86_64.nexe, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata\computed_hashes.json, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata\verified_contents.json, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata\yandex\computed_hashes.json, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.Kometa, C:\Users\Acer\AppData\Local\Kometa\User Data\Default\Local Storage\chrome-extension_kcknbenjnkkjknphmnidanjifbgphjke_0.localstorage, , [51ea724c2278261014a36c5539c97e82],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\manifest.json, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\alerter\block.html, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\alerter\block.js, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\background\background.js, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\background\blacklist.js, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\background\index.html, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\background\plugin.js, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\background\whitelist.js, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\common\common.js, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\content\content.js, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\images\icon_128.png, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\images\icon_48.png, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi\npsafe_surfing.dll, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\ppapi\safe_surfing.nmf, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\ppapi\safe_surfing_arm.nexe, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\ppapi\safe_surfing_x86_32.nexe, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\ppapi\safe_surfing_x86_64.nexe, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\_metadata\computed_hashes.json, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\_metadata\verified_contents.json, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\_metadata\yandex\computed_hashes.json, , [a2999b23a6f461d5d894457f4db5c838],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome.manifest, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\install.rdf, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\safesurfing.xul, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\alerter\block.html, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\alerter\block.js, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\background\background.js, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\background\blacklist.js, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\background\plugin.js, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\background\prefs_storage.js, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\background\url_handler.js, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\background\whitelist.js, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\chrome\content\common\common.js, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\images\icon_48.png, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE}\plugins\npsafe_surfing.dll, , [a3985c620397bd791855c3013ac8ee12],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\manifest.json, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\alerter\block.html, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\alerter\block.js, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\images\icon_128.png, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\images\icon_48.png, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\ppapi\safe_surfing_arm.nexe, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\ppapi\safe_surfing_x86_32.nexe, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata\computed_hashes.json, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata\verified_contents.json, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata\yandex\computed_hashes.json, , [12297f3f7a20092d2e40a222dd25e61a],
PUP.Optional.Linkury.ACMB1, C:\Program Files (x86)\Common Files\Nimkix\InstallationConfiguration.xml, , [a497a81638628bab72f38c10c63efa06],
PUP.Optional.Linkury.ACMB1, C:\Program Files (x86)\Common Files\Nimkix\uninstall.dat, , [a497a81638628bab72f38c10c63efa06],
PUP.Optional.Linkury.ACMB1, C:\Program Files (x86)\Common Files\Nimkix\uninstall.ico, , [a497a81638628bab72f38c10c63efa06],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\manifest.json, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\common\browseraction.js, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\common\config.js, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\common\feed.js, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\common\utils.js, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\common\winner.js, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\logo_128x.png, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\logo_16x.png, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\logo_19x.png, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\logo_24x.png, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\logo_32x.png, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\logo_48x.png, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\newtablogo.png, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\toolbar-icon-ask.ico, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\toolbar-icons.png, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\revert\index.css, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\revert\index.html, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\revert\index.js, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\settings\common\redirect.js, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\settings\partner\Reporting.js, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\_metadata\computed_hashes.json, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\_metadata\verified_contents.json, , [4deef0cecbcf7bbb4ed8a6f6a65ec13f],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\manifest.json, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\common\browseraction.js, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\common\config.js, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\common\feed.js, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\common\utils.js, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\common\winner.js, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\content_script\overlayer.js, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\logo\logo_128x.png, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\logo\logo_16x.png, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\logo\logo_19x.png, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\logo\logo_48x.png, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\newtab\newtab.html, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\revert\index.css, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\revert\index.html, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\revert\index.js, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\settings\common\redirect.js, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\settings\partner\Reporting.js, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\_metadata\computed_hashes.json, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\_metadata\verified_contents.json, , [f546b80691092a0cd254c6d629db46ba],
PUP.Optional.TerraClicks.ShrtCln, C:\Users\Acer\AppData\Local\Microsoft\Windows\INetCookies\Low\TCFTQLPU.txt, , [0a3185393b5f7eb847cfb2ea06fe3dc3],
PUP.Optional.Linkury.ACMB1, C:\Users\Acer\AppData\Roaming\Config.xml, , [0f2c8935c7d39f97d385851756aeb749],
PUP.Optional.Linkury.ACMB1, C:\Users\Acer\AppData\Roaming\InstallationConfiguration.xml, , [a695dce2eeac6acc4118a6f66f9537c9],
PUP.Optional.GoSearch, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\prefs.js, Dobré: (), Špatné: (user_pref("browser.search.defaultenginename", "GoSearch");), ,[93a84a7488125adcd5b6f99f42c28b75]
PUP.Optional.GoSearch, C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\prefs.js, Dobré: (), Špatné: (user_pref("browser.search.selectedEngine", "GoSearch");), ,[4eed7a4474261e186bd1910cd72d6a96]

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

winxclub
nováček
Příspěvky: 6
Registrován: září 16
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod winxclub » 09 lis 2016 22:04

# AdwCleaner v6.030 - Logfile created 09/11/2016 at 21:57:50
# Updated on 19/10/2016 by Malwarebytes
# Database : 2016-11-08.1 [Server]
# Operating System : Windows 8.1 (X64)
# Username : Acer - ACER-PC
# Running from : C:\Users\Acer\Desktop\AdwCleaner.exe
# Mode: Clean
# Support : hxxps://www.malwarebytes.com/support



***** [ Services ] *****

[-] Service deleted: rtop
[-] Service deleted: ByteFenceService


***** [ Folders ] *****

[-] Folder deleted: C:\Users\Acer\AppData\Local\Kometa
[-] Folder deleted: C:\Users\Acer\AppData\Local\Mail.Ru
[-] Folder deleted: C:\Users\Acer\AppData\Local\Nichrome
[-] Folder deleted: C:\Users\Acer\AppData\Local\Orbitum
[-] Folder deleted: C:\Users\Acer\AppData\Local\torch
[-] Folder deleted: C:\Users\Acer\AppData\Local\Xpom
[-] Folder deleted: C:\Users\Acer\AppData\Local\fupdate
[-] Folder deleted: C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence
[-] Folder deleted: C:\Program Files\ByteFence
[-] Folder deleted: C:\ProgramData\ByteFence
[-] Folder deleted: C:\ProgramData\Mail.Ru
[#] Folder deleted on reboot: C:\ProgramData\Application Data\ByteFence
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Mail.Ru
[-] Folder deleted: C:\Program Files (x86)\Mail.Ru
[-] Folder deleted: C:\Program Files (x86)\Common Files\freemake shared
[-] Folder deleted: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}
[-] Folder deleted: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\search@mail.ru
[-] Folder deleted: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\homepage@mail.ru
[-] Folder deleted: C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd
[-] Folder deleted: C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof


***** [ Files ] *****

[-] File deleted: C:\Users\Acer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk
[-] File deleted: C:\Users\Acer\Favorites\Mail.Ru.url
[-] File deleted: C:\Users\Acer\Favorites\Mail.Ru Агент - используй для общения!.url
[-] File deleted: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\searchplugins\GoSearch.xml
[-] File deleted: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\searchplugins\mailru.xml
[-] File deleted: C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ojlcebdkbpjdpiligkdbbkdkfjmchbfd_0.localstorage
[-] File deleted: C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ccfifbojenkenpkmnbnndeadpfdiffof_0.localstorage


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Shortcuts ] *****

[!] Shortcut not deleted: C:\Users\Acer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk


***** [ Scheduled Tasks ] *****



***** [ Registry ] *****

[-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\ByteFenceService
[#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\ByteFenceService
[-] Key deleted: HKU\.DEFAULT\Software\Mail.Ru
[-] Key deleted: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\ByteFence
[-] Key deleted: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Media Get LLC
[-] Key deleted: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\PRODUCTSETUP
[-] Key deleted: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Mail.Ru
[-] Key deleted: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Ultimate-Discounter
[-] Key deleted: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\csastats
[-] Key deleted: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\AppDataLow\Software\Mail.Ru
[#] Key deleted on reboot: HKU\S-1-5-18\Software\Mail.Ru
[#] Key deleted on reboot: HKCU\Software\ByteFence
[#] Key deleted on reboot: HKCU\Software\Media Get LLC
[#] Key deleted on reboot: HKCU\Software\PRODUCTSETUP
[#] Key deleted on reboot: HKCU\Software\Mail.Ru
[#] Key deleted on reboot: HKCU\Software\Ultimate-Discounter
[#] Key deleted on reboot: HKCU\Software\csastats
[#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\Mail.Ru
[-] Key deleted: HKLM\SOFTWARE\ByteFence
[-] Key deleted: HKLM\SOFTWARE\Mail.Ru
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
[#] Key deleted on reboot: [x64] HKCU\Software\ByteFence
[#] Key deleted on reboot: [x64] HKCU\Software\Media Get LLC
[#] Key deleted on reboot: [x64] HKCU\Software\PRODUCTSETUP
[#] Key deleted on reboot: [x64] HKCU\Software\Mail.Ru
[#] Key deleted on reboot: [x64] HKCU\Software\Ultimate-Discounter
[#] Key deleted on reboot: [x64] HKCU\Software\csastats
[#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\Software\Mail.Ru
[-] Key deleted: [x64] HKLM\SOFTWARE\ByteFence
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3129290B-0B12-4FA9-B6FA-1E1A70E52929}
[-] Key deleted: HKLM\SOFTWARE\Classes\Installer\Features\B092921321B09AF46BAFE1A1075E9292
[-] Key deleted: HKLM\SOFTWARE\Classes\Installer\Products\B092921321B09AF46BAFE1A1075E9292
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B092921321B09AF46BAFE1A1075E9292
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B092921321B09AF46BAFE1A1075E9292
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Installer\Features\B092921321B09AF46BAFE1A1075E9292
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Installer\Products\B092921321B09AF46BAFE1A1075E9292
[-] Data restored: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
[-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
[-] Key deleted: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Microsoft\Internet Explorer\SearchScopes\0633EE93-D776-472f-A0FF-E1416B8B2E3A
[-] Key deleted: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Microsoft\Internet Explorer\SearchScopes\{A06ED961-D98F-4CF9-A89B-80AB11DB149C}
[-] Key deleted: HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\0633EE93-D776-472f-A0FF-E1416B8B2E3A
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A06ED961-D98F-4CF9-A89B-80AB11DB149C}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\0633EE93-D776-472f-A0FF-E1416B8B2E3A
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A06ED961-D98F-4CF9-A89B-80AB11DB149C}
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data restored: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{060486CD-08C4-4200-B0CE-BDAC651AD413} [NameServer]
[-] Data restored: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{2507E7FA-76EF-44B4-8211-141F612C41AE} [NameServer]
[-] Data restored: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{46AC5AA6-2674-4DE1-8EF6-CB9A74B5D2B4} [NameServer]
[-] Data restored: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{AD636DF0-4E91-4B69-9C77-B9120B52D8F5} [NameServer]
[-] Data restored: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{C8882C40-2A2F-46E1-BFF2-C4B6F042A023} [NameServer]
[-] Data restored: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{E50FA07D-656A-4FDE-930F-A8090CDFAEFB} [NameServer]
[-] Data restored: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{EA2595C5-EBE1-4E14-B38C-D5CC6222F723} [NameServer]
[-] Data restored: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{060486CD-08C4-4200-B0CE-BDAC651AD413} [NameServer]
[-] Data restored: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{2507E7FA-76EF-44B4-8211-141F612C41AE} [NameServer]
[-] Data restored: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{46AC5AA6-2674-4DE1-8EF6-CB9A74B5D2B4} [NameServer]
[-] Data restored: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{AD636DF0-4E91-4B69-9C77-B9120B52D8F5} [NameServer]
[-] Data restored: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{C8882C40-2A2F-46E1-BFF2-C4B6F042A023} [NameServer]
[-] Data restored: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{E50FA07D-656A-4FDE-930F-A8090CDFAEFB} [NameServer]
[-] Data restored: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{EA2595C5-EBE1-4E14-B38C-D5CC6222F723} [NameServer]
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\foxi69.tlscdn.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\hao123.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mpc.am
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\search.mpc.am
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\tlscdn.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.hao123.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\filmfanatic2.dl.myway.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\flightsearchapp.dl.myway.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\fromdoctopdf.dl.myway.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\hao123.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mpc.am
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\myway.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.mpc.am
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ttdetect.staticimgfarm.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\weatherblink.dl.myway.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.hao123.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\foxi69.tlscdn.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\hao123.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mpc.am
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\search.mpc.am
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\tlscdn.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.hao123.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\filmfanatic2.dl.myway.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\flightsearchapp.dl.myway.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\fromdoctopdf.dl.myway.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\hao123.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mpc.am
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\myway.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.mpc.am
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ttdetect.staticimgfarm.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\weatherblink.dl.myway.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.hao123.com
[-] Key deleted: HKLM\SOFTWARE\Classes\*\shell\ByteFence File Scan
[-] Key deleted: HKLM\SOFTWARE\Classes\Directory\shell\ByteFence Folder Scan
[-] Key deleted: HKLM\SOFTWARE\Google\Chrome\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj
[-] Key deleted: HKLM\SOFTWARE\Google\Chrome\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd
[-] Key deleted: HKLM\SOFTWARE\Google\Chrome\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof


***** [ Web browsers ] *****

[-] Chrome preferences cleaned: "browser.search.defaultenginename" - "GoSearch"
[-] Chrome preferences cleaned: "browser.search.selectedEngine" - "GoSearch"
[-] Chrome preferences cleaned: "browser.startup.homepage" - "hxxps://mail.ru/cnt/11956636?fr=ffhp1.0.3&gp=800000"
[-] [C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Deleted: hxxp://granena.ru/?utm_content=31b5cebd ... d=20161015
[-] [C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: ccfifbojenkenpkmnbnndeadpfdiffof
[-] [C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: oelpkepjlgmehajehfeicfbjdiobdkfj
[-] [C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: ojlcebdkbpjdpiligkdbbkdkfjmchbfd
[-] [C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default] [homepage] Deleted: hxxp://granena.ru/?utm_content=31b5cebd ... d=20161015


*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [1117 Bytes] - [27/05/2016 16:06:10]
C:\AdwCleaner\AdwCleaner[C2].txt - [16683 Bytes] - [12/10/2016 14:10:44]
C:\AdwCleaner\AdwCleaner[C3].txt - [15745 Bytes] - [09/11/2016 21:57:50]
C:\AdwCleaner\AdwCleaner[S1].txt - [15203 Bytes] - [27/05/2016 15:58:54]
C:\AdwCleaner\AdwCleaner[S2].txt - [15222 Bytes] - [12/10/2016 14:09:13]
C:\AdwCleaner\AdwCleaner[S3].txt - [16426 Bytes] - [09/11/2016 15:39:07]
C:\AdwCleaner\AdwCleaner[S4].txt - [16500 Bytes] - [09/11/2016 21:55:40]

########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [16115 Bytes] ##########

winxclub
nováček
Příspěvky: 6
Registrován: září 16
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod winxclub » 09 lis 2016 22:12

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 8.1 x64
Ran by Acer (Administrator) on st 09. 11. 2016 at 22:09:02,21
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 5

Successfully deleted: C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke (Folder)
Successfully deleted: C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kcknbenjnkkjknphmnidanjifbgphjke_0.localstorage-journal (File)
Successfully deleted: C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kcknbenjnkkjknphmnidanjifbgphjke_0.localstorage (File)
Successfully deleted: C:\Users\Acer\AppData\Local\ucozmedia (Folder)
Successfully deleted: C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\extensions\{3B4DE07A-DE43-4DBC-873F-05835FF67DCE} (Folder)

Deleted the following from C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\h2ub0sj9.default\prefs.js
user_pref(extensions.homepage@mail.ru.info, {\gp\:800000,\product_id\:\db3801e5-cec1-4e70-b441-9dc72c20d678\,\install_id\:\db3801e5-cec1-4e70-b441-9dc72c20d678\,\
user_pref(extensions.homepage@mail.ru.lastHomepage, about:home);
user_pref(extensions.homepage@mail.ru.lastPageType, 1);
user_pref(extensions.homepage@mail.ru.metric_state_go_metric, {\lastDayNumber\:10,\lastDayDate\:\2016-11-09T00:00:00.000Z\});
user_pref(extensions.homepage@mail.ru.metric_state_mrds_metric, {\lastDayNumber\:10,\lastDayDate\:\2016-11-09T00:00:00.000Z\});
user_pref(extensions.search@mail.ru.info, {\gp\:800000,\product_id\:\d3510b02-30f6-4cd3-a596-2bcde820c28e\,\install_id\:\d3510b02-30f6-4cd3-a596-2bcde820c28e\,\c
user_pref(extensions.search@mail.ru.metric_state_go_metric, {\lastDayNumber\:10,\lastDayDate\:\2016-11-09T00:00:00.000Z\});
user_pref(extensions.search@mail.ru.metric_state_mrds_metric, {\lastDayNumber\:10,\lastDayDate\:\2016-11-09T00:00:00.000Z\});
user_pref(extensions.xpiState, {\app-profile\:{\homepage@mail.ru\:{\d\:\C:\\\\Users\\\\Acer\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\h2ub0sj9.defau
user_pref(keyword.URL, hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&);



Registry: 6

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 09. 11. 2016 at 22:11:59,86
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 10 lis 2016 09:37

. spusť znovu Malwarebytes' Anti-Malware a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Sophos Virus Removal Tool je praktický softwarový nástroj, který by mohl odstranit infekce, které antivirový program nedetekuje .
Stáhněte si ho zde z některého odkazu:
http://www.majorgeeks.com/mg/get/sophos ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,2.html

Viry mohou zpomalit počítač, nebo se snaží ukrást vaše data, a ani nevíte , že je máte. Co potřebujete, je rychlý a snadný způsob, jak je najít a zbavit se jich, pokud již máte antivirový program v počítači nainstalován , můžete nainstalovat i nástroj Sophos Virus Removal , který identifikuje a vyčistí zbylé infekce, které mohl Váš antivirový program přehlédnout.
K použití Sophos Virus Removal Tool na něj poklepejte a stiskněte tlačítko „Start scanning“ . Pak bude Sophos Virus Removal Tool vyhledávat a odstraňovat viry, které najde. Může být vyžadován restart.


Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.adlice.com/download/roguekil ... HlwZT14ODY

64bit.:
http://www.adlice.com/download/roguekil ... HlwZT14NjQ
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7,8,10 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Open Report “ , v okně pak na „Open TXT“ a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

winxclub
nováček
Příspěvky: 6
Registrován: září 16
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod winxclub » 24 lis 2016 19:51

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 24. 11. 2016
Čas skenování: 19:04
Protokol: vysledky testu 2.txt
Správce: Ano

Verze: 2.2.1.1043
Databáze malwaru: v2016.11.24.08
Databáze rootkitů: v2016.11.20.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows 8.1
CPU: x64
Souborový systém: NTFS
Uživatel: Acer

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 307058
Uplynulý čas: 27 min, 46 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 1
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\AliExpress_helper.exe, 14740, Smazat při restartu, [4eca566e1f7b6bcb33e304d11ce744bc]

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 32
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{6DC6EE87-F3BB-40EB-BCEE-12F7D6E3EEDF}, Do karantény, [d048e8dc6a3057dfbe09fbbbc53ef808],
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{959D527D-6C27-4879-A644-065526D6969C}, Do karantény, [988090343763de585d68d0e61ae957a9],
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Do karantény, [988090343763de585d68d0e61ae957a9],
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Do karantény, [988090343763de585d68d0e61ae957a9],
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Do karantény, [988090343763de585d68d0e61ae957a9],
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{BAF87BD0-A924-4108-AFA5-A5FA720A2E86}, Do karantény, [9e7a1ea65545092df9ca882e3dc64db3],
PUP.Optional.InstallMonster, HKLM\SOFTWARE\CLASSES\My Little Pony Hack Cheats Tool.DynamicNS, Do karantény, [49cf279dc5d53afc8b50bdcf956ed52b],
PUP.Optional.InstallMonster, HKLM\SOFTWARE\WOW6432NODE\CLASSES\My Little Pony Hack Cheats Tool.DynamicNS, Do karantény, [bc5c8e36f7a3e84eb12ab9d3b54e6898],
PUP.Optional.InstallMonster, HKLM\SOFTWARE\CLASSES\WOW6432NODE\My Little Pony Hack Cheats Tool.DynamicNS, Do karantény, [bc5c8e36f7a3e84eb12ab9d3b54e6898],
PUP.Optional.AliExpress, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{872BF1B7-483E-44FA-95B9-9779ABE4B070}_is1, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{7B3D29B9-811D-4C49-ADC5-AC231D4A933C}, Smazat při restartu, [839562624d4ddf573f8013c55da4c33d],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{DFCB6BE6-0AAA-4962-893A-F572443C9FEB}, Smazat při restartu, [b3659b299cfe58defcc35d7be021d030],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E1F47057-BD5B-4914-BEED-31815D55DED0}, Smazat při restartu, [97811da795053303566982563bc6d12f],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E7E78F21-7E2A-4B13-A647-1FF05845C0FE}, Smazat při restartu, [968272520b8fb38340e3397aa65ddb25],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\InternetSD, Smazat při restartu, [1800b3116a30e2541e0406ad9b68629e],
PUP.Optional.StartPage.ShrtCln, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\PowerMonitor, Smazat při restartu, [0d0becd85f3bf64069640cc718ea34cc],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WarThunder 01440, Smazat při restartu, [7b9d794b9406e2540432ab38aa57bd43],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WarThunder 05, Smazat při restartu, [8c8c0eb67327de58092d6a7957aa06fa],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WarThunder 0Sat0, Smazat při restartu, [ff196a5addbdf93dab8b9053b74a06fa],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WarThunder 0Sun0, Smazat při restartu, [b26670542f6bbc7a2f072cb75ea30af6],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WarThunder0, Smazat při restartu, [6cacc8fc3268152140f60bd8ae53f60a],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WarThunder1, Smazat při restartu, [3cdc754f0e8c10263cfa5e85f70aea16],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WarThunder2, Smazat při restartu, [0f09596b8d0d3cfaf44260837091d52b],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WarThunder3, Smazat při restartu, [b761a321a8f20e28eb4b7172dd24fc04],
PUP.Optional.MorePowerfulCleaner, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\MPCDisabled, Do karantény, [a177f0d4e7b367cf232c4d7ec73b946c],
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}, Do karantény, [c553f1d32773ad89c972eaed9869bf41],
PUP.Optional.MorePowerfulCleaner, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\MPCDisabled, Do karantény, [24f4784c445645f19db244875ba7857b],
PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{9CDC5B93-3DAC-4388-B9DA-55E30FB79C91}, Do karantény, [16022a9a0298a49270ca9d3aee13956b],
PUP.Optional.InstallCore, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\csastats, Do karantény, [64b4f6ce613993a34d3a815836cc31cf],
PUP.Optional.Gameo, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\GoldenGate, Do karantény, [70a87a4a0694033334bec51aaa578d73],
PUP.Optional.ProductSetup, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\PRODUCTSETUP, Do karantény, [63b5c202970387afc758dabdf11105fb],
PUP.Optional.StartPage, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\START PAGE, Do karantény, [02161da77b1f25118ed13d977c86d030],

Hodnoty registru: 14
PUP.Optional.Elex.SHHKRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{6710C780-E20E-4C49-A87D-321850ED3D7C}, Do karantény, [a0785a6a4a5059dd8c5d4b2593708d73],
PUP.Optional.Elex.SHHKRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS|{6710C780-E20E-4C49-A87D-321850ED3D7C}, Do karantény, [a0785a6a4a5059dd8c5d4b2593708d73],
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{7B3D29B9-811D-4C49-ADC5-AC231D4A933C}|Path, \WarThunder2, Smazat při restartu, [839562624d4ddf573f8013c55da4c33d]
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{DFCB6BE6-0AAA-4962-893A-F572443C9FEB}|Path, \WarThunder1, Smazat při restartu, [b3659b299cfe58defcc35d7be021d030]
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E1F47057-BD5B-4914-BEED-31815D55DED0}|Path, \WarThunder3, Smazat při restartu, [97811da795053303566982563bc6d12f]
PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E7E78F21-7E2A-4B13-A647-1FF05845C0FE}|Path, \InternetSD, Smazat při restartu, [968272520b8fb38340e3397aa65ddb25]
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|hp, http://www.trotux.com/?z=8bf581d2e71d72 ... =ffsengext, Do karantény, [c553f1d32773ad89c972eaed9869bf41]
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|tab, http://www.trotux.com/?z=8bf581d2e71d72 ... =ffsengext, Do karantény, [f523edd7d3c701352e0d3e99ba47a957]
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|sp, http://www.trotux.com/search/?q={searchTerms}&z=8bf581d2e71d72744c46fffgdzeq7m7b5q8t4wfbbz&from=opt&uid=TOSHIBAXMQ01ABD075_35UVTA5PTXX35UVTA5PT&type=sp, Do karantény, [e2369e2615854de989b2b4233dc47d83]
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|surl, http://www.trotux.com/search/?&z=8bf581 ... type=sp&q=, Do karantény, [5fb9b014306ad16523188b4c847dc53b]
PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{9CDC5B93-3DAC-4388-B9DA-55E30FB79C91}|DisplayName, trotux - Uninstall, Do karantény, [16022a9a0298a49270ca9d3aee13956b]
PUP.Optional.StartPage.Generic, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|uedsxobuia, explorer "http://granena.ru/?utm_source=uoua03n&utm_content=e739009bccd5f1e6d71a91bff5994529&utm_term=E63BD1FB7A121F890B6FB2F8C2A59667&utm_d=20161015", Do karantény, [1008ac18f3a7d462a85a01d6fb066f91]
PUP.Optional.ProductSetup, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\PRODUCTSETUP|tb, 0B1J1K0B2S2W1D1S, Do karantény, [63b5c202970387afc758dabdf11105fb]
PUP.Optional.StartPage, HKU\S-1-5-21-1120215860-3048865371-3881767144-1001\SOFTWARE\START PAGE|Start Page, http://granena.ru/?utm_content=31b5cebd ... d=20161015, Do karantény, [02161da77b1f25118ed13d977c86d030]

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 50
PUP.Optional.Gameo, C:\Users\Acer\AppData\Roaming\GoldenGate, Do karantény, [59bfe8dcbedc84b28868c41b5ba6d22e],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress, Smazat při restartu, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\alerter, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\background, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\common, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\content, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\images, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\ppapi, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\_metadata, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\_metadata\yandex, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke, Do karantény, [07115272633778be2c3f09c916eb629e],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0, Do karantény, [07115272633778be2c3f09c916eb629e],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata, Do karantény, [07115272633778be2c3f09c916eb629e],
PUP.Optional.AliExpress, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AliExpress, Do karantény, [1008aa1a3f5b6dc9b714fa686d960000],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\data_reduction_proxy_leveldb, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Extension Rules, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Local Storage, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Web Applications, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Web Applications\_crx_cmegngdghknoiclpbcjlajfkphoelcia, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\ShaderCache, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\ShaderCache\GPUCache, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.Linkury.ACMB1, C:\Program Files (x86)\Common Files\Nimkix, Do karantény, [8c8c952f9bff3df9a6ffae8fef14c43c],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\common, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\revert, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\settings, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\settings\common, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\settings\partner, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\_metadata, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\common, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\content_script, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\logo, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\newtab, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\revert, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\settings, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\settings\common, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\settings\partner, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\_metadata, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj, Do karantény, [1404a0244b4f53e3404548f5df24c040],

Soubory: 235
PUP.Optional.BundleInstaller, C:\Users\Acer\AppData\Local\Temp\ICReinstall_prius-online_3903488344.exe, Do karantény, [fd1b8143e5b5cb6bc98b815443c060a0],
PUP.Optional.BundleInstaller, C:\Users\Acer\Downloads\prius-online_3903488344.exe, Do karantény, [96822f95435763d358fceaebb54e4bb5],
PUP.Optional.OpenCandy, C:\Users\Acer\Downloads\Cheat Engine 6.5.1 [1].exe, Do karantény, [5cbca024495156e0b7b8f611a45da15f],
PUP.Optional.InstallCore, C:\Users\Acer\Downloads\Cheat Engine 6.5.1.exe, Do karantény, [9e7adaeaf3a758def91b53e5689b0cf4],
PUP.Optional.Gameo, C:\Users\Acer\AppData\Roaming\GoldenGate\3dcdd8bc386c12f910cbb51bb9c9a531.logic.db, Do karantény, [59bfe8dcbedc84b28868c41b5ba6d22e],
PUP.Optional.StartPage, C:\Windows\System32\Tasks\WarThunder1, Do karantény, [8f890bb90a904ee8999b964d19e88080],
PUP.Optional.StartPage, C:\Windows\System32\Tasks\WarThunder2, Do karantény, [6aae269eadeda492db5923c033cea65a],
PUP.Optional.StartPage, C:\Windows\System32\Tasks\WarThunder3, Do karantény, [2aee695b8416cb6be94b647f10f124dc],
PUP.Optional.Elex, C:\Program Files (x86)\SSFK.exe, Do karantény, [44d4a22206943df976d8a127b949857b],
PUP.Optional.Linkury, C:\Users\Acer\AppData\Roaming\ApplicationHosting.dat, Do karantény, [0315aa1a336705311b1c7f5115ed6898],
PUP.Optional.Linkury, C:\Users\Acer\AppData\Roaming\md.xml, Do karantény, [f523576decae0d2959df319f847e758b],
PUP.Optional.Linkury, C:\Users\Acer\AppData\Roaming\noah.dat, Do karantény, [34e4ad178911a294b485efe18d75f50b],
PUP.Optional.Linkury, C:\Users\Acer\AppData\Roaming\uninstall_temp.ico, Do karantény, [cf49ccf896047bbb24166a6611f1f808],
PUP.Optional.Linkury, C:\Users\Acer\AppData\Roaming\lobby.dat, Do karantény, [a57300c40991979fc9f377590bf75da3],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.mysearch.com_0.localstorage, Do karantény, [70a87d47c6d474c217f1666c8979b44c],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.mysearch.com_0.localstorage-journal, Do karantény, [3ade3b89603ac07631d7765c768ce41c],
PUP.Optional.Linkury.Gen, C:\Users\Acer\AppData\Roaming\Doubledax.tst, Do karantény, [011754706139bc7a5c4c667452b07888],
PUP.Optional.Linkury.Gen, C:\Users\Acer\AppData\Roaming\U--Fresh.tst, Do karantény, [a6721ca8792191a5cade2fab9b673cc4],
PUP.Optional.StartPage, C:\Windows\System32\Tasks\InternetSD, Do karantény, [54c49034a5f5e254d24f5360ea1901ff],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\unins000.exe, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\AliExpress.exe, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\AliExpresswinIcon.ico, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\AliExpress_helper.exe, Smazat při restartu, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\ffmpeg.dll, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\helper.dat, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\icudtl.dat, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\natives_blob.bin, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\node.dll, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\nw.dll, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\nw_elf.dll, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\resources.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\unins000.dat, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\hi.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\am.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\ar.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\bg.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\bn.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\ca.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\cs.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\da.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\de.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\el.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\en-GB.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\en-US.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\es-419.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\es.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\et.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\fa.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\fi.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\fil.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\fr.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\gu.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\he.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\hr.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\hu.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\id.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\it.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\ja.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\kn.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\ko.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\lt.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\lv.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\ml.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\mr.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\ms.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\nb.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\nl.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\pl.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\pt-BR.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\pt-PT.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\ro.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\ru.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\sk.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\sl.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\sr.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\sv.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\sw.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\ta.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\te.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\th.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\tr.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\uk.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\vi.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\zh-CN.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\Program Files (x86)\AliExpress\locales\zh-TW.pak, Do karantény, [4eca566e1f7b6bcb33e304d11ce744bc],
PUP.Optional.AliExpress, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AliExpress.lnk, Do karantény, [60b8972d5842999d918c993c9d6620e0],
PUP.Optional.AliExpress, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\AliExpress.lnk, Do karantény, [c1575173a4f6a096948cd8fd27dc6997],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\manifest.json, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\alerter\block.html, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\alerter\block.js, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\background\background.js, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\background\blacklist.js, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\background\index.html, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\background\plugin.js, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\background\whitelist.js, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\common\common.js, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\content\content.js, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\images\icon_128.png, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\images\icon_48.png, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi\npsafe_surfing.dll, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\ppapi\safe_surfing.nmf, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\ppapi\safe_surfing_arm.nexe, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\ppapi\safe_surfing_x86_32.nexe, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\ppapi\safe_surfing_x86_64.nexe, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\_metadata\computed_hashes.json, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\_metadata\verified_contents.json, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\_metadata\yandex\computed_hashes.json, Do karantény, [b95fa61ebcde8fa778f11fb3936ec937],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata\computed_hashes.json, Do karantény, [07115272633778be2c3f09c916eb629e],
PUP.Optional.TheSafeSurfing, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcknbenjnkkjknphmnidanjifbgphjke\4.18_0\_metadata\verified_contents.json, Do karantény, [07115272633778be2c3f09c916eb629e],
PUP.Optional.AliExpress, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AliExpress\AliExpress.lnk, Do karantény, [1008aa1a3f5b6dc9b714fa686d960000],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\First Run, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Local State, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\ChromeDWriteFontCache, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cookies, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cookies-journal, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Favicons, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Favicons-journal, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\History, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\History-journal, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Login Data, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Login Data-journal, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Network Persistent State, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Preferences, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\README, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Secure Preferences, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Top Sites, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Top Sites-journal, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\TransportSecurity, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Visited Links, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Web Data, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Web Data-journal, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000010, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\data_0, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\data_1, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\data_2, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\data_3, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000001, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000002, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000003, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000004, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000005, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000006, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000007, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000008, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000009, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_00000a, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_00000b, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_00000c, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_00000d, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_00000e, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_00000f, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000011, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000012, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000013, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000014, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000015, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000016, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000017, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000018, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000019, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_00001a, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_00001b, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_00001c, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_00001d, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_00001e, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_00001f, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000020, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000021, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000022, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\f_000023, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Cache\index, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\data_reduction_proxy_leveldb\000003.log, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\data_reduction_proxy_leveldb\CURRENT, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\data_reduction_proxy_leveldb\LOCK, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\data_reduction_proxy_leveldb\LOG, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000001, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Extension Rules\000003.log, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Extension Rules\CURRENT, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Extension Rules\LOCK, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Extension Rules\LOG, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Extension Rules\MANIFEST-000001, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Web Applications\_crx_cmegngdghknoiclpbcjlajfkphoelcia\AliExpress.ico, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\Default\Web Applications\_crx_cmegngdghknoiclpbcjlajfkphoelcia\AliExpress.ico.md5, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\ShaderCache\GPUCache\data_0, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\ShaderCache\GPUCache\data_1, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\ShaderCache\GPUCache\data_2, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\ShaderCache\GPUCache\data_3, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.AliExpress, C:\Users\Acer\AppData\Local\AliExpress\User Data\ShaderCache\GPUCache\index, Do karantény, [33e50db716849a9c7f95cc0934cf2ad6],
PUP.Optional.Linkury.ACMB1, C:\Program Files (x86)\Common Files\Nimkix\InstallationConfiguration.xml, Do karantény, [8c8c952f9bff3df9a6ffae8fef14c43c],
PUP.Optional.Linkury.ACMB1, C:\Program Files (x86)\Common Files\Nimkix\uninstall.dat, Do karantény, [8c8c952f9bff3df9a6ffae8fef14c43c],
PUP.Optional.Linkury.ACMB1, C:\Program Files (x86)\Common Files\Nimkix\uninstall.ico, Do karantény, [8c8c952f9bff3df9a6ffae8fef14c43c],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\manifest.json, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\common\browseraction.js, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\common\config.js, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\common\feed.js, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\common\utils.js, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\common\winner.js, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\logo_128x.png, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\logo_16x.png, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\logo_19x.png, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\logo_24x.png, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\logo_32x.png, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\logo_48x.png, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\newtablogo.png, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\toolbar-icon-ask.ico, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\logo\toolbar-icons.png, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\revert\index.css, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\revert\index.html, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\revert\index.js, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\settings\common\redirect.js, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\settings\partner\Reporting.js, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\_metadata\computed_hashes.json, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\akmiedbgcldondenkldoenhjiaabhfpp\28.4_0\_metadata\verified_contents.json, Do karantény, [7e9a5f65f4a60e28b6cffb42e122fe02],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\manifest.json, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\common\browseraction.js, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\common\config.js, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\common\feed.js, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\common\utils.js, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\common\winner.js, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\content_script\overlayer.js, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\logo\logo_128x.png, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\logo\logo_16x.png, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\logo\logo_19x.png, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\logo\logo_48x.png, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\newtab\newtab.html, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\revert\index.css, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\revert\index.html, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\revert\index.js, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\settings\common\redirect.js, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\settings\partner\Reporting.js, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\_metadata\computed_hashes.json, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.MySearch, C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekiiabdngfpbnkglbhbonpkcllccoopj\28.8_0\_metadata\verified_contents.json, Do karantény, [1404a0244b4f53e3404548f5df24c040],
PUP.Optional.TerraClicks.ShrtCln, C:\Users\Acer\AppData\Local\Microsoft\Windows\INetCookies\Low\TCFTQLPU.txt, Do karantény, [9484f8cc1f7bd95d49317ebf26dd9b65],
PUP.Optional.Linkury.ACMB1, C:\Users\Acer\AppData\Roaming\Config.xml, Do karantény, [ca4ec103f9a1a195702d7bc211f2b24e],
PUP.Optional.Linkury.ACMB1, C:\Users\Acer\AppData\Roaming\InstallationConfiguration.xml, Do karantény, [9e7aedd7801aa492bee09ca1f40ff010],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 25 lis 2016 10:09

Ještě sophos a RK.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 47 hostů