Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 21:05:56, on 30. 5. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17037)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Users\Andrejko\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
C:\Users\Andrejko\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe
C:\Users\Andrejko\AppData\Local\Microsoft\Windows\INetCache\IE\YHBH4C9H\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: CrossriderApp0035510 - {11111111-1111-1111-1111-110311551110} - C:\Program Files (x86)\iWebar\iWebar-bho.dll
O2 - BHO: CrossriderApp0048292 - {11111111-1111-1111-1111-110411821192} - C:\Program Files (x86)\Sense\Sense-bho.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: ShopperProBHO - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll
O2 - BHO: HulaToo - {ab65caf0-fc3b-40f8-8b88-6d096a48f659} - C:\Program Files (x86)\HulaToo\HulaToobho.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Andrejko\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Andrejko\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe
O4 - HKCU\..\Run: [GoobzoYouTubeAccelerator] "C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe" /startup
O4 - HKCU\..\Run: [FLV Player] C:\Users\Andrejko\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [MKLOL] "C:\Program Files (x86)\MKJogo\MKLOL\MK.exe" -auto
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
O8 - Extra context menu item: Odeslat do Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O9 - Extra 'Tools' menuitem: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Protect Monitor (ProtectMonitor) - Unknown owner - C:\Program Files\PCDApp\StartHelp.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: SafetyNut Manager2 (SafetyNutManager2) - SafetyNut Inc - C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\SafetyNutManager.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Update HulaToo - Unknown owner - C:\Program Files (x86)\HulaToo\updateHulaToo.exe
O23 - Service: Util HulaToo - Unknown owner - C:\Program Files (x86)\HulaToo\bin\utilHulaToo.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: YouTubeAcceleratorService - GOOBZO - C:\Program Files (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
--
End of file - 14452 bytes
Prosím o kontrolu logu... Vyřešeno
- Orcus
- člen Security týmu
-
Elite Level 10.5
- Příspěvky: 10645
- Registrován: duben 10
- Bydliště: Okolo rostou 3 růže =o)
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu...
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.
===================================================
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
===================================================
Stáhni AdwCleaner (by Xplode)
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
===================================================
Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.
===================================================
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
===================================================
Stáhni AdwCleaner (by Xplode)
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
===================================================
Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.
Láska hřeje, ale uhlí je uhlí.
Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.

Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.
Re: Prosím o kontrolu logu...
# AdwCleaner v3.211 - Report created 31/05/2014 at 00:08:11
# Updated 26/05/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Andrejko - ANDREJ
# Running from : C:\Users\Andrejko\Downloads\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
Service Found : F06DEFF2-5B9C-490D-910F-35D3A91196222
Service Found : Update HulaToo
Service Found : Util HulaToo
***** [ Files / Folders ] *****
File Found : C:\Windows\System32\Tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-1
File Found : C:\Windows\System32\Tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-3
File Found : C:\Windows\System32\Tasks\ShopperProJSUpd
File Found : C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart
File Found : C:\Windows\System32\Tasks\SPDriver
File Found : C:\Windows\Tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-1.job
File Found : C:\Windows\Tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-3.job
Folder Found : C:\Program Files (x86)\HulaToo
Folder Found : C:\Program Files (x86)\iWebar
Folder Found : C:\Program Files (x86)\Sense
Folder Found : C:\Program Files (x86)\ShopperPro
Folder Found : C:\Program Files (x86)\YouTube Accelerator
Folder Found : C:\ProgramData\Goobzo
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
Folder Found : C:\ProgramData\SafetyNut
Folder Found : C:\ProgramData\ShopperPro
Folder Found : C:\Users\Andrejko\AppData\Local\FilesFrog Update Checker
Folder Found : C:\Users\Andrejko\AppData\Local\webplayer
Folder Found : C:\Users\Andrejko\AppData\LocalLow\DataMngr
Folder Found : C:\Users\Andrejko\AppData\LocalLow\Goobzo
Folder Found : C:\Users\Andrejko\AppData\LocalLow\iWebar
Folder Found : C:\Users\Andrejko\AppData\LocalLow\Sense
Folder Found : C:\Users\Andrejko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
Folder Found : C:\Users\Public\Documents\Goobzo
Folder Found : C:\Users\Public\Documents\ShopperPro
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\AppDataLow\Software
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\Goobzo
Key Found : HKCU\Software\HulaToo
Key Found : HKCU\Software\installedbrowserextensions
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311551110}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311551110}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411821192}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411821192}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\FLV Player
Key Found : HKCU\Software\SafetyNut
Key Found : HKCU\Software\Somoto
Key Found : HKCU\Software\Webplayer
Key Found : [x64] HKCU\Software\Goobzo
Key Found : [x64] HKCU\Software\HulaToo
Key Found : [x64] HKCU\Software\installedbrowserextensions
Key Found : [x64] HKCU\Software\SafetyNut
Key Found : [x64] HKCU\Software\Somoto
Key Found : [x64] HKCU\Software\Webplayer
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110311551110}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110311551110}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411821192}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411821192}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220322552210}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422822292}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0035510.BHO
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0035510.BHO.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0035510.Sandbox
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0035510.Sandbox.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0048292.BHO
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0048292.BHO.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0048292.Sandbox
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0048292.Sandbox.1
Key Found : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{32C53681-8E69-4659-8320-7422685BD486}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355555510}
Key Found : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455825592}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366556610}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466826692}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
Key Found : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO
Key Found : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440344554410}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440444824492}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{596EAA89-F3D2-4174-9BD9-F7D79C744CDA}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EAB5257A-1FB3-474C-9B42-231F52622E72}
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Found : HKLM\Software\Goobzo
Key Found : HKLM\Software\HulaToo
Key Found : HKLM\Software\installedbrowserextensions
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker
Key Found : HKLM\Software\SafetyNut
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110311551110}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110311551110}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411821192}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411821192}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220322552210}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422822292}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{32C53681-8E69-4659-8320-7422685BD486}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355555510}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455825592}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366556610}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466826692}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : [x64] HKLM\SOFTWARE\installedbrowserextensions
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311551110}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311551110}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411821192}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411821192}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HulaToo
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FLV Player]
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17037
-\\ Google Chrome v35.0.1916.114
[ File : C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [12994 octets] - [31/05/2014 00:08:11]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [13055 octets] ##########
# Updated 26/05/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Andrejko - ANDREJ
# Running from : C:\Users\Andrejko\Downloads\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
Service Found : F06DEFF2-5B9C-490D-910F-35D3A91196222
Service Found : Update HulaToo
Service Found : Util HulaToo
***** [ Files / Folders ] *****
File Found : C:\Windows\System32\Tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-1
File Found : C:\Windows\System32\Tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-3
File Found : C:\Windows\System32\Tasks\ShopperProJSUpd
File Found : C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart
File Found : C:\Windows\System32\Tasks\SPDriver
File Found : C:\Windows\Tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-1.job
File Found : C:\Windows\Tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-3.job
Folder Found : C:\Program Files (x86)\HulaToo
Folder Found : C:\Program Files (x86)\iWebar
Folder Found : C:\Program Files (x86)\Sense
Folder Found : C:\Program Files (x86)\ShopperPro
Folder Found : C:\Program Files (x86)\YouTube Accelerator
Folder Found : C:\ProgramData\Goobzo
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
Folder Found : C:\ProgramData\SafetyNut
Folder Found : C:\ProgramData\ShopperPro
Folder Found : C:\Users\Andrejko\AppData\Local\FilesFrog Update Checker
Folder Found : C:\Users\Andrejko\AppData\Local\webplayer
Folder Found : C:\Users\Andrejko\AppData\LocalLow\DataMngr
Folder Found : C:\Users\Andrejko\AppData\LocalLow\Goobzo
Folder Found : C:\Users\Andrejko\AppData\LocalLow\iWebar
Folder Found : C:\Users\Andrejko\AppData\LocalLow\Sense
Folder Found : C:\Users\Andrejko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
Folder Found : C:\Users\Public\Documents\Goobzo
Folder Found : C:\Users\Public\Documents\ShopperPro
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\AppDataLow\Software
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\Goobzo
Key Found : HKCU\Software\HulaToo
Key Found : HKCU\Software\installedbrowserextensions
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311551110}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311551110}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411821192}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411821192}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\FLV Player
Key Found : HKCU\Software\SafetyNut
Key Found : HKCU\Software\Somoto
Key Found : HKCU\Software\Webplayer
Key Found : [x64] HKCU\Software\Goobzo
Key Found : [x64] HKCU\Software\HulaToo
Key Found : [x64] HKCU\Software\installedbrowserextensions
Key Found : [x64] HKCU\Software\SafetyNut
Key Found : [x64] HKCU\Software\Somoto
Key Found : [x64] HKCU\Software\Webplayer
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110311551110}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110311551110}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411821192}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411821192}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220322552210}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422822292}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0035510.BHO
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0035510.BHO.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0035510.Sandbox
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0035510.Sandbox.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0048292.BHO
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0048292.BHO.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0048292.Sandbox
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0048292.Sandbox.1
Key Found : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{32C53681-8E69-4659-8320-7422685BD486}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355555510}
Key Found : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455825592}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366556610}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466826692}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
Key Found : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO
Key Found : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440344554410}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440444824492}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{596EAA89-F3D2-4174-9BD9-F7D79C744CDA}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EAB5257A-1FB3-474C-9B42-231F52622E72}
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Found : HKLM\Software\Goobzo
Key Found : HKLM\Software\HulaToo
Key Found : HKLM\Software\installedbrowserextensions
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker
Key Found : HKLM\Software\SafetyNut
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110311551110}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110311551110}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411821192}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411821192}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220322552210}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422822292}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{32C53681-8E69-4659-8320-7422685BD486}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355555510}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455825592}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366556610}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466826692}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : [x64] HKLM\SOFTWARE\installedbrowserextensions
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311551110}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311551110}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411821192}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411821192}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HulaToo
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FLV Player]
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17037
-\\ Google Chrome v35.0.1916.114
[ File : C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [12994 octets] - [31/05/2014 00:08:11]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [13055 octets] ##########
Re: Prosím o kontrolu logu...
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 31. 5. 2014
Scan Time: 0:16:15
Logfile: ssa.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.03.04.09
Rootkit Database: v2014.02.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Andrejko
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 302195
Time Elapsed: 15 min, 6 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe, 4616, , [0148748ba3d786b04d16724e1de6e51b]
Modules: 0
(No malicious items detected)
Registry Keys: 90
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110311551110}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440344554410}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355555510}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660366556610}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355555510}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660366556610}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440344554410}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035510.BHO.1, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110311551110}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035510.BHO, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035510.BHO, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035510.BHO.1, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110311551110}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110311551110}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220322552210}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035510.Sandbox.1, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035510.Sandbox, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035510.Sandbox, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035510.Sandbox.1, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220322552210}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110311551110}\INPROCSERVER32, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110411821192}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440444824492}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550455825592}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660466826692}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550455825592}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660466826692}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440444824492}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0048292.BHO.1, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110411821192}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0048292.BHO, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0048292.BHO, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0048292.BHO.1, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110411821192}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110411821192}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220422822292}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0048292.Sandbox.1, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0048292.Sandbox, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0048292.Sandbox, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0048292.Sandbox.1, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220422822292}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110411821192}\INPROCSERVER32, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, , [d376629d05750d2942e172027e847c84],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, , [d376629d05750d2942e172027e847c84],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\SearchQUIEHelper.DNSGuard, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\SearchQUIEHelper.DNSGuard.1, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SearchQUIEHelper.DNSGuard, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SearchQUIEHelper.DNSGuard.1, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\CLASSES\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{8FB1A663-2820-468B-95C4-5060A4C5F413}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{8FB1A663-2820-468B-95C4-5060A4C5F413}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\CLASSES\ShopperPro.ShopperProBHO.1, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\CLASSES\ShopperPro.ShopperProBHO, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperPro.ShopperProBHO, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperPro.ShopperProBHO.1, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.Somoto, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\FilesFrog Update Checker, , [fe4b17e8b9c1b6807e590f65fe029769],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Sense, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\iWebar, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ShopperPro, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPDRIVER_1.36.1.172, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\iWebar, , [3d0cc13e1664c96dd2e98b2728dbf50b],
PUP.Optional.YouTubeAccelerator.A, HKLM\SOFTWARE\WOW6432NODE\GOOBZO\YouTube Accelerator, , [a3a68b746b0f06300b518040b84bd030],
PUP.Software.Updater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}, , [c98041be6614a98d74a25c4026dc837d],
PUP.Optional.SafetyNut.A, HKLM\SOFTWARE\WOW6432NODE\SAFETYNUT, , [5eeb4db2afcb072f28369d13649f629e],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\SENSE\IE, , [2029a857b3c7e2544faa276908fa40c0],
PUP.Optional.YouTubeAccelerator.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\YouTubeAcceleratorService, , [0f3ac03f3c3eaa8ca1b7358bec1711ef],
PUP.Optional.iWebar.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\iWebar, , [b19831ce2c4e84b2cfd8d1be936f3dc3],
PUP.Optional.YouTubeAccelerator.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOBZO\YouTube Accelerator, , [62e755aa9bdf4fe7d786328e56ad3bc5],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [3a0fd12e532773c39adc2e9138cbee12],
PUP.Optional.iWebar.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\iWebar, , [d5748976dd9d37fff8af2f607092956b],
PUP.Optional.YouTubeAccelerator.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOBZO\YouTube Accelerator, , [9faa46b95228ec4a0855eed2d330738d],
PUP.Optional.YouTubeAccelerator.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOBZO\LANGUAGE\YouTubeAccelerator, , [ce7bce313149b18576e86c54bf4440c0],
PUP.Optional.iWebar.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\iWebar, , [6cdddd2284f69a9c85a8cdc480827e82],
PUP.Optional.Somoto.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOMOTO\SDP, , [4dfc9669d0aa8babb5d2dad53cc7ef11],
PUP.Optional.YouTubeAccelerator.A, HKU\S-1-5-21-817296699-4016285348-1085084602-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOBZO\YouTube Accelerator, , [90b9ce31ed8d2d098ecff6ca0003d729],
PUP.Optional.YouTubeAccelerator.A, HKU\S-1-5-21-817296699-4016285348-1085084602-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOBZO\LANGUAGE\YouTubeAccelerator, , [3316a6591e5cf6401648fec27f8435cb],
Registry Values: 5
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SPDriver, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe, , [2227b946552546f0055a9b256e95a65a]
PUP.Optional.ShopperPro.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SPDriver, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe, , [2227b946552546f0055a9b256e95a65a]
PUP.Optional.SafetyNut.A, HKLM\SOFTWARE\WOW6432NODE\SAFETYNUT|browser, cr, , [5eeb4db2afcb072f28369d13649f629e]
PUP.Optional.ShopperPro.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|GoobzoYouTubeAccelerator, "C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe" /startup, , [0148748ba3d786b04d16724e1de6e51b]
PUP.Optional.Somoto.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOMOTO\SDP|affid, network_smb_linkbucks2, , [4dfc9669d0aa8babb5d2dad53cc7ef11]
Registry Data: 0
(No malicious items detected)
Folders: 23
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.SafetyNut.A, C:\ProgramData\SafetyNut, , [0643f50af981db5b332a69479f64b44c],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox\content, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\ProgramData\ShopperPro, , [3514ea15106a340272f0efd1f211cb35],
PUP.Optional.FilesFrog.A, C:\Users\Andrejko\AppData\Local\FilesFrog Update Checker, , [4efbd827453576c09f4330560ef45ea2],
PUP.Optional.FilesFrog.A, C:\Users\Andrejko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker, , [1633c7388cee4cea697ad6b00bf7dd23],
PUP.Optional.YouTubeAccelerator.A, C:\ProgramData\GOOBZO\YouTube Accelerator, , [2f1aaa55d7a340f6496a04847d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\userCode, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\icons, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\icons\actions, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\popupResource, , [8dbcae514436ee48f0874a4189793dc3],
Files: 139
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-bho64.dll, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense-bho64.dll, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Datamngr.A, C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\safetynut_ie.dll, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\safetynut_ie.dll, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Somoto, C:\Users\Andrejko\AppData\Local\FilesFrog Update Checker\uninstall.exe, , [fe4b17e8b9c1b6807e590f65fe029769],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\background.html, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\360-48292.crx, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\48292.crx, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\48292.xpi, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense-bg.exe, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense-buttonutil.dll, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense-buttonutil.exe, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense-buttonutil64.dll, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense-buttonutil64.exe, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense.ico, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Uninstall.exe, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\utils.exe, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.SafetyNut.A, C:\ProgramData\SafetyNut\coordinator.cfg, , [0643f50af981db5b332a69479f64b44c],
PUP.Optional.SafetyNut.A, C:\ProgramData\SafetyNut\general.cfg, , [0643f50af981db5b332a69479f64b44c],
PUP.Optional.SafetyNut.A, C:\ProgramData\SafetyNut\S-1-5-21-817296699-4016285348-1085084602-1002.cfg, , [0643f50af981db5b332a69479f64b44c],
PUP.Optional.SafetyNut.A, C:\ProgramData\SafetyNut\S-1-5-32.cfg, , [0643f50af981db5b332a69479f64b44c],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\background.html, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\35510.crx, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\35510.xpi, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\360-35510.crx, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\55bb3565-b1d7-4a6f-9574-e5b0df03743f-3.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-bg.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil.dll, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil64.dll, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil64.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar.ico, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\Uninstall.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\utils.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\manifest.json, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\config.json, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\database1_0_0.json, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\ShopperPro.crx, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\ShopperPro.dll, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\ShopperPro.zip, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\ShopperPro64.dll, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\SPRemove.exe, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\Updater.exe, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox\chrome.manifest, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox\install.rdf, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox\content\overlay.js, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox\content\overlay.xul, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox\content\shopperpro_128.png, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\jsdrv.exe, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\jsdrv.sys, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\config.json, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\database1_0_0.json, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.sys, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\ProgramData\ShopperPro\config.json, , [3514ea15106a340272f0efd1f211cb35],
PUP.Optional.ShopperPro.A, C:\ProgramData\ShopperPro\database1_0_0.json, , [3514ea15106a340272f0efd1f211cb35],
PUP.Optional.YouTubeAccelerator.A, C:\Program Files (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe, , [0f3ac03f3c3eaa8ca1b7358bec1711ef],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe, , [0148748ba3d786b04d16724e1de6e51b],
PUP.Optional.FilesFrog.A, C:\Users\Andrejko\AppData\Local\FilesFrog Update Checker\update_checker.exe, , [4efbd827453576c09f4330560ef45ea2],
PUP.Optional.FilesFrog.A, C:\Users\Andrejko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker\Check for Updates.lnk, , [1633c7388cee4cea697ad6b00bf7dd23],
PUP.Optional.FilesFrog.A, C:\Users\Andrejko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker\Uninstall.lnk, , [1633c7388cee4cea697ad6b00bf7dd23],
PUP.Optional.YouTubeAccelerator.A, C:\ProgramData\GOOBZO\YouTube Accelerator\config.xml, , [2f1aaa55d7a340f6496a04847d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\background.html, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\chromeCoreFilesIndex.txt, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\crossriderManifest.json, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\manifest.json, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\popup.html, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\manifest.xml, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins.json, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\1.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\102.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\104.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\13.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\14.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\155.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\17.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\177.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\182.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\183.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\184.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\19.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\195.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\207.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\21.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\217.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\22.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\220.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\223.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\226.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\244.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\246.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\256.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\28.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\4.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\47.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\64.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\7.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\72.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\78.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\80.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\9.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\91.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\93.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\97.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\userCode\background.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\userCode\extension.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\icons\icon128.png, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\icons\icon16.png, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\icons\icon48.png, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\icons\actions\1.png, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\background.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\main.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\platformVersion.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api\chrome.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api\cookie.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api\message.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api\monitor.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api\pageAction.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api\pageActionBG.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\app_api.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\bg_app_api.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\consts.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\cookie_store.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\crossriderAPI.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\delegate.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\events.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\extensionDataStore.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\installer.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\logFile.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\logging.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\onBGDocumentLoad.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\reports.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\storageWrapper.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\updateManager.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\util.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\xhr.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\popupResource\newPopup.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\popupResource\popup.js, , [8dbcae514436ee48f0874a4189793dc3],
Physical Sectors: 0
(No malicious items detected)
(end)
www.malwarebytes.org
Scan Date: 31. 5. 2014
Scan Time: 0:16:15
Logfile: ssa.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.03.04.09
Rootkit Database: v2014.02.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Andrejko
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 302195
Time Elapsed: 15 min, 6 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe, 4616, , [0148748ba3d786b04d16724e1de6e51b]
Modules: 0
(No malicious items detected)
Registry Keys: 90
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110311551110}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440344554410}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355555510}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660366556610}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355555510}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660366556610}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440344554410}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035510.BHO.1, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110311551110}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035510.BHO, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035510.BHO, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035510.BHO.1, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110311551110}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110311551110}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220322552210}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035510.Sandbox.1, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035510.Sandbox, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035510.Sandbox, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035510.Sandbox.1, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220322552210}, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110311551110}\INPROCSERVER32, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110411821192}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440444824492}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550455825592}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660466826692}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550455825592}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660466826692}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440444824492}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0048292.BHO.1, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110411821192}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0048292.BHO, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0048292.BHO, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0048292.BHO.1, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110411821192}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110411821192}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220422822292}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0048292.Sandbox.1, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0048292.Sandbox, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0048292.Sandbox, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0048292.Sandbox.1, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220422822292}, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Sense.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110411821192}\INPROCSERVER32, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, , [d376629d05750d2942e172027e847c84],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, , [d376629d05750d2942e172027e847c84],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\SearchQUIEHelper.DNSGuard, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\SearchQUIEHelper.DNSGuard.1, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SearchQUIEHelper.DNSGuard, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SearchQUIEHelper.DNSGuard.1, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\CLASSES\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{8FB1A663-2820-468B-95C4-5060A4C5F413}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{8FB1A663-2820-468B-95C4-5060A4C5F413}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\CLASSES\ShopperPro.ShopperProBHO.1, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\CLASSES\ShopperPro.ShopperProBHO, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperPro.ShopperProBHO, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperPro.ShopperProBHO.1, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}, , [86c3fd023f3bb87e6748ef8713ef9e62],
PUP.Optional.Somoto, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\FilesFrog Update Checker, , [fe4b17e8b9c1b6807e590f65fe029769],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Sense, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\iWebar, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ShopperPro, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPDRIVER_1.36.1.172, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\iWebar, , [3d0cc13e1664c96dd2e98b2728dbf50b],
PUP.Optional.YouTubeAccelerator.A, HKLM\SOFTWARE\WOW6432NODE\GOOBZO\YouTube Accelerator, , [a3a68b746b0f06300b518040b84bd030],
PUP.Software.Updater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}, , [c98041be6614a98d74a25c4026dc837d],
PUP.Optional.SafetyNut.A, HKLM\SOFTWARE\WOW6432NODE\SAFETYNUT, , [5eeb4db2afcb072f28369d13649f629e],
PUP.Optional.Sense.A, HKLM\SOFTWARE\WOW6432NODE\SENSE\IE, , [2029a857b3c7e2544faa276908fa40c0],
PUP.Optional.YouTubeAccelerator.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\YouTubeAcceleratorService, , [0f3ac03f3c3eaa8ca1b7358bec1711ef],
PUP.Optional.iWebar.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\iWebar, , [b19831ce2c4e84b2cfd8d1be936f3dc3],
PUP.Optional.YouTubeAccelerator.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOBZO\YouTube Accelerator, , [62e755aa9bdf4fe7d786328e56ad3bc5],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [3a0fd12e532773c39adc2e9138cbee12],
PUP.Optional.iWebar.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\iWebar, , [d5748976dd9d37fff8af2f607092956b],
PUP.Optional.YouTubeAccelerator.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOBZO\YouTube Accelerator, , [9faa46b95228ec4a0855eed2d330738d],
PUP.Optional.YouTubeAccelerator.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOBZO\LANGUAGE\YouTubeAccelerator, , [ce7bce313149b18576e86c54bf4440c0],
PUP.Optional.iWebar.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\iWebar, , [6cdddd2284f69a9c85a8cdc480827e82],
PUP.Optional.Somoto.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOMOTO\SDP, , [4dfc9669d0aa8babb5d2dad53cc7ef11],
PUP.Optional.YouTubeAccelerator.A, HKU\S-1-5-21-817296699-4016285348-1085084602-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOBZO\YouTube Accelerator, , [90b9ce31ed8d2d098ecff6ca0003d729],
PUP.Optional.YouTubeAccelerator.A, HKU\S-1-5-21-817296699-4016285348-1085084602-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOBZO\LANGUAGE\YouTubeAccelerator, , [3316a6591e5cf6401648fec27f8435cb],
Registry Values: 5
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SPDriver, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe, , [2227b946552546f0055a9b256e95a65a]
PUP.Optional.ShopperPro.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SPDriver, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe, , [2227b946552546f0055a9b256e95a65a]
PUP.Optional.SafetyNut.A, HKLM\SOFTWARE\WOW6432NODE\SAFETYNUT|browser, cr, , [5eeb4db2afcb072f28369d13649f629e]
PUP.Optional.ShopperPro.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|GoobzoYouTubeAccelerator, "C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe" /startup, , [0148748ba3d786b04d16724e1de6e51b]
PUP.Optional.Somoto.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOMOTO\SDP|affid, network_smb_linkbucks2, , [4dfc9669d0aa8babb5d2dad53cc7ef11]
Registry Data: 0
(No malicious items detected)
Folders: 23
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.SafetyNut.A, C:\ProgramData\SafetyNut, , [0643f50af981db5b332a69479f64b44c],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox\content, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\ProgramData\ShopperPro, , [3514ea15106a340272f0efd1f211cb35],
PUP.Optional.FilesFrog.A, C:\Users\Andrejko\AppData\Local\FilesFrog Update Checker, , [4efbd827453576c09f4330560ef45ea2],
PUP.Optional.FilesFrog.A, C:\Users\Andrejko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker, , [1633c7388cee4cea697ad6b00bf7dd23],
PUP.Optional.YouTubeAccelerator.A, C:\ProgramData\GOOBZO\YouTube Accelerator, , [2f1aaa55d7a340f6496a04847d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\userCode, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\icons, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\icons\actions, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\popupResource, , [8dbcae514436ee48f0874a4189793dc3],
Files: 139
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-bho64.dll, , [89c029d6255547ef1015b4b03cc5ee12],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense-bho64.dll, , [9cad718e91e9ca6c4dbcf7960bf6ea16],
PUP.Optional.Datamngr.A, C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\safetynut_ie.dll, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Datamngr.A, C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\safetynut_ie.dll, , [65e4f40be199b680d70ec5afcc369f61],
PUP.Optional.Somoto, C:\Users\Andrejko\AppData\Local\FilesFrog Update Checker\uninstall.exe, , [fe4b17e8b9c1b6807e590f65fe029769],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\background.html, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\360-48292.crx, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\48292.crx, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\48292.xpi, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense-bg.exe, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense-buttonutil.dll, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense-buttonutil.exe, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense-buttonutil64.dll, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense-buttonutil64.exe, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Sense.ico, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\Uninstall.exe, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.Sense.A, C:\Program Files (x86)\Sense\utils.exe, , [57f2bf404733290d64933b55ac56966a],
PUP.Optional.SafetyNut.A, C:\ProgramData\SafetyNut\coordinator.cfg, , [0643f50af981db5b332a69479f64b44c],
PUP.Optional.SafetyNut.A, C:\ProgramData\SafetyNut\general.cfg, , [0643f50af981db5b332a69479f64b44c],
PUP.Optional.SafetyNut.A, C:\ProgramData\SafetyNut\S-1-5-21-817296699-4016285348-1085084602-1002.cfg, , [0643f50af981db5b332a69479f64b44c],
PUP.Optional.SafetyNut.A, C:\ProgramData\SafetyNut\S-1-5-32.cfg, , [0643f50af981db5b332a69479f64b44c],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\background.html, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\35510.crx, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\35510.xpi, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\360-35510.crx, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\55bb3565-b1d7-4a6f-9574-e5b0df03743f-3.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-bg.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil.dll, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil64.dll, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil64.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar.ico, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\Uninstall.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\utils.exe, , [64e5b6492b4f53e35662bdf51ee5d22e],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\manifest.json, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\config.json, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\database1_0_0.json, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\ShopperPro.crx, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\ShopperPro.dll, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\ShopperPro.zip, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\ShopperPro64.dll, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\SPRemove.exe, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\Updater.exe, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox\chrome.manifest, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox\install.rdf, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox\content\overlay.js, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox\content\overlay.xul, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\FireFox\content\shopperpro_128.png, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\jsdrv.exe, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\jsdrv.sys, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\config.json, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\database1_0_0.json, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.sys, , [2227b946552546f0055a9b256e95a65a],
PUP.Optional.ShopperPro.A, C:\ProgramData\ShopperPro\config.json, , [3514ea15106a340272f0efd1f211cb35],
PUP.Optional.ShopperPro.A, C:\ProgramData\ShopperPro\database1_0_0.json, , [3514ea15106a340272f0efd1f211cb35],
PUP.Optional.YouTubeAccelerator.A, C:\Program Files (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe, , [0f3ac03f3c3eaa8ca1b7358bec1711ef],
PUP.Optional.ShopperPro.A, C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe, , [0148748ba3d786b04d16724e1de6e51b],
PUP.Optional.FilesFrog.A, C:\Users\Andrejko\AppData\Local\FilesFrog Update Checker\update_checker.exe, , [4efbd827453576c09f4330560ef45ea2],
PUP.Optional.FilesFrog.A, C:\Users\Andrejko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker\Check for Updates.lnk, , [1633c7388cee4cea697ad6b00bf7dd23],
PUP.Optional.FilesFrog.A, C:\Users\Andrejko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker\Uninstall.lnk, , [1633c7388cee4cea697ad6b00bf7dd23],
PUP.Optional.YouTubeAccelerator.A, C:\ProgramData\GOOBZO\YouTube Accelerator\config.xml, , [2f1aaa55d7a340f6496a04847d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\background.html, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\chromeCoreFilesIndex.txt, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\crossriderManifest.json, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\manifest.json, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\popup.html, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\manifest.xml, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins.json, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\1.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\102.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\104.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\13.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\14.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\155.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\17.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\177.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\182.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\183.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\184.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\19.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\195.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\207.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\21.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\217.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\22.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\220.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\223.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\226.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\244.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\246.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\256.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\28.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\4.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\47.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\64.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\7.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\72.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\78.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\80.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\9.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\91.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\93.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\plugins\97.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\userCode\background.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\extensionData\userCode\extension.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\icons\icon128.png, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\icons\icon16.png, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\icons\icon48.png, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\icons\actions\1.png, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\background.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\main.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\platformVersion.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api\chrome.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api\cookie.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api\message.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api\monitor.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api\pageAction.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\api\pageActionBG.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\app_api.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\bg_app_api.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\consts.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\cookie_store.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\crossriderAPI.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\delegate.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\events.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\extensionDataStore.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\installer.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\logFile.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\logging.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\onBGDocumentLoad.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\reports.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\storageWrapper.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\updateManager.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\util.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\xhr.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\popupResource\newPopup.js, , [8dbcae514436ee48f0874a4189793dc3],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.261_0\js\lib\popupResource\popup.js, , [8dbcae514436ee48f0874a4189793dc3],
Physical Sectors: 0
(No malicious items detected)
(end)
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu...
- Znovu spusť MbAM a dej Skenovat nyní
- Po proběhnutí programu se ti objeví hláška, tak klikni na „Vše do karantény“ -> „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a ulož na Plochu.
- Zkopíruj sem celý obsah toho logu.
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
- Po proběhnutí programu se ti objeví hláška, tak klikni na „Vše do karantény“ -> „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a ulož na Plochu.
- Zkopíruj sem celý obsah toho logu.
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu...
Problém jsem už vyřešil mám sem ještě dát ty logy ? :)
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu...
Jo , dej je sem..
+
Odinstaluj:
youtube accelerator
+
Odinstaluj:
youtube accelerator
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu...
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 1. 6. 2014
Scan Time: 11:18:17
Logfile: Log.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.06.01.04
Rootkit Database: v2014.05.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Andrejko
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 342814
Time Elapsed: 12 min, 59 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 26
PUP.Optional.HulaToo.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update HulaToo, , [ff49f380e09bec4af7608ee3fe0333cd],
PUP.Optional.HulaToo.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util HulaToo, , [17314d26215a48eef76028497988d52b],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{ab65caf0-fc3b-40f8-8b88-6d096a48f659}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{596eaa89-f3d2-4174-9bd9-f7d79c744cda}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{32C53681-8E69-4659-8320-7422685BD486}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{32C53681-8E69-4659-8320-7422685BD486}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{596eaa89-f3d2-4174-9bd9-f7d79c744cda}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HulaToo, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\20891, , [be8a136015661c1ae3bda5fb24de11ef],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21836, , [2a1e77fcfa8180b6e0c0e4bcb74b639d],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\HulaToo, , [f157a4cf275481b50ec08b11e71b14ec],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\20891, , [5cec8ae9cab13cfa0b95a1ff1fe3aa56],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\21836, , [d87042311f5cd95defb1a0007d851ee2],
PUP.Optional.ObjectBrowser.A, HKLM\SOFTWARE\WOW6432NODE\SENSE\INSTALLER, , [a4a4294a5f1cd6607c15fca52fd36f91],
PUP.Optional.HulaToo.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\HulaToo, , [9fa9561d275496a08d40019b58aa2ad6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21836, , [71d7254ec7b4162001a06e32db2750b0],
Registry Values: 1
PUP.Optional.ObjectBrowser.A, HKLM\SOFTWARE\WOW6432NODE\SENSE\INSTALLER|BundledIe, 1, , [a4a4294a5f1cd6607c15fca52fd36f91]
Registry Data: 0
(No malicious items detected)
Folders: 6
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\TEMP, , [5debadc6552626107a526c307e84d729],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0, , [e16774ff3f3cb87e88024241a062f709],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam, , [e662ff7483f86fc76b2384ff7a88e11f],
Files: 37
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\updateHulaToo.exe, , [ff49f380e09bec4af7608ee3fe0333cd],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\utilHulaToo.exe, , [17314d26215a48eef76028497988d52b],
PUP.Optional.ScramblePacker.A, C:\Users\Andrejko\AppData\Local\Installer\Install_25731\sense.exe, , [c088afc4e497f83e59a50478ea17c13f],
PUP.Optional.Superfish.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, , [410713607b0069cd4f00a6ee5ba78b75],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0.localstorage, , [c48481f26714d85ed696bfdd1fe3c43c],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\HulaToo.ico, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\7za.exe, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\HulaTooBHO.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\HulaTooUninstall.exe, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\updateHulaToo.InstallState, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\7za.exe, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\BrowserAdapterS.7z, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\HulaToo.BrowserAdapter.exe, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\HulaToo.PurBrowse64.exe, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\HulaToo.PurBrowseG.zip, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\HulaTooBAApp.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\utilHulaToo.InstallState, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins\HulaToo.Bromon.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins\HulaToo.BrowserAdapterS.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins\HulaToo.CompatibilityChecker.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins\HulaToo.FFUpdate.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins\HulaToo.IEUpdate.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins\HulaToo.PurBrowseG.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-1.job, , [d96f551ec2b9ef47e63b801f09f9e917],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-3.job, , [67e181f20a71f73f39e8544b43bfee12],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0\1, , [e16774ff3f3cb87e88024241a062f709],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\000083.ldb, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\000085.ldb, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\000101.ldb, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\000104.log, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\CURRENT, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\LOCK, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\LOG, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\LOG.old, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\MANIFEST-000103, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.ASK.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "search_url": "http://dts.search.ask.com/sr?src=crb&gct=ds&appid=128&systemid=488&v=a12627-348&apn_uid=3052830855634133&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}",), ,[3117413254279b9bb5045c309d67bf41]
Physical Sectors: 0
(No malicious items detected)
(end)
www.malwarebytes.org
Scan Date: 1. 6. 2014
Scan Time: 11:18:17
Logfile: Log.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.06.01.04
Rootkit Database: v2014.05.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Andrejko
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 342814
Time Elapsed: 12 min, 59 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 26
PUP.Optional.HulaToo.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update HulaToo, , [ff49f380e09bec4af7608ee3fe0333cd],
PUP.Optional.HulaToo.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util HulaToo, , [17314d26215a48eef76028497988d52b],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{ab65caf0-fc3b-40f8-8b88-6d096a48f659}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{596eaa89-f3d2-4174-9bd9-f7d79c744cda}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{32C53681-8E69-4659-8320-7422685BD486}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{32C53681-8E69-4659-8320-7422685BD486}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{596eaa89-f3d2-4174-9bd9-f7d79c744cda}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HulaToo, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, , [5debadc6552626107a526c307e84d729],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\20891, , [be8a136015661c1ae3bda5fb24de11ef],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21836, , [2a1e77fcfa8180b6e0c0e4bcb74b639d],
PUP.Optional.HulaToo.A, HKLM\SOFTWARE\WOW6432NODE\HulaToo, , [f157a4cf275481b50ec08b11e71b14ec],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\20891, , [5cec8ae9cab13cfa0b95a1ff1fe3aa56],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\21836, , [d87042311f5cd95defb1a0007d851ee2],
PUP.Optional.ObjectBrowser.A, HKLM\SOFTWARE\WOW6432NODE\SENSE\INSTALLER, , [a4a4294a5f1cd6607c15fca52fd36f91],
PUP.Optional.HulaToo.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\HulaToo, , [9fa9561d275496a08d40019b58aa2ad6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-817296699-4016285348-1085084602-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21836, , [71d7254ec7b4162001a06e32db2750b0],
Registry Values: 1
PUP.Optional.ObjectBrowser.A, HKLM\SOFTWARE\WOW6432NODE\SENSE\INSTALLER|BundledIe, 1, , [a4a4294a5f1cd6607c15fca52fd36f91]
Registry Data: 0
(No malicious items detected)
Folders: 6
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\TEMP, , [5debadc6552626107a526c307e84d729],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0, , [e16774ff3f3cb87e88024241a062f709],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam, , [e662ff7483f86fc76b2384ff7a88e11f],
Files: 37
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\updateHulaToo.exe, , [ff49f380e09bec4af7608ee3fe0333cd],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\utilHulaToo.exe, , [17314d26215a48eef76028497988d52b],
PUP.Optional.ScramblePacker.A, C:\Users\Andrejko\AppData\Local\Installer\Install_25731\sense.exe, , [c088afc4e497f83e59a50478ea17c13f],
PUP.Optional.Superfish.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, , [410713607b0069cd4f00a6ee5ba78b75],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0.localstorage, , [c48481f26714d85ed696bfdd1fe3c43c],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\HulaToo.ico, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\7za.exe, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\HulaTooBHO.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\HulaTooUninstall.exe, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\updateHulaToo.InstallState, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\7za.exe, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\BrowserAdapterS.7z, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\HulaToo.BrowserAdapter.exe, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\HulaToo.PurBrowse64.exe, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\HulaToo.PurBrowseG.zip, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\HulaTooBAApp.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\utilHulaToo.InstallState, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins\HulaToo.Bromon.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins\HulaToo.BrowserAdapterS.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins\HulaToo.CompatibilityChecker.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins\HulaToo.FFUpdate.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins\HulaToo.IEUpdate.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.HulaToo.A, C:\Program Files (x86)\HulaToo\bin\plugins\HulaToo.PurBrowseG.dll, , [5debadc6552626107a526c307e84d729],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-1.job, , [d96f551ec2b9ef47e63b801f09f9e917],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-3.job, , [67e181f20a71f73f39e8544b43bfee12],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0\1, , [e16774ff3f3cb87e88024241a062f709],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\000083.ldb, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\000085.ldb, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\000101.ldb, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\000104.log, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\CURRENT, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\LOCK, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\LOG, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\LOG.old, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.CrossRider.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam\MANIFEST-000103, , [e662ff7483f86fc76b2384ff7a88e11f],
PUP.Optional.ASK.A, C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "search_url": "http://dts.search.ask.com/sr?src=crb&gct=ds&appid=128&systemid=488&v=a12627-348&apn_uid=3052830855634133&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}",), ,[3117413254279b9bb5045c309d67bf41]
Physical Sectors: 0
(No malicious items detected)
(end)
Re: Prosím o kontrolu logu...
adwcleaner : # AdwCleaner v3.211 - Report created 01/06/2014 at 11:34:53
# Updated 26/05/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Andrejko - ANDREJ
# Running from : C:\Users\Andrejko\Downloads\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : F06DEFF2-5B9C-490D-910F-35D3A91196222
[#] Service Deleted : Update HulaToo
[#] Service Deleted : Util HulaToo
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Goobzo
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
Folder Deleted : C:\Program Files (x86)\YouTube Accelerator
Folder Deleted : C:\Users\Andrejko\AppData\Local\webplayer
Folder Deleted : C:\Users\Andrejko\AppData\LocalLow\DataMngr
Folder Deleted : C:\Users\Andrejko\AppData\LocalLow\Goobzo
Folder Deleted : C:\Users\Andrejko\AppData\LocalLow\iWebar
Folder Deleted : C:\Users\Andrejko\AppData\LocalLow\Sense
Folder Deleted : C:\Users\Public\Documents\Goobzo
Folder Deleted : C:\Users\Public\Documents\ShopperPro
File Deleted : C:\Windows\System32\Tasks\ShopperProJSUpd
File Deleted : C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart
File Deleted : C:\Windows\System32\Tasks\SPDriver
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FLV Player]
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EAB5257A-1FB3-474C-9B42-231F52622E72}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKCU\Software\Goobzo
Key Deleted : HKCU\Software\installedbrowserextensions
Key Deleted : HKCU\Software\SafetyNut
Key Deleted : HKCU\Software\Somoto
Key Deleted : HKCU\Software\Webplayer
Key Deleted : HKCU\Software\AppDataLow\Software
Key Deleted : HKLM\Software\Goobzo
Key Deleted : HKLM\Software\installedbrowserextensions
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\FLV Player
Key Deleted : [x64] HKLM\SOFTWARE\installedbrowserextensions
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17037
-\\ Google Chrome v35.0.1916.114
[ File : C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gc ... nrs=AG1&q={searchTerms}
*************************
AdwCleaner[R0].txt - [13264 octets] - [31/05/2014 00:09:54]
AdwCleaner[R1].txt - [6022 octets] - [01/06/2014 11:34:20]
AdwCleaner[S0].txt - [5593 octets] - [01/06/2014 11:34:53]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5653 octets] ##########
# Updated 26/05/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Andrejko - ANDREJ
# Running from : C:\Users\Andrejko\Downloads\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : F06DEFF2-5B9C-490D-910F-35D3A91196222
[#] Service Deleted : Update HulaToo
[#] Service Deleted : Util HulaToo
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Goobzo
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
Folder Deleted : C:\Program Files (x86)\YouTube Accelerator
Folder Deleted : C:\Users\Andrejko\AppData\Local\webplayer
Folder Deleted : C:\Users\Andrejko\AppData\LocalLow\DataMngr
Folder Deleted : C:\Users\Andrejko\AppData\LocalLow\Goobzo
Folder Deleted : C:\Users\Andrejko\AppData\LocalLow\iWebar
Folder Deleted : C:\Users\Andrejko\AppData\LocalLow\Sense
Folder Deleted : C:\Users\Public\Documents\Goobzo
Folder Deleted : C:\Users\Public\Documents\ShopperPro
File Deleted : C:\Windows\System32\Tasks\ShopperProJSUpd
File Deleted : C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart
File Deleted : C:\Windows\System32\Tasks\SPDriver
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FLV Player]
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EAB5257A-1FB3-474C-9B42-231F52622E72}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKCU\Software\Goobzo
Key Deleted : HKCU\Software\installedbrowserextensions
Key Deleted : HKCU\Software\SafetyNut
Key Deleted : HKCU\Software\Somoto
Key Deleted : HKCU\Software\Webplayer
Key Deleted : HKCU\Software\AppDataLow\Software
Key Deleted : HKLM\Software\Goobzo
Key Deleted : HKLM\Software\installedbrowserextensions
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\FLV Player
Key Deleted : [x64] HKLM\SOFTWARE\installedbrowserextensions
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17037
-\\ Google Chrome v35.0.1916.114
[ File : C:\Users\Andrejko\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gc ... nrs=AG1&q={searchTerms}
*************************
AdwCleaner[R0].txt - [13264 octets] - [31/05/2014 00:09:54]
AdwCleaner[R1].txt - [6022 octets] - [01/06/2014 11:34:20]
AdwCleaner[S0].txt - [5593 octets] - [01/06/2014 11:34:53]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5653 octets] ##########
Re: Prosím o kontrolu logu...
JRT : ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Andrejko on ne 01. 06. 2014 at 11:47:29,03
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 01. 06. 2014 at 11:50:47,64
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Andrejko on ne 01. 06. 2014 at 11:47:29,03
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 01. 06. 2014 at 11:50:47,64
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu...
. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu...
Rogue island : RogueKiller V9.0.0.0 (x64) [May 29 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 8.1 (6.3.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Andrejko [Práva správce]
Mód : Kontrola -- Datum : 06/02/2014 16:48:31
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 12 ¤¤¤
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-817296699-4016285348-1085084602-1002\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-817296699-4016285348-1085084602-1002\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-817296699-4016285348-1085084602-1002\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-817296699-4016285348-1085084602-1002\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 429 ¤¤¤
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoRevokeClassObject : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619aaea0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoRegisterClassObject : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619841e4
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoCreateInstance : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6194cbe0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - RoGetAgileReference : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619640a0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoDisableCallCancellation : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619ac8d0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoSetProxyBlanket : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61949318
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoGetApartmentType : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619abc40
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoTaskMemFree : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61921b90
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoCreateFreeThreadedMarshaler : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6194d0e0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoWaitForMultipleHandles : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6194d394
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoTaskMemRealloc : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6194d990
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoEnableCallCancellation : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619ac91c
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoCancelCall : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61a39860
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - StringFromGUID2 : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6194ab00
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CLSIDFromString : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619396ac
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoInitializeEx : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61949b70
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoUninitialize : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6194959c
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoTaskMemAlloc : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61921bd0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoGetMalloc : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61922670
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoFreeUnusedLibraries : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61922c14
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - PropVariantClear : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619abbe0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoGetInterfaceAndReleaseStream : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6199dd74
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoReleaseMarshalData : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61938e00
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoMarshalInterThreadInterfaceInStream : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6199dc34
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CreateStreamOnHGlobal : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61952ac4
[IAT:Addr] (explorer.exe) api-ms-win-core-winrt-string-l1-1-0.dll - WindowsCreateString : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6199df80
[IAT:Addr] (explorer.exe) api-ms-win-core-winrt-string-l1-1-0.dll - WindowsDeleteString : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6199dec0
[IAT:Addr] (explorer.exe) api-ms-win-core-winrt-string-l1-1-0.dll - WindowsCreateStringReference : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6199ddf0
[IAT:Addr] (explorer.exe) api-ms-win-core-winrt-string-l1-1-0.dll - WindowsGetStringRawBuffer : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6199dea0
[IAT:Addr] (explorer.exe) api-ms-win-power-base-l1-1-0.dll - GetPwrCapabilities : C:\Windows\SYSTEM32\powrprof.dll @ 0x7ffc5f971aa0
[IAT:Addr] (explorer.exe) api-ms-win-power-base-l1-1-0.dll - PowerDeterminePlatformRoleEx : C:\Windows\SYSTEM32\powrprof.dll @ 0x7ffc5f971890
[IAT:Addr] (explorer.exe) api-ms-win-power-base-l1-1-0.dll - CallNtPowerInformation : C:\Windows\SYSTEM32\powrprof.dll @ 0x7ffc5f971050
[IAT:Addr] (explorer.exe) api-ms-win-core-com-private-l1-1-0.dll - CoRegisterMessageFilter : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619a86b0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-private-l1-1-0.dll - CoRevokeInitializeSpy : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619ac1b8
[IAT:Addr] (explorer.exe) api-ms-win-core-com-private-l1-1-0.dll - CoRegisterInitializeSpy : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619ac2b4
[IAT:Addr] (explorer.exe) api-ms-win-eventing-controller-l1-1-0.dll - EnableTraceEx2 : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc626090e0
[IAT:Addr] (explorer.exe) api-ms-win-eventing-controller-l1-1-0.dll - StartTraceW : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc6260d900
[IAT:Addr] (explorer.exe) api-ms-win-eventing-controller-l1-1-0.dll - StopTraceW : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc62606510
[IAT:Addr] (explorer.exe) api-ms-win-service-management-l2-1-0.dll - NotifyServiceStatusChangeW : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc6260bc74
[IAT:Addr] (explorer.exe) api-ms-win-service-management-l2-1-0.dll - QueryServiceConfigW : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc62605eb4
[IAT:Addr] (explorer.exe) api-ms-win-core-winrt-l1-1-0.dll - RoGetActivationFactory : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6196080c
[IAT:Addr] (explorer.exe) api-ms-win-security-lsalookup-l1-1-1.dll - GetIdentityProviderInfoByGUID : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc62607fa4
[IAT:Addr] (explorer.exe) api-ms-win-security-lsalookup-l1-1-1.dll - ReleaseIdentityProviderEnumContext : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc62604a00
[IAT:Addr] (explorer.exe) api-ms-win-security-lsalookup-l1-1-1.dll - EnumerateIdentityProviders : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc62604a28
[IAT:Addr] (explorer.exe) api-ms-win-security-lsalookup-l1-1-1.dll - GetDefaultIdentityProvider : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc62608e84
[EAT:Addr] (explorer.exe) ncryptsslp.dll - AsyncGetClassBits : C:\Windows\system32\urlmon.dll @ 0x7ffc57c670b0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - AsyncInstallDistributionUnit : C:\Windows\system32\urlmon.dll @ 0x7ffc57c67210
[EAT:Addr] (explorer.exe) ncryptsslp.dll - BindAsyncMoniker : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51f90
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CDLGetLongPathNameA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c678d0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CDLGetLongPathNameW : C:\Windows\system32\urlmon.dll @ 0x7ffc57c678e8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CORPolicyProvider : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51674
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoGetClassObjectFromURL : C:\Windows\system32\urlmon.dll @ 0x7ffc57c673fc
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInstall : C:\Windows\system32\urlmon.dll @ 0x7ffc57c67460
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCanonicalizeIUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57c15660
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCombineIUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57c180a0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCombineUrl : C:\Windows\system32\urlmon.dll @ 0x7ffc57c046a4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCombineUrlEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57c043c0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCompareUrl : C:\Windows\system32\urlmon.dll @ 0x7ffc57c55280
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCreateSecurityManager : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd1ee0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCreateZoneManager : C:\Windows\system32\urlmon.dll @ 0x7ffc57be0810
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetFeatureSettingsChanged : C:\Windows\system32\urlmon.dll @ 0x7ffc57c90284
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetGetProtocolFlags : C:\Windows\system32\urlmon.dll @ 0x7ffc57c5537c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetGetSecurityUrl : C:\Windows\system32\urlmon.dll @ 0x7ffc57c553d0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetGetSecurityUrlEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57c19cd0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetGetSession : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd2460
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetIsFeatureEnabled : C:\Windows\system32\urlmon.dll @ 0x7ffc57c18dc0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetIsFeatureEnabledForIUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57c151b8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetIsFeatureEnabledForUrl : C:\Windows\system32\urlmon.dll @ 0x7ffc57c11820
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetIsFeatureZoneElevationEnabled : C:\Windows\system32\urlmon.dll @ 0x7ffc57c5586c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetParseIUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57c056a8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetParseUrl : C:\Windows\system32\urlmon.dll @ 0x7ffc57be1490
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetQueryInfo : C:\Windows\system32\urlmon.dll @ 0x7ffc57c17c50
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetSetFeatureEnabled : C:\Windows\system32\urlmon.dll @ 0x7ffc57c55af4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CompareSecurityIds : C:\Windows\system32\urlmon.dll @ 0x7ffc57bed1a4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CompatFlagsFromClsid : C:\Windows\system32\urlmon.dll @ 0x7ffc57c14044
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CopyBindInfo : C:\Windows\system32\urlmon.dll @ 0x7ffc57c63020
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CopyStgMedium : C:\Windows\system32\urlmon.dll @ 0x7ffc57bdba0c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateAsyncBindCtx : C:\Windows\system32\urlmon.dll @ 0x7ffc57c286c0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateAsyncBindCtxEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57c13d14
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateFormatEnumerator : C:\Windows\system32\urlmon.dll @ 0x7ffc57bf68e0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateIUriBuilder : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd3660
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateURLMoniker : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2ccf4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateURLMonikerEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd78d0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateURLMonikerEx2 : C:\Windows\system32\urlmon.dll @ 0x7ffc57c140f0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd16f0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateUriFromMultiByteString : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51ee4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateUriPriv : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51ef8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateUriWithFragment : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51f40
[EAT:Addr] (explorer.exe) ncryptsslp.dll - DllCanUnloadNow : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd1600
[EAT:Addr] (explorer.exe) ncryptsslp.dll - DllGetClassObject : C:\Windows\system32\urlmon.dll @ 0x7ffc57c1ab3c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - DllInstall : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52458
[EAT:Addr] (explorer.exe) ncryptsslp.dll - DllRegisterServer : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52464
[EAT:Addr] (explorer.exe) ncryptsslp.dll - DllRegisterServerEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (explorer.exe) ncryptsslp.dll - DllUnregisterServer : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52470
[EAT:Addr] (explorer.exe) ncryptsslp.dll - Extract : C:\Windows\system32\urlmon.dll @ 0x7ffc57c67f74
[EAT:Addr] (explorer.exe) ncryptsslp.dll - FaultInIEFeature : C:\Windows\system32\urlmon.dll @ 0x7ffc57c68fe8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - FileBearsMarkOfTheWeb : C:\Windows\system32\urlmon.dll @ 0x7ffc57c06b60
[EAT:Addr] (explorer.exe) ncryptsslp.dll - FindMediaType : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52e9c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - FindMediaTypeClass : C:\Windows\system32\urlmon.dll @ 0x7ffc57bf6080
[EAT:Addr] (explorer.exe) ncryptsslp.dll - FindMimeFromData : C:\Windows\system32\urlmon.dll @ 0x7ffc57c150bc
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetAddSitesFileUrl : C:\Windows\system32\urlmon.dll @ 0x7ffc57c902b0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetClassFileOrMime : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2b8ec
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetClassURL : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52074
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetComponentIDFromCLSSPEC : C:\Windows\system32\urlmon.dll @ 0x7ffc57c692e8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetIDNFlagsForUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57bec7f0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetIUriPriv : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51f60
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetIUriPriv2 : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51f50
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetLabelsFromNamedHost : C:\Windows\system32\urlmon.dll @ 0x7ffc57c98b54
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetMarkOfTheWeb : C:\Windows\system32\urlmon.dll @ 0x7ffc57c89390
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetPortFromUrlScheme : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51e94
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetPropertyFromName : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51ea4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetPropertyName : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51eb4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetSoftwareUpdateInfo : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetUrlmonThreadNotificationHwnd : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2deb4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetZoneFromAlternateDataStreamEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd6d90
[EAT:Addr] (explorer.exe) ncryptsslp.dll - HlinkGoBack : C:\Windows\system32\urlmon.dll @ 0x7ffc57c86e78
[EAT:Addr] (explorer.exe) ncryptsslp.dll - HlinkGoForward : C:\Windows\system32\urlmon.dll @ 0x7ffc57c86f24
[EAT:Addr] (explorer.exe) ncryptsslp.dll - HlinkNavigateMoniker : C:\Windows\system32\urlmon.dll @ 0x7ffc57c86fd0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - HlinkNavigateString : C:\Windows\system32\urlmon.dll @ 0x7ffc57c87004
[EAT:Addr] (explorer.exe) ncryptsslp.dll - HlinkSimpleNavigateToMoniker : C:\Windows\system32\urlmon.dll @ 0x7ffc57c87038
[EAT:Addr] (explorer.exe) ncryptsslp.dll - HlinkSimpleNavigateToString : C:\Windows\system32\urlmon.dll @ 0x7ffc57c875e8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IECompatLogCSSFix : C:\Windows\system32\urlmon.dll @ 0x7ffc57c612fc
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IEDllLoader : C:\Windows\system32\urlmon.dll @ 0x7ffc57c526f0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IEGetUserPrivateNamespaceName : C:\Windows\system32\urlmon.dll @ 0x7ffc57c63244
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IEInstallScope : C:\Windows\system32\urlmon.dll @ 0x7ffc57c67554
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IntlPercentEncodeNormalize : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51f70
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsAsyncMoniker : C:\Windows\system32\urlmon.dll @ 0x7ffc57c121fc
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsDWORDProperty : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51ec4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsIntranetAvailable : C:\Windows\system32\urlmon.dll @ 0x7ffc57c90668
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsJITInProgress : C:\Windows\system32\urlmon.dll @ 0x7ffc57beb328
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsLoggingEnabledA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c8855c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsLoggingEnabledW : C:\Windows\system32\urlmon.dll @ 0x7ffc57c88688
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsStringProperty : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51ed4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsValidURL : C:\Windows\system32\urlmon.dll @ 0x7ffc57c07610
[EAT:Addr] (explorer.exe) ncryptsslp.dll - MkParseDisplayNameEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57c292f0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - ObtainUserAgentString : C:\Windows\system32\urlmon.dll @ 0x7ffc57c5dce0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - PrivateCoInstall : C:\Windows\system32\urlmon.dll @ 0x7ffc57c67560
[EAT:Addr] (explorer.exe) ncryptsslp.dll - QueryAssociations : C:\Windows\system32\urlmon.dll @ 0x7ffc57bee9c0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - QueryClsidAssociation : C:\Windows\system32\urlmon.dll @ 0x7ffc57c60a8c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RegisterBindStatusCallback : C:\Windows\system32\urlmon.dll @ 0x7ffc57c0f600
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RegisterFormatEnumerator : C:\Windows\system32\urlmon.dll @ 0x7ffc57c11c6c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RegisterMediaTypeClass : C:\Windows\system32\urlmon.dll @ 0x7ffc57c520c0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RegisterMediaTypes : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52210
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RegisterWebPlatformPermanentSecurityManager : C:\Windows\system32\urlmon.dll @ 0x7ffc57c08c54
[EAT:Addr] (explorer.exe) ncryptsslp.dll - ReleaseBindInfo : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd7d40
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RevokeBindStatusCallback : C:\Windows\system32\urlmon.dll @ 0x7ffc57c0fbf0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RevokeFormatEnumerator : C:\Windows\system32\urlmon.dll @ 0x7ffc57c522cc
[EAT:Addr] (explorer.exe) ncryptsslp.dll - SetAccessForIEAppContainer : C:\Windows\system32\urlmon.dll @ 0x7ffc57c63258
[EAT:Addr] (explorer.exe) ncryptsslp.dll - SetSoftwareUpdateAdvertisementState : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (explorer.exe) ncryptsslp.dll - ShouldDisplayPunycodeForUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57c5de50
[EAT:Addr] (explorer.exe) ncryptsslp.dll - ShouldShowIntranetWarningSecband : C:\Windows\system32\urlmon.dll @ 0x7ffc57c13a3c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - ShowTrustAlertDialog : C:\Windows\system32\urlmon.dll @ 0x7ffc57c90820
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLDownloadA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c55cc4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLDownloadToCacheFileA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c87d9c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLDownloadToCacheFileW : C:\Windows\system32\urlmon.dll @ 0x7ffc57bfa0c4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLDownloadToFileA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c87f10
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLDownloadToFileW : C:\Windows\system32\urlmon.dll @ 0x7ffc57bfefd0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLDownloadW : C:\Windows\system32\urlmon.dll @ 0x7ffc57c55d78
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLOpenBlockingStreamA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c88058
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLOpenBlockingStreamW : C:\Windows\system32\urlmon.dll @ 0x7ffc57c88138
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLOpenPullStreamA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c8821c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLOpenPullStreamW : C:\Windows\system32\urlmon.dll @ 0x7ffc57c882e0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLOpenStreamA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c88408
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLOpenStreamW : C:\Windows\system32\urlmon.dll @ 0x7ffc57c884d0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - UnregisterWebPlatformPermanentSecurityManager : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2c9b4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - UrlMkBuildVersion : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52804
[EAT:Addr] (explorer.exe) ncryptsslp.dll - UrlMkGetSessionOption : C:\Windows\system32\urlmon.dll @ 0x7ffc57be3e60
[EAT:Addr] (explorer.exe) ncryptsslp.dll - UrlMkSetSessionOption : C:\Windows\system32\urlmon.dll @ 0x7ffc57c0d0e4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - UrlmonCleanupCurrentThread : C:\Windows\system32\urlmon.dll @ 0x7ffc57bfa27c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - WriteHitLogging : C:\Windows\system32\urlmon.dll @ 0x7ffc57c885d0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - ZonesReInit : C:\Windows\system32\urlmon.dll @ 0x7ffc57c89c30
[IAT:Addr] (iexplore.exe) api-ms-win-downlevel-shell32-l1-1-0.dll - SetCurrentProcessExplicitAppUserModelID : C:\Windows\SYSTEM32\shcore.dll @ 0x7ffc5deb6d08
[IAT:Addr] (iexplore.exe) api-ms-win-downlevel-shell32-l1-1-0.dll - CommandLineToArgvW : C:\Windows\SYSTEM32\shcore.dll @ 0x7ffc5de948e8
[IAT:Addr] (iexplore.exe) api-ms-win-downlevel-shell32-l1-1-0.dll - SetCurrentProcessExplicitAppUserModelID : C:\Windows\SYSTEM32\shcore.dll @ 0x7ffc5deb6d08
[IAT:Addr] (iexplore.exe) api-ms-win-downlevel-shell32-l1-1-0.dll - CommandLineToArgvW : C:\Windows\SYSTEM32\shcore.dll @ 0x7ffc5de948e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - AsyncGetClassBits : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c670b0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - AsyncInstallDistributionUnit : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67210
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - BindAsyncMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f90
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CDLGetLongPathNameA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c678d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CDLGetLongPathNameW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c678e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CORPolicyProvider : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51674
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoGetClassObjectFromURL : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c673fc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInstall : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67460
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCanonicalizeIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c15660
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCombineIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c180a0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCombineUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c046a4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCombineUrlEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c043c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCompareUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55280
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCreateSecurityManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd1ee0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCreateZoneManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57be0810
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetFeatureSettingsChanged : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c90284
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetProtocolFlags : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5537c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetSecurityUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c553d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetSecurityUrlEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c19cd0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetSession : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd2460
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureEnabled : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c18dc0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureEnabledForIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c151b8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureEnabledForUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c11820
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureZoneElevationEnabled : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5586c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetParseIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c056a8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetParseUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57be1490
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetQueryInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c17c50
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetSetFeatureEnabled : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55af4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CompareSecurityIds : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bed1a4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CompatFlagsFromClsid : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c14044
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CopyBindInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c63020
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CopyStgMedium : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bdba0c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateAsyncBindCtx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c286c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateAsyncBindCtxEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c13d14
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateFormatEnumerator : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bf68e0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateIUriBuilder : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd3660
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateURLMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2ccf4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateURLMonikerEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd78d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateURLMonikerEx2 : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c140f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd16f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUriFromMultiByteString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ee4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUriPriv : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ef8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUriWithFragment : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f40
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllCanUnloadNow : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd1600
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllGetClassObject : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c1ab3c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllInstall : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52458
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllRegisterServer : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52464
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllRegisterServerEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllUnregisterServer : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52470
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - Extract : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67f74
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FaultInIEFeature : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c68fe8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FileBearsMarkOfTheWeb : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c06b60
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FindMediaType : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52e9c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FindMediaTypeClass : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bf6080
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FindMimeFromData : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c150bc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetAddSitesFileUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c902b0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetClassFileOrMime : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2b8ec
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetClassURL : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52074
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetComponentIDFromCLSSPEC : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c692e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetIDNFlagsForUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bec7f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetIUriPriv : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f60
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetIUriPriv2 : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f50
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetLabelsFromNamedHost : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c98b54
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetMarkOfTheWeb : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c89390
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetPortFromUrlScheme : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51e94
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetPropertyFromName : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ea4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetPropertyName : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51eb4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetSoftwareUpdateInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetUrlmonThreadNotificationHwnd : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2deb4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetZoneFromAlternateDataStreamEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd6d90
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkGoBack : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c86e78
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkGoForward : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c86f24
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkNavigateMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c86fd0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkNavigateString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87004
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkSimpleNavigateToMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87038
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkSimpleNavigateToString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c875e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IECompatLogCSSFix : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c612fc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IEDllLoader : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c526f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IEGetUserPrivateNamespaceName : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c63244
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IEInstallScope : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67554
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IntlPercentEncodeNormalize : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f70
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsAsyncMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c121fc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsDWORDProperty : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ec4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsIntranetAvailable : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c90668
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsJITInProgress : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57beb328
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsLoggingEnabledA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c8855c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsLoggingEnabledW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88688
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsStringProperty : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ed4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsValidURL : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c07610
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - MkParseDisplayNameEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c292f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ObtainUserAgentString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5dce0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - PrivateCoInstall : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67560
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - QueryAssociations : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bee9c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - QueryClsidAssociation : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c60a8c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterBindStatusCallback : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c0f600
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterFormatEnumerator : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c11c6c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterMediaTypeClass : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c520c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterMediaTypes : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52210
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterWebPlatformPermanentSecurityManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c08c54
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ReleaseBindInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd7d40
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RevokeBindStatusCallback : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c0fbf0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RevokeFormatEnumerator : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c522cc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - SetAccessForIEAppContainer : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c63258
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - SetSoftwareUpdateAdvertisementState : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ShouldDisplayPunycodeForUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5de50
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ShouldShowIntranetWarningSecband : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c13a3c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ShowTrustAlertDialog : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c90820
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55cc4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToCacheFileA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87d9c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToCacheFileW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bfa0c4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToFileA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87f10
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToFileW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bfefd0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55d78
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenBlockingStreamA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88058
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenBlockingStreamW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88138
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenPullStreamA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c8821c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenPullStreamW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c882e0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenStreamA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88408
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenStreamW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c884d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UnregisterWebPlatformPermanentSecurityManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2c9b4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlMkBuildVersion : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52804
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlMkGetSessionOption : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57be3e60
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlMkSetSessionOption : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c0d0e4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlmonCleanupCurrentThread : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bfa27c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - WriteHitLogging : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c885d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ZonesReInit : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c89c30
[IAT:Addr] (iexplore.exe) api-ms-win-downlevel-shell32-l1-1-0.dll - SetCurrentProcessExplicitAppUserModelID : C:\Windows\SYSTEM32\shcore.dll @ 0x7ffc5deb6d08
[IAT:Addr] (iexplore.exe) api-ms-win-downlevel-shell32-l1-1-0.dll - CommandLineToArgvW : C:\Windows\SYSTEM32\shcore.dll @ 0x7ffc5de948e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - AsyncGetClassBits : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c670b0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - AsyncInstallDistributionUnit : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67210
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - BindAsyncMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f90
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CDLGetLongPathNameA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c678d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CDLGetLongPathNameW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c678e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CORPolicyProvider : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51674
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoGetClassObjectFromURL : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c673fc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInstall : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67460
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCanonicalizeIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c15660
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCombineIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c180a0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCombineUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c046a4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCombineUrlEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c043c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCompareUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55280
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCreateSecurityManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd1ee0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCreateZoneManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57be0810
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetFeatureSettingsChanged : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c90284
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetProtocolFlags : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5537c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetSecurityUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c553d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetSecurityUrlEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c19cd0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetSession : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd2460
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureEnabled : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c18dc0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureEnabledForIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c151b8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureEnabledForUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c11820
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureZoneElevationEnabled : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5586c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetParseIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c056a8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetParseUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57be1490
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetQueryInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c17c50
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetSetFeatureEnabled : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55af4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CompareSecurityIds : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bed1a4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CompatFlagsFromClsid : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c14044
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CopyBindInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c63020
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CopyStgMedium : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bdba0c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateAsyncBindCtx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c286c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateAsyncBindCtxEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c13d14
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateFormatEnumerator : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bf68e0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateIUriBuilder : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd3660
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateURLMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2ccf4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateURLMonikerEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd78d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateURLMonikerEx2 : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c140f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd16f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUriFromMultiByteString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ee4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUriPriv : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ef8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUriWithFragment : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f40
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllCanUnloadNow : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd1600
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllGetClassObject : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c1ab3c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllInstall : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52458
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllRegisterServer : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52464
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllRegisterServerEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllUnregisterServer : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52470
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - Extract : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67f74
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FaultInIEFeature : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c68fe8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FileBearsMarkOfTheWeb : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c06b60
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FindMediaType : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52e9c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FindMediaTypeClass : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bf6080
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FindMimeFromData : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c150bc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetAddSitesFileUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c902b0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetClassFileOrMime : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2b8ec
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetClassURL : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52074
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetComponentIDFromCLSSPEC : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c692e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetIDNFlagsForUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bec7f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetIUriPriv : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f60
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetIUriPriv2 : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f50
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetLabelsFromNamedHost : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c98b54
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetMarkOfTheWeb : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c89390
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetPortFromUrlScheme : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51e94
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetPropertyFromName : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ea4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetPropertyName : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51eb4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetSoftwareUpdateInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetUrlmonThreadNotificationHwnd : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2deb4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetZoneFromAlternateDataStreamEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd6d90
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkGoBack : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c86e78
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkGoForward : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c86f24
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkNavigateMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c86fd0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkNavigateString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87004
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkSimpleNavigateToMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87038
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkSimpleNavigateToString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c875e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IECompatLogCSSFix : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c612fc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IEDllLoader : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c526f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IEGetUserPrivateNamespaceName : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c63244
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IEInstallScope : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67554
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IntlPercentEncodeNormalize : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f70
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsAsyncMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c121fc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsDWORDProperty : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ec4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsIntranetAvailable : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c90668
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsJITInProgress : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57beb328
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsLoggingEnabledA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c8855c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsLoggingEnabledW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88688
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsStringProperty : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ed4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsValidURL : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c07610
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - MkParseDisplayNameEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c292f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ObtainUserAgentString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5dce0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - PrivateCoInstall : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67560
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - QueryAssociations : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bee9c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - QueryClsidAssociation : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c60a8c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterBindStatusCallback : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c0f600
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterFormatEnumerator : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c11c6c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterMediaTypeClass : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c520c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterMediaTypes : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52210
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterWebPlatformPermanentSecurityManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c08c54
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ReleaseBindInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd7d40
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RevokeBindStatusCallback : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c0fbf0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RevokeFormatEnumerator : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c522cc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - SetAccessForIEAppContainer : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c63258
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - SetSoftwareUpdateAdvertisementState : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ShouldDisplayPunycodeForUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5de50
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ShouldShowIntranetWarningSecband : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c13a3c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ShowTrustAlertDialog : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c90820
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55cc4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToCacheFileA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87d9c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToCacheFileW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bfa0c4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToFileA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87f10
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToFileW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bfefd0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55d78
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenBlockingStreamA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88058
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenBlockingStreamW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88138
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenPullStreamA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c8821c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenPullStreamW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c882e0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenStreamA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88408
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenStreamW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c884d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UnregisterWebPlatformPermanentSecurityManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2c9b4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlMkBuildVersion : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52804
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlMkGetSessionOption : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57be3e60
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlMkSetSessionOption : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c0d0e4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlmonCleanupCurrentThread : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bfa27c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - WriteHitLogging : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c885d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ZonesReInit : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c89c30
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD10JPVT-80A1YT0 +++++
--- User ---
[MBR] 5121ed68627e23ab97862d4b9d9f4d5e
[BSP] 4816b00b2e7efa2cda2c0a65fdf3e385 : Unknown MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_DEL_06012014_121750.log - RKreport_SCN_06012014_121746.log
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 8.1 (6.3.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Andrejko [Práva správce]
Mód : Kontrola -- Datum : 06/02/2014 16:48:31
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 12 ¤¤¤
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-817296699-4016285348-1085084602-1002\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-817296699-4016285348-1085084602-1002\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-817296699-4016285348-1085084602-1002\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-817296699-4016285348-1085084602-1002\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 429 ¤¤¤
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoRevokeClassObject : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619aaea0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoRegisterClassObject : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619841e4
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoCreateInstance : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6194cbe0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - RoGetAgileReference : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619640a0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoDisableCallCancellation : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619ac8d0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoSetProxyBlanket : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61949318
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoGetApartmentType : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619abc40
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoTaskMemFree : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61921b90
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoCreateFreeThreadedMarshaler : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6194d0e0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoWaitForMultipleHandles : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6194d394
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoTaskMemRealloc : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6194d990
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoEnableCallCancellation : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619ac91c
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoCancelCall : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61a39860
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - StringFromGUID2 : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6194ab00
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CLSIDFromString : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619396ac
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoInitializeEx : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61949b70
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoUninitialize : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6194959c
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoTaskMemAlloc : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61921bd0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoGetMalloc : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61922670
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoFreeUnusedLibraries : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61922c14
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - PropVariantClear : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619abbe0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoGetInterfaceAndReleaseStream : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6199dd74
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoReleaseMarshalData : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61938e00
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CoMarshalInterThreadInterfaceInStream : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6199dc34
[IAT:Addr] (explorer.exe) api-ms-win-core-com-l1-1-1.dll - CreateStreamOnHGlobal : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc61952ac4
[IAT:Addr] (explorer.exe) api-ms-win-core-winrt-string-l1-1-0.dll - WindowsCreateString : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6199df80
[IAT:Addr] (explorer.exe) api-ms-win-core-winrt-string-l1-1-0.dll - WindowsDeleteString : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6199dec0
[IAT:Addr] (explorer.exe) api-ms-win-core-winrt-string-l1-1-0.dll - WindowsCreateStringReference : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6199ddf0
[IAT:Addr] (explorer.exe) api-ms-win-core-winrt-string-l1-1-0.dll - WindowsGetStringRawBuffer : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6199dea0
[IAT:Addr] (explorer.exe) api-ms-win-power-base-l1-1-0.dll - GetPwrCapabilities : C:\Windows\SYSTEM32\powrprof.dll @ 0x7ffc5f971aa0
[IAT:Addr] (explorer.exe) api-ms-win-power-base-l1-1-0.dll - PowerDeterminePlatformRoleEx : C:\Windows\SYSTEM32\powrprof.dll @ 0x7ffc5f971890
[IAT:Addr] (explorer.exe) api-ms-win-power-base-l1-1-0.dll - CallNtPowerInformation : C:\Windows\SYSTEM32\powrprof.dll @ 0x7ffc5f971050
[IAT:Addr] (explorer.exe) api-ms-win-core-com-private-l1-1-0.dll - CoRegisterMessageFilter : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619a86b0
[IAT:Addr] (explorer.exe) api-ms-win-core-com-private-l1-1-0.dll - CoRevokeInitializeSpy : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619ac1b8
[IAT:Addr] (explorer.exe) api-ms-win-core-com-private-l1-1-0.dll - CoRegisterInitializeSpy : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc619ac2b4
[IAT:Addr] (explorer.exe) api-ms-win-eventing-controller-l1-1-0.dll - EnableTraceEx2 : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc626090e0
[IAT:Addr] (explorer.exe) api-ms-win-eventing-controller-l1-1-0.dll - StartTraceW : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc6260d900
[IAT:Addr] (explorer.exe) api-ms-win-eventing-controller-l1-1-0.dll - StopTraceW : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc62606510
[IAT:Addr] (explorer.exe) api-ms-win-service-management-l2-1-0.dll - NotifyServiceStatusChangeW : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc6260bc74
[IAT:Addr] (explorer.exe) api-ms-win-service-management-l2-1-0.dll - QueryServiceConfigW : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc62605eb4
[IAT:Addr] (explorer.exe) api-ms-win-core-winrt-l1-1-0.dll - RoGetActivationFactory : C:\Windows\SYSTEM32\combase.dll @ 0x7ffc6196080c
[IAT:Addr] (explorer.exe) api-ms-win-security-lsalookup-l1-1-1.dll - GetIdentityProviderInfoByGUID : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc62607fa4
[IAT:Addr] (explorer.exe) api-ms-win-security-lsalookup-l1-1-1.dll - ReleaseIdentityProviderEnumContext : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc62604a00
[IAT:Addr] (explorer.exe) api-ms-win-security-lsalookup-l1-1-1.dll - EnumerateIdentityProviders : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc62604a28
[IAT:Addr] (explorer.exe) api-ms-win-security-lsalookup-l1-1-1.dll - GetDefaultIdentityProvider : C:\Windows\SYSTEM32\sechost.dll @ 0x7ffc62608e84
[EAT:Addr] (explorer.exe) ncryptsslp.dll - AsyncGetClassBits : C:\Windows\system32\urlmon.dll @ 0x7ffc57c670b0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - AsyncInstallDistributionUnit : C:\Windows\system32\urlmon.dll @ 0x7ffc57c67210
[EAT:Addr] (explorer.exe) ncryptsslp.dll - BindAsyncMoniker : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51f90
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CDLGetLongPathNameA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c678d0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CDLGetLongPathNameW : C:\Windows\system32\urlmon.dll @ 0x7ffc57c678e8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CORPolicyProvider : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51674
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoGetClassObjectFromURL : C:\Windows\system32\urlmon.dll @ 0x7ffc57c673fc
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInstall : C:\Windows\system32\urlmon.dll @ 0x7ffc57c67460
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCanonicalizeIUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57c15660
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCombineIUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57c180a0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCombineUrl : C:\Windows\system32\urlmon.dll @ 0x7ffc57c046a4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCombineUrlEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57c043c0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCompareUrl : C:\Windows\system32\urlmon.dll @ 0x7ffc57c55280
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCreateSecurityManager : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd1ee0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetCreateZoneManager : C:\Windows\system32\urlmon.dll @ 0x7ffc57be0810
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetFeatureSettingsChanged : C:\Windows\system32\urlmon.dll @ 0x7ffc57c90284
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetGetProtocolFlags : C:\Windows\system32\urlmon.dll @ 0x7ffc57c5537c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetGetSecurityUrl : C:\Windows\system32\urlmon.dll @ 0x7ffc57c553d0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetGetSecurityUrlEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57c19cd0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetGetSession : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd2460
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetIsFeatureEnabled : C:\Windows\system32\urlmon.dll @ 0x7ffc57c18dc0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetIsFeatureEnabledForIUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57c151b8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetIsFeatureEnabledForUrl : C:\Windows\system32\urlmon.dll @ 0x7ffc57c11820
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetIsFeatureZoneElevationEnabled : C:\Windows\system32\urlmon.dll @ 0x7ffc57c5586c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetParseIUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57c056a8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetParseUrl : C:\Windows\system32\urlmon.dll @ 0x7ffc57be1490
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetQueryInfo : C:\Windows\system32\urlmon.dll @ 0x7ffc57c17c50
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CoInternetSetFeatureEnabled : C:\Windows\system32\urlmon.dll @ 0x7ffc57c55af4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CompareSecurityIds : C:\Windows\system32\urlmon.dll @ 0x7ffc57bed1a4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CompatFlagsFromClsid : C:\Windows\system32\urlmon.dll @ 0x7ffc57c14044
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CopyBindInfo : C:\Windows\system32\urlmon.dll @ 0x7ffc57c63020
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CopyStgMedium : C:\Windows\system32\urlmon.dll @ 0x7ffc57bdba0c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateAsyncBindCtx : C:\Windows\system32\urlmon.dll @ 0x7ffc57c286c0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateAsyncBindCtxEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57c13d14
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateFormatEnumerator : C:\Windows\system32\urlmon.dll @ 0x7ffc57bf68e0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateIUriBuilder : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd3660
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateURLMoniker : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2ccf4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateURLMonikerEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd78d0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateURLMonikerEx2 : C:\Windows\system32\urlmon.dll @ 0x7ffc57c140f0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd16f0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateUriFromMultiByteString : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51ee4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateUriPriv : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51ef8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - CreateUriWithFragment : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51f40
[EAT:Addr] (explorer.exe) ncryptsslp.dll - DllCanUnloadNow : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd1600
[EAT:Addr] (explorer.exe) ncryptsslp.dll - DllGetClassObject : C:\Windows\system32\urlmon.dll @ 0x7ffc57c1ab3c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - DllInstall : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52458
[EAT:Addr] (explorer.exe) ncryptsslp.dll - DllRegisterServer : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52464
[EAT:Addr] (explorer.exe) ncryptsslp.dll - DllRegisterServerEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (explorer.exe) ncryptsslp.dll - DllUnregisterServer : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52470
[EAT:Addr] (explorer.exe) ncryptsslp.dll - Extract : C:\Windows\system32\urlmon.dll @ 0x7ffc57c67f74
[EAT:Addr] (explorer.exe) ncryptsslp.dll - FaultInIEFeature : C:\Windows\system32\urlmon.dll @ 0x7ffc57c68fe8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - FileBearsMarkOfTheWeb : C:\Windows\system32\urlmon.dll @ 0x7ffc57c06b60
[EAT:Addr] (explorer.exe) ncryptsslp.dll - FindMediaType : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52e9c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - FindMediaTypeClass : C:\Windows\system32\urlmon.dll @ 0x7ffc57bf6080
[EAT:Addr] (explorer.exe) ncryptsslp.dll - FindMimeFromData : C:\Windows\system32\urlmon.dll @ 0x7ffc57c150bc
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetAddSitesFileUrl : C:\Windows\system32\urlmon.dll @ 0x7ffc57c902b0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetClassFileOrMime : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2b8ec
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetClassURL : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52074
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetComponentIDFromCLSSPEC : C:\Windows\system32\urlmon.dll @ 0x7ffc57c692e8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetIDNFlagsForUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57bec7f0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetIUriPriv : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51f60
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetIUriPriv2 : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51f50
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetLabelsFromNamedHost : C:\Windows\system32\urlmon.dll @ 0x7ffc57c98b54
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetMarkOfTheWeb : C:\Windows\system32\urlmon.dll @ 0x7ffc57c89390
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetPortFromUrlScheme : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51e94
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetPropertyFromName : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51ea4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetPropertyName : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51eb4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetSoftwareUpdateInfo : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetUrlmonThreadNotificationHwnd : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2deb4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - GetZoneFromAlternateDataStreamEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd6d90
[EAT:Addr] (explorer.exe) ncryptsslp.dll - HlinkGoBack : C:\Windows\system32\urlmon.dll @ 0x7ffc57c86e78
[EAT:Addr] (explorer.exe) ncryptsslp.dll - HlinkGoForward : C:\Windows\system32\urlmon.dll @ 0x7ffc57c86f24
[EAT:Addr] (explorer.exe) ncryptsslp.dll - HlinkNavigateMoniker : C:\Windows\system32\urlmon.dll @ 0x7ffc57c86fd0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - HlinkNavigateString : C:\Windows\system32\urlmon.dll @ 0x7ffc57c87004
[EAT:Addr] (explorer.exe) ncryptsslp.dll - HlinkSimpleNavigateToMoniker : C:\Windows\system32\urlmon.dll @ 0x7ffc57c87038
[EAT:Addr] (explorer.exe) ncryptsslp.dll - HlinkSimpleNavigateToString : C:\Windows\system32\urlmon.dll @ 0x7ffc57c875e8
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IECompatLogCSSFix : C:\Windows\system32\urlmon.dll @ 0x7ffc57c612fc
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IEDllLoader : C:\Windows\system32\urlmon.dll @ 0x7ffc57c526f0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IEGetUserPrivateNamespaceName : C:\Windows\system32\urlmon.dll @ 0x7ffc57c63244
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IEInstallScope : C:\Windows\system32\urlmon.dll @ 0x7ffc57c67554
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IntlPercentEncodeNormalize : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51f70
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsAsyncMoniker : C:\Windows\system32\urlmon.dll @ 0x7ffc57c121fc
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsDWORDProperty : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51ec4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsIntranetAvailable : C:\Windows\system32\urlmon.dll @ 0x7ffc57c90668
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsJITInProgress : C:\Windows\system32\urlmon.dll @ 0x7ffc57beb328
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsLoggingEnabledA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c8855c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsLoggingEnabledW : C:\Windows\system32\urlmon.dll @ 0x7ffc57c88688
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsStringProperty : C:\Windows\system32\urlmon.dll @ 0x7ffc57c51ed4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - IsValidURL : C:\Windows\system32\urlmon.dll @ 0x7ffc57c07610
[EAT:Addr] (explorer.exe) ncryptsslp.dll - MkParseDisplayNameEx : C:\Windows\system32\urlmon.dll @ 0x7ffc57c292f0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - ObtainUserAgentString : C:\Windows\system32\urlmon.dll @ 0x7ffc57c5dce0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - PrivateCoInstall : C:\Windows\system32\urlmon.dll @ 0x7ffc57c67560
[EAT:Addr] (explorer.exe) ncryptsslp.dll - QueryAssociations : C:\Windows\system32\urlmon.dll @ 0x7ffc57bee9c0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - QueryClsidAssociation : C:\Windows\system32\urlmon.dll @ 0x7ffc57c60a8c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RegisterBindStatusCallback : C:\Windows\system32\urlmon.dll @ 0x7ffc57c0f600
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RegisterFormatEnumerator : C:\Windows\system32\urlmon.dll @ 0x7ffc57c11c6c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RegisterMediaTypeClass : C:\Windows\system32\urlmon.dll @ 0x7ffc57c520c0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RegisterMediaTypes : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52210
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RegisterWebPlatformPermanentSecurityManager : C:\Windows\system32\urlmon.dll @ 0x7ffc57c08c54
[EAT:Addr] (explorer.exe) ncryptsslp.dll - ReleaseBindInfo : C:\Windows\system32\urlmon.dll @ 0x7ffc57bd7d40
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RevokeBindStatusCallback : C:\Windows\system32\urlmon.dll @ 0x7ffc57c0fbf0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - RevokeFormatEnumerator : C:\Windows\system32\urlmon.dll @ 0x7ffc57c522cc
[EAT:Addr] (explorer.exe) ncryptsslp.dll - SetAccessForIEAppContainer : C:\Windows\system32\urlmon.dll @ 0x7ffc57c63258
[EAT:Addr] (explorer.exe) ncryptsslp.dll - SetSoftwareUpdateAdvertisementState : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (explorer.exe) ncryptsslp.dll - ShouldDisplayPunycodeForUri : C:\Windows\system32\urlmon.dll @ 0x7ffc57c5de50
[EAT:Addr] (explorer.exe) ncryptsslp.dll - ShouldShowIntranetWarningSecband : C:\Windows\system32\urlmon.dll @ 0x7ffc57c13a3c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - ShowTrustAlertDialog : C:\Windows\system32\urlmon.dll @ 0x7ffc57c90820
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLDownloadA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c55cc4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLDownloadToCacheFileA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c87d9c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLDownloadToCacheFileW : C:\Windows\system32\urlmon.dll @ 0x7ffc57bfa0c4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLDownloadToFileA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c87f10
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLDownloadToFileW : C:\Windows\system32\urlmon.dll @ 0x7ffc57bfefd0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLDownloadW : C:\Windows\system32\urlmon.dll @ 0x7ffc57c55d78
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLOpenBlockingStreamA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c88058
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLOpenBlockingStreamW : C:\Windows\system32\urlmon.dll @ 0x7ffc57c88138
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLOpenPullStreamA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c8821c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLOpenPullStreamW : C:\Windows\system32\urlmon.dll @ 0x7ffc57c882e0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLOpenStreamA : C:\Windows\system32\urlmon.dll @ 0x7ffc57c88408
[EAT:Addr] (explorer.exe) ncryptsslp.dll - URLOpenStreamW : C:\Windows\system32\urlmon.dll @ 0x7ffc57c884d0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - UnregisterWebPlatformPermanentSecurityManager : C:\Windows\system32\urlmon.dll @ 0x7ffc57c2c9b4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - UrlMkBuildVersion : C:\Windows\system32\urlmon.dll @ 0x7ffc57c52804
[EAT:Addr] (explorer.exe) ncryptsslp.dll - UrlMkGetSessionOption : C:\Windows\system32\urlmon.dll @ 0x7ffc57be3e60
[EAT:Addr] (explorer.exe) ncryptsslp.dll - UrlMkSetSessionOption : C:\Windows\system32\urlmon.dll @ 0x7ffc57c0d0e4
[EAT:Addr] (explorer.exe) ncryptsslp.dll - UrlmonCleanupCurrentThread : C:\Windows\system32\urlmon.dll @ 0x7ffc57bfa27c
[EAT:Addr] (explorer.exe) ncryptsslp.dll - WriteHitLogging : C:\Windows\system32\urlmon.dll @ 0x7ffc57c885d0
[EAT:Addr] (explorer.exe) ncryptsslp.dll - ZonesReInit : C:\Windows\system32\urlmon.dll @ 0x7ffc57c89c30
[IAT:Addr] (iexplore.exe) api-ms-win-downlevel-shell32-l1-1-0.dll - SetCurrentProcessExplicitAppUserModelID : C:\Windows\SYSTEM32\shcore.dll @ 0x7ffc5deb6d08
[IAT:Addr] (iexplore.exe) api-ms-win-downlevel-shell32-l1-1-0.dll - CommandLineToArgvW : C:\Windows\SYSTEM32\shcore.dll @ 0x7ffc5de948e8
[IAT:Addr] (iexplore.exe) api-ms-win-downlevel-shell32-l1-1-0.dll - SetCurrentProcessExplicitAppUserModelID : C:\Windows\SYSTEM32\shcore.dll @ 0x7ffc5deb6d08
[IAT:Addr] (iexplore.exe) api-ms-win-downlevel-shell32-l1-1-0.dll - CommandLineToArgvW : C:\Windows\SYSTEM32\shcore.dll @ 0x7ffc5de948e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - AsyncGetClassBits : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c670b0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - AsyncInstallDistributionUnit : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67210
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - BindAsyncMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f90
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CDLGetLongPathNameA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c678d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CDLGetLongPathNameW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c678e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CORPolicyProvider : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51674
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoGetClassObjectFromURL : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c673fc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInstall : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67460
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCanonicalizeIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c15660
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCombineIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c180a0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCombineUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c046a4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCombineUrlEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c043c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCompareUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55280
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCreateSecurityManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd1ee0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCreateZoneManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57be0810
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetFeatureSettingsChanged : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c90284
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetProtocolFlags : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5537c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetSecurityUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c553d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetSecurityUrlEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c19cd0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetSession : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd2460
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureEnabled : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c18dc0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureEnabledForIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c151b8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureEnabledForUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c11820
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureZoneElevationEnabled : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5586c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetParseIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c056a8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetParseUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57be1490
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetQueryInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c17c50
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetSetFeatureEnabled : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55af4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CompareSecurityIds : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bed1a4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CompatFlagsFromClsid : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c14044
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CopyBindInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c63020
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CopyStgMedium : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bdba0c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateAsyncBindCtx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c286c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateAsyncBindCtxEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c13d14
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateFormatEnumerator : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bf68e0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateIUriBuilder : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd3660
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateURLMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2ccf4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateURLMonikerEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd78d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateURLMonikerEx2 : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c140f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd16f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUriFromMultiByteString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ee4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUriPriv : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ef8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUriWithFragment : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f40
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllCanUnloadNow : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd1600
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllGetClassObject : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c1ab3c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllInstall : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52458
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllRegisterServer : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52464
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllRegisterServerEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllUnregisterServer : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52470
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - Extract : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67f74
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FaultInIEFeature : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c68fe8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FileBearsMarkOfTheWeb : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c06b60
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FindMediaType : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52e9c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FindMediaTypeClass : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bf6080
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FindMimeFromData : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c150bc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetAddSitesFileUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c902b0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetClassFileOrMime : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2b8ec
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetClassURL : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52074
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetComponentIDFromCLSSPEC : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c692e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetIDNFlagsForUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bec7f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetIUriPriv : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f60
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetIUriPriv2 : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f50
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetLabelsFromNamedHost : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c98b54
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetMarkOfTheWeb : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c89390
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetPortFromUrlScheme : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51e94
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetPropertyFromName : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ea4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetPropertyName : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51eb4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetSoftwareUpdateInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetUrlmonThreadNotificationHwnd : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2deb4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetZoneFromAlternateDataStreamEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd6d90
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkGoBack : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c86e78
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkGoForward : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c86f24
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkNavigateMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c86fd0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkNavigateString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87004
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkSimpleNavigateToMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87038
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkSimpleNavigateToString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c875e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IECompatLogCSSFix : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c612fc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IEDllLoader : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c526f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IEGetUserPrivateNamespaceName : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c63244
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IEInstallScope : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67554
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IntlPercentEncodeNormalize : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f70
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsAsyncMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c121fc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsDWORDProperty : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ec4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsIntranetAvailable : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c90668
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsJITInProgress : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57beb328
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsLoggingEnabledA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c8855c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsLoggingEnabledW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88688
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsStringProperty : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ed4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsValidURL : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c07610
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - MkParseDisplayNameEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c292f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ObtainUserAgentString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5dce0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - PrivateCoInstall : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67560
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - QueryAssociations : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bee9c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - QueryClsidAssociation : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c60a8c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterBindStatusCallback : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c0f600
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterFormatEnumerator : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c11c6c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterMediaTypeClass : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c520c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterMediaTypes : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52210
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterWebPlatformPermanentSecurityManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c08c54
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ReleaseBindInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd7d40
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RevokeBindStatusCallback : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c0fbf0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RevokeFormatEnumerator : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c522cc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - SetAccessForIEAppContainer : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c63258
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - SetSoftwareUpdateAdvertisementState : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ShouldDisplayPunycodeForUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5de50
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ShouldShowIntranetWarningSecband : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c13a3c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ShowTrustAlertDialog : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c90820
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55cc4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToCacheFileA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87d9c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToCacheFileW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bfa0c4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToFileA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87f10
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToFileW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bfefd0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55d78
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenBlockingStreamA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88058
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenBlockingStreamW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88138
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenPullStreamA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c8821c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenPullStreamW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c882e0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenStreamA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88408
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenStreamW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c884d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UnregisterWebPlatformPermanentSecurityManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2c9b4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlMkBuildVersion : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52804
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlMkGetSessionOption : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57be3e60
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlMkSetSessionOption : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c0d0e4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlmonCleanupCurrentThread : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bfa27c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - WriteHitLogging : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c885d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ZonesReInit : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c89c30
[IAT:Addr] (iexplore.exe) api-ms-win-downlevel-shell32-l1-1-0.dll - SetCurrentProcessExplicitAppUserModelID : C:\Windows\SYSTEM32\shcore.dll @ 0x7ffc5deb6d08
[IAT:Addr] (iexplore.exe) api-ms-win-downlevel-shell32-l1-1-0.dll - CommandLineToArgvW : C:\Windows\SYSTEM32\shcore.dll @ 0x7ffc5de948e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - AsyncGetClassBits : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c670b0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - AsyncInstallDistributionUnit : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67210
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - BindAsyncMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f90
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CDLGetLongPathNameA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c678d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CDLGetLongPathNameW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c678e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CORPolicyProvider : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51674
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoGetClassObjectFromURL : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c673fc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInstall : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67460
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCanonicalizeIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c15660
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCombineIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c180a0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCombineUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c046a4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCombineUrlEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c043c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCompareUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55280
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCreateSecurityManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd1ee0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetCreateZoneManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57be0810
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetFeatureSettingsChanged : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c90284
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetProtocolFlags : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5537c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetSecurityUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c553d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetSecurityUrlEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c19cd0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetGetSession : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd2460
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureEnabled : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c18dc0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureEnabledForIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c151b8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureEnabledForUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c11820
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetIsFeatureZoneElevationEnabled : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5586c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetParseIUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c056a8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetParseUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57be1490
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetQueryInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c17c50
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CoInternetSetFeatureEnabled : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55af4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CompareSecurityIds : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bed1a4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CompatFlagsFromClsid : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c14044
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CopyBindInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c63020
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CopyStgMedium : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bdba0c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateAsyncBindCtx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c286c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateAsyncBindCtxEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c13d14
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateFormatEnumerator : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bf68e0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateIUriBuilder : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd3660
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateURLMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2ccf4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateURLMonikerEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd78d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateURLMonikerEx2 : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c140f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd16f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUriFromMultiByteString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ee4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUriPriv : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ef8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - CreateUriWithFragment : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f40
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllCanUnloadNow : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd1600
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllGetClassObject : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c1ab3c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllInstall : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52458
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllRegisterServer : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52464
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllRegisterServerEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - DllUnregisterServer : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52470
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - Extract : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67f74
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FaultInIEFeature : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c68fe8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FileBearsMarkOfTheWeb : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c06b60
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FindMediaType : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52e9c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FindMediaTypeClass : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bf6080
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - FindMimeFromData : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c150bc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetAddSitesFileUrl : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c902b0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetClassFileOrMime : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2b8ec
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetClassURL : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52074
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetComponentIDFromCLSSPEC : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c692e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetIDNFlagsForUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bec7f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetIUriPriv : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f60
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetIUriPriv2 : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f50
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetLabelsFromNamedHost : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c98b54
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetMarkOfTheWeb : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c89390
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetPortFromUrlScheme : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51e94
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetPropertyFromName : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ea4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetPropertyName : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51eb4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetSoftwareUpdateInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetUrlmonThreadNotificationHwnd : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2deb4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - GetZoneFromAlternateDataStreamEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd6d90
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkGoBack : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c86e78
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkGoForward : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c86f24
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkNavigateMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c86fd0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkNavigateString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87004
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkSimpleNavigateToMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87038
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - HlinkSimpleNavigateToString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c875e8
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IECompatLogCSSFix : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c612fc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IEDllLoader : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c526f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IEGetUserPrivateNamespaceName : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c63244
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IEInstallScope : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67554
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IntlPercentEncodeNormalize : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51f70
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsAsyncMoniker : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c121fc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsDWORDProperty : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ec4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsIntranetAvailable : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c90668
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsJITInProgress : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57beb328
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsLoggingEnabledA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c8855c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsLoggingEnabledW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88688
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsStringProperty : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c51ed4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - IsValidURL : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c07610
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - MkParseDisplayNameEx : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c292f0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ObtainUserAgentString : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5dce0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - PrivateCoInstall : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c67560
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - QueryAssociations : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bee9c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - QueryClsidAssociation : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c60a8c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterBindStatusCallback : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c0f600
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterFormatEnumerator : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c11c6c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterMediaTypeClass : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c520c0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterMediaTypes : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52210
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RegisterWebPlatformPermanentSecurityManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c08c54
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ReleaseBindInfo : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bd7d40
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RevokeBindStatusCallback : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c0fbf0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - RevokeFormatEnumerator : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c522cc
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - SetAccessForIEAppContainer : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c63258
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - SetSoftwareUpdateAdvertisementState : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2e070
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ShouldDisplayPunycodeForUri : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c5de50
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ShouldShowIntranetWarningSecband : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c13a3c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ShowTrustAlertDialog : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c90820
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55cc4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToCacheFileA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87d9c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToCacheFileW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bfa0c4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToFileA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c87f10
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadToFileW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bfefd0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLDownloadW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c55d78
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenBlockingStreamA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88058
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenBlockingStreamW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88138
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenPullStreamA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c8821c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenPullStreamW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c882e0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenStreamA : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c88408
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - URLOpenStreamW : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c884d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UnregisterWebPlatformPermanentSecurityManager : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c2c9b4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlMkBuildVersion : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c52804
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlMkGetSessionOption : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57be3e60
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlMkSetSessionOption : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c0d0e4
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - UrlmonCleanupCurrentThread : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57bfa27c
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - WriteHitLogging : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c885d0
[EAT:Addr] (iexplore.exe) ncryptsslp.dll - ZonesReInit : C:\Windows\SYSTEM32\urlmon.dll @ 0x7ffc57c89c30
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD10JPVT-80A1YT0 +++++
--- User ---
[MBR] 5121ed68627e23ab97862d4b9d9f4d5e
[BSP] 4816b00b2e7efa2cda2c0a65fdf3e385 : Unknown MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_DEL_06012014_121750.log - RKreport_SCN_06012014_121746.log
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 86 hostů