Prosím kontrolu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

kurizek
nováček
Příspěvky: 3
Registrován: červen 14
Pohlaví: Žena
Stav:
Offline

Prosím kontrolu

Příspěvekod kurizek » 29 čer 2014 15:18

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:18:14, on 29.6.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\WebcamMax\wcmmon.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Users\OK\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\OK\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\OK\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\OK\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\OK\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\OK\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\OK\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\OK\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\OK\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Trend Micro NSC BHO - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg32.dll
O2 - BHO: Search-Results Toolbar - {3ec1a45c-8bc3-4bfe-b226-4051c5d3d068} - C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (file missing)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: TmBpIeBHO - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O3 - Toolbar: Search-Results Toolbar - {3ec1a45c-8bc3-4bfe-b226-4051c5d3d068} - C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll (file missing)
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [AsusVibeLuncher] C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe /start
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~2.EXE
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe
O4 - HKCU\..\Run: [WebcamMaxAutoRun] "C:\Program Files (x86)\WebcamMax\wcmmon.exe" -a
O4 - HKCU\..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [Google Update] "C:\Users\OK\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\OK\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [Media Finder] "C:\Program Files (x86)\Media Finder\MF.exe" /opentotray
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [BitTorrent] "C:\Users\OK\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
O4 - Global Startup: FancyStart daemon.lnk = ?
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll
O18 - Protocol: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg32.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AMD Reservation Manager - Advanced Micro Devices - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
O23 - Service: Trend Micro Solution Platform (Amsp) - Trend Micro Inc. - C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Datamngr Coordinator (DatamngrCoordinator) - Koyote-Lab Inc - C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TiMiniService - Trend Micro Inc. - C:\Program Files\Trend Micro\Titanium\TiMiniService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 16008 bytes

Reklama
Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Re: Prosím kontrolu

Příspěvekod fredik » 29 čer 2014 15:55

Vítej na fóru.

Stáhni AdwCleaner (by Xplode)
Ulož si ho na plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovém disku jako AdwCleaner[R?].txt), celý jeho obsah sem vlož.


Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět

kurizek
nováček
Příspěvky: 3
Registrován: červen 14
Pohlaví: Žena
Stav:
Offline

Re: Prosím kontrolu

Příspěvekod kurizek » 29 čer 2014 16:57

Děkuji

# AdwCleaner v3.213 - Report created 29/06/2014 at 16:49:27
# Updated 23/06/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : OK - OK-PC
# Running from : C:\Users\OK\Downloads\adwcleaner_3.213.exe
# Option : Scan

***** [ Services ] *****

Service Found : DatamngrCoordinator
Service Found : F06DEFF2-5B9C-490D-910F-35D3A9119622

***** [ Files / Folders ] *****

File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\Ask.xml
File Found : C:\Users\OK\AppData\Local\Temp\END
File Found : C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
File Found : C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\searchplugins\Ask.xml
File Found : C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\searchplugins\Askcom.xml
File Found : C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\searchplugins\icqplugin.xml
File Found : C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\searchplugins\Search_Results.xml
File Found : C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\searchplugins\SweetIm.xml
File Found : C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js
Folder Found : C:\Program Files (x86)\BabylonToolbar
Folder Found : C:\Program Files (x86)\ICQ6Toolbar
Folder Found : C:\Program Files (x86)\Movies Toolbar
Folder Found : C:\Program Files (x86)\Search Results Toolbar
Folder Found : C:\Program Files (x86)\SweetIM
Folder Found : C:\ProgramData\Babylon
Folder Found : C:\ProgramData\BitGuard
Folder Found : C:\ProgramData\Browser Manager
Folder Found : C:\ProgramData\BrowserProtect
Folder Found : C:\ProgramData\DataMngr
Folder Found : C:\ProgramData\ICQ\ICQToolbar
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder
Folder Found : C:\ProgramData\Partner
Folder Found : C:\ProgramData\wincert
Folder Found : C:\Users\OK\AppData\Local\apn
Folder Found : C:\Users\OK\AppData\Local\Babylon
Folder Found : C:\Users\OK\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
Folder Found : C:\Users\OK\AppData\Local\torch
Folder Found : C:\Users\OK\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\OK\AppData\LocalLow\DataMngr
Folder Found : C:\Users\OK\AppData\LocalLow\searchresultstb
Folder Found : C:\Users\OK\AppData\Roaming\Babylon
Folder Found : C:\Users\OK\AppData\Roaming\Media Finder
Folder Found : C:\Users\OK\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com
Folder Found : C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Found : C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\Extensions\ffxtlbr@babylon.com
Folder Found : C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\SweetPacksToolbarData
Folder Found : C:\Users\OK\AppData\Roaming\OpenCandy

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}
Key Found : HKCU\Software\PIP
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\SweetIM
Key Found : HKCU\Software\torch
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\PIP
Key Found : [x64] HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\SweetIM
Key Found : [x64] HKCU\Software\torch
Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Found : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\MF
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2414}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\sweetpacksupdatemanager_rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Results Toolbar
Key Found : HKLM\Software\PIP
Key Found : HKLM\Software\SafetyNut
Key Found : HKLM\Software\SweetIM
Key Found : HKLM\Software\torch
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2414}
Key Found : [x64] HKLM\SOFTWARE\Speedchecker Limited
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Media Finder]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [DataMngr]
Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x86]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17126


-\\ Mozilla Firefox v29.0.1 (cs)

[ File : C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js ]

Line Found : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Line Found : user_pref("browser.newtab.url", "hxxp://home.sweetim.com/?src=97&barid={94AB92B4-4498-11E2-AFAD-E0B9A59B48E3}");
Line Found : user_pref("browser.search.defaultengine", "Ask.com");
Line Found : user_pref("browser.search.defaultenginename", "Ask.com");
Line Found : user_pref("browser.search.order.1", "Ask.com");
Line Found : user_pref("browser.search.selectedEngine", "Ask.com");
Line Found : user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?o=APN10649A&gct=hp&d=414-146&v=a12627-124&t=4");
Line Found : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Line Found : user_pref("extensions.BabylonToolbar_i.babExt", "");
Line Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=111015");
Line Found : user_pref("extensions.BabylonToolbar_i.hardId", "3c83b596000000000000eab9a59aaf3a");
Line Found : user_pref("extensions.BabylonToolbar_i.id", "3c83b596000000000000eab9a59aaf3a");
Line Found : user_pref("extensions.BabylonToolbar_i.instlDay", "15446");
Line Found : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Line Found : user_pref("extensions.BabylonToolbar_i.newTab", false);
Line Found : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Line Found : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Line Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Line Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Line Found : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
Line Found : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Line Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1715:17:45");
Line Found : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Line Found : user_pref("extensions.enabledAddons", "toolbar%40ask.com:3.13.1.100013,%7BA59A9C81-B964-BE12-4B1C-DE2CE845CA2D%7D:5.0.0.12627,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1");
Line Found : user_pref("icqtoolbar.installsource", "1");
Line Found : user_pref("icqtoolbar.skip_default_search", "yes");
Line Found : user_pref("sweetim.toolbar.RevertDialog.enable", "false");
Line Found : user_pref("sweetim.toolbar.UserSelectedSaveSettings", "true");
Line Found : user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "0");
Line Found : user_pref("sweetim.toolbar.Visibility.enable", "true");
Line Found : user_pref("sweetim.toolbar.Visibility.intervaldays", "7");
Line Found : user_pref("sweetim.toolbar.cargo", "3.1010000.10002");
Line Found : user_pref("sweetim.toolbar.cda.DisableOveride.enable", "true");
Line Found : user_pref("sweetim.toolbar.cda.HideOveride.enable", "true");
Line Found : user_pref("sweetim.toolbar.cda.RemoveOveride.enable", "true");
Line Found : user_pref("sweetim.toolbar.cda.returnValue", "none");
Line Found : user_pref("sweetim.toolbar.dialogs.0.enable", "true");
Line Found : user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-handler.js");
Line Found : user_pref("sweetim.toolbar.dialogs.0.height", "335");
Line Found : user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog");
Line Found : user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;");
Line Found : user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff.asp?lang=$locale_id;&toolbar_version=$ITEM_VERSION;&crg=$cargo;");
Line Found : user_pref("sweetim.toolbar.dialogs.0.width", "761");
Line Found : user_pref("sweetim.toolbar.dialogs.1.enable", "true");
Line Found : user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-handler.js");
Line Found : user_pref("sweetim.toolbar.dialogs.1.height", "300");
Line Found : user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog");
Line Found : user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog");
Line Found : user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html");
Line Found : user_pref("sweetim.toolbar.dialogs.1.width", "500");
Line Found : user_pref("sweetim.toolbar.dialogs.2.enable", "true");
Line Found : user_pref("sweetim.toolbar.dialogs.2.handler", "chrome://sim_toolbar_package/content/cdadialog-handler.js");
Line Found : user_pref("sweetim.toolbar.dialogs.2.height", "150");
Line Found : user_pref("sweetim.toolbar.dialogs.2.id", "id_dialog_hide_disable_remove");
Line Found : user_pref("sweetim.toolbar.dialogs.2.title", "Option Dialog");
Line Found : user_pref("sweetim.toolbar.dialogs.2.url", "hxxp://www.sweetim.com/simffbar/simcdadialog.asp");
Line Found : user_pref("sweetim.toolbar.dialogs.2.width", "530");
Line Found : user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.google.com/.*|.*.google.co.in/.*|.*.google.com.br/.*|.*.google.es/.*|.*.youtube.com/.*|.*.yahoo.com/.*|.[...]
Line Found : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
Line Found : user_pref("sweetim.toolbar.keywordUrlGuard.enable", "false");
Line Found : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
Line Found : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
Line Found : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
Line Found : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
Line Found : user_pref("sweetim.toolbar.mode.debug", "false");
Line Found : user_pref("sweetim.toolbar.newtab.created", "true");
Line Found : user_pref("sweetim.toolbar.newtab.enable", "true");
Line Found : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "Ask.com");
Line Found : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "Ask.com");
Line Found : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://start.icq.com/sk27211/");
Line Found : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Line Found : user_pref("sweetim.toolbar.rc.url", "hxxp://www.sweetim.com/simffbar/rc.html?toolbar_version=$ITEM_VERSION;&crg=$cargo;");
Line Found : user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true");
Line Found : user_pref("sweetim.toolbar.scripts.0.callback", "simVerification");
Line Found : user_pref("sweetim.toolbar.scripts.0.domain-blacklist", "");
Line Found : user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(www.|apps.)?facebook\\.com.*");
Line Found : user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb");
Line Found : user_pref("sweetim.toolbar.scripts.0.enable", "false");
Line Found : user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb");
Line Found : user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js");
Line Found : user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "true");
Line Found : user_pref("sweetim.toolbar.scripts.1.callback", "simVerification");
Line Found : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Line Found : user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "hxxps://(www.|apps.)?facebook\\.com.*");
Line Found : user_pref("sweetim.toolbar.scripts.1.elementid", "id_script_sim_fb");
Line Found : user_pref("sweetim.toolbar.scripts.1.enable", "false");
Line Found : user_pref("sweetim.toolbar.scripts.1.id", "id_script_fb_hxxpS");
Line Found : user_pref("sweetim.toolbar.scripts.1.url", "hxxps://sc.sweetim.com/apps/in/fb/infb.js");
Line Found : user_pref("sweetim.toolbar.scripts.2.addcontextdiv", "false");
Line Found : user_pref("sweetim.toolbar.scripts.2.callback", "");
Line Found : user_pref("sweetim.toolbar.scripts.2.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..*|.*.yahoo..*|.*.youtube.com.*|.*ask.com.*|.*.sweetim.com.*");
Line Found : user_pref("sweetim.toolbar.scripts.2.domain-whitelist", "");
Line Found : user_pref("sweetim.toolbar.scripts.2.elementid", "id_predict_include_script");
Line Found : user_pref("sweetim.toolbar.scripts.2.enable", "false");
Line Found : user_pref("sweetim.toolbar.scripts.2.id", "id_script_prad");
Line Found : user_pref("sweetim.toolbar.scripts.2.url", "hxxp://cdn1.certified-apps.com/scripts/shared/enable.js?si=3104&tid=chff1");
Line Found : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"hxxp://*google.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://search.yahoo.com/*\" param=\"[...]
Line Found : user_pref("sweetim.toolbar.search.history", "nejnavstevovanejsi");
Line Found : user_pref("sweetim.toolbar.search.history.capacity", "10");
Line Found : user_pref("sweetim.toolbar.searchguard.enable", "false");
Line Found : user_pref("sweetim.toolbar.searchguard.initialized_by_rc", "true");
Line Found : user_pref("sweetim.toolbar.simapp_id", "{94AB92B4-4498-11E2-AFAD-E0B9A59B48E3}");
Line Found : user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com/?crg=3.1010000.10002&barid={94AB92B4-4498-11E2-AFAD-E0B9A59B48E3}");
Line Found : user_pref("sweetim.toolbar.version", "1.9.0.0");

-\\ Google Chrome v

[ File : C:\Users\OK\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found [Search Provider] : hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10002&barid={94AB92B4-4498-11E2-AFAD-E0B9A59B48E3}
Found [Search Provider] : hxxp://dts.search-results.com/sr?src=cr ... nrs=AGA&q={searchTerms}
Found [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gc ... nrs=AGA&q={searchTerms}
Found [Search Provider] : hxxp://websearch.ask.com/redirect?clien ... YYYYYCZ&q={searchTerms}&
Found [Startup_urls] : hxxp://home.sweetim.com/?crg=3.1010000.10002&barid={94AB92B4-4498-11E2-AFAD-E0B9A59B48E3}
Found [Startup_urls] : hxxp://www.searchnu.com/414?appid=146
Found [Extension] : dednnpigldgdbpgcdpfppmlcnnbjciel
Found [Extension] : jcdgjdiieiljkfkdcloehkohchhpekkn
Found [Extension] : kiplfnciaokpcennlkldkdaeaaomamof
Found [Extension] : ogccgbmabaphcakpiclgcnmcnimhokcj

*************************

AdwCleaner[R0].txt - [22146 octets] - [29/06/2014 16:49:27]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [22207 octets] ##########

kurizek
nováček
Příspěvky: 3
Registrován: červen 14
Pohlaví: Žena
Stav:
Offline

Re: Prosím kontrolu

Příspěvekod kurizek » 29 čer 2014 19:21

Procesy: 3
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe, 1900, , [84b68fef403be650dbac18bca161a957]
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe, 2136, , [84b68fef403be650dbac18bca161a957]
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe, 5448, , [df5b631bde9dfc3a6e3cd7bdbf43758b]

Moduly: 14
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\Datamngr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\Datamngr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\Datamngr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\mgrldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\mgrldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\mgrldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\mgrldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\mgrldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],

Klíče registru: 24
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\SearchQUIEHelper.DNSGuard, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\SearchQUIEHelper.DNSGuard.1, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SearchQUIEHelper.DNSGuard, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SearchQUIEHelper.DNSGuard.1, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, HKU\S-1-5-21-2857083962-1031787881-2126814166-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, , [2614e896651636007a43d81051b212ee],
PUP.Optional.MoviesToolbar.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DATAMNGRCOORDINATOR, , [84b68fef403be650dbac18bca161a957],
PUP.Optional.DataMngr.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Datamngr, , [1f1bf985dba0fe38a10a82653ac9b44c],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2857083962-1031787881-2126814166-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [50eacdb136458caa4732a41c38cab947],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-2857083962-1031787881-2126814166-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, , [63d783fb0d6e78bedfdd5e8aaa59728e],
PUP.Optional.MoviesToolbar.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\F06DEFF2-5B9C-490D-910F-35D3A9119622, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.SearchResults.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3ec1a45c-8bc3-4bfe-b226-4051c5d3d068}, , [2614f7877dfe989e81dfb6d9d52fc63a],
PUP.Optional.SearchResults.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}, , [2614f7877dfe989e81dfb6d9d52fc63a],
PUP.Optional.SearchResults.A, HKU\S-1-5-21-2857083962-1031787881-2126814166-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}, , [2614f7877dfe989e81dfb6d9d52fc63a],
PUP.Optional.SearchResults.A, HKU\S-1-5-21-2857083962-1031787881-2126814166-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}, , [2614f7877dfe989e81dfb6d9d52fc63a],
PUP.Optional.SearchResults.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}, , [2614f7877dfe989e81dfb6d9d52fc63a],

Hodnoty registru: 5
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|DATAMNGR, C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~2.EXE, , [ef4b4e30aecd34029e4dfce8e91a728e]
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, {94AB92B4-4498-11E2-AFAD-E0B9A59B48E3}, , [2614e896651636007a43d81051b212ee]
PUP.Optional.MoviesToolbar.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DATAMNGRCOORDINATOR|ImagePath, C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe, , [84b68fef403be650dbac18bca161a957]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-2857083962-1031787881-2126814166-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, {94AB92B4-4498-11E2-AFAD-E0B9A59B48E3}, , [63d783fb0d6e78bedfdd5e8aaa59728e]
PUP.Optional.SearchResults.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}, Search-Results Toolbar, , [2614f7877dfe989e81dfb6d9d52fc63a]

Data registru: 0
(No malicious items detected)

Složky: 21
PUP.Optional.Datamngr.A, C:\ProgramData\Datamngr, , [49f1611de19adc5ad02318d421e25fa1],
PUP.Optional.Datamngr.A, C:\Program Files (x86)\Search Results Toolbar\Datamngr, , [2e0c45392b50a88e63d9464e90723bc5],
PUP.Optional.Datamngr.A, C:\Program Files (x86)\Search Results Toolbar\Datamngr\x64, , [2e0c45392b50a88e63d9464e90723bc5],
PUP.Optional.OpenCandy, C:\Users\OK\AppData\Roaming\OpenCandy, , [91a94d31601b999d2741d0c49f63f709],
PUP.Optional.OpenCandy, C:\Users\OK\AppData\Roaming\OpenCandy\788C6C8BF7904E4A922C5137C681333A, , [91a94d31601b999d2741d0c49f63f709],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\x64, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.SweetIM.A, C:\Program Files (x86)\SweetIM\Toolbars, , [5bdf3648dd9ed95db62cd8bc2bd7a858],
PUP.Optional.SweetIM.A, C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer, , [5bdf3648dd9ed95db62cd8bc2bd7a858],
PUP.Optional.SweetIM.A, C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT, , [5bdf3648dd9ed95db62cd8bc2bd7a858],
PUP.Optional.WhiteSmoke.A, C:\Users\OK\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj, , [e7534a34a4d755e110f28c0d61a15da3],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\components, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\defaults, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\defaults\preferences, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.ColorMyFacebook.A, C:\Users\OK\AppData\Local\Color My Facebook, , [5dddc8b645360531e02d12894eb48f71],
PUP.Optional.ColorMyFacebook.A, C:\Users\OK\AppData\Local\Color My Facebook\Chrome, , [5dddc8b645360531e02d12894eb48f71],
PUP.Optional.CrossRider.A, C:\Users\OK\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdlgbpbmiiagaikjbednkikinokbkbcb, , [a397e599c4b7e15593fcddbf45bd728e],

Soubory: 123
PUP.Optional.Datamngr.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\IEBHO.dll, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Datamngr.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\IEBHO.dll, , [9d9db0ceb5c69f975fdad0b2847e03fd],
PUP.Optional.Softonic.A, C:\Users\OK\AppData\Local\Temp\KMP_3.9.0.124.exe, , [93a77d0179028bab800978ade51c3ac6],
PUP.Optional.Conduit, C:\Users\OK\AppData\Local\Temp\nsuBCBE.tmp\bsplayer.exe, , [291188f6ec8f38fe7302199c976d9070],
PUP.Optional.MoviesToolbar.A, C:\Windows\Temp\79585260\SetupDataMngr_Koyote.exe, , [58e23747a3d8eb4be23e26f79d64c739],
PUP.Optional.MoviesToolbar.A, C:\Windows\Temp\7e08797c\SetupDataMngr_Koyote.exe, , [6fcbb2cccbb0c4720818a07d6b96c23e],
PUP.Optional.MoviesToolbar.A, C:\Windows\Temp\ac5f2480\SetupDataMngr_Koyote.exe, , [cc6e621ced8e5cdac35d61bca35ea858],
PUP.Optional.OpenCandy, C:\Users\OK\Downloads\DTLite4453-0297.exe, , [f743017d81fa9e98695f7639eb1956aa],
PUP.Optional.OpenCandy, C:\Users\OK\Downloads\DTLite4454-0314.exe, , [72c825596e0daf877b4d8b242fd5619f],
PUP.Optional.Conduit, C:\Users\OK\Downloads\bsplayer-setup.exe, , [3a00eb9357242d093d387045b64ee818],
RiskWare.Tool.CK, C:\Windows\AutoKMS.exe, , [9f9b2e50b2c9c86e30a9c2d67193e818],
PUP.Optional.SweetIM.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\searchplugins\sweetim.xml, , [cb6f661803783afcdf7bdddd3dc58977],
PUP.Optional.Datamngr.A, C:\ProgramData\Wincert\win32cert.dll, , [8bafaed0ea9186b0144c06e5887bc13f],
PUP.Optional.Datamngr.A, C:\ProgramData\Wincert\win64cert.dll, , [94a6fd81552682b4f26e03e863a056aa],
PUP.Optional.Datamngr.A, C:\ProgramData\Wincert\win32prop.dll, , [7ebcea94691280b6a1c0e506719222de],
PUP.Optional.Datamngr.A, C:\ProgramData\Wincert\win64prop.dll, , [ce6cc9b5ff7cf145115014d76d96e21e],
PUP.Optional.Datamngr.A, C:\ProgramData\Datamngr\coordinator.cfg, , [49f1611de19adc5ad02318d421e25fa1],
PUP.Optional.Datamngr.A, C:\ProgramData\Datamngr\general.cfg, , [49f1611de19adc5ad02318d421e25fa1],
PUP.Optional.Datamngr.A, C:\ProgramData\Datamngr\S-1-5-21-2857083962-1031787881-2126814166-1001.cfg, , [49f1611de19adc5ad02318d421e25fa1],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe, , [84b68fef403be650dbac18bca161a957],
PUP.Optional.Datamngr.A, C:\Program Files (x86)\Search Results Toolbar\Datamngr\del_DM_LL_nsf98BB.dll, , [2e0c45392b50a88e63d9464e90723bc5],
PUP.Optional.Datamngr.A, C:\Program Files (x86)\Search Results Toolbar\Datamngr\x64\del_DM_LL_nsf98BB.dll, , [2e0c45392b50a88e63d9464e90723bc5],
PUP.Optional.OpenCandy, C:\Users\OK\AppData\Roaming\OpenCandy\788C6C8BF7904E4A922C5137C681333A\AVG-PC-TuneUp2014.exe, , [91a94d31601b999d2741d0c49f63f709],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\Datamngr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrChrome.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\del_DM_DLL_nscDE45.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\del_DM_LL_nscDE45.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\del_mg_nscDE45.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\favicon.ico, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\Helper.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\Internet Explorer Settings.exe, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\mgrldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\setmgrc1.cfg, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\Uninstall.exe, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\Datamngr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\del_DM_LL_nscDE45.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\Internet Explorer Settings.exe, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\mgrldr.dll, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.MoviesToolbar.A, C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\setmgrc1.cfg, , [df5b631bde9dfc3a6e3cd7bdbf43758b],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\chrome.manifest, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\install.rdf, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\components\acplus-autocomplete.js, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\babylon.css, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\babylon.xul, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\mtstart.js, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\server.js, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\tmplt.js, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\arwDwn.gif, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\bbyln.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\help_16.gif, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\home.gif, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\logo.PNG, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\privecy_16_hot.gif, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\tellafriend.gif, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\vssver.scc, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ae.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\bg.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ch.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cn.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cz.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\de.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\eg.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\en.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\es.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\fr.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\gr.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\he.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\il.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\it.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ja.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\jp.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\nl.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\no.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pl.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pt.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ro.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ru.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sa.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\se.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sv.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\Thumbs.db, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\tr.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ua.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\us.png, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\defaults\preferences\babylon.js, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\extensions\ffxtlbr@babylon.com\defaults\preferences\instlPref.js, , [c278e9955e1d8ea8bc1b1f7ad82aa060],
PUP.Optional.ColorMyFacebook.A, C:\Users\OK\AppData\Local\Color My Facebook\Chrome\Color My Facebook.crx, , [5dddc8b645360531e02d12894eb48f71],
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.aflt", "babsst");), ,[6dcde39bc7b442f43aa2f4c5f90bcb35]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.babExt", "");), ,[90aa2955d4a77cba13c93c7d0df7db25]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.babTrack", "affID=111015");), ,[f84293ebd6a513234597c7f233d12dd3]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.hardId", "3c83b596000000000000eab9a59aaf3a");), ,[ff3b0e70453633033d9fd0e91fe5b54b]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.id", "3c83b596000000000000eab9a59aaf3a");), ,[e654c7b73f3c8da93d9f5b5e81837987]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.instlDay", "15446");), ,[ce6c0678a1dae94dae2e4f6a6c9819e7]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.instlRef", "sst");), ,[003a82fcc2b9f73f54882a8fa06436ca]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.newTab", false);), ,[ae8cee902853d462bc20bffa72922bd5]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");), ,[96a4c9b5483381b5d20aaa0f40c4f60a]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");), ,[63d70f6faccf3df913c93f7a82827987]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.smplGrp", "none");), ,[2b0f5b23126950e608d4b5045aaac739]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.srcExt", "ss");), ,[04365f1f700b7cbac11bdcdd93713ec2]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.tlbrId", "base");), ,[ad8db4cabdbee84e9a42dcdd5fa52ad6]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");), ,[84b6ff7f80fbb2848755942534d060a0]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1715:17:45");), ,[1525f688017a2214aa322396c53f8c74]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");), ,[54e6fe804734e0568c506e4bd82c17e9]
PUP.Optional.ASK.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\prefs.js, Dobré: (), Špatné: (user_pref("browser.startup.homepage", "http://www.search.ask.com/?o=APN10649A&gct=hp&d=414-146&v=a12627-124&t=4");), ,[71c9ee90e19a26107a711d9cd82c7090]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.id", "3c83b596000000000000eab9a59aaf3a");), ,[65d5f589fa8181b5500eebced133dc24]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.hardId", "3c83b596000000000000eab9a59aaf3a");), ,[c1791f5f651662d4005ee1d8758f8779]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.instlDay", "15446");), ,[78c276085b20280e73eb1a9fee16fb05]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");), ,[c27857277dfe64d280de35849371ba46]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");), ,[d5650b73ff7c1d19c49ac9f08084c739]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1715:17:45");), ,[ef4b225c80fb38febea04c6d36ce649c]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");), ,[d268a5d9d2a92c0ac39bbbfe808441bf]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");), ,[9c9e81fd96e5b18572ec4a6f4aba24dc]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.aflt", "babsst");), ,[3703a0decdae1521e07ed5e4f70d41bf]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.smplGrp", "none");), ,[4feb1965601b3df98ad4af0a15ef48b8]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.tlbrId", "base");), ,[b387e29c5229d0663826883119ebb64a]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.newTab", false);), ,[8dad4935ee8dfc3a71ed4f6a23e1aa56]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.babTrack", "affID=111015");), ,[8fabf985681370c68ed05960669e0000]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.babExt", "");), ,[3bff84fa59229f97de80ffba36cedf21]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.srcExt", "ss");), ,[55e5502e433841f5aab48930a3618878]
PUP.Optional.Babylon.A, C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\8pts6lo8.default\user.js, Dobré: (), Špatné: (user_pref("extensions.BabylonToolbar_i.instlRef", "sst");), ,[3ffb740ad5a690a65d0171480ff56997]

Fyzické sektory: 0
(No malicious items detected)


(end)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím kontrolu

Příspěvekod jaro3 » 29 čer 2014 20:55

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 91 hostů