Prosím o zkontrolování logu(zřejmě vetřelec v PC)

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Gilmak
Level 1.5
Level 1.5
Příspěvky: 112
Registrován: květen 13
Bydliště: České Budějovice
Pohlaví: Muž
Stav:
Offline

Prosím o zkontrolování logu(zřejmě vetřelec v PC)

Příspěvekod Gilmak » 10 říj 2014 20:17

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:02:10, on 10.10.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)

FIREFOX: 26.0 (cs)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Users\Jiří\AppData\Local\CatalinaGroup\Update\CatalinaUpdate.exe
C:\Users\Jiří\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\PROGRA~2\Raptr\raptr_im.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Jiří\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.b1.org/?bsrc=hmior&chid=c167991
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN10640A& ... 81-360&t=4
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - (no file)
O2 - BHO: ZiperFly - {1B4D240E-8BDE-4C8D-8B93-C74D2F8A8284} - C:\Program Files (x86)\ZiperFly\ziperfly_ie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.9.799\AVG SafeGuard toolbar_toolbar.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.9.799\AVG SafeGuard toolbar_toolbar.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup
O4 - HKCU\..\Run: [CatalinaGroup Update] "C:\Users\Jiří\AppData\Local\CatalinaGroup\Update\CatalinaUpdate.exe" /c
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Jiří\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Jiří\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - Startup: DesktopWeatherAlerts.lnk = ?
O4 - Startup: Weather Alerts.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: ZiperFly - {1B4D240E-8BDE-4C8D-8B93-C74D2F8A8284} - C:\Program Files (x86)\ZiperFly\ziperfly_ie.dll
O9 - Extra 'Tools' menuitem: ZiperFly - {1B4D240E-8BDE-4C8D-8B93-C74D2F8A8284} - C:\Program Files (x86)\ZiperFly\ziperfly_ie.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{D100AE59-2AF9-4DA7-A7A5-DED7C242CC8C}: NameServer = 10.255.255.10
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater18.1.9 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12623 bytes
PC SESTAVA:
CPU:AMD FX-8300
GPU:ASUS GeForce 1050 Ti 4GB
MB:ASUS 970 PRO GAMING/AURA
8GB RAM
Windows 10 64bit

Reklama
Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o zkontrolování logu(zřejmě vetřelec v PC)

Příspěvekod Orcus » 10 říj 2014 22:39

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.

===================================================

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

===================================================

Stáhni AdwCleaner (by Xplode)

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

===================================================

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
Gilmak
Level 1.5
Level 1.5
Příspěvky: 112
Registrován: květen 13
Bydliště: České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o zkontrolování logu(zřejmě vetřelec v PC)

Příspěvekod Gilmak » 11 říj 2014 14:09

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 10.10.2014
Čas skenování: 22:49:29
Protokol: Plno virů.txt
Správce: Ano

Verze: 2.00.2.1012
Databáze malwaru: v2014.10.10.09
Databáze rootkitů: v2014.10.08.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Self-protection: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: JiA?A­

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 342194
Uplynulý čas: 23 min, 39 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristics: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 1
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\WeatherAlerts.exe, 4664, , [df323cd74f2d78be820be4041ce643bd]

Moduly: 0
(No malicious items detected)

Klíče registru: 16
PUP.Optional.WeatherAlerts.A, HKU\S-1-5-21-439781340-798337663-949953369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DesktopWeatherAlerts, , [c24ff91a86f6c373cebbe95ce0258f71],
PUP.Optional.Somoto, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\FilesFrog Update Checker, , [21f06ea57a022f0745e6b275857b4eb2],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\AmiBs.Installer, , [71a00c072a5250e629105eefad561ce4],
PUP.Optional.PriceGong.A, HKLM\SOFTWARE\CLASSES\APPID\PriceGongIE.DLL, , [b061e13291eb072f5e7be16b996aa55b],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\AmiBs.Installer, , [35dc3bd8304c5dd9013829247093c937],
PUP.Optional.PriceGong.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\PriceGongIE.DLL, , [1cf53cd74c30e3535683a1ab867dc739],
PUP.Optional.PriceGong.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\bkomkajifikmkfnjgphkjcfeepbnojok, , [63aee2316b115cda548763e950b3e818],
PUP.Optional.GreyGray.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\ceiapeodjfjcbfkfkfbdpgbhbgiidjdb, , [e42d48cb205c38fe2a320f71ce3630d0],
PUP.Optional.SafetyNut.A, HKLM\SOFTWARE\WOW6432NODE\SAFETYNUT, , [fd146fa44933290dcd3b7cea4cb8b64a],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, , [4dc4e132aece81b5df9d64fdc63ea759],
PUP.Optional.Somoto.A, HKU\S-1-5-21-439781340-798337663-949953369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Somoto, , [24ed02113e3e0a2c9de50d09946ff907],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-439781340-798337663-949953369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [1df469aacfade15516afbd87de256d93],
PUP.Optional.Softonic.A, HKU\S-1-5-21-439781340-798337663-949953369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [749d0a0985f7b482afd6f54480834eb2],
PUP.Optional.Somoto.A, HKU\S-1-5-21-439781340-798337663-949953369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOMOTO\SDP, , [9879c05396e69c9a15248dd8788c6a96],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-439781340-798337663-949953369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, , [8f82f320126aa98de5960d549c686c94],
PUP.Optional.VideoPlayer.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Video Player, , [fc1545ce16661c1aa274b63728da4bb5],

Hodnoty registru: 5
PUP.Optional.VideoPlayer.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|ext@VideoPlayerV3beta3321.net, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff, , [c1502ae9fe7eca6c06d5c17cce352cd4]
PUP.Optional.SafetyNut.A, HKLM\SOFTWARE\WOW6432NODE\SAFETYNUT|browser, cr, , [fd146fa44933290dcd3b7cea4cb8b64a]
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, {401B6F50-26B6-11E3-B653-50E549697F32}, , [4dc4e132aece81b5df9d64fdc63ea759]
PUP.Optional.Somoto.A, HKU\S-1-5-21-439781340-798337663-949953369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOMOTO\SDP|affid, diablo3crack, , [9879c05396e69c9a15248dd8788c6a96]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-439781340-798337663-949953369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, {401B6F50-26B6-11E3-B653-50E549697F32}, , [8f82f320126aa98de5960d549c686c94]

Data registru: 0
(No malicious items detected)

Složky: 37
PUP.Optional.FilesFrog.A, C:\Users\JiA?A­\AppData\Local\FilesFrog Update Checker, , [3dd4b65dfe7e6dc9b5168462e1217888],
PUP.Optional.FilesFrog.A, C:\Users\JiA?A­\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker, , [46cb4ec5fb811e181cb0984efa08728e],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\Local_Weather_LLC, , [34dd799ac3b90432b5d708e023df4bb5],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\Local_Weather_LLC\WeatherAlerts.exe_Url_veo15wx11vjihgqrmoclek0enwdwtkrn, , [34dd799ac3b90432b5d708e023df4bb5],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\Local_Weather_LLC\WeatherAlerts.exe_Url_veo15wx11vjihgqrmoclek0enwdwtkrn\1.4.0.0, , [34dd799ac3b90432b5d708e023df4bb5],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\content, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\locale, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\locale\en-US, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\skin, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\modules, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\plugins, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong, , [cc45c251c8b45fd726dee20bf2107f81],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ch, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff\chrome, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff\chrome\content, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff\chrome\content\icons, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff\chrome\content\icons\default, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ie, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\default_apps, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Extensions, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\PepperFlash, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\VisualElements, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Firefox, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Firefox\content, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\IE, , [749df2217507ad89fb20678707fb08f8],

Soubory: 203
PUP.Optional.Bitcoin, C:\Windows\SysWOW64\acumncopobqp.exe, , [0d04e330cdaffb3b7ed80dce28d96799],
PUP.Optional.Bitcoin, C:\Windows\SysWOW64\acumncteoch.exe, , [4ec35eb5acd0ea4c65f1617ac63b8080],
PUP.Optional.Bitcoin, C:\Windows\SysWOW64\acumnctter.exe, , [e42d11021864cf670c4a18c3e31e7090],
PUP.Optional.Bitcoin, C:\Windows\SysWOW64\acumncwncsjt.exe, , [927fec2787f544f2b79fd10a32cf7c84],
PUP.BitCoinMiner, C:\Windows\SysWOW64\lcpmncopobqp.exe, , [937ee92a017bef474040958c50b1ce32],
PUP.BitCoinMiner, C:\Windows\SysWOW64\lcpmncteoch.exe, , [55bc779cf18b51e56b1526fbd52c1ee2],
PUP.BitCoinMiner, C:\Windows\SysWOW64\lcpmnctter.exe, , [f31e39da7a02f4421c6430f1d82960a0],
PUP.BitCoinMiner, C:\Windows\SysWOW64\lcpmncwncsjt.exe, , [769b4ac9c6b61026f18f4bd625dcd32d],
Trojan.BitMiner, C:\Windows\SysWOW64\dcgmncopobqp.exe, , [df3227ec3745082eaea5a34934cd35cb],
Trojan.BitMiner, C:\Windows\SysWOW64\dcgmncteoch.exe, , [bd5453c09be102342e2501eba958fe02],
Trojan.BitMiner, C:\Windows\SysWOW64\dcgmnctter.exe, , [51c0de35106c42f4be9519d3758c44bc],
Trojan.BitMiner, C:\Windows\SysWOW64\dcgmncwncsjt.exe, , [729f49ca85f7af87f75c9d4fcc358779],
PUP.Adware.MediaGet, C:\Users\JiA?A­\Downloads\MediaGet_id3025352ids1s.exe, , [0908130091eb58de4ac3e820b05060a0],
PUP.Optional.Softonic, C:\Users\JiA?A­\Downloads\SoftonicDownloader_for_synthesia (1).exe, , [ea279c774537a096e6539682b150d42c],
PUP.Optional.Softonic, C:\Users\JiA?A­\Downloads\SoftonicDownloader_for_synthesia.exe, , [ae63bb58bcc03cfae851ef29b34e04fc],
PUP.Optional.SweetIM, C:\Users\JiA?A­\Downloads\audacity_mp_pgr.exe, , [8889987b225aa492e2fe320df70ea759],
HackTool.Agent.H, C:\Users\JiA?A­\Downloads\[cheat-project.com] WinJect 1.7 2009-05-02.rar, , [759c6ba8cab257dfd923b47b46bc837d],
HackTool.Agent.DC, C:\Users\JiA?A­\Downloads\Extreme-Injector.rar, , [8a8746cdc8b4bc7a76f3074630d1bb45],
PUP.Optional.Amonetize, C:\Users\JiA?A­\Downloads\Nepotvrzeno 19948.crdownload, , [070af51e027a7fb75add4e63ff0230d0],
PUP.Optional.Amonetize, C:\Users\JiA?A­\Downloads\Nepotvrzeno 318890.crdownload, , [24ed17fc6a12eb4bd760545d3ec3e51b],
PUP.BitCoinMiner, C:\Users\JiA?A­\Downloads\cgminer-2.11.4-windows.zip, , [4dc4d0435f1d61d50742827bc23f0cf4],
PUP.Optional.Cgminer, C:\Users\JiA?A­\Downloads\cgminer-3.5.1-windows.zip, , [7899c64d423ae74f9e05d680db26936d],
RiskWare.Tool.CK, C:\Users\JiA?A­\Downloads\sw.bin, , [34dd38db6814290d1f174319f0103bc5],
PUP.Optional.WeatherAlerts.A, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\DesktopWeatherAlertsuninstall.exe, , [c24ff91a86f6c373cebbe95ce0258f71],
PUP.Optional.Somoto, C:\Users\JiA?A­\AppData\Local\FilesFrog Update Checker\uninstall.exe, , [21f06ea57a022f0745e6b275857b4eb2],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DesktopWeatherAlerts.lnk, , [e92869aaf587e254a06d72d7ba4956aa],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Weather Alerts.lnk, , [c64b050e0d6f9b9b6ba3c485d72c0af6],
PUP.Optional.AppsHat.A, C:\Windows\Tasks\Apps Hat-firefoxinstaller.job, , [33dec44fc7b583b37d463150ce369a66],
PUP.Optional.AppsHat.A, C:\Windows\System32\Tasks\Apps Hat-firefoxinstaller, , [79988d869ede67cff7cda9d8fb09f907],
PUP.Optional.FilesFrog.A, C:\Users\JiA?A­\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker\Uninstall.lnk, , [46cb4ec5fb811e181cb0984efa08728e],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\Local_Weather_LLC\WeatherAlerts.exe_Url_veo15wx11vjihgqrmoclek0enwdwtkrn\1.4.0.0\user.config, , [34dd799ac3b90432b5d708e023df4bb5],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\DesktopWeatherAlertsApp.exe, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\DesktopWeatherAlertsApp.exe.config, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\DesktopWeatherAlertsApp0.dat, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\DesktopWeatherAlertsBrowser.exe, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\DesktopWeatherAlertsBrowser.exe.config, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\DesktopWeatherAlertsK.dat, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\DesktopWeatherAlertsU.dat, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\ICSharpCode.SharpZipLib.dll, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\mod.DesktopWeatherAlertsApp0.dat, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\uninstall.exe, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\WAUpdater.exe, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\WAUpdater.exe.config, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\WeatherAlerts.exe, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.WeatherAlerts, C:\Users\JiA?A­\AppData\Local\WeatherAlerts\WeatherAlerts.exe.config, , [df323cd74f2d78be820be4041ce643bd],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\1.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\407.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\83.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\a.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\b.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\c.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\d.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\e.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\f.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\g.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\h.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\i.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\j.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\k.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\l.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\m.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\mru.xml, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\n.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\o.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\p.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\q.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\r.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\s.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\t.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\u.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\v.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\w.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\wlu.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\x.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\y.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\LocalLow\PriceGong\Data\z.txt, , [d0417e954735eb4b2dbfc623ed15bf41],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome.manifest, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\install.rdf, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\content\options.js, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\content\options.xul, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\content\overlay.js, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\content\preferences.xul, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\content\pricegong-3.x.xul, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\content\pricegong-4.x.xul, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\locale\en-US\overlay.dtd, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\locale\en-US\pricegong.dtd, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\skin\overlay.css, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\skin\PriceGong.png, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\modules\pg_tab_wrapper.js, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\plugins\npPriceGong_FF.dll, , [36db1cf7e29a62d442dc36b6a65c21df],
PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Contact Us.lnk, , [cc45c251c8b45fd726dee20bf2107f81],
PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Help.lnk, , [cc45c251c8b45fd726dee20bf2107f81],
PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Homepage.lnk, , [cc45c251c8b45fd726dee20bf2107f81],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\uninstall.exe, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ch\VideoPlayerV3beta3321.crx, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff\chrome.manifest, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff\install.rdf, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff\chrome\content\ffVideoPlayerV3beta3321.js, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff\chrome\content\ffVideoPlayerV3beta3321ffaction.js, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff\chrome\content\overlay.xul, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff\chrome\content\icons\Thumbs.db, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.VideoPlayer.A, C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta3321\ff\chrome\content\icons\default\VideoPlayerV3beta3321_32.png, , [fc1545ce16661c1aa274b63728da4bb5],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\DynamicPricer.exe.config, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\DynamicPricer.zip, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\log.txt, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\background.html, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\background.js, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\manifest.json, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\chrome.exe, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\delegate_execute.exe, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\33.0.1750.117.manifest, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\chrome_100_percent.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\chrome_elf.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\chrome_touch_100_percent.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\d3dcompiler_43.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\d3dcompiler_46.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\ffmpegsumo.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\icudt.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\libegl.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\libglesv2.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\libpeerconnection.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\metro_driver.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\nacl64.exe, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\nacl_irt_x86_32.nexe, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\nacl_irt_x86_64.nexe, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\pdf.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\ppgooglenaclpluginchrome.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\resources.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\secondarytile.png, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\widevinecdmadapter.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\xinput1_3.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\default_apps\docs.crx, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\default_apps\drive.crx, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\default_apps\external_extensions.json, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\default_apps\gmail.crx, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\default_apps\search.crx, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\default_apps\youtube.crx, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Extensions\external_extensions.json, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\hi.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\am.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\ar.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\bg.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\bn.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\ca.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\cs.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\da.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\de.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\el.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\en-GB.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\en-US.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\es-419.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\es.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\et.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\fa.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\fi.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\fil.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\fr.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\gu.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\he.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\hr.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\hu.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\id.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\it.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\ja.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\kn.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\ko.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\lt.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\lv.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\ml.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\mr.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\ms.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\nb.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\nl.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\pl.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\pt-BR.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\pt-PT.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\ro.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\ru.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\sk.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\sl.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\sr.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\sv.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\sw.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\ta.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\te.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\th.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\tr.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\uk.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\vi.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\zh-CN.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\Locales\zh-TW.pak, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\PepperFlash\manifest.json, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\PepperFlash\pepflashplayer.dll, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\VisualElements\logo.png, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\VisualElements\smalllogo.png, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Chrome\Browser\33.0.1750.117\VisualElements\splash-620x300.png, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Firefox\chrome.manifest, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Firefox\install.rdf, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Firefox\content\browserOverlay.js, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Firefox\content\browserOverlay.xul, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.DynamicPricer.A, C:\Users\JiA?A­\AppData\Local\DynamicPricer\Firefox\content\h.css, , [749df2217507ad89fb20678707fb08f8],
PUP.Optional.Ask.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\prefs.js, Dobré: (), Špatné: (user_pref("keyword.URL", "http://dts.search.ask.com/sr?src=ffb&gct=ds&appid=129&systemid=473&v=n12281-360&apn_dtid=BND101&apn_ptnrs=AG1&apn_uid=9192357210334415&o=APN10640&q=");), ,[53be749f215be6508447004e1de84ab6]
PUP.Optional.ASK.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\prefs.js, Dobré: (), Špatné: (user_pref("browser.startup.homepage", "http://www.search.ask.com/?o=APN10640A&gct=hp&d=473-129&v=n12281-360&t=4");), ,[fc1566adacd00c2a4dc43f102bda1de3]

Fyzické sektory: 0
(No malicious items detected)


(end)
PC SESTAVA:
CPU:AMD FX-8300
GPU:ASUS GeForce 1050 Ti 4GB
MB:ASUS 970 PRO GAMING/AURA
8GB RAM
Windows 10 64bit

Uživatelský avatar
Gilmak
Level 1.5
Level 1.5
Příspěvky: 112
Registrován: květen 13
Bydliště: České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o zkontrolování logu(zřejmě vetřelec v PC)

Příspěvekod Gilmak » 11 říj 2014 14:10

# AdwCleaner v3.311 - Report created 11/10/2014 at 13:50:20
# Updated 30/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Jiří - JIŘÍ-PC
# Running from : C:\Users\Jiří\Downloads\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****

Service Found : BCUService
Service Found : wStLib64

***** [ Files / Folders ] *****

File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\Ask.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml
File Found : C:\Users\Jiří\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\searchplugins\Ask.xml
File Found : C:\Users\Jiří\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\user.js
File Found : C:\Windows\System32\drivers\wStLib64.sys
Folder Found : C:\Program Files (x86)\AVG SafeGuard toolbar
Folder Found : C:\Program Files (x86)\AVG Security Toolbar
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Program Files (x86)\DeviceVM
Folder Found : C:\Program Files (x86)\SmartTweak
Folder Found : C:\Program Files (x86)\VideoPlayerV3
Folder Found : C:\Program Files\PCDApp
Folder Found : C:\ProgramData\AVG SafeGuard toolbar
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\AVG Security Toolbar
Folder Found : C:\ProgramData\Media Get LLC
Folder Found : C:\ProgramData\RegClean
Folder Found : C:\ProgramData\SafetyNut
Folder Found : C:\Users\Jiří\AppData\Local\apn
Folder Found : C:\Users\Jiří\AppData\Local\AVG SafeGuard toolbar
Folder Found : C:\Users\Jiří\AppData\Local\b1e
Folder Found : C:\Users\Jiří\AppData\Local\Media Get LLC
Folder Found : C:\Users\Jiří\AppData\Local\MediaGet2
Folder Found : C:\Users\Jiří\AppData\Local\Orbitum
Folder Found : C:\Users\Jiří\AppData\Local\webplayer
Folder Found : C:\Users\Jiří\AppData\LocalLow\AVG SafeGuard toolbar
Folder Found : C:\Users\Jiří\AppData\Roaming\B1Toolbar
Folder Found : C:\Users\Jiří\AppData\Roaming\Media Get LLC
Folder Found : C:\Users\Jiří\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaGet2
Folder Found : C:\Users\Jiří\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
Folder Found : C:\Users\Jiří\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Weather Alerts

***** [ Scheduled Tasks ] *****

Task Found : SomotoUpdateCheckerAutoStart

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\ac5c8e1cb533a4eb97d9178a9b12fda3
Key Found : HKCU\Software\APN PIP
Key Found : HKCU\Software\AVG SafeGuard toolbar
Key Found : HKCU\Software\AVG Security Toolbar
Key Found : HKCU\Software\DeviceVM
Key Found : HKCU\Software\Media Get LLC
Key Found : HKCU\Software\MediaGet
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MediaGet
Key Found : HKCU\Software\OCS
Key Found : HKCU\Software\powerpack
Key Found : HKCU\Software\smarttweak
Key Found : HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\APN PIP
Key Found : [x64] HKCU\Software\AVG SafeGuard toolbar
Key Found : [x64] HKCU\Software\AVG Security Toolbar
Key Found : [x64] HKCU\Software\DeviceVM
Key Found : [x64] HKCU\Software\Media Get LLC
Key Found : [x64] HKCU\Software\MediaGet
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : [x64] HKCU\Software\OCS
Key Found : [x64] HKCU\Software\powerpack
Key Found : [x64] HKCU\Software\smarttweak
Key Found : [x64] HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\AVG SafeGuard toolbar
Key Found : HKLM\SOFTWARE\AVG Security Toolbar
Key Found : HKLM\SOFTWARE\Classes\AddressBarSearch.SearchHook
Key Found : HKLM\SOFTWARE\Classes\AddressBarSearch.SearchHook.1
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{77AA6435-2488-4A94-9FE5-49519DD2ED9B}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Found : HKLM\SOFTWARE\DeviceVM
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\DesktopWeatherAlertsApp_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\DesktopWeatherAlertsApp_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FixMyRegistry
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PriceGong
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : HKLM\SOFTWARE\PIP
Key Found : HKLM\SOFTWARE\Trymedia Systems
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : [x64] HKLM\SOFTWARE\Speedchecker Limited
Key Found : [x64] HKLM\SOFTWARE\systweak
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [BCU]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16635

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.search.ask.com/?o=APN10640A& ... 81-360&t=4

-\\ Mozilla Firefox v26.0 (cs)

[ File : C:\Users\Jiří\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\prefs.js ]

Line Found : user_pref("browser.search.defaultenginename", "Ask.com");
Line Found : user_pref("browser.search.order.1", "Ask.com");
Line Found : user_pref("browser.search.selectedEngine", "Ask.com");
Line Found : user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?o=APN10640A&gct=hp&d=473-129&v=n12281-360&t=4");
Line Found : user_pref("keyword.url", "hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=129&systemid=473&v=n12281-360&apn_dtid=BND101&apn_ptnrs=AG1&apn_uid=9192357210334415&o=APN10640&q=");

-\\ Google Chrome v37.0.2062.124

[ File : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gc ... nrs=AG1&q={searchTerms}

*************************

AdwCleaner[R0].txt - [12843 octets] - [11/10/2014 13:50:20]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [12904 octets] ##########
PC SESTAVA:
CPU:AMD FX-8300
GPU:ASUS GeForce 1050 Ti 4GB
MB:ASUS 970 PRO GAMING/AURA
8GB RAM
Windows 10 64bit

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o zkontrolování logu(zřejmě vetřelec v PC)

Příspěvekod jaro3 » 12 říj 2014 09:29

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Gilmak
Level 1.5
Level 1.5
Příspěvky: 112
Registrován: květen 13
Bydliště: České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o zkontrolování logu(zřejmě vetřelec v PC)

Příspěvekod Gilmak » 12 říj 2014 18:14

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.2 (10.09.2014:1)
OS: Windows 7 Home Premium x64
Ran by Jiýˇ on ne 12.10.2014 at 18:08:08,31
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-439781340-798337663-949953369-1000\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updateGreyGray_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updateGreyGray_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\utilGreyGray_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\utilGreyGray_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\DynamicPricerInstaller_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\DynamicPricerInstaller_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\DynamicPricer_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\DynamicPricer_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\updateGreyGray_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\updateGreyGray_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\utilGreyGray_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\utilGreyGray_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\DynamicPricerInstaller_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\DynamicPricerInstaller_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\DynamicPricer_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\DynamicPricer_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2449FF94-864F-4F8F-AC73-4FB12D4FC990}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Program Files (x86)\apps hat"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"



~~~ FireFox

Successfully deleted: [File] C:\Users\Jiýˇ\AppData\Roaming\mozilla\firefox\profiles\zggcmf46.default\searchplugins\ask.xml
Successfully deleted the following from C:\Users\Jiýˇ\AppData\Roaming\mozilla\firefox\profiles\zggcmf46.default\prefs.js

user_pref("extensions.foxcub.config.encodedConfig", "{\"core\":{\"configUrl\":\"hxxp://download.seznam.cz/software/conf/\",\"updateUrl\":\"hxxp://download.seznam.cz/software/c
user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?o=APN10640A&gct=hp&d=473-129&v=n12281-360&t=4");
user_pref("browser.search.selectedEngine", "Ask.com");
user_pref("browser.search.defaultenginename", "Ask.com");
user_pref("keyword.url", "hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=129&systemid=473&v=n12281-360&apn_dtid=BND101&apn_ptnrs=AG1&apn_uid=9192357210334415&o=APN10640&q="



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 12.10.2014 at 18:13:08,55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
PC SESTAVA:
CPU:AMD FX-8300
GPU:ASUS GeForce 1050 Ti 4GB
MB:ASUS 970 PRO GAMING/AURA
8GB RAM
Windows 10 64bit

Uživatelský avatar
Gilmak
Level 1.5
Level 1.5
Příspěvky: 112
Registrován: květen 13
Bydliště: České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o zkontrolování logu(zřejmě vetřelec v PC)

Příspěvekod Gilmak » 12 říj 2014 18:45

AdwCleaner v3.311 - Report created 12/10/2014 at 18:36:23
# Updated 30/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Jiří - JIŘÍ-PC
# Running from : C:\Users\Jiří\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\Jiří\AppData\Local\AVG SafeGuard toolbar
File Deleted : C:\Users\Jiří\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\searchplugins\Ask.xml

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v26.0 (cs)

[ File : C:\Users\Jiří\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\prefs.js ]

Line Deleted : user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?o=APN10640A&gct=hp&d=473-129&v=n12281-360&t=4");
Line Deleted : user_pref("browser.search.selectedEngine", "Ask.com");
Line Deleted : user_pref("browser.search.defaultenginename", "Ask.com");
Line Deleted : user_pref("keyword.url", "hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=129&systemid=473&v=n12281-360&apn_dtid=BND101&apn_ptnrs=AG1&apn_uid=9192357210334415&o=APN10640&q=");

-\\ Google Chrome v37.0.2062.124

[ File : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gc ... nrs=AG1&q={searchTerms}

*************************

AdwCleaner[R0].txt - [13057 octets] - [11/10/2014 13:50:20]
AdwCleaner[R1].txt - [2028 octets] - [12/10/2014 18:15:03]
AdwCleaner[S0].txt - [12055 octets] - [11/10/2014 13:52:23]
AdwCleaner[S1].txt - [1891 octets] - [12/10/2014 18:36:23]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1951 octets] ##########
PC SESTAVA:
CPU:AMD FX-8300
GPU:ASUS GeForce 1050 Ti 4GB
MB:ASUS 970 PRO GAMING/AURA
8GB RAM
Windows 10 64bit

Uživatelský avatar
Gilmak
Level 1.5
Level 1.5
Příspěvky: 112
Registrován: květen 13
Bydliště: České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o zkontrolování logu(zřejmě vetřelec v PC)

Příspěvekod Gilmak » 12 říj 2014 19:04

alwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 12.10.2014
Čas skenování: 18:42:59
Protokol: MBAM.txt
Správce: Ano

Verze: 2.00.2.1012
Databáze malwaru: v2014.10.10.09
Databáze rootkitů: v2014.10.08.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Self-protection: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: JiA?A­

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 340855
Uplynulý čas: 20 min, 43 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristics: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(No malicious items detected)

Moduly: 0
(No malicious items detected)

Klíče registru: 0
(No malicious items detected)

Hodnoty registru: 0
(No malicious items detected)

Data registru: 0
(No malicious items detected)

Složky: 0
(No malicious items detected)

Soubory: 1
PUP.Optional.ASK.A, C:\Users\JiA?A­\AppData\Roaming\Mozilla\Firefox\Profiles\zggcmf46.default\prefs.js, Dobré: (), Špatné: (user_pref("browser.startup.homepage", "http://www.search.ask.com/?o=APN10640A&gct=hp&d=473-129&v=n12281-360&t=4");), ,[22ef68abe7959f976ca5e56a2ed7da26]

Fyzické sektory: 0
(No malicious items detected)


(end)
PC SESTAVA:
CPU:AMD FX-8300
GPU:ASUS GeForce 1050 Ti 4GB
MB:ASUS 970 PRO GAMING/AURA
8GB RAM
Windows 10 64bit

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o zkontrolování logu(zřejmě vetřelec v PC)

Příspěvekod jaro3 » 13 říj 2014 09:50

. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 107 hostů