Dobrý den
Již dva dny zkouším řešit problém pročetla jsem hodně sekcí ale nevím si dál rady.Nefunguje mi internet jen na stahování mohu načítat stránky některé poněk hůře ale at se snažím o jakékoliv stažení ,nefunguje ani aktualizace hitjack jsem stáhla pro jeho malou velikost ostaní se zaseknou asi kolem 4 mb spíš měně.Zkouším přes ie mozilu a free rapid všude stejné.Při trasování je vše v pořádku dokonce v tak dokonalém které jsem nikdy neměla jsem na wifi .Poskytovatel se semnou odmítá bavit prý je vše ok .Tento problém ale nastal u všech pc které ma připojené na switch nikdo nestáhne ani jeden soubor .Dělala jsem udržbu přes eset ale začalo to házet modrou smrt eset jsem odinstalovala modrá smrt přestala ale problém který jsem řešila na začátku je ještě horší a nemohu si stáhnout ani jiný antivir ani aktualizace win nic nefunguje přikládám log apředem díky za jakoukoliv pomoc
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 12:26:25, on 18.1.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
FIREFOX: 34.0.5 (x86 cs)
Boot mode: Normal
Running processes:
K:\programy ++\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
K:\instalace programy\NetWorx\networx.exe
C:\Program Files\NetSoftware\NetSoftware.exe
C:\Users\nikdo\AppData\Local\Temp\widows.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_257.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_257.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
K:\stahování\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - K:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - (no file)
O2 - BHO: InternetPanelBHO - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\NetSoftware\IEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NetWorx] "K:\instalace programy\NetWorx\networx.exe" /auto
O4 - HKLM\..\Run: [NetSoftware] "C:\Program Files\NetSoftware\Starter.exe" /path="C:\Program Files\NetSoftware"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] K:\programy ++\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - Startup: 284db1d79e871dc8e3adb71dcdf8747f.exe
O4 - Startup: svhost.exe
O4 - Global Startup: GIGABYTE OC_GURU.lnk = C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU\OC_GURU.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - K:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - K:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - K:\programy ++\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10144 bytes
kontrola ,nefunguje internet stahování, ping ok Vyřešeno
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: kontrola ,nefunguje internet stahování, ping ok
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranìní historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit doèasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner
Ulož si ho na svojí plochu
Ukonči všechny programy, okna a prohlížeče
Spusť program poklepáním a klikni na „Search“
Po skenu se objeví log (jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na Kopírovat do schránky a a vlož sem celý log.
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranìní historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit doèasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner
Ulož si ho na svojí plochu
Ukonči všechny programy, okna a prohlížeče
Spusť program poklepáním a klikni na „Search“
Po skenu se objeví log (jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na Kopírovat do schránky a a vlož sem celý log.
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: kontrola ,nefunguje internet stahování, ping ok
# AdwCleaner v4.108 - Report created 18/01/2015 at 18:18:34
# Updated 17/01/2015 by Xplode
# Database : 2015-01-13.2 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : nikdo - NIKDY
# Running from : C:\Users\nikdo\Desktop\adwcleaner_4.108(2).exe
# Option : Scan
***** [ Services ] *****
Service Found : vToolbarUpdater18.2.0
***** [ Files / Folders ] *****
File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\delta-homes.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
File Found : C:\Users\nikdo\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\avg-secure-search.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\funmoods.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\Conduit.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\funmoods.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\user.js
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\Askcom.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\funmoods.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\qip-search.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\user.js
File Found : C:\Users\Public\Desktop\iLivid.lnk
File Found : C:\Users\Public\Desktop\iLivid.lnk
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Program Files (x86)\SupTab
Folder Found : C:\Program Files (x86)\WinZipper
Folder Found : C:\ProgramData\AlawarWrapper
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\AVG Security Toolbar
Folder Found : C:\ProgramData\IePluginServices
Folder Found : C:\ProgramData\Trymedia
Folder Found : C:\ProgramData\WindowsMangerProtect
Folder Found : C:\Users\nikdo\AppData\Local\AlawarWrapper
Folder Found : C:\Users\nikdo\AppData\Local\apn
Folder Found : C:\Users\nikdo\AppData\Local\cool_mirage
Folder Found : C:\Users\nikdo\AppData\Local\PackageAware
Folder Found : C:\Users\nikdo\AppData\Local\SwvUpdater
Folder Found : C:\Users\nikdo\AppData\LocalLow\Funmoods
Folder Found : C:\Users\nikdo\AppData\LocalLow\PriceGong
Folder Found : C:\Users\nikdo\AppData\Roaming\eCyber
Folder Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\Extensions\Avg@toolbar
Folder Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\Extensions\{32A1FD71-835E-4B11-8E54-886FDA0B4C89}
Folder Found : C:\Users\nikdo\AppData\Roaming\WinZipper
Folder Found : C:\Users\Public\Documents\AlawarWrapper
Folder Found : C:\Users\Public\Documents\iWin
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191
Key Found : HKCU\Software\1ClickDownload
Key Found : HKCU\Software\27ccc8c626aecdf2927cdc5ef0c9bde2
Key Found : HKCU\Software\284db1d79e871dc8e3adb71dcdf8747f
Key Found : HKCU\Software\84de8db26feb13
Key Found : HKCU\Software\AppDataLow\Software\adawarebp
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKCU\Software\Mozilla\Extends
Key Found : HKCU\Software\SupHpUISoft
Key Found : [x64] HKCU\Software\1ClickDownload
Key Found : [x64] HKCU\Software\DataMngr
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : [x64] HKCU\Software\SupHpUISoft
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{A2773ED4-83BD-488A-A186-73590706C916}
Key Found : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Found : HKLM\SOFTWARE\Classes\S
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\DataMngr
Key Found : HKLM\SOFTWARE\delta-homesSoftware
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh
Key Found : HKLM\SOFTWARE\hdcode
Key Found : HKLM\SOFTWARE\istartsurfSoftware
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : HKLM\SOFTWARE\SupDp
Key Found : HKLM\SOFTWARE\SupTab
Key Found : HKLM\SOFTWARE\supWindowsMangerProtect
Key Found : HKLM\SOFTWARE\supWPM
Key Found : HKLM\SOFTWARE\systweak
Key Found : HKLM\SOFTWARE\Trymedia Systems
Key Found : HKLM\SOFTWARE\V9
Key Found : HKLM\SOFTWARE\winzipersvc
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16428
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant] - hxxp://search.qip.ru/ie
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [bProtectTabs] - hxxp://mixidj.delta-search.com/?affID=1 ... 6F65CE77B8
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds& ... BA04191&q={searchTerms}
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.delta-homes.com/?type=hp&ts= ... JX0BA04191
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.delta-homes.com/?type=hp&ts= ... JX0BA04191
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds& ... BA04191&q={searchTerms}
-\\ Mozilla Firefox v35.0 (x86 cs)
[g0syoo15.default-1349863581988] - Line Found : user_pref("browser.newtab.url", "hxxp://www.delta-homes.com/newtab/?type=nt&ts=1419407016&from=wpm12233&uid=SAMSUNGXHD103SJ_S246JX0BA04191");
[g0syoo15.default-1349863581988] - Line Found : user_pref("browser.search.selectedEngine", "AVG Secure Search");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.aflt", "ddrnw");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.dfltLng", "");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.dfltSrch", true);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.dnsErr", true);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.excTlbr", false);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.hmpg", true);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=ddrnw");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.id", "c20d6c7b0000000000001c6f65ce77b8");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.instlDay", "15710");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.instlRef", "");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.newTab", true);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=ddrnw");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.prdct", "funmoods");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.prtnrId", "funmoods");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.smplGrp", "none");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.srchPrvdr", "Search");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.tlbrId", "base");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=ddrnw&q=");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.vrsn", "1.5.11.16");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.vrsnTs", "1.5.11.1622:26:22");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.vrsni", "1.5.11.16");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.quick_start.enable_search1", false);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595..clientLogIsEnabled", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.CT2832595", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.CurrentServerDate", "20-7-2012");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.DSInstall", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.DialogsAlignMode", "LTR");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.DialogsGetterLastCheckTime", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.DownloadReferralCookieData", "");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FirstServerDate", "20-7-2012");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FirstTime", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FirstTimeFF3", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FirstTimeHiddenVer", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FixPageNotFoundErrors", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.GroupingServerCheckInterval", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.HPInstall", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.HasUserGlobalKeys", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.HomePageProtectorEnabled", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.HomepageBeforeUnload", "www.seznam.cz");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.Initialize", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.InitializeCommonPrefs", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.InstallationAndCookieDataSentCount", 2);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.InstallationType", "Unknown");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.InstalledDate", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsAlertDBUpdated", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsGrouping", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsInitSetupIni", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsMulticommunity", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsOpenThankYouPage", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsOpenUninstallPage", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsProtectorsInit", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LanguagePackLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LanguagePackReloadIntervalMM", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LastLogin_3.14.1.0", "Tue Jun 19 2012 06:03:26 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LatestVersion", "3.13.0.6");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.Locale", "en");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.MCDetectTooltipHeight", "83");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.MCDetectTooltipWidth", "295");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.MyStuffEnabledAtInstallation", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.OriginalFirstVersion", "3.14.1.0");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SHRINK_TOOLBAR", 1);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SavedHomepage", "chrome://branding/locale/browserconfig.properties");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchCaption", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchEngineBeforeUnload", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchFromAddressBarIsInit", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=2&q=");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchInNewTabEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchInNewTabIntervalMM", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchInNewTabLastCheckTime", "Tue Jun 19 2012 00:38:59 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchProtectorEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchProtectorToolbarDisabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SendProtectorDataViaLogin", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ServiceMapLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SettingsLastCheckTime", "Tue Jun 19 2012 06:03:25 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SettingsLastUpdate", "1342353688");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2832595&SearchSource=13");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ThirdPartyComponentsInterval", 504);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ThirdPartyComponentsLastCheck", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ThirdPartyComponentsLastUpdate", "1331805997");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ToolbarDisabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ToolbarShrinkedFromSetup", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.UserID", "UN66842355699789321");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ValidationData_Toolbar", 2);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.alertChannelId", "1224658");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.activetoolbar", "77657374");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.toolbar_market", "637A");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.toolbarurl", "687474703A2F2F746F6F6C6261722E696E6E6F67616D65732E64652F746F6F6C626172732F776573742F746F6F6C6261722E706870");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.west_password_cz", "5A57787063327468");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.west_session_id_cz", "30366139633234643932643930343531");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.west_username_cz", "61584A6C6247467A");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.west_world_url_cz", "687474703A2F2F637A31312E7468652D776573742E637A");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.globalFirstTimeInfoLastCheckTime", "Tue Jun 19 2012 00:39:02 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.homepageProtectorEnableByLogin", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.initDone", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.isAppTrackingManagerOn", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffPublihserMinWidth", 400);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffServiceIntervalMM", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.navigateToUrlOnSearch", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.revertSettingsEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.searchProtectorDialogDelayInSec", 10);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.searchProtectorEnableByLogin", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.testingCtid", "");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.toolbarAppMetaDataLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.toolbarContextMenuLastCheckTime", "Tue Jun 19 2012 00:38:55 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.usagesFlag", 2);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2832595&SearchSource=13");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ConduitSearchList", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "G9mW7heT/8xIX1frcduu0A==");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "mfQ70fvlD2zuBxSBj8rQqA==");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "UgzXjW7BIkfdx+x39Ruv3w==");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "4BgM4MhF/sOgPsDNmIs3Yw==");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\nikdo\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\h3z7n07y.default-1340054342780\\conduitCommon\\modules\\3.14.1.0");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.14.1.0");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ToolbarsList", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.globalUserId", "391fe62a-3022-4398-9628-b9e8e063f367");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.alertEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Jun 19 2012 01:38:58 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.locale", "en");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.userId", "c828a219-d890-4df5-b53d-ead686137cd0");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("browser.search.defaultthis.engineName", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=3&q={searchTerms}");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
-\\ Google Chrome v39.0.2171.99
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
-\\ Chromium v
[C:\Users\nikdo\AppData\Local\Chromium\User Data\Default\preferences] - Found [Homepage] : hxxp://qip.ru
*************************
AdwCleaner[R0].txt - [31704 octets] - [18/01/2015 18:18:34]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [31765 octets] ##########
# Updated 17/01/2015 by Xplode
# Database : 2015-01-13.2 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : nikdo - NIKDY
# Running from : C:\Users\nikdo\Desktop\adwcleaner_4.108(2).exe
# Option : Scan
***** [ Services ] *****
Service Found : vToolbarUpdater18.2.0
***** [ Files / Folders ] *****
File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\delta-homes.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
File Found : C:\Users\nikdo\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\avg-secure-search.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\funmoods.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\Conduit.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\funmoods.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\user.js
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\Askcom.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\funmoods.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\qip-search.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\user.js
File Found : C:\Users\Public\Desktop\iLivid.lnk
File Found : C:\Users\Public\Desktop\iLivid.lnk
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Program Files (x86)\SupTab
Folder Found : C:\Program Files (x86)\WinZipper
Folder Found : C:\ProgramData\AlawarWrapper
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\AVG Security Toolbar
Folder Found : C:\ProgramData\IePluginServices
Folder Found : C:\ProgramData\Trymedia
Folder Found : C:\ProgramData\WindowsMangerProtect
Folder Found : C:\Users\nikdo\AppData\Local\AlawarWrapper
Folder Found : C:\Users\nikdo\AppData\Local\apn
Folder Found : C:\Users\nikdo\AppData\Local\cool_mirage
Folder Found : C:\Users\nikdo\AppData\Local\PackageAware
Folder Found : C:\Users\nikdo\AppData\Local\SwvUpdater
Folder Found : C:\Users\nikdo\AppData\LocalLow\Funmoods
Folder Found : C:\Users\nikdo\AppData\LocalLow\PriceGong
Folder Found : C:\Users\nikdo\AppData\Roaming\eCyber
Folder Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\Extensions\Avg@toolbar
Folder Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\Extensions\{32A1FD71-835E-4B11-8E54-886FDA0B4C89}
Folder Found : C:\Users\nikdo\AppData\Roaming\WinZipper
Folder Found : C:\Users\Public\Documents\AlawarWrapper
Folder Found : C:\Users\Public\Documents\iWin
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191
Key Found : HKCU\Software\1ClickDownload
Key Found : HKCU\Software\27ccc8c626aecdf2927cdc5ef0c9bde2
Key Found : HKCU\Software\284db1d79e871dc8e3adb71dcdf8747f
Key Found : HKCU\Software\84de8db26feb13
Key Found : HKCU\Software\AppDataLow\Software\adawarebp
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKCU\Software\Mozilla\Extends
Key Found : HKCU\Software\SupHpUISoft
Key Found : [x64] HKCU\Software\1ClickDownload
Key Found : [x64] HKCU\Software\DataMngr
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : [x64] HKCU\Software\SupHpUISoft
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{A2773ED4-83BD-488A-A186-73590706C916}
Key Found : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Found : HKLM\SOFTWARE\Classes\S
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\DataMngr
Key Found : HKLM\SOFTWARE\delta-homesSoftware
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh
Key Found : HKLM\SOFTWARE\hdcode
Key Found : HKLM\SOFTWARE\istartsurfSoftware
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : HKLM\SOFTWARE\SupDp
Key Found : HKLM\SOFTWARE\SupTab
Key Found : HKLM\SOFTWARE\supWindowsMangerProtect
Key Found : HKLM\SOFTWARE\supWPM
Key Found : HKLM\SOFTWARE\systweak
Key Found : HKLM\SOFTWARE\Trymedia Systems
Key Found : HKLM\SOFTWARE\V9
Key Found : HKLM\SOFTWARE\winzipersvc
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16428
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant] - hxxp://search.qip.ru/ie
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [bProtectTabs] - hxxp://mixidj.delta-search.com/?affID=1 ... 6F65CE77B8
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds& ... BA04191&q={searchTerms}
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.delta-homes.com/?type=hp&ts= ... JX0BA04191
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.delta-homes.com/?type=hp&ts= ... JX0BA04191
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds& ... BA04191&q={searchTerms}
-\\ Mozilla Firefox v35.0 (x86 cs)
[g0syoo15.default-1349863581988] - Line Found : user_pref("browser.newtab.url", "hxxp://www.delta-homes.com/newtab/?type=nt&ts=1419407016&from=wpm12233&uid=SAMSUNGXHD103SJ_S246JX0BA04191");
[g0syoo15.default-1349863581988] - Line Found : user_pref("browser.search.selectedEngine", "AVG Secure Search");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.aflt", "ddrnw");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.dfltLng", "");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.dfltSrch", true);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.dnsErr", true);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.excTlbr", false);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.hmpg", true);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=ddrnw");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.id", "c20d6c7b0000000000001c6f65ce77b8");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.instlDay", "15710");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.instlRef", "");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.newTab", true);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=ddrnw");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.prdct", "funmoods");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.prtnrId", "funmoods");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.smplGrp", "none");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.srchPrvdr", "Search");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.tlbrId", "base");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=ddrnw&q=");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.vrsn", "1.5.11.16");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.vrsnTs", "1.5.11.1622:26:22");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.vrsni", "1.5.11.16");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.quick_start.enable_search1", false);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595..clientLogIsEnabled", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.CT2832595", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.CurrentServerDate", "20-7-2012");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.DSInstall", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.DialogsAlignMode", "LTR");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.DialogsGetterLastCheckTime", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.DownloadReferralCookieData", "");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FirstServerDate", "20-7-2012");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FirstTime", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FirstTimeFF3", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FirstTimeHiddenVer", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FixPageNotFoundErrors", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.GroupingServerCheckInterval", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.HPInstall", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.HasUserGlobalKeys", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.HomePageProtectorEnabled", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.HomepageBeforeUnload", "www.seznam.cz");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.Initialize", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.InitializeCommonPrefs", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.InstallationAndCookieDataSentCount", 2);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.InstallationType", "Unknown");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.InstalledDate", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsAlertDBUpdated", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsGrouping", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsInitSetupIni", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsMulticommunity", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsOpenThankYouPage", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsOpenUninstallPage", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsProtectorsInit", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LanguagePackLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LanguagePackReloadIntervalMM", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LastLogin_3.14.1.0", "Tue Jun 19 2012 06:03:26 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LatestVersion", "3.13.0.6");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.Locale", "en");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.MCDetectTooltipHeight", "83");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.MCDetectTooltipWidth", "295");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.MyStuffEnabledAtInstallation", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.OriginalFirstVersion", "3.14.1.0");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SHRINK_TOOLBAR", 1);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SavedHomepage", "chrome://branding/locale/browserconfig.properties");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchCaption", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchEngineBeforeUnload", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchFromAddressBarIsInit", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=2&q=");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchInNewTabEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchInNewTabIntervalMM", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchInNewTabLastCheckTime", "Tue Jun 19 2012 00:38:59 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchProtectorEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchProtectorToolbarDisabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SendProtectorDataViaLogin", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ServiceMapLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SettingsLastCheckTime", "Tue Jun 19 2012 06:03:25 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SettingsLastUpdate", "1342353688");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2832595&SearchSource=13");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ThirdPartyComponentsInterval", 504);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ThirdPartyComponentsLastCheck", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ThirdPartyComponentsLastUpdate", "1331805997");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ToolbarDisabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ToolbarShrinkedFromSetup", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.UserID", "UN66842355699789321");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ValidationData_Toolbar", 2);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.alertChannelId", "1224658");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.activetoolbar", "77657374");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.toolbar_market", "637A");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.toolbarurl", "687474703A2F2F746F6F6C6261722E696E6E6F67616D65732E64652F746F6F6C626172732F776573742F746F6F6C6261722E706870");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.west_password_cz", "5A57787063327468");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.west_session_id_cz", "30366139633234643932643930343531");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.west_username_cz", "61584A6C6247467A");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.west_world_url_cz", "687474703A2F2F637A31312E7468652D776573742E637A");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.globalFirstTimeInfoLastCheckTime", "Tue Jun 19 2012 00:39:02 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.homepageProtectorEnableByLogin", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.initDone", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.isAppTrackingManagerOn", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffPublihserMinWidth", 400);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffServiceIntervalMM", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.navigateToUrlOnSearch", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.revertSettingsEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.searchProtectorDialogDelayInSec", 10);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.searchProtectorEnableByLogin", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.testingCtid", "");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.toolbarAppMetaDataLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.toolbarContextMenuLastCheckTime", "Tue Jun 19 2012 00:38:55 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.usagesFlag", 2);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2832595&SearchSource=13");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ConduitSearchList", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "G9mW7heT/8xIX1frcduu0A==");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "mfQ70fvlD2zuBxSBj8rQqA==");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "UgzXjW7BIkfdx+x39Ruv3w==");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "4BgM4MhF/sOgPsDNmIs3Yw==");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\nikdo\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\h3z7n07y.default-1340054342780\\conduitCommon\\modules\\3.14.1.0");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.14.1.0");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ToolbarsList", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.globalUserId", "391fe62a-3022-4398-9628-b9e8e063f367");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.alertEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Jun 19 2012 01:38:58 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.locale", "en");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.userId", "c828a219-d890-4df5-b53d-ead686137cd0");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("browser.search.defaultthis.engineName", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=3&q={searchTerms}");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
-\\ Google Chrome v39.0.2171.99
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
-\\ Chromium v
[C:\Users\nikdo\AppData\Local\Chromium\User Data\Default\preferences] - Found [Homepage] : hxxp://qip.ru
*************************
AdwCleaner[R0].txt - [31704 octets] - [18/01/2015 18:18:34]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [31765 octets] ##########
Re: kontrola ,nefunguje internet stahování, ping ok
nezapoměla jsem jen se mi nepovedlo stáhnout poslední soubor malwarebytes po práci budu pokračovat ,děkuji
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: kontrola ,nefunguje internet stahování, ping ok
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Ještě MbAM.
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Ještě MbAM.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: kontrola ,nefunguje internet stahování, ping ok
dodán scen z malware
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 19.1.2015
Scan Time: 16:44:36
Logfile: log malwar.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.01.19.08
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: nikdo
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 378300
Time Elapsed: 3 min, 56 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 30
PUP.Optional.MixiDJToolbar.A, HKLM\SOFTWARE\CLASSES\APPID\{A2773ED4-83BD-488A-A186-73590706C916}, , [b68e6a8f1d6c5fd7ffdc2ef8ec17aa56],
PUP.Optional.MixiDJToolbar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{A2773ED4-83BD-488A-A186-73590706C916}, , [b68e6a8f1d6c5fd7ffdc2ef8ec17aa56],
PUP.Optional.Babylon.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [60e451a828618fa7ba7bd815df23956b],
PUP.Optional.SupTab.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [4202a554a6e3e452387fb53c60a2a15f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [4202a554a6e3e452387fb53c60a2a15f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [4202a554a6e3e452387fb53c60a2a15f],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\CLASSES\Updater.AmiUpd.1, , [59ebe41523666ec864f48c6d17eb4fb1],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Updater.AmiUpd.1, , [3d0726d3028790a6db7de31625ddcc34],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\Updater.AmiUpd, , [62e2da1f4b3e62d4a44d0484da298c74],
PUP.Optional.SecurityProtection.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\noajmlkipclmeolfcnflkjhijkigpfjh, , [da6a31c8f990d75fb54ca0d700036a96],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [a99bc0392a5f7fb717cec712ad578779],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, , [2f15ce2b1376e84e786d3b6047bc4fb1],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\delta-homesSoftware, , [95af76838cfda294d875573722e149b7],
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\istartsurfSoftware, , [d66e5d9c6a1f2e08d702a9e1966d51af],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, , [90b4b445583186b03ffb6d8123e1e61a],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, , [d66e3abf375253e39193d2b7db2834cc],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Updater.AmiUpd, , [a2a2e514a7e2d36343ae86029d66a65a],
PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\fdloijijlkoblmigdofommgnheckmaki, , [a2a205f479104ee80791c7c4768e6a96],
PUP.Optional.SecurityProtection.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\noajmlkipclmeolfcnflkjhijkigpfjh, , [bf85b6436b1e1026d72ad0a734cf6a96],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [88bc12e793f647ef44a1d009c341e41c],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, , [fc484bae2465d75f3fb366222ed5e11f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, , [7dc703f68900e155a47f296010f3649c],
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, , [ef553ebb2a5f69cdca863c42cb38c43c],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, , [8db7e118e3a6d56157fa85f9e320bc44],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, , [261e85740089a78feeb78847f90ba65a],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, , [7ec6669390f974c2c66e6866976dfe02],
PUP.Optional.WebSearches.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SupHpUISoft, , [ad97a75297f250e622b1ff8b38cb6e92],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [ba8aba3fa6e353e3b5cd3942986bb749],
PUP.Optional.Qone8, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [360e10e9dfaae5515e862eab010316ea],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [9ea636c35534d85ecfb38eeda65d0df3],
Registry Values: 4
PUP.Optional.BrowserProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\ABOUTURLS|bProtectTabs, http://mixidj.delta-search.com/?affID=1 ... 6F65CE77B8, , [a89c639659307eb8debc636e9371fa06]
PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\extensions\faststartff@gmail.com, , [b58f34c59eebe25498bcf4f95ca8d729]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, , [fc484bae2465d75f3fb366222ed5e11f]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, ild, , [7dc703f68900e155a47f296010f3649c]
Registry Data: 6
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191),,[3a0ac33698f1f83e4d240d837f86926e]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.istartsurf.com/web/?type=ds& ... BA04191&q={searchTerms}, Good: (www.google.com), Bad: (http://www.istartsurf.com/web/?type=ds& ... BA04191&q={searchTerms}),,[45ffdf1a4a3f0b2bafb8345cc342ac54]
PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.delta-homes.com/?type=hp&ts= ... JX0BA04191, Good: (www.google.com), Bad: (http://www.delta-homes.com/?type=hp&ts= ... JX0BA04191),,[44006a8fb5d47eb898d1b6e62dd8dc24]
PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.delta-homes.com/?type=hp&ts= ... JX0BA04191, Good: (www.google.com), Bad: (http://www.delta-homes.com/?type=hp&ts= ... JX0BA04191),,[b78d34c537528ea8a5c8069651b429d7]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[66de54a5f891a78ff07af2a9fe075aa6]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191),,[11336d8cc4c576c0abc65b35d72e6c94]
Folders: 37
PUP.Optional.SoftwareUpdater.A, C:\Users\nikdo\AppData\Local\SwvUpdater, , [d47040b9315867cf0bfae8a9e122c838],
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct, , [49fbcf2af891ae88865af344a26115eb],
PUP.Optional.PriceGong.A, C:\Users\nikdo\AppData\LocalLow\PriceGong, , [261e9a5fd7b2a690e12a94aa8a796b95],
PUP.Optional.PriceGong.A, C:\Users\nikdo\AppData\LocalLow\PriceGong\Data, , [261e9a5fd7b2a690e12a94aa8a796b95],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, , [f54fb148810831055bafdd7304ffa35d],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, , [f54fb148810831055bafdd7304ffa35d],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\LocalLow\Funmoods, , [04407e7b0386a591c393133e55ae1ce4],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\LocalLow\Funmoods\Funmoods, , [04407e7b0386a591c393133e55ae1ce4],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
Files: 71
Trojan.BitCoinMiner, C:\Users\nikdo\Downloads\ESET NOD32 2014 antivirus 8.0.304.1 (x86,x64)(CZ,SK).rar.part, , [053f05f4e3a663d33f15a9bb42bf44bc],
PUP.Optional.SecurityProtection.A, C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx, , [fe468a6fe0a99e98827eed8a2fd453ad],
PUP.Optional.IStartSurf.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml, , [ca7ad128d8b1979fc7403b51d42fe719],
PUP.Optional.SoftwareUpdater.A, C:\Users\nikdo\AppData\Local\SwvUpdater\Updater.xml, , [d47040b9315867cf0bfae8a9e122c838],
PUP.Optional.SoftwareUpdater.A, C:\Users\nikdo\AppData\Local\SwvUpdater\status.cfg, , [d47040b9315867cf0bfae8a9e122c838],
PUP.Optional.Delta.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\delta-homes.xml, , [d0746c8d860358de4d8dfb9c11f249b7],
PUP.Optional.Conduit.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\conduit.xml, , [b98be4158009270f05b42984877cb947],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\funmoods.xml, , [e36122d71970b97d825ca607d82b6997],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\funmoods.xml, , [94b005f4ef9af6407c627c3109fa6e92],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\funmoods.xml, , [0b39c6331c6d5ed84a94c4e9857ec13f],
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\ESET Fix SB 2.1.0.exe, , [49fbcf2af891ae88865af344a26115eb],
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\m.exe, , [49fbcf2af891ae88865af344a26115eb],
PUP.Optional.PriceGong.A, C:\Users\nikdo\AppData\LocalLow\PriceGong\Data\mru.xml, , [261e9a5fd7b2a690e12a94aa8a796b95],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, , [f54fb148810831055bafdd7304ffa35d],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-09-28[12-38-47-571].log, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\update.exe, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\bk_shadow.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\btn.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\close.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml.bak, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_box.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_check.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_bk.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_check.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit-ie8.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit2.0.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.Delta.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "http://www.delta-homes.com/newtab/?type=nt&ts=1419407016&from=wpm12233&uid=SAMSUNGXHD103SJ_S246JX0BA04191");), ,[c183fcfd90f925116b320fc663a24fb1]
PUP.Optional.Conduit.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\prefs.js, Good: (), Bad: (user_pref("browser.search.defaulturl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=3&q={searchTerms}");), ,[61e322d71475ce68196a5f7733d2e917]
PUP.Optional.Conduit.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\prefs.js, Good: (), Bad: (user_pref("CT2832595.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=2&q=");), ,[e85cc4354445d95dcdb75086e71e6898]
Physical Sectors: 0
(No malicious items detected)
(end)
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 19.1.2015
Scan Time: 16:44:36
Logfile: log malwar.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.01.19.08
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: nikdo
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 378300
Time Elapsed: 3 min, 56 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 30
PUP.Optional.MixiDJToolbar.A, HKLM\SOFTWARE\CLASSES\APPID\{A2773ED4-83BD-488A-A186-73590706C916}, , [b68e6a8f1d6c5fd7ffdc2ef8ec17aa56],
PUP.Optional.MixiDJToolbar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{A2773ED4-83BD-488A-A186-73590706C916}, , [b68e6a8f1d6c5fd7ffdc2ef8ec17aa56],
PUP.Optional.Babylon.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [60e451a828618fa7ba7bd815df23956b],
PUP.Optional.SupTab.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [4202a554a6e3e452387fb53c60a2a15f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [4202a554a6e3e452387fb53c60a2a15f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [4202a554a6e3e452387fb53c60a2a15f],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\CLASSES\Updater.AmiUpd.1, , [59ebe41523666ec864f48c6d17eb4fb1],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Updater.AmiUpd.1, , [3d0726d3028790a6db7de31625ddcc34],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\Updater.AmiUpd, , [62e2da1f4b3e62d4a44d0484da298c74],
PUP.Optional.SecurityProtection.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\noajmlkipclmeolfcnflkjhijkigpfjh, , [da6a31c8f990d75fb54ca0d700036a96],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [a99bc0392a5f7fb717cec712ad578779],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, , [2f15ce2b1376e84e786d3b6047bc4fb1],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\delta-homesSoftware, , [95af76838cfda294d875573722e149b7],
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\istartsurfSoftware, , [d66e5d9c6a1f2e08d702a9e1966d51af],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, , [90b4b445583186b03ffb6d8123e1e61a],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, , [d66e3abf375253e39193d2b7db2834cc],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Updater.AmiUpd, , [a2a2e514a7e2d36343ae86029d66a65a],
PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\fdloijijlkoblmigdofommgnheckmaki, , [a2a205f479104ee80791c7c4768e6a96],
PUP.Optional.SecurityProtection.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\noajmlkipclmeolfcnflkjhijkigpfjh, , [bf85b6436b1e1026d72ad0a734cf6a96],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [88bc12e793f647ef44a1d009c341e41c],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, , [fc484bae2465d75f3fb366222ed5e11f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, , [7dc703f68900e155a47f296010f3649c],
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, , [ef553ebb2a5f69cdca863c42cb38c43c],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, , [8db7e118e3a6d56157fa85f9e320bc44],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, , [261e85740089a78feeb78847f90ba65a],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, , [7ec6669390f974c2c66e6866976dfe02],
PUP.Optional.WebSearches.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SupHpUISoft, , [ad97a75297f250e622b1ff8b38cb6e92],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [ba8aba3fa6e353e3b5cd3942986bb749],
PUP.Optional.Qone8, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [360e10e9dfaae5515e862eab010316ea],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [9ea636c35534d85ecfb38eeda65d0df3],
Registry Values: 4
PUP.Optional.BrowserProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\ABOUTURLS|bProtectTabs, http://mixidj.delta-search.com/?affID=1 ... 6F65CE77B8, , [a89c639659307eb8debc636e9371fa06]
PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\extensions\faststartff@gmail.com, , [b58f34c59eebe25498bcf4f95ca8d729]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, , [fc484bae2465d75f3fb366222ed5e11f]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, ild, , [7dc703f68900e155a47f296010f3649c]
Registry Data: 6
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191),,[3a0ac33698f1f83e4d240d837f86926e]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.istartsurf.com/web/?type=ds& ... BA04191&q={searchTerms}, Good: (www.google.com), Bad: (http://www.istartsurf.com/web/?type=ds& ... BA04191&q={searchTerms}),,[45ffdf1a4a3f0b2bafb8345cc342ac54]
PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.delta-homes.com/?type=hp&ts= ... JX0BA04191, Good: (www.google.com), Bad: (http://www.delta-homes.com/?type=hp&ts= ... JX0BA04191),,[44006a8fb5d47eb898d1b6e62dd8dc24]
PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.delta-homes.com/?type=hp&ts= ... JX0BA04191, Good: (www.google.com), Bad: (http://www.delta-homes.com/?type=hp&ts= ... JX0BA04191),,[b78d34c537528ea8a5c8069651b429d7]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[66de54a5f891a78ff07af2a9fe075aa6]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191),,[11336d8cc4c576c0abc65b35d72e6c94]
Folders: 37
PUP.Optional.SoftwareUpdater.A, C:\Users\nikdo\AppData\Local\SwvUpdater, , [d47040b9315867cf0bfae8a9e122c838],
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct, , [49fbcf2af891ae88865af344a26115eb],
PUP.Optional.PriceGong.A, C:\Users\nikdo\AppData\LocalLow\PriceGong, , [261e9a5fd7b2a690e12a94aa8a796b95],
PUP.Optional.PriceGong.A, C:\Users\nikdo\AppData\LocalLow\PriceGong\Data, , [261e9a5fd7b2a690e12a94aa8a796b95],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, , [f54fb148810831055bafdd7304ffa35d],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, , [f54fb148810831055bafdd7304ffa35d],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\LocalLow\Funmoods, , [04407e7b0386a591c393133e55ae1ce4],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\LocalLow\Funmoods\Funmoods, , [04407e7b0386a591c393133e55ae1ce4],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
Files: 71
Trojan.BitCoinMiner, C:\Users\nikdo\Downloads\ESET NOD32 2014 antivirus 8.0.304.1 (x86,x64)(CZ,SK).rar.part, , [053f05f4e3a663d33f15a9bb42bf44bc],
PUP.Optional.SecurityProtection.A, C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx, , [fe468a6fe0a99e98827eed8a2fd453ad],
PUP.Optional.IStartSurf.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml, , [ca7ad128d8b1979fc7403b51d42fe719],
PUP.Optional.SoftwareUpdater.A, C:\Users\nikdo\AppData\Local\SwvUpdater\Updater.xml, , [d47040b9315867cf0bfae8a9e122c838],
PUP.Optional.SoftwareUpdater.A, C:\Users\nikdo\AppData\Local\SwvUpdater\status.cfg, , [d47040b9315867cf0bfae8a9e122c838],
PUP.Optional.Delta.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\delta-homes.xml, , [d0746c8d860358de4d8dfb9c11f249b7],
PUP.Optional.Conduit.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\conduit.xml, , [b98be4158009270f05b42984877cb947],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\funmoods.xml, , [e36122d71970b97d825ca607d82b6997],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\funmoods.xml, , [94b005f4ef9af6407c627c3109fa6e92],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\funmoods.xml, , [0b39c6331c6d5ed84a94c4e9857ec13f],
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\ESET Fix SB 2.1.0.exe, , [49fbcf2af891ae88865af344a26115eb],
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\m.exe, , [49fbcf2af891ae88865af344a26115eb],
PUP.Optional.PriceGong.A, C:\Users\nikdo\AppData\LocalLow\PriceGong\Data\mru.xml, , [261e9a5fd7b2a690e12a94aa8a796b95],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, , [f54fb148810831055bafdd7304ffa35d],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-09-28[12-38-47-571].log, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\update.exe, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\bk_shadow.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\btn.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\close.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml.bak, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_box.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_check.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_bk.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_check.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit-ie8.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit2.0.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.Delta.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "http://www.delta-homes.com/newtab/?type=nt&ts=1419407016&from=wpm12233&uid=SAMSUNGXHD103SJ_S246JX0BA04191");), ,[c183fcfd90f925116b320fc663a24fb1]
PUP.Optional.Conduit.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\prefs.js, Good: (), Bad: (user_pref("browser.search.defaulturl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=3&q={searchTerms}");), ,[61e322d71475ce68196a5f7733d2e917]
PUP.Optional.Conduit.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\prefs.js, Good: (), Bad: (user_pref("CT2832595.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=2&q=");), ,[e85cc4354445d95dcdb75086e71e6898]
Physical Sectors: 0
(No malicious items detected)
(end)
Re: kontrola ,nefunguje internet stahování, ping ok
provedeno adw cleaneru
# AdwCleaner v4.108 - Report created 19/01/2015 at 16:56:46
# Updated 17/01/2015 by Xplode
# Database : 2015-01-18.1 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : nikdo - NIKDY
# Running from : C:\Users\nikdo\Desktop\adwcleaner_4.108(2).exe
# Option : Clean
***** [ Services ] *****
Service Deleted : vToolbarUpdater18.2.0
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\ProgramData\AlawarWrapper
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Program Files (x86)\WinZipper
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Users\nikdo\AppData\Local\apn
Folder Deleted : C:\Users\nikdo\AppData\Local\cool_mirage
Folder Deleted : C:\Users\nikdo\AppData\Local\PackageAware
Folder Deleted : C:\Users\nikdo\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\nikdo\AppData\Local\AlawarWrapper
Folder Deleted : C:\Users\nikdo\AppData\LocalLow\Funmoods
Folder Deleted : C:\Users\nikdo\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\nikdo\AppData\Roaming\eCyber
Folder Deleted : C:\Users\nikdo\AppData\Roaming\WinZipper
Folder Deleted : C:\Users\Public\Documents\iWin
Folder Deleted : C:\Users\Public\Documents\AlawarWrapper
Folder Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\Extensions\{32A1FD71-835E-4B11-8E54-886FDA0B4C89}
Folder Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\Extensions\Avg@toolbar
File Deleted : C:\Users\Public\Desktop\iLivid.lnk
File Deleted : C:\Users\nikdo\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\Askcom.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\avg-secure-search.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\Conduit.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\delta-homes.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\funmoods.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\funmoods.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\funmoods.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\qip-search.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\user.js
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\user.js
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Shortcut Disinfected : C:\Users\nikdo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\nikdo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\nikdo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\nikdo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKCU\Software\Mozilla\Extends
Key Deleted : HKCU\Software\27ccc8c626aecdf2927cdc5ef0c9bde2
Key Deleted : HKCU\Software\284db1d79e871dc8e3adb71dcdf8747f
Key Deleted : HKCU\Software\84de8db26feb13
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A2773ED4-83BD-488A-A186-73590706C916}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKCU\Software\AppDataLow\Software\adawarebp
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\delta-homesSoftware
Key Deleted : HKLM\SOFTWARE\hdcode
Key Deleted : HKLM\SOFTWARE\istartsurfSoftware
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\supWPM
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\Trymedia Systems
Key Deleted : HKLM\SOFTWARE\V9
Key Deleted : HKLM\SOFTWARE\winzipersvc
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16428
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [bProtectTabs]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v35.0 (x86 cs)
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("browser.newtab.url", "hxxp://www.delta-homes.com/newtab/?type=nt&ts=1419407016&from=wpm12233&uid=SAMSUNGXHD103SJ_S246JX0BA04191");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.aflt", "ddrnw");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.dfltLng", "");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.dfltSrch", true);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.dnsErr", true);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.excTlbr", false);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.hmpg", true);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=ddrnw");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.id", "c20d6c7b0000000000001c6f65ce77b8");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.instlDay", "15710");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.instlRef", "");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.newTab", true);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=ddrnw");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.prdct", "funmoods");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.prtnrId", "funmoods");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.smplGrp", "none");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.srchPrvdr", "Search");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.tlbrId", "base");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=ddrnw&q=");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.vrsn", "1.5.11.16");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.11.1622:26:22");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.vrsni", "1.5.11.16");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.quick_start.enable_search1", false);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595..clientLogIsEnabled", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.CT2832595", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.CurrentServerDate", "20-7-2012");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.DSInstall", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.DialogsAlignMode", "LTR");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.DialogsGetterLastCheckTime", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.DownloadReferralCookieData", "");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FirstServerDate", "20-7-2012");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FirstTime", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FirstTimeFF3", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FirstTimeHiddenVer", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FixPageNotFoundErrors", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.GroupingServerCheckInterval", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.HPInstall", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.HasUserGlobalKeys", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.HomePageProtectorEnabled", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.HomepageBeforeUnload", "www.seznam.cz");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.Initialize", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.InitializeCommonPrefs", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.InstallationAndCookieDataSentCount", 2);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.InstallationType", "Unknown");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.InstalledDate", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsAlertDBUpdated", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsGrouping", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsInitSetupIni", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsMulticommunity", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsOpenThankYouPage", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsOpenUninstallPage", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsProtectorsInit", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LanguagePackLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LanguagePackReloadIntervalMM", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LastLogin_3.14.1.0", "Tue Jun 19 2012 06:03:26 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LatestVersion", "3.13.0.6");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.Locale", "en");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.MCDetectTooltipHeight", "83");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.MCDetectTooltipWidth", "295");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.MyStuffEnabledAtInstallation", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.OriginalFirstVersion", "3.14.1.0");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SHRINK_TOOLBAR", 1);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SavedHomepage", "chrome://branding/locale/browserconfig.properties");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchCaption", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchEngineBeforeUnload", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchFromAddressBarIsInit", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=2&q=");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchInNewTabEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchInNewTabIntervalMM", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchInNewTabLastCheckTime", "Tue Jun 19 2012 00:38:59 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchProtectorEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchProtectorToolbarDisabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SendProtectorDataViaLogin", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ServiceMapLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SettingsLastCheckTime", "Tue Jun 19 2012 06:03:25 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SettingsLastUpdate", "1342353688");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2832595&SearchSource=13");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ThirdPartyComponentsInterval", 504);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ThirdPartyComponentsLastCheck", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ThirdPartyComponentsLastUpdate", "1331805997");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ToolbarDisabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ToolbarShrinkedFromSetup", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.UserID", "UN66842355699789321");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ValidationData_Toolbar", 2);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.alertChannelId", "1224658");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.activetoolbar", "77657374");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.toolbar_market", "637A");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.toolbarurl", "687474703A2F2F746F6F6C6261722E696E6E6F67616D65732E64652F746F6F6C626172732F776573742F746F6F6C6261722E706870");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.west_password_cz", "5A57787063327468");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.west_session_id_cz", "30366139633234643932643930343531");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.west_username_cz", "61584A6C6247467A");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.west_world_url_cz", "687474703A2F2F637A31312E7468652D776573742E637A");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.globalFirstTimeInfoLastCheckTime", "Tue Jun 19 2012 00:39:02 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.homepageProtectorEnableByLogin", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.initDone", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.isAppTrackingManagerOn", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffPublihserMinWidth", 400);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffServiceIntervalMM", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.navigateToUrlOnSearch", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.revertSettingsEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.searchProtectorDialogDelayInSec", 10);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.searchProtectorEnableByLogin", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.testingCtid", "");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.toolbarAppMetaDataLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.toolbarContextMenuLastCheckTime", "Tue Jun 19 2012 00:38:55 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.usagesFlag", 2);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2832595&SearchSource=13");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ConduitSearchList", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "G9mW7heT/8xIX1frcduu0A==");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "mfQ70fvlD2zuBxSBj8rQqA==");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "UgzXjW7BIkfdx+x39Ruv3w==");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "4BgM4MhF/sOgPsDNmIs3Yw==");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\nikdo\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\h3z7n07y.default-1340054342780\\conduitCommon\\modules\\3.14.1.0");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.14.1.0");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.globalUserId", "391fe62a-3022-4398-9628-b9e8e063f367");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Jun 19 2012 01:38:58 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.userId", "c828a219-d890-4df5-b53d-ead686137cd0");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("browser.search.defaultthis.engineName", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=3&q={searchTerms}");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
-\\ Google Chrome v39.0.2171.99
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
-\\ Chromium v
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
[C:\Users\nikdo\AppData\Local\Chromium\User Data\Default\preferences] - Deleted [Homepage] : hxxp://qip.ru
*************************
AdwCleaner[R0].txt - [31930 octets] - [18/01/2015 18:18:34]
AdwCleaner[R1].txt - [31991 octets] - [19/01/2015 16:54:44]
AdwCleaner[S0].txt - [33776 octets] - [19/01/2015 16:56:46]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [33837 octets] ##########
# AdwCleaner v4.108 - Report created 19/01/2015 at 16:56:46
# Updated 17/01/2015 by Xplode
# Database : 2015-01-18.1 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : nikdo - NIKDY
# Running from : C:\Users\nikdo\Desktop\adwcleaner_4.108(2).exe
# Option : Clean
***** [ Services ] *****
Service Deleted : vToolbarUpdater18.2.0
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\ProgramData\AlawarWrapper
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Program Files (x86)\WinZipper
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Users\nikdo\AppData\Local\apn
Folder Deleted : C:\Users\nikdo\AppData\Local\cool_mirage
Folder Deleted : C:\Users\nikdo\AppData\Local\PackageAware
Folder Deleted : C:\Users\nikdo\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\nikdo\AppData\Local\AlawarWrapper
Folder Deleted : C:\Users\nikdo\AppData\LocalLow\Funmoods
Folder Deleted : C:\Users\nikdo\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\nikdo\AppData\Roaming\eCyber
Folder Deleted : C:\Users\nikdo\AppData\Roaming\WinZipper
Folder Deleted : C:\Users\Public\Documents\iWin
Folder Deleted : C:\Users\Public\Documents\AlawarWrapper
Folder Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\Extensions\{32A1FD71-835E-4B11-8E54-886FDA0B4C89}
Folder Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\Extensions\Avg@toolbar
File Deleted : C:\Users\Public\Desktop\iLivid.lnk
File Deleted : C:\Users\nikdo\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\Askcom.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\avg-secure-search.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\Conduit.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\delta-homes.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\funmoods.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\funmoods.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\funmoods.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\qip-search.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\user.js
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\user.js
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Shortcut Disinfected : C:\Users\nikdo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\nikdo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\nikdo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\nikdo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKCU\Software\Mozilla\Extends
Key Deleted : HKCU\Software\27ccc8c626aecdf2927cdc5ef0c9bde2
Key Deleted : HKCU\Software\284db1d79e871dc8e3adb71dcdf8747f
Key Deleted : HKCU\Software\84de8db26feb13
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A2773ED4-83BD-488A-A186-73590706C916}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKCU\Software\AppDataLow\Software\adawarebp
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\delta-homesSoftware
Key Deleted : HKLM\SOFTWARE\hdcode
Key Deleted : HKLM\SOFTWARE\istartsurfSoftware
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\supWPM
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\Trymedia Systems
Key Deleted : HKLM\SOFTWARE\V9
Key Deleted : HKLM\SOFTWARE\winzipersvc
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16428
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [bProtectTabs]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v35.0 (x86 cs)
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("browser.newtab.url", "hxxp://www.delta-homes.com/newtab/?type=nt&ts=1419407016&from=wpm12233&uid=SAMSUNGXHD103SJ_S246JX0BA04191");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.aflt", "ddrnw");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.dfltLng", "");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.dfltSrch", true);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.dnsErr", true);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.excTlbr", false);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.hmpg", true);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=ddrnw");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.id", "c20d6c7b0000000000001c6f65ce77b8");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.instlDay", "15710");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.instlRef", "");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.newTab", true);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=ddrnw");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.prdct", "funmoods");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.prtnrId", "funmoods");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.smplGrp", "none");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.srchPrvdr", "Search");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.tlbrId", "base");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=ddrnw&q=");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.vrsn", "1.5.11.16");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.11.1622:26:22");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.vrsni", "1.5.11.16");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.quick_start.enable_search1", false);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595..clientLogIsEnabled", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.CT2832595", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.CurrentServerDate", "20-7-2012");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.DSInstall", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.DialogsAlignMode", "LTR");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.DialogsGetterLastCheckTime", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.DownloadReferralCookieData", "");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FirstServerDate", "20-7-2012");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FirstTime", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FirstTimeFF3", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FirstTimeHiddenVer", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FixPageNotFoundErrors", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.GroupingServerCheckInterval", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.HPInstall", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.HasUserGlobalKeys", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.HomePageProtectorEnabled", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.HomepageBeforeUnload", "www.seznam.cz");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.Initialize", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.InitializeCommonPrefs", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.InstallationAndCookieDataSentCount", 2);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.InstallationType", "Unknown");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.InstalledDate", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsAlertDBUpdated", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsGrouping", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsInitSetupIni", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsMulticommunity", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsOpenThankYouPage", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsOpenUninstallPage", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsProtectorsInit", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LanguagePackLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LanguagePackReloadIntervalMM", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LastLogin_3.14.1.0", "Tue Jun 19 2012 06:03:26 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LatestVersion", "3.13.0.6");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.Locale", "en");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.MCDetectTooltipHeight", "83");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.MCDetectTooltipWidth", "295");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.MyStuffEnabledAtInstallation", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.OriginalFirstVersion", "3.14.1.0");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SHRINK_TOOLBAR", 1);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SavedHomepage", "chrome://branding/locale/browserconfig.properties");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchCaption", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchEngineBeforeUnload", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchFromAddressBarIsInit", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=2&q=");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchInNewTabEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchInNewTabIntervalMM", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchInNewTabLastCheckTime", "Tue Jun 19 2012 00:38:59 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchProtectorEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchProtectorToolbarDisabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SendProtectorDataViaLogin", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ServiceMapLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SettingsLastCheckTime", "Tue Jun 19 2012 06:03:25 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SettingsLastUpdate", "1342353688");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2832595&SearchSource=13");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ThirdPartyComponentsInterval", 504);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ThirdPartyComponentsLastCheck", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ThirdPartyComponentsLastUpdate", "1331805997");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ToolbarDisabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ToolbarShrinkedFromSetup", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.UserID", "UN66842355699789321");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ValidationData_Toolbar", 2);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.alertChannelId", "1224658");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.activetoolbar", "77657374");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.toolbar_market", "637A");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.toolbarurl", "687474703A2F2F746F6F6C6261722E696E6E6F67616D65732E64652F746F6F6C626172732F776573742F746F6F6C6261722E706870");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.west_password_cz", "5A57787063327468");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.west_session_id_cz", "30366139633234643932643930343531");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.west_username_cz", "61584A6C6247467A");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.west_world_url_cz", "687474703A2F2F637A31312E7468652D776573742E637A");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.globalFirstTimeInfoLastCheckTime", "Tue Jun 19 2012 00:39:02 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.homepageProtectorEnableByLogin", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.initDone", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.isAppTrackingManagerOn", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffPublihserMinWidth", 400);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffServiceIntervalMM", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.navigateToUrlOnSearch", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.revertSettingsEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.searchProtectorDialogDelayInSec", 10);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.searchProtectorEnableByLogin", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.testingCtid", "");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.toolbarAppMetaDataLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.toolbarContextMenuLastCheckTime", "Tue Jun 19 2012 00:38:55 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.usagesFlag", 2);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2832595&SearchSource=13");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ConduitSearchList", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "G9mW7heT/8xIX1frcduu0A==");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "mfQ70fvlD2zuBxSBj8rQqA==");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "UgzXjW7BIkfdx+x39Ruv3w==");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "4BgM4MhF/sOgPsDNmIs3Yw==");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\nikdo\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\h3z7n07y.default-1340054342780\\conduitCommon\\modules\\3.14.1.0");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.14.1.0");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.globalUserId", "391fe62a-3022-4398-9628-b9e8e063f367");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Jun 19 2012 01:38:58 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.userId", "c828a219-d890-4df5-b53d-ead686137cd0");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("browser.search.defaultthis.engineName", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=3&q={searchTerms}");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
-\\ Google Chrome v39.0.2171.99
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
-\\ Chromium v
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
[C:\Users\nikdo\AppData\Local\Chromium\User Data\Default\preferences] - Deleted [Homepage] : hxxp://qip.ru
*************************
AdwCleaner[R0].txt - [31930 octets] - [18/01/2015 18:18:34]
AdwCleaner[R1].txt - [31991 octets] - [19/01/2015 16:54:44]
AdwCleaner[S0].txt - [33776 octets] - [19/01/2015 16:56:46]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [33837 octets] ##########
Re: kontrola ,nefunguje internet stahování, ping ok
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Professional x64
Ran by nikdo on po 19.01.2015 at 17:02:42,03
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440}
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully deleted [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\bProtectTabs
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
~~~ Files
Successfully deleted: [File] "C:\Windows\wininit.ini"
~~~ Folders
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted: [Folder] C:\Users\nikdo\AppData\Roaming\mozilla\firefox\profiles\h3z7n07y.default-1340054342780\conduitcommon
Emptied folder: C:\Users\nikdo\AppData\Roaming\mozilla\firefox\profiles\h3z7n07y.default-1340054342780\minidumps [38 files]
Emptied folder: C:\Users\nikdo\AppData\Roaming\mozilla\firefox\profiles\g0syoo15.default-1349863581988\minidumps [383 files]
~~~ Event Viewer Logs were cleared
zde je text z jrt
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 19.01.2015 at 17:05:56,47
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Professional x64
Ran by nikdo on po 19.01.2015 at 17:02:42,03
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440}
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully deleted [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\bProtectTabs
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
~~~ Files
Successfully deleted: [File] "C:\Windows\wininit.ini"
~~~ Folders
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted: [Folder] C:\Users\nikdo\AppData\Roaming\mozilla\firefox\profiles\h3z7n07y.default-1340054342780\conduitcommon
Emptied folder: C:\Users\nikdo\AppData\Roaming\mozilla\firefox\profiles\h3z7n07y.default-1340054342780\minidumps [38 files]
Emptied folder: C:\Users\nikdo\AppData\Roaming\mozilla\firefox\profiles\g0syoo15.default-1349863581988\minidumps [383 files]
~~~ Event Viewer Logs were cleared
zde je text z jrt
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 19.01.2015 at 17:05:56,47
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: kontrola ,nefunguje internet stahování, ping ok
Odinstaluj:
Spybot - Search & Destroy
. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Spybot - Search & Destroy
. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: kontrola ,nefunguje internet stahování, ping ok
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 20.1.2015
Scan Time: 16:46:12
Logfile: log k.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.01.20.07
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: nikdo
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 378821
Time Elapsed: 3 min, 27 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
www.malwarebytes.org
Scan Date: 20.1.2015
Scan Time: 16:46:12
Logfile: log k.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.01.20.07
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: nikdo
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 378821
Time Elapsed: 3 min, 27 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
Re: kontrola ,nefunguje internet stahování, ping ok
poslední provedená část kontroly
RogueKiller V10.2.0.0 (x64) [Jan 19 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : nikdo [Práva správce]
Mód : Prohledat -- Datum : 01/20/2015 16:59:29
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 26 ¤¤¤
[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.centrum.cz/ -> Nalezeno
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.centrum.cz/ -> Nalezeno
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms} -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E185C1E4-E1AF-4554-94D5-B23829320333} | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{E185C1E4-E1AF-4554-94D5-B23829320333} | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{E185C1E4-E1AF-4554-94D5-B23829320333} | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 0 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 0 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowUser : 0 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowUser : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
¤¤¤ Úlohy : 2 ¤¤¤
[Suspicious.Path] \\{59BF6E3D-FE4C-49B8-A1E8-E6F513944F6A} -- C:\Users\nikdo\Desktop\Setup\SETUP.EXE -> Nalezeno
[Suspicious.Path] \\{B9E36A42-505F-45A8-B10E-3892BD832F94} -- C:\Users\nikdo\Desktop\Setup\SETUP.EXE -> Nalezeno
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] g0syoo15.default-1349863581988 : user_pref("browser.startup.homepage", "www.centrum.cz"); -> Nalezeno
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HD103SJ ATA Device +++++
--- User ---
[MBR] d6e3ec34ff2fcd1cd69c9085c1147cbb
[BSP] 0376dbff6967f308ccdff6efd94ab64f : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 953867 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: OCZ-AGILITY3 ATA Device +++++
--- User ---
[MBR] 2f570e319eab6b19b3c5647a44b5dc55
[BSP] 19711608946a274f028ea6f53d22f296 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 57139 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive2: Generic- Compact Flash USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive3: Generic- SM/xD-Picture USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive4: Generic- SD/MMC USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive5: Generic- MS/MS-Pro USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
RogueKiller V10.2.0.0 (x64) [Jan 19 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : nikdo [Práva správce]
Mód : Prohledat -- Datum : 01/20/2015 16:59:29
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 26 ¤¤¤
[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.centrum.cz/ -> Nalezeno
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.centrum.cz/ -> Nalezeno
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms} -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E185C1E4-E1AF-4554-94D5-B23829320333} | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{E185C1E4-E1AF-4554-94D5-B23829320333} | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{E185C1E4-E1AF-4554-94D5-B23829320333} | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 0 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 0 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowUser : 0 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowUser : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
¤¤¤ Úlohy : 2 ¤¤¤
[Suspicious.Path] \\{59BF6E3D-FE4C-49B8-A1E8-E6F513944F6A} -- C:\Users\nikdo\Desktop\Setup\SETUP.EXE -> Nalezeno
[Suspicious.Path] \\{B9E36A42-505F-45A8-B10E-3892BD832F94} -- C:\Users\nikdo\Desktop\Setup\SETUP.EXE -> Nalezeno
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] g0syoo15.default-1349863581988 : user_pref("browser.startup.homepage", "www.centrum.cz"); -> Nalezeno
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HD103SJ ATA Device +++++
--- User ---
[MBR] d6e3ec34ff2fcd1cd69c9085c1147cbb
[BSP] 0376dbff6967f308ccdff6efd94ab64f : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 953867 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: OCZ-AGILITY3 ATA Device +++++
--- User ---
[MBR] 2f570e319eab6b19b3c5647a44b5dc55
[BSP] 19711608946a274f028ea6f53d22f296 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 57139 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive2: Generic- Compact Flash USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive3: Generic- SM/xD-Picture USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive4: Generic- SD/MMC USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive5: Generic- MS/MS-Pro USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: kontrola ,nefunguje internet stahování, ping ok
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Vypni antivir
Stáhni
Zoek.exe
a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:
klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Vypni antivir
Stáhni
Zoek.exe
a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:
Kód: Vybrat vše
autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;
klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 93 hostů