Kontrola logu_ Zpomalený NTB
Napsal: 19 dub 2016 15:02
Dobrý den, nejlepším rešením by bylo asi rovnou naformatovani, ale momentálně nemam na co uložit data, proto to chci ještě zkusit řešit takto. Příkládám logy HJT a ADWcleaner. Chtěl jsem přidat i log z Malwarebytes ale po 8 hodinovem skenovani, ktere nebylo stale u konce jsem to vzdal. Předem děkuji za pomoc.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:52:08, on 18.4.2016
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal
Running processes:
C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\MaRcoS\Downloads\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: 127.0.0.2 d3.connectify.me
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.connectify.me
O15 - ESC Trusted Zone: http://*.fastspring.com
O15 - ESC Trusted Zone: http://*.connectify.me (HKLM)
O15 - ESC Trusted Zone: http://*.fastspring.com (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Sentinel HASP License Manager (hasplms) - SafeNet Inc. - C:\Windows\system32\hasplms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
--
End of file - 4860 bytes
/////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
# AdwCleaner v3.210 - Report created 22/05/2014 at 20:14:38
# Updated 19/05/2014 by Xplode
# Operating System : Windows 7 Ultimate (32 bits)
# Username : MaRcoS - NOTEBOOK
# Running from : C:\Users\MaRcoS\Downloads\adwcleaner_3.210.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files\Gophoto.it
Folder Deleted : C:\Program Files\GreenTree Applications
Folder Deleted : C:\Program Files\HDvidCodec.com
Folder Deleted : C:\Program Files\HDvid-Codec V9.0
Folder Deleted : C:\Users\MaRcoS\AppData\Roaming\Mozilla\Firefox\Profiles\ht4cs84k.default\Extensions\fca3238e-0f52-4634-8e93-c36d211b2ea9@c1c012cf-93b0-488e-a2c5-453d23bec199.com
File Deleted : C:\Users\MaRcoS\AppData\Roaming\Mozilla\Firefox\Profiles\ht4cs84k.default\Extensions\gophoto@gophoto.it.xpi
File Deleted : C:\Users\MaRcoS\AppData\Roaming\Mozilla\Firefox\Profiles\ht4cs84k.default\searchplugins\buenosearch.xml
File Deleted : C:\Users\MaRcoS\AppData\Roaming\Mozilla\Firefox\Profiles\ht4cs84k.default\user.js
File Deleted : C:\Windows\System32\Tasks\EPUpdater
File Deleted : C:\Windows\Tasks\HDvid-Codec V9.0-chromeinstaller.job
File Deleted : C:\Windows\System32\Tasks\HDvid-Codec V9.0-chromeinstaller
File Deleted : C:\Windows\Tasks\HDvid-Codec V9.0-codedownloader.job
File Deleted : C:\Windows\System32\Tasks\HDvid-Codec V9.0-codedownloader
File Deleted : C:\Windows\Tasks\HDvid-Codec V9.0-enabler.job
File Deleted : C:\Windows\System32\Tasks\HDvid-Codec V9.0-enabler
File Deleted : C:\Windows\Tasks\HDvid-Codec V9.0-firefoxinstaller.job
File Deleted : C:\Windows\System32\Tasks\HDvid-Codec V9.0-firefoxinstaller
File Deleted : C:\Windows\Tasks\HDvid-Codec V9.0-updater.job
File Deleted : C:\Windows\System32\Tasks\HDvid-Codec V9.0-updater
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\acfoobbgoakpihljnfedbcfaipcdlfhk
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AEC4E7FA-19B1-4D3D-B7CD-D21BC3C4F50C}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AEC4E7FA-19B1-4D3D-B7CD-D21BC3C4F50C}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B283248F-CCEF-4A3D-84F0-D027C1A75D80}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B283248F-CCEF-4A3D-84F0-D027C1A75D80}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B0F8080B-F328-4C18-9108-F0C5C2A5A508}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B0F8080B-F328-4C18-9108-F0C5C2A5A508}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3FE65989-B2A3-4271-AC0F-CF563AD25536}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3FE65989-B2A3-4271-AC0F-CF563AD25536}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8285AD0C-F78C-4963-B5D4-CCCF5E3E8EB3}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8285AD0C-F78C-4963-B5D4-CCCF5E3E8EB3}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F87465B4-E3D0-4A8A-B339-93E1FDDC208C}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F87465B4-E3D0-4A8A-B339-93E1FDDC208C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\bi_client_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\bi_client_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\desk365_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\desk365_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0051356.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0051356.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0051356.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0051356.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511131156}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522132256}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555135556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566136656}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440544134456}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511131156}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3d8b1d0d-c097-4dc8-b897-a925ac103ef0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{81d298dc-b7d9-45b1-ac2b-12d81a6d017e}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cf9b8cdf-f5d0-4ad5-928f-d6b52c9f10d2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f82a0c1c-479f-45d4-9616-8f82b2dccdfd}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\HDvid-Codec V9.0
Key Deleted : HKLM\Software\hdcode
Key Deleted : HKLM\Software\winzipersvc
Key Deleted : HKLM\Software\HDvid-Codec V9.0
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HDvid-Codec V9.0
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16464
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v20.0.1 (cs)
[ File : C:\Users\MaRcoS\AppData\Roaming\Mozilla\Firefox\Profiles\ht4cs84k.default\prefs.js ]
[ File : C:\Users\ostatní\AppData\Roaming\Mozilla\Firefox\Profiles\fr2j4gnj.default\prefs.js ]
-\\ Google Chrome v
[ File : C:\Users\MaRcoS\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
Deleted [Search Provider] : hxxp://search.qvo6.com/web/?utm_source= ... default&q={searchTerms}
Deleted [Search Provider] : hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=7CDD001E339CB767&affID=128403&tsp=5174
Deleted [Homepage] : hxxp://www.buenosearch.com/?babsrc=HP_s ... 3&tsp=5174
Deleted [Extension] : pfmopbbadnfoelckkcmjjeaaegjpjjbk
*************************
AdwCleaner[R0].txt - [4542 octets] - [20/10/2013 14:36:22]
AdwCleaner[R1].txt - [4478 octets] - [20/10/2013 16:33:22]
AdwCleaner[R2].txt - [7975 octets] - [22/05/2014 20:11:50]
AdwCleaner[S0].txt - [4067 octets] - [20/10/2013 16:34:42]
AdwCleaner[S1].txt - [7116 octets] - [22/05/2014 20:14:38]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [7176 octets] ##########
# AdwCleaner v5.112 - Logfile created 18/04/2016 at 18:05:54
# Updated 17/04/2016 by Xplode
# Database : 2016-04-17.1 [Server]
# Operating system : Windows 7 Ultimate (X86)
# Username : MaRcoS - NOTEBOOK
# Running from : C:\Users\MaRcoS\Desktop\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
Folder Found : C:\ProgramData\ytd video downloader
Folder Found : C:\ProgramData\Application Data\ytd video downloader
Folder Found : C:\Users\ostatní\AppData\Roaming\Mozilla\Firefox\Profiles\fr2j4gnj.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
***** [ Files ] *****
File Found : C:\Users\MaRcoS\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ambjmeohlajelahhhniggkkceagdlcgj_0.localstorage
File Found : C:\Users\MaRcoS\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ambjmeohlajelahhhniggkkceagdlcgj
File Found : C:\Users\MaRcoS\AppData\Roaming\Mozilla\Firefox\Profiles\ht4cs84k.default\invalidprefs.js
File Found : C:\Users\ostatní\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_dsms0mj1bbhn4.cloudfront.net_0.localstorage
File Found : C:\Users\ostatní\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
File Found : C:\Users\ostatní\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
File Found : C:\Users\ostatní\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
***** [ DLL ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
Task Found : EPUpdater
***** [ Registry ] *****
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-chromeinstaller.job]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-chromeinstaller.job.fp]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-firefoxinstaller.job]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-firefoxinstaller.job.fp]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-codedownloader.job]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-codedownloader.job.fp]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-enabler.job]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-enabler.job.fp]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-updater.job]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-updater.job.fp]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [HDvid-Codec V9.0-bg.exe]
Key Found : HKLM\SOFTWARE\Classes\WinZipper.001
Key Found : HKLM\SOFTWARE\Classes\WinZipper.7z
Key Found : HKLM\SOFTWARE\Classes\WinZipper.arj
Key Found : HKLM\SOFTWARE\Classes\WinZipper.bz2
Key Found : HKLM\SOFTWARE\Classes\WinZipper.bzip2
Key Found : HKLM\SOFTWARE\Classes\WinZipper.cab
Key Found : HKLM\SOFTWARE\Classes\WinZipper.cpio
Key Found : HKLM\SOFTWARE\Classes\WinZipper.deb
Key Found : HKLM\SOFTWARE\Classes\WinZipper.dmg
Key Found : HKLM\SOFTWARE\Classes\WinZipper.fat
Key Found : HKLM\SOFTWARE\Classes\WinZipper.gz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.gzip
Key Found : HKLM\SOFTWARE\Classes\WinZipper.hfs
Key Found : HKLM\SOFTWARE\Classes\WinZipper.iso
Key Found : HKLM\SOFTWARE\Classes\WinZipper.lha
Key Found : HKLM\SOFTWARE\Classes\WinZipper.lzh
Key Found : HKLM\SOFTWARE\Classes\WinZipper.lzma
Key Found : HKLM\SOFTWARE\Classes\WinZipper.ntfs
Key Found : HKLM\SOFTWARE\Classes\WinZipper.rar
Key Found : HKLM\SOFTWARE\Classes\WinZipper.rpm
Key Found : HKLM\SOFTWARE\Classes\WinZipper.squashfs
Key Found : HKLM\SOFTWARE\Classes\WinZipper.swm
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tar
Key Found : HKLM\SOFTWARE\Classes\WinZipper.taz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tbz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tbz2
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tgz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tpz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.txz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.vhd
Key Found : HKLM\SOFTWARE\Classes\WinZipper.wim
Key Found : HKLM\SOFTWARE\Classes\WinZipper.xar
Key Found : HKLM\SOFTWARE\Classes\WinZipper.xz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.z
Key Found : HKLM\SOFTWARE\Classes\WinZipper.zip
Key Found : HKCU\Software\Classes\acestream
Key Found : HKLM\SOFTWARE\Classes\AmiBs.Boot
Key Found : HKLM\SOFTWARE\Classes\AmiBs.Boot.1
Key Found : HKU\S-1-5-21-2004603084-3878806734-3781825048-1001\Software\Classes\acestream
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved [{4F622628-7632-4B28-B184-D7BA0CA3273B}]
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\eSupport.com
Key Found : HKCU\Software\Video Player
Key Found : HKU\S-1-5-21-2004603084-3878806734-3781825048-1001\Software\Conduit
Key Found : HKU\S-1-5-21-2004603084-3878806734-3781825048-1001\Software\eSupport.com
Key Found : HKU\S-1-5-21-2004603084-3878806734-3781825048-1001\Software\Video Player
***** [ Web browsers ] *****
*************************
C:\AdwCleaner\AdwCleaner[R0].txt - [4542 bytes] - [20/10/2013 14:36:22]
C:\AdwCleaner\AdwCleaner[R1].txt - [4478 bytes] - [20/10/2013 16:33:22]
C:\AdwCleaner\AdwCleaner[R2].txt - [7975 bytes] - [22/05/2014 20:11:50]
C:\AdwCleaner\AdwCleaner[S0].txt - [4067 bytes] - [20/10/2013 16:34:42]
C:\AdwCleaner\AdwCleaner[S1].txt - [13367 bytes] - [22/05/2014 20:14:38]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [13441 bytes] ##########
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:52:08, on 18.4.2016
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal
Running processes:
C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\MaRcoS\Downloads\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: 127.0.0.2 d3.connectify.me
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.connectify.me
O15 - ESC Trusted Zone: http://*.fastspring.com
O15 - ESC Trusted Zone: http://*.connectify.me (HKLM)
O15 - ESC Trusted Zone: http://*.fastspring.com (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Sentinel HASP License Manager (hasplms) - SafeNet Inc. - C:\Windows\system32\hasplms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
--
End of file - 4860 bytes
/////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
# AdwCleaner v3.210 - Report created 22/05/2014 at 20:14:38
# Updated 19/05/2014 by Xplode
# Operating System : Windows 7 Ultimate (32 bits)
# Username : MaRcoS - NOTEBOOK
# Running from : C:\Users\MaRcoS\Downloads\adwcleaner_3.210.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files\Gophoto.it
Folder Deleted : C:\Program Files\GreenTree Applications
Folder Deleted : C:\Program Files\HDvidCodec.com
Folder Deleted : C:\Program Files\HDvid-Codec V9.0
Folder Deleted : C:\Users\MaRcoS\AppData\Roaming\Mozilla\Firefox\Profiles\ht4cs84k.default\Extensions\fca3238e-0f52-4634-8e93-c36d211b2ea9@c1c012cf-93b0-488e-a2c5-453d23bec199.com
File Deleted : C:\Users\MaRcoS\AppData\Roaming\Mozilla\Firefox\Profiles\ht4cs84k.default\Extensions\gophoto@gophoto.it.xpi
File Deleted : C:\Users\MaRcoS\AppData\Roaming\Mozilla\Firefox\Profiles\ht4cs84k.default\searchplugins\buenosearch.xml
File Deleted : C:\Users\MaRcoS\AppData\Roaming\Mozilla\Firefox\Profiles\ht4cs84k.default\user.js
File Deleted : C:\Windows\System32\Tasks\EPUpdater
File Deleted : C:\Windows\Tasks\HDvid-Codec V9.0-chromeinstaller.job
File Deleted : C:\Windows\System32\Tasks\HDvid-Codec V9.0-chromeinstaller
File Deleted : C:\Windows\Tasks\HDvid-Codec V9.0-codedownloader.job
File Deleted : C:\Windows\System32\Tasks\HDvid-Codec V9.0-codedownloader
File Deleted : C:\Windows\Tasks\HDvid-Codec V9.0-enabler.job
File Deleted : C:\Windows\System32\Tasks\HDvid-Codec V9.0-enabler
File Deleted : C:\Windows\Tasks\HDvid-Codec V9.0-firefoxinstaller.job
File Deleted : C:\Windows\System32\Tasks\HDvid-Codec V9.0-firefoxinstaller
File Deleted : C:\Windows\Tasks\HDvid-Codec V9.0-updater.job
File Deleted : C:\Windows\System32\Tasks\HDvid-Codec V9.0-updater
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\acfoobbgoakpihljnfedbcfaipcdlfhk
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AEC4E7FA-19B1-4D3D-B7CD-D21BC3C4F50C}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AEC4E7FA-19B1-4D3D-B7CD-D21BC3C4F50C}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B283248F-CCEF-4A3D-84F0-D027C1A75D80}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B283248F-CCEF-4A3D-84F0-D027C1A75D80}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B0F8080B-F328-4C18-9108-F0C5C2A5A508}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B0F8080B-F328-4C18-9108-F0C5C2A5A508}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3FE65989-B2A3-4271-AC0F-CF563AD25536}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3FE65989-B2A3-4271-AC0F-CF563AD25536}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8285AD0C-F78C-4963-B5D4-CCCF5E3E8EB3}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8285AD0C-F78C-4963-B5D4-CCCF5E3E8EB3}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F87465B4-E3D0-4A8A-B339-93E1FDDC208C}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F87465B4-E3D0-4A8A-B339-93E1FDDC208C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\bi_client_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\bi_client_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\desk365_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\desk365_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0051356.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0051356.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0051356.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0051356.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511131156}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522132256}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555135556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566136656}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440544134456}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511131156}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3d8b1d0d-c097-4dc8-b897-a925ac103ef0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{81d298dc-b7d9-45b1-ac2b-12d81a6d017e}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cf9b8cdf-f5d0-4ad5-928f-d6b52c9f10d2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f82a0c1c-479f-45d4-9616-8f82b2dccdfd}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\HDvid-Codec V9.0
Key Deleted : HKLM\Software\hdcode
Key Deleted : HKLM\Software\winzipersvc
Key Deleted : HKLM\Software\HDvid-Codec V9.0
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HDvid-Codec V9.0
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16464
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v20.0.1 (cs)
[ File : C:\Users\MaRcoS\AppData\Roaming\Mozilla\Firefox\Profiles\ht4cs84k.default\prefs.js ]
[ File : C:\Users\ostatní\AppData\Roaming\Mozilla\Firefox\Profiles\fr2j4gnj.default\prefs.js ]
-\\ Google Chrome v
[ File : C:\Users\MaRcoS\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
Deleted [Search Provider] : hxxp://search.qvo6.com/web/?utm_source= ... default&q={searchTerms}
Deleted [Search Provider] : hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=7CDD001E339CB767&affID=128403&tsp=5174
Deleted [Homepage] : hxxp://www.buenosearch.com/?babsrc=HP_s ... 3&tsp=5174
Deleted [Extension] : pfmopbbadnfoelckkcmjjeaaegjpjjbk
*************************
AdwCleaner[R0].txt - [4542 octets] - [20/10/2013 14:36:22]
AdwCleaner[R1].txt - [4478 octets] - [20/10/2013 16:33:22]
AdwCleaner[R2].txt - [7975 octets] - [22/05/2014 20:11:50]
AdwCleaner[S0].txt - [4067 octets] - [20/10/2013 16:34:42]
AdwCleaner[S1].txt - [7116 octets] - [22/05/2014 20:14:38]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [7176 octets] ##########
# AdwCleaner v5.112 - Logfile created 18/04/2016 at 18:05:54
# Updated 17/04/2016 by Xplode
# Database : 2016-04-17.1 [Server]
# Operating system : Windows 7 Ultimate (X86)
# Username : MaRcoS - NOTEBOOK
# Running from : C:\Users\MaRcoS\Desktop\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
Folder Found : C:\ProgramData\ytd video downloader
Folder Found : C:\ProgramData\Application Data\ytd video downloader
Folder Found : C:\Users\ostatní\AppData\Roaming\Mozilla\Firefox\Profiles\fr2j4gnj.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
***** [ Files ] *****
File Found : C:\Users\MaRcoS\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ambjmeohlajelahhhniggkkceagdlcgj_0.localstorage
File Found : C:\Users\MaRcoS\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ambjmeohlajelahhhniggkkceagdlcgj
File Found : C:\Users\MaRcoS\AppData\Roaming\Mozilla\Firefox\Profiles\ht4cs84k.default\invalidprefs.js
File Found : C:\Users\ostatní\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_dsms0mj1bbhn4.cloudfront.net_0.localstorage
File Found : C:\Users\ostatní\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
File Found : C:\Users\ostatní\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
File Found : C:\Users\ostatní\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
***** [ DLL ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
Task Found : EPUpdater
***** [ Registry ] *****
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-chromeinstaller.job]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-chromeinstaller.job.fp]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-firefoxinstaller.job]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-firefoxinstaller.job.fp]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-codedownloader.job]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-codedownloader.job.fp]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-enabler.job]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-enabler.job.fp]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-updater.job]
Value Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [HDvid-Codec V9.0-updater.job.fp]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [HDvid-Codec V9.0-bg.exe]
Key Found : HKLM\SOFTWARE\Classes\WinZipper.001
Key Found : HKLM\SOFTWARE\Classes\WinZipper.7z
Key Found : HKLM\SOFTWARE\Classes\WinZipper.arj
Key Found : HKLM\SOFTWARE\Classes\WinZipper.bz2
Key Found : HKLM\SOFTWARE\Classes\WinZipper.bzip2
Key Found : HKLM\SOFTWARE\Classes\WinZipper.cab
Key Found : HKLM\SOFTWARE\Classes\WinZipper.cpio
Key Found : HKLM\SOFTWARE\Classes\WinZipper.deb
Key Found : HKLM\SOFTWARE\Classes\WinZipper.dmg
Key Found : HKLM\SOFTWARE\Classes\WinZipper.fat
Key Found : HKLM\SOFTWARE\Classes\WinZipper.gz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.gzip
Key Found : HKLM\SOFTWARE\Classes\WinZipper.hfs
Key Found : HKLM\SOFTWARE\Classes\WinZipper.iso
Key Found : HKLM\SOFTWARE\Classes\WinZipper.lha
Key Found : HKLM\SOFTWARE\Classes\WinZipper.lzh
Key Found : HKLM\SOFTWARE\Classes\WinZipper.lzma
Key Found : HKLM\SOFTWARE\Classes\WinZipper.ntfs
Key Found : HKLM\SOFTWARE\Classes\WinZipper.rar
Key Found : HKLM\SOFTWARE\Classes\WinZipper.rpm
Key Found : HKLM\SOFTWARE\Classes\WinZipper.squashfs
Key Found : HKLM\SOFTWARE\Classes\WinZipper.swm
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tar
Key Found : HKLM\SOFTWARE\Classes\WinZipper.taz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tbz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tbz2
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tgz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tpz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.txz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.vhd
Key Found : HKLM\SOFTWARE\Classes\WinZipper.wim
Key Found : HKLM\SOFTWARE\Classes\WinZipper.xar
Key Found : HKLM\SOFTWARE\Classes\WinZipper.xz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.z
Key Found : HKLM\SOFTWARE\Classes\WinZipper.zip
Key Found : HKCU\Software\Classes\acestream
Key Found : HKLM\SOFTWARE\Classes\AmiBs.Boot
Key Found : HKLM\SOFTWARE\Classes\AmiBs.Boot.1
Key Found : HKU\S-1-5-21-2004603084-3878806734-3781825048-1001\Software\Classes\acestream
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved [{4F622628-7632-4B28-B184-D7BA0CA3273B}]
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\eSupport.com
Key Found : HKCU\Software\Video Player
Key Found : HKU\S-1-5-21-2004603084-3878806734-3781825048-1001\Software\Conduit
Key Found : HKU\S-1-5-21-2004603084-3878806734-3781825048-1001\Software\eSupport.com
Key Found : HKU\S-1-5-21-2004603084-3878806734-3781825048-1001\Software\Video Player
***** [ Web browsers ] *****
*************************
C:\AdwCleaner\AdwCleaner[R0].txt - [4542 bytes] - [20/10/2013 14:36:22]
C:\AdwCleaner\AdwCleaner[R1].txt - [4478 bytes] - [20/10/2013 16:33:22]
C:\AdwCleaner\AdwCleaner[R2].txt - [7975 bytes] - [22/05/2014 20:11:50]
C:\AdwCleaner\AdwCleaner[S0].txt - [4067 bytes] - [20/10/2013 16:34:42]
C:\AdwCleaner\AdwCleaner[S1].txt - [13367 bytes] - [22/05/2014 20:14:38]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [13441 bytes] ##########