Prosím o kontrolu logu. Mám problém s nastavením administrátorského oprávnění. Některé soubory (exe) nejdou spustit.
Píše mi to, že nemám patřičná oprávnění. V uživatelském účtu mám vše nastavené na administrátora.
Díky
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 18:51:40, on 2.12.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17420)
FIREFOX: 33.1 (x86 cs)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_239.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_239.exe
C:\Users\uzivatel\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe
O23 - Service: Intel(R) Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Endpoint Encryption Agent - Unknown owner - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: SafePCRepairService (SafePCRepair_89Service) - COMPANYVERS_NAME - C:\PROGRA~2\SAFEPC~2\bar\1.bin\89barsvc.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wacom Professional Service (WTabletServicePro) - Wacom Technology, Corp. - C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
--
End of file - 15614 bytes
Prosím o kontrolu logu
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu
# AdwCleaner v4.103 - Report created 03/12/2014 at 20:44:41
# Updated 01/12/2014 by Xplode
# Database : 2014-12-03.1 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : uzivatel - VLK3
# Running from : C:\Users\uzivatel\Desktop\Cisteni pc\adwcleaner_4.103.exe
# Option : Scan
***** [ Services ] *****
Service Found : SafePCRepair_89Service
***** [ Files / Folders ] *****
Folder Found : C:\Program Files (x86)\ICQ6Toolbar
Folder Found : C:\Program Files (x86)\SafePCRepair
Folder Found : C:\Program Files (x86)\SafePCRepair_89
Folder Found : C:\ProgramData\Ask
Folder Found : C:\ProgramData\ICQ\ICQToolbar
Folder Found : C:\ProgramData\iolo
Folder Found : C:\Users\uzivatel\AppData\Local\iolo
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\AppDataLow\Software\Mindspark
Key Found : HKCU\Software\AppDataLow\Software\SafePCRepair_89
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DCA50CB4-6A78-4465-8A4C-EEEFE15DA7C8}
Key Found : HKCU\Software\SafePCRepair_89
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DCA50CB4-6A78-4465-8A4C-EEEFE15DA7C8}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}
Key Found : [x64] HKCU\Software\SafePCRepair_89
Key Found : HKLM\SOFTWARE\Classes\CLSID\{065C1A21-97F8-45FB-A9F0-861B60FACEC8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{13119113-0854-469D-807A-171568457991}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3204358F-5904-46A6-841F-D6B5BE3EF4E3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{33119133-0854-469D-807A-171568457991}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3AE67737-0E3E-44AA-AA5E-46A68BF017FF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3EE5B726-044A-48D2-AA7B-049BD9A0F62A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{60FBBE03-57FF-49D8-B38E-053D3F489825}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6A5182F1-C0B8-42B8-96CC-7F329CD46913}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6C153418-8E4D-4FAF-AF27-5201E38463A7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A26A2F05-AC4D-4A1E-9531-9125F7309B78}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A9D9EA68-5D09-43EF-A0C5-6F6A6F82A0E1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5D6240-7DF0-435D-9B9B-F8586A99DE86}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F343045E-E20A-46E1-82D8-9962C43EFC9E}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FBB360DC-CB6C-4D6A-808A-2C773151BFFF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FFD7DDAC-EC28-42A5-8D39-917B9078604B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Found : HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SettingsPlugin
Key Found : HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SettingsPlugin.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991}
Key Found : HKLM\SOFTWARE\ICQ\ICQToolbar
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SafePCRepair_89bar Uninstall Firefox
Key Found : HKLM\SOFTWARE\MozillaPlugins\@SafePCRepair_89.com/Plugin
Key Found : HKLM\SOFTWARE\SafePCRepair_89
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17420
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] - hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
-\\ Mozilla Firefox v33.1 (x86 cs)
*************************
AdwCleaner[R0].txt - [4764 octets] - [03/12/2014 20:44:41]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [4824 octets] ##########
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 3.12.2014
Scan Time: 20:50:09
Logfile: log.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2014.12.03.11
Rootkit Database: v2014.12.03.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: uzivatel
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 376598
Time Elapsed: 19 min, 4 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 184
PUP.Optional.AudioToAudioToolBar.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SafePCRepair_89Service, , [c0b74a14d4a882b4a55f63d3d927b14f],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{33119133-0854-469d-807A-171568457991}, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{13119113-0854-469d-807A-171568457991}, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncher.1, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncher, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncher, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncher.1, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{03119103-0854-469d-807A-171568457991}, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{23119123-0854-469D-807A-171568457991}, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{23119123-0854-469D-807A-171568457991}, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{03119103-0854-469d-807A-171568457991}, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncherSettings.1, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncherSettings, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncherSettings, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncherSettings.1, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{a9d9ea68-5d09-43ef-a0c5-6f6a6f82a0e1}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{e81003f0-8f21-4a23-8142-403d821198ac}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{0bc5607d-dc04-410a-b137-73f2ee733596}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2438F6B7-0532-4C8C-9C5C-B34935DD3D70}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{34930B93-003D-4FF8-BF64-6A6F27547B0E}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{535062C7-0E84-4CD0-BEB2-59F41DD1A8F5}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A5935A23-63D1-4216-B6B3-7B392880EB21}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A983B26D-76CB-41C6-947E-4EEFF0906747}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B98BE44D-266A-45FE-814D-DB708279E238}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2438F6B7-0532-4C8C-9C5C-B34935DD3D70}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{34930B93-003D-4FF8-BF64-6A6F27547B0E}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{535062C7-0E84-4CD0-BEB2-59F41DD1A8F5}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A5935A23-63D1-4216-B6B3-7B392880EB21}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A983B26D-76CB-41C6-947E-4EEFF0906747}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B98BE44D-266A-45FE-814D-DB708279E238}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{0bc5607d-dc04-410a-b137-73f2ee733596}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SettingsPlugin.1, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SettingsPlugin, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SettingsPlugin, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SettingsPlugin.1, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{E81003F0-8F21-4A23-8142-403D821198AC}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SafePCRepair_89bar Uninstall Firefox, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\SafePCRepair_89, , [abcc1945ec901521fd6995dd4bb89967],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@SafePCRepair_89.com/Plugin, , [caad421c88f41323f86bc1b1e61d5ea2],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1674423443-3875478260-2121563268-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SafePCRepair_89, , [d7a068f6fa82b4825d0050228a79df21],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1674423443-3875478260-2121563268-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Mindspark, , [a3d469f5720a74c285ba15adc1436898],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1674423443-3875478260-2121563268-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\SafePCRepair_89, , [95e20c527309c5712eba1a4f877c9a66],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{b6de1d4c-f21b-4056-a99c-1727fd6400ce}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{63498647-b3ef-4a8a-8c98-163ecf8048fe}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{356E8E19-4DEB-4F01-8DB4-1A0C99129CE7}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5AB21B6C-9EAA-465D-9C21-A1F75981773C}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C62485E9-50DB-4F12-AE49-5D0A9B8BAC2C}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{356E8E19-4DEB-4F01-8DB4-1A0C99129CE7}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5AB21B6C-9EAA-465D-9C21-A1F75981773C}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C62485E9-50DB-4F12-AE49-5D0A9B8BAC2C}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{63498647-b3ef-4a8a-8c98-163ecf8048fe}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ToolbarProtector.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ToolbarProtector, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ToolbarProtector, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ToolbarProtector.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{fe617740-9986-4a5b-a4a8-a66d64ce5e7d}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{f7b9f27c-2e1a-429c-972a-da83f1165b74}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2E685A5C-6D12-4C22-AA7B-32E7467FD7A0}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{590CFF64-4C98-4B32-887C-4F6BC8C89899}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{6E2A759A-C5FC-45BA-92B8-85A6131B1324}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2E685A5C-6D12-4C22-AA7B-32E7467FD7A0}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{590CFF64-4C98-4B32-887C-4F6BC8C89899}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6E2A759A-C5FC-45BA-92B8-85A6131B1324}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{f7b9f27c-2e1a-429c-972a-da83f1165b74}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{79223c67-251e-4447-94fe-762be858d73e}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{b2a921d8-e831-468f-bbc6-16416342c0a7}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B4BCF535-178F-43C9-98B3-1C5447AAF153}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B4BCF535-178F-43C9-98B3-1C5447AAF153}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{b2a921d8-e831-468f-bbc6-16416342c0a7}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{b5d376a7-0327-4265-bbcd-b8e3326e39c7}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.DynamicBarButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.DynamicBarButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.DynamicBarButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.DynamicBarButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{76816fb7-2009-45ec-a3d7-0d45c67d5bd7}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{c78cce0d-f991-44f4-b450-33c4fd189e38}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{41A55DD5-AF6C-482F-9FED-0F3326D71800}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E07DD2E8-0B35-4F00-B311-1F079B94A1B4}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{41A55DD5-AF6C-482F-9FED-0F3326D71800}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E07DD2E8-0B35-4F00-B311-1F079B94A1B4}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{c78cce0d-f991-44f4-b450-33c4fd189e38}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.FeedManager.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.FeedManager, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.FeedManager, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.FeedManager.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{816098C9-EC16-4106-9FF7-E19580B2C338}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLMenu.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLMenu, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLMenu, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLMenu.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{816098C9-EC16-4106-9FF7-E19580B2C338}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{43223489-51e1-4e5c-bbc4-3645dce39afe}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{ccb31621-e2c6-43e7-b5d8-2b161973d5c3}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{35C03DE9-8BA0-4B87-B3D1-51944C349FF1}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7E84E65B-E911-4DC3-B316-E2E854343D1B}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{35C03DE9-8BA0-4B87-B3D1-51944C349FF1}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7E84E65B-E911-4DC3-B316-E2E854343D1B}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{ccb31621-e2c6-43e7-b5d8-2b161973d5c3}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{2accb327-7218-4979-8eb7-0e653bc0ea66}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.MultipleButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.MultipleButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.MultipleButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.MultipleButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9e256edc-b241-4c5b-b949-c347f3b614fd}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{0abe162e-a121-4f56-a7df-a94c95300943}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{457C8D0E-3805-4860-B2CF-DC1CD664AD6B}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{943BEEA6-4A9B-4BBD-A3A4-9EE530425941}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9E0E974B-5E9C-4850-89AB-F7B9F189CCAD}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{457C8D0E-3805-4860-B2CF-DC1CD664AD6B}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{943BEEA6-4A9B-4BBD-A3A4-9EE530425941}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9E0E974B-5E9C-4850-89AB-F7B9F189CCAD}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{0abe162e-a121-4f56-a7df-a94c95300943}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.XMLSessionPlugin.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.XMLSessionPlugin, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.XMLSessionPlugin, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.XMLSessionPlugin.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{9E256EDC-B241-4C5B-B949-C347F3B614FD}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{2f8ae8d5-8f22-40e8-9c9d-b14f5fa9fbcf}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{88a26450-768b-4c55-bdca-d5830e5856dd}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{898E0428-E588-4945-8438-1CC2920D99F1}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{898E0428-E588-4945-8438-1CC2920D99F1}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{88a26450-768b-4c55-bdca-d5830e5856dd}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.RadioSettings.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.RadioSettings, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.RadioSettings, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.RadioSettings.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{99e2e307-a956-4d7d-b1c2-b7448af6b33f}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.Radio.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.Radio, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.Radio, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.Radio.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{a8d7fcf9-a855-449b-aa9f-230ba62c4b4e}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ScriptButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ScriptButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ScriptButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ScriptButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{10019e3c-1039-4c6a-8231-0c657afc4bc4}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{95cd0b4b-5782-435e-993d-ba07b30710a6}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{565ABC73-E8CB-4261-8FDE-C281445CA53D}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{59B4F810-41AC-40F0-9FF1-703EAD14C290}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A42FD199-B78F-452F-B31F-5755D6105704}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B24F3E66-6E22-456F-85F0-43BEF5784F6C}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{565ABC73-E8CB-4261-8FDE-C281445CA53D}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{59B4F810-41AC-40F0-9FF1-703EAD14C290}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A42FD199-B78F-452F-B31F-5755D6105704}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B24F3E66-6E22-456F-85F0-43BEF5784F6C}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{95cd0b4b-5782-435e-993d-ba07b30710a6}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5ed1334e-4e55-40cd-accb-05ce52ad981d}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5ED1334E-4E55-40CD-ACCB-05CE52AD981D}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{fe97fe9a-ef03-47e0-9df9-8ebb728c5d93}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{FE97FE9A-EF03-47E0-9DF9-8EBB728C5D93}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{50066dbf-71b9-4489-b62e-4188d3048db2}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{6c227856-d369-4b3f-a317-89e4b1cd1a83}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{394E9A2F-F433-43F1-9A2E-EAC2C6BB8D80}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E07714D8-5006-492B-A2B1-B433949D6B1D}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{394E9A2F-F433-43F1-9A2E-EAC2C6BB8D80}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E07714D8-5006-492B-A2B1-B433949D6B1D}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{6c227856-d369-4b3f-a317-89e4b1cd1a83}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ThirdPartyInstaller.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ThirdPartyInstaller, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ThirdPartyInstaller, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ThirdPartyInstaller.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{50066DBF-71B9-4489-B62E-4188D3048DB2}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0c7d2cd6-27fb-46c4-8311-de0905048f1a}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.UrlAlertButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.UrlAlertButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.UrlAlertButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.UrlAlertButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5806dc83-95c8-4120-a305-cbce6260adf1}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{154690a0-7778-41b5-a3ab-eb51e2482b74}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3C6E6F5A-8105-423A-AD2C-892FDAC11F49}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{499616EC-7C3D-499E-95ED-5D37D7FC7A3F}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3C6E6F5A-8105-423A-AD2C-892FDAC11F49}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{499616EC-7C3D-499E-95ED-5D37D7FC7A3F}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{154690a0-7778-41b5-a3ab-eb51e2482b74}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLPanel.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLPanel, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLPanel, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLPanel.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5806DC83-95C8-4120-A305-CBCE6260ADF1}, , [78ff3b237a0285b1c566ae70bc4736ca],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 8
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\chrome, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\gen1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\IE9Mesg, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Message, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Settings, , [78ff3b237a0285b1c566ae70bc4736ca],
Files: 58
PUP.Optional.AudioToAudioToolBar.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89barsvc.exe, , [c0b74a14d4a882b4a55f63d3d927b14f],
PUP.Optional.FunWebProducts.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89sknlcr.dll, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89bar.dll, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.Bandoo.A, C:\Users\uzivatel\Downloads\iMeshSetup-r1354-n-bf.exe, , [3f38adb1621a4de93157ad9c758c6c94],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89auxstb.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89bprtct.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89brmon.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89brstub.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89datact.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89dlghk.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89dyn.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89feedmg.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89highin.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89hkstub.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89htmlmu.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89httpct.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89idle.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89ieovr.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89impipe.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89medint.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89mlbtn.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89msg.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89Plugin.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89radio.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89regfft.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89reghk.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89regiet.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89script.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89skin.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89skplay.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89SrcAs.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89SrchMn.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89tpinst.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89uabtn.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\AppIntegrator64.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\AppIntegratorStub64.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\BOOTSTRAP.JS, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\CHROME.MANIFEST, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\CREXT.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\CrExtP89.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\DPNMNGR.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\EXEMANAGER.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\Hpg64.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\INSTALL.RDF, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\installKeys.js, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\LOGO.BMP, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\NP89Stub.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8EXTEX.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8EXTPEX.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8HTML.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8RES.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8TICKER.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\VERIFY.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\chrome\89ffxtbr.jar, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\gen1\COMMON.T8S, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\IE9Mesg\COMMON.T8S, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Message\COMMON.T8S, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Settings\s_pid.dat, , [78ff3b237a0285b1c566ae70bc4736ca],
Physical Sectors: 0
(No malicious items detected)
(end)
# Updated 01/12/2014 by Xplode
# Database : 2014-12-03.1 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : uzivatel - VLK3
# Running from : C:\Users\uzivatel\Desktop\Cisteni pc\adwcleaner_4.103.exe
# Option : Scan
***** [ Services ] *****
Service Found : SafePCRepair_89Service
***** [ Files / Folders ] *****
Folder Found : C:\Program Files (x86)\ICQ6Toolbar
Folder Found : C:\Program Files (x86)\SafePCRepair
Folder Found : C:\Program Files (x86)\SafePCRepair_89
Folder Found : C:\ProgramData\Ask
Folder Found : C:\ProgramData\ICQ\ICQToolbar
Folder Found : C:\ProgramData\iolo
Folder Found : C:\Users\uzivatel\AppData\Local\iolo
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\AppDataLow\Software\Mindspark
Key Found : HKCU\Software\AppDataLow\Software\SafePCRepair_89
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DCA50CB4-6A78-4465-8A4C-EEEFE15DA7C8}
Key Found : HKCU\Software\SafePCRepair_89
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DCA50CB4-6A78-4465-8A4C-EEEFE15DA7C8}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}
Key Found : [x64] HKCU\Software\SafePCRepair_89
Key Found : HKLM\SOFTWARE\Classes\CLSID\{065C1A21-97F8-45FB-A9F0-861B60FACEC8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{13119113-0854-469D-807A-171568457991}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3204358F-5904-46A6-841F-D6B5BE3EF4E3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{33119133-0854-469D-807A-171568457991}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3AE67737-0E3E-44AA-AA5E-46A68BF017FF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3EE5B726-044A-48D2-AA7B-049BD9A0F62A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{60FBBE03-57FF-49D8-B38E-053D3F489825}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6A5182F1-C0B8-42B8-96CC-7F329CD46913}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6C153418-8E4D-4FAF-AF27-5201E38463A7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A26A2F05-AC4D-4A1E-9531-9125F7309B78}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A9D9EA68-5D09-43EF-A0C5-6F6A6F82A0E1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5D6240-7DF0-435D-9B9B-F8586A99DE86}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F343045E-E20A-46E1-82D8-9962C43EFC9E}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FBB360DC-CB6C-4D6A-808A-2C773151BFFF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FFD7DDAC-EC28-42A5-8D39-917B9078604B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Found : HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SettingsPlugin
Key Found : HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SettingsPlugin.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991}
Key Found : HKLM\SOFTWARE\ICQ\ICQToolbar
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SafePCRepair_89bar Uninstall Firefox
Key Found : HKLM\SOFTWARE\MozillaPlugins\@SafePCRepair_89.com/Plugin
Key Found : HKLM\SOFTWARE\SafePCRepair_89
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17420
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] - hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
-\\ Mozilla Firefox v33.1 (x86 cs)
*************************
AdwCleaner[R0].txt - [4764 octets] - [03/12/2014 20:44:41]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [4824 octets] ##########
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 3.12.2014
Scan Time: 20:50:09
Logfile: log.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2014.12.03.11
Rootkit Database: v2014.12.03.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: uzivatel
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 376598
Time Elapsed: 19 min, 4 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 184
PUP.Optional.AudioToAudioToolBar.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SafePCRepair_89Service, , [c0b74a14d4a882b4a55f63d3d927b14f],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{33119133-0854-469d-807A-171568457991}, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{13119113-0854-469d-807A-171568457991}, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncher.1, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncher, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncher, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncher.1, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{03119103-0854-469d-807A-171568457991}, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{23119123-0854-469D-807A-171568457991}, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{23119123-0854-469D-807A-171568457991}, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{03119103-0854-469d-807A-171568457991}, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncherSettings.1, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncherSettings, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncherSettings, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncherSettings.1, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{a9d9ea68-5d09-43ef-a0c5-6f6a6f82a0e1}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{e81003f0-8f21-4a23-8142-403d821198ac}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{0bc5607d-dc04-410a-b137-73f2ee733596}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2438F6B7-0532-4C8C-9C5C-B34935DD3D70}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{34930B93-003D-4FF8-BF64-6A6F27547B0E}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{535062C7-0E84-4CD0-BEB2-59F41DD1A8F5}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A5935A23-63D1-4216-B6B3-7B392880EB21}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A983B26D-76CB-41C6-947E-4EEFF0906747}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B98BE44D-266A-45FE-814D-DB708279E238}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2438F6B7-0532-4C8C-9C5C-B34935DD3D70}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{34930B93-003D-4FF8-BF64-6A6F27547B0E}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{535062C7-0E84-4CD0-BEB2-59F41DD1A8F5}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A5935A23-63D1-4216-B6B3-7B392880EB21}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A983B26D-76CB-41C6-947E-4EEFF0906747}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B98BE44D-266A-45FE-814D-DB708279E238}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{0bc5607d-dc04-410a-b137-73f2ee733596}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SettingsPlugin.1, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SettingsPlugin, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SettingsPlugin, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SettingsPlugin.1, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{E81003F0-8F21-4A23-8142-403D821198AC}, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SafePCRepair_89bar Uninstall Firefox, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\SafePCRepair_89, , [abcc1945ec901521fd6995dd4bb89967],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@SafePCRepair_89.com/Plugin, , [caad421c88f41323f86bc1b1e61d5ea2],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1674423443-3875478260-2121563268-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SafePCRepair_89, , [d7a068f6fa82b4825d0050228a79df21],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1674423443-3875478260-2121563268-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Mindspark, , [a3d469f5720a74c285ba15adc1436898],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1674423443-3875478260-2121563268-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\SafePCRepair_89, , [95e20c527309c5712eba1a4f877c9a66],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{b6de1d4c-f21b-4056-a99c-1727fd6400ce}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{63498647-b3ef-4a8a-8c98-163ecf8048fe}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{356E8E19-4DEB-4F01-8DB4-1A0C99129CE7}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5AB21B6C-9EAA-465D-9C21-A1F75981773C}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C62485E9-50DB-4F12-AE49-5D0A9B8BAC2C}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{356E8E19-4DEB-4F01-8DB4-1A0C99129CE7}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5AB21B6C-9EAA-465D-9C21-A1F75981773C}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C62485E9-50DB-4F12-AE49-5D0A9B8BAC2C}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{63498647-b3ef-4a8a-8c98-163ecf8048fe}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ToolbarProtector.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ToolbarProtector, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ToolbarProtector, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ToolbarProtector.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{fe617740-9986-4a5b-a4a8-a66d64ce5e7d}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{f7b9f27c-2e1a-429c-972a-da83f1165b74}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2E685A5C-6D12-4C22-AA7B-32E7467FD7A0}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{590CFF64-4C98-4B32-887C-4F6BC8C89899}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{6E2A759A-C5FC-45BA-92B8-85A6131B1324}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2E685A5C-6D12-4C22-AA7B-32E7467FD7A0}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{590CFF64-4C98-4B32-887C-4F6BC8C89899}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6E2A759A-C5FC-45BA-92B8-85A6131B1324}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{f7b9f27c-2e1a-429c-972a-da83f1165b74}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{79223c67-251e-4447-94fe-762be858d73e}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{b2a921d8-e831-468f-bbc6-16416342c0a7}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B4BCF535-178F-43C9-98B3-1C5447AAF153}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B4BCF535-178F-43C9-98B3-1C5447AAF153}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{b2a921d8-e831-468f-bbc6-16416342c0a7}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{b5d376a7-0327-4265-bbcd-b8e3326e39c7}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.DynamicBarButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.DynamicBarButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.DynamicBarButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.DynamicBarButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{76816fb7-2009-45ec-a3d7-0d45c67d5bd7}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{c78cce0d-f991-44f4-b450-33c4fd189e38}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{41A55DD5-AF6C-482F-9FED-0F3326D71800}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E07DD2E8-0B35-4F00-B311-1F079B94A1B4}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{41A55DD5-AF6C-482F-9FED-0F3326D71800}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E07DD2E8-0B35-4F00-B311-1F079B94A1B4}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{c78cce0d-f991-44f4-b450-33c4fd189e38}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.FeedManager.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.FeedManager, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.FeedManager, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.FeedManager.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{816098C9-EC16-4106-9FF7-E19580B2C338}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLMenu.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLMenu, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLMenu, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLMenu.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{816098C9-EC16-4106-9FF7-E19580B2C338}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{43223489-51e1-4e5c-bbc4-3645dce39afe}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{ccb31621-e2c6-43e7-b5d8-2b161973d5c3}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{35C03DE9-8BA0-4B87-B3D1-51944C349FF1}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7E84E65B-E911-4DC3-B316-E2E854343D1B}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{35C03DE9-8BA0-4B87-B3D1-51944C349FF1}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7E84E65B-E911-4DC3-B316-E2E854343D1B}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{ccb31621-e2c6-43e7-b5d8-2b161973d5c3}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{2accb327-7218-4979-8eb7-0e653bc0ea66}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.MultipleButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.MultipleButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.MultipleButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.MultipleButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9e256edc-b241-4c5b-b949-c347f3b614fd}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{0abe162e-a121-4f56-a7df-a94c95300943}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{457C8D0E-3805-4860-B2CF-DC1CD664AD6B}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{943BEEA6-4A9B-4BBD-A3A4-9EE530425941}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9E0E974B-5E9C-4850-89AB-F7B9F189CCAD}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{457C8D0E-3805-4860-B2CF-DC1CD664AD6B}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{943BEEA6-4A9B-4BBD-A3A4-9EE530425941}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9E0E974B-5E9C-4850-89AB-F7B9F189CCAD}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{0abe162e-a121-4f56-a7df-a94c95300943}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.XMLSessionPlugin.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.XMLSessionPlugin, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.XMLSessionPlugin, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.XMLSessionPlugin.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{9E256EDC-B241-4C5B-B949-C347F3B614FD}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{2f8ae8d5-8f22-40e8-9c9d-b14f5fa9fbcf}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{88a26450-768b-4c55-bdca-d5830e5856dd}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{898E0428-E588-4945-8438-1CC2920D99F1}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{898E0428-E588-4945-8438-1CC2920D99F1}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{88a26450-768b-4c55-bdca-d5830e5856dd}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.RadioSettings.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.RadioSettings, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.RadioSettings, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.RadioSettings.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{99e2e307-a956-4d7d-b1c2-b7448af6b33f}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.Radio.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.Radio, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.Radio, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.Radio.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{a8d7fcf9-a855-449b-aa9f-230ba62c4b4e}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ScriptButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ScriptButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ScriptButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ScriptButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{10019e3c-1039-4c6a-8231-0c657afc4bc4}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{95cd0b4b-5782-435e-993d-ba07b30710a6}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{565ABC73-E8CB-4261-8FDE-C281445CA53D}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{59B4F810-41AC-40F0-9FF1-703EAD14C290}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A42FD199-B78F-452F-B31F-5755D6105704}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B24F3E66-6E22-456F-85F0-43BEF5784F6C}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{565ABC73-E8CB-4261-8FDE-C281445CA53D}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{59B4F810-41AC-40F0-9FF1-703EAD14C290}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A42FD199-B78F-452F-B31F-5755D6105704}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B24F3E66-6E22-456F-85F0-43BEF5784F6C}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{95cd0b4b-5782-435e-993d-ba07b30710a6}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5ed1334e-4e55-40cd-accb-05ce52ad981d}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5ED1334E-4E55-40CD-ACCB-05CE52AD981D}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{fe97fe9a-ef03-47e0-9df9-8ebb728c5d93}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{FE97FE9A-EF03-47E0-9DF9-8EBB728C5D93}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{50066dbf-71b9-4489-b62e-4188d3048db2}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{6c227856-d369-4b3f-a317-89e4b1cd1a83}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{394E9A2F-F433-43F1-9A2E-EAC2C6BB8D80}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E07714D8-5006-492B-A2B1-B433949D6B1D}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{394E9A2F-F433-43F1-9A2E-EAC2C6BB8D80}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E07714D8-5006-492B-A2B1-B433949D6B1D}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{6c227856-d369-4b3f-a317-89e4b1cd1a83}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ThirdPartyInstaller.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ThirdPartyInstaller, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ThirdPartyInstaller, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ThirdPartyInstaller.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{50066DBF-71B9-4489-B62E-4188D3048DB2}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0c7d2cd6-27fb-46c4-8311-de0905048f1a}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.UrlAlertButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.UrlAlertButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.UrlAlertButton, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.UrlAlertButton.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5806dc83-95c8-4120-a305-cbce6260adf1}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{154690a0-7778-41b5-a3ab-eb51e2482b74}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3C6E6F5A-8105-423A-AD2C-892FDAC11F49}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{499616EC-7C3D-499E-95ED-5D37D7FC7A3F}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3C6E6F5A-8105-423A-AD2C-892FDAC11F49}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{499616EC-7C3D-499E-95ED-5D37D7FC7A3F}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{154690a0-7778-41b5-a3ab-eb51e2482b74}, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLPanel.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLPanel, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLPanel, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLPanel.1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5806DC83-95C8-4120-A305-CBCE6260ADF1}, , [78ff3b237a0285b1c566ae70bc4736ca],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 8
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\chrome, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\gen1, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\IE9Mesg, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Message, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Settings, , [78ff3b237a0285b1c566ae70bc4736ca],
Files: 58
PUP.Optional.AudioToAudioToolBar.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89barsvc.exe, , [c0b74a14d4a882b4a55f63d3d927b14f],
PUP.Optional.FunWebProducts.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89sknlcr.dll, , [354291cd2e4ea393b22c23dd4ab927d9],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89bar.dll, , [d6a1411db6c6e353b964d1f711f1fa06],
PUP.Optional.Bandoo.A, C:\Users\uzivatel\Downloads\iMeshSetup-r1354-n-bf.exe, , [3f38adb1621a4de93157ad9c758c6c94],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89auxstb.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89bprtct.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89brmon.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89brstub.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89datact.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89dlghk.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89dyn.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89feedmg.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89highin.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89hkstub.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89htmlmu.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89httpct.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89idle.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89ieovr.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89impipe.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89medint.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89mlbtn.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89msg.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89Plugin.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89radio.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89regfft.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89reghk.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89regiet.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89script.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89skin.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89skplay.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89SrcAs.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89SrchMn.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89tpinst.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89uabtn.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\AppIntegrator64.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\AppIntegratorStub64.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\BOOTSTRAP.JS, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\CHROME.MANIFEST, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\CREXT.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\CrExtP89.exe, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\DPNMNGR.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\EXEMANAGER.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\Hpg64.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\INSTALL.RDF, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\installKeys.js, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\LOGO.BMP, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\NP89Stub.dll, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8EXTEX.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8EXTPEX.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8HTML.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8RES.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8TICKER.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\VERIFY.DLL, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\chrome\89ffxtbr.jar, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\gen1\COMMON.T8S, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\IE9Mesg\COMMON.T8S, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Message\COMMON.T8S, , [78ff3b237a0285b1c566ae70bc4736ca],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Settings\s_pid.dat, , [78ff3b237a0285b1c566ae70bc4736ca],
Physical Sectors: 0
(No malicious items detected)
(end)
- Orcus
- člen Security týmu
-
Elite Level 10.5
- Příspěvky: 10645
- Registrován: duben 10
- Bydliště: Okolo rostou 3 růže =o)
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Znovu spusť MbAM a dej Skenovat nyní
Po proběhnutí programu se ti objeví hláška, tak klikni na „Vše do karantény“ -> „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a ulož na Plochu.
Zkopíruj sem celý obsah toho logu.
====================================================
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
Klikni na „ Smazat“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
====================================================
Stáhni si Junkware Removal Tool
na svojí plochu.
Deaktivuj si svůj antivirový program.
Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
====================================================
Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Po proběhnutí programu se ti objeví hláška, tak klikni na „Vše do karantény“ -> „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a ulož na Plochu.
Zkopíruj sem celý obsah toho logu.
====================================================
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
Klikni na „ Smazat“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
====================================================
Stáhni si Junkware Removal Tool
na svojí plochu.
Deaktivuj si svůj antivirový program.
Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
====================================================
Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Láska hřeje, ale uhlí je uhlí.
Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.

Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.
Re: Prosím o kontrolu logu
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 4.12.2014
Scan Time: 19:42:12
Logfile: 2014_12_04.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2014.12.04.08
Rootkit Database: v2014.12.03.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: uzivatel
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 377090
Time Elapsed: 15 min, 10 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 184
PUP.Optional.AudioToAudioToolBar.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SafePCRepair_89Service, Quarantined, [c216d38b037981b53bcb9f97ab557090],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{33119133-0854-469d-807A-171568457991}, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{13119113-0854-469d-807A-171568457991}, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncher.1, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncher, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncher, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncher.1, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{03119103-0854-469d-807A-171568457991}, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{23119123-0854-469D-807A-171568457991}, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{23119123-0854-469D-807A-171568457991}, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{03119103-0854-469d-807A-171568457991}, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncherSettings.1, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncherSettings, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncherSettings, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncherSettings.1, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{a9d9ea68-5d09-43ef-a0c5-6f6a6f82a0e1}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{e81003f0-8f21-4a23-8142-403d821198ac}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{0bc5607d-dc04-410a-b137-73f2ee733596}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2438F6B7-0532-4C8C-9C5C-B34935DD3D70}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{34930B93-003D-4FF8-BF64-6A6F27547B0E}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{535062C7-0E84-4CD0-BEB2-59F41DD1A8F5}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A5935A23-63D1-4216-B6B3-7B392880EB21}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A983B26D-76CB-41C6-947E-4EEFF0906747}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B98BE44D-266A-45FE-814D-DB708279E238}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2438F6B7-0532-4C8C-9C5C-B34935DD3D70}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{34930B93-003D-4FF8-BF64-6A6F27547B0E}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{535062C7-0E84-4CD0-BEB2-59F41DD1A8F5}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A5935A23-63D1-4216-B6B3-7B392880EB21}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A983B26D-76CB-41C6-947E-4EEFF0906747}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B98BE44D-266A-45FE-814D-DB708279E238}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{0bc5607d-dc04-410a-b137-73f2ee733596}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SettingsPlugin.1, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SettingsPlugin, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SettingsPlugin, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SettingsPlugin.1, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{E81003F0-8F21-4A23-8142-403D821198AC}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SafePCRepair_89bar Uninstall Firefox, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\SafePCRepair_89, Quarantined, [fedae27c354747ef502d0e6524df669a],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@SafePCRepair_89.com/Plugin, Quarantined, [6276005e2e4e9c9a94e65221689b40c0],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1674423443-3875478260-2121563268-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SafePCRepair_89, Quarantined, [55838fcfd0acee48d0a4f87be1220ff1],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1674423443-3875478260-2121563268-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Mindspark, Quarantined, [fddb6df10e6e7abc084df2d10ef6d12f],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1674423443-3875478260-2121563268-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\SafePCRepair_89, Quarantined, [e3f5c09e90ec9d993dc3d299659ecb35],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{b6de1d4c-f21b-4056-a99c-1727fd6400ce}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{63498647-b3ef-4a8a-8c98-163ecf8048fe}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{356E8E19-4DEB-4F01-8DB4-1A0C99129CE7}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5AB21B6C-9EAA-465D-9C21-A1F75981773C}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C62485E9-50DB-4F12-AE49-5D0A9B8BAC2C}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{356E8E19-4DEB-4F01-8DB4-1A0C99129CE7}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5AB21B6C-9EAA-465D-9C21-A1F75981773C}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C62485E9-50DB-4F12-AE49-5D0A9B8BAC2C}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{63498647-b3ef-4a8a-8c98-163ecf8048fe}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ToolbarProtector.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ToolbarProtector, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ToolbarProtector, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ToolbarProtector.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{fe617740-9986-4a5b-a4a8-a66d64ce5e7d}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{f7b9f27c-2e1a-429c-972a-da83f1165b74}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2E685A5C-6D12-4C22-AA7B-32E7467FD7A0}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{590CFF64-4C98-4B32-887C-4F6BC8C89899}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{6E2A759A-C5FC-45BA-92B8-85A6131B1324}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2E685A5C-6D12-4C22-AA7B-32E7467FD7A0}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{590CFF64-4C98-4B32-887C-4F6BC8C89899}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6E2A759A-C5FC-45BA-92B8-85A6131B1324}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{f7b9f27c-2e1a-429c-972a-da83f1165b74}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{79223c67-251e-4447-94fe-762be858d73e}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{b2a921d8-e831-468f-bbc6-16416342c0a7}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B4BCF535-178F-43C9-98B3-1C5447AAF153}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B4BCF535-178F-43C9-98B3-1C5447AAF153}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{b2a921d8-e831-468f-bbc6-16416342c0a7}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{b5d376a7-0327-4265-bbcd-b8e3326e39c7}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.DynamicBarButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.DynamicBarButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.DynamicBarButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.DynamicBarButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{76816fb7-2009-45ec-a3d7-0d45c67d5bd7}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{c78cce0d-f991-44f4-b450-33c4fd189e38}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{41A55DD5-AF6C-482F-9FED-0F3326D71800}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E07DD2E8-0B35-4F00-B311-1F079B94A1B4}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{41A55DD5-AF6C-482F-9FED-0F3326D71800}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E07DD2E8-0B35-4F00-B311-1F079B94A1B4}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{c78cce0d-f991-44f4-b450-33c4fd189e38}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.FeedManager.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.FeedManager, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.FeedManager, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.FeedManager.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{816098C9-EC16-4106-9FF7-E19580B2C338}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLMenu.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLMenu, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLMenu, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLMenu.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{816098C9-EC16-4106-9FF7-E19580B2C338}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{43223489-51e1-4e5c-bbc4-3645dce39afe}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{ccb31621-e2c6-43e7-b5d8-2b161973d5c3}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{35C03DE9-8BA0-4B87-B3D1-51944C349FF1}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7E84E65B-E911-4DC3-B316-E2E854343D1B}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{35C03DE9-8BA0-4B87-B3D1-51944C349FF1}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7E84E65B-E911-4DC3-B316-E2E854343D1B}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{ccb31621-e2c6-43e7-b5d8-2b161973d5c3}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{2accb327-7218-4979-8eb7-0e653bc0ea66}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.MultipleButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.MultipleButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.MultipleButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.MultipleButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9e256edc-b241-4c5b-b949-c347f3b614fd}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{0abe162e-a121-4f56-a7df-a94c95300943}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{457C8D0E-3805-4860-B2CF-DC1CD664AD6B}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{943BEEA6-4A9B-4BBD-A3A4-9EE530425941}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9E0E974B-5E9C-4850-89AB-F7B9F189CCAD}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{457C8D0E-3805-4860-B2CF-DC1CD664AD6B}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{943BEEA6-4A9B-4BBD-A3A4-9EE530425941}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9E0E974B-5E9C-4850-89AB-F7B9F189CCAD}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{0abe162e-a121-4f56-a7df-a94c95300943}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.XMLSessionPlugin.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.XMLSessionPlugin, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.XMLSessionPlugin, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.XMLSessionPlugin.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{9E256EDC-B241-4C5B-B949-C347F3B614FD}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{2f8ae8d5-8f22-40e8-9c9d-b14f5fa9fbcf}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{88a26450-768b-4c55-bdca-d5830e5856dd}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{898E0428-E588-4945-8438-1CC2920D99F1}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{898E0428-E588-4945-8438-1CC2920D99F1}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{88a26450-768b-4c55-bdca-d5830e5856dd}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.RadioSettings.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.RadioSettings, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.RadioSettings, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.RadioSettings.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{99e2e307-a956-4d7d-b1c2-b7448af6b33f}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.Radio.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.Radio, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.Radio, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.Radio.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{a8d7fcf9-a855-449b-aa9f-230ba62c4b4e}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ScriptButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ScriptButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ScriptButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ScriptButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{10019e3c-1039-4c6a-8231-0c657afc4bc4}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{95cd0b4b-5782-435e-993d-ba07b30710a6}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{565ABC73-E8CB-4261-8FDE-C281445CA53D}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{59B4F810-41AC-40F0-9FF1-703EAD14C290}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A42FD199-B78F-452F-B31F-5755D6105704}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B24F3E66-6E22-456F-85F0-43BEF5784F6C}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{565ABC73-E8CB-4261-8FDE-C281445CA53D}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{59B4F810-41AC-40F0-9FF1-703EAD14C290}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A42FD199-B78F-452F-B31F-5755D6105704}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B24F3E66-6E22-456F-85F0-43BEF5784F6C}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{95cd0b4b-5782-435e-993d-ba07b30710a6}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5ed1334e-4e55-40cd-accb-05ce52ad981d}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5ED1334E-4E55-40CD-ACCB-05CE52AD981D}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{fe97fe9a-ef03-47e0-9df9-8ebb728c5d93}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{FE97FE9A-EF03-47E0-9DF9-8EBB728C5D93}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{50066dbf-71b9-4489-b62e-4188d3048db2}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{6c227856-d369-4b3f-a317-89e4b1cd1a83}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{394E9A2F-F433-43F1-9A2E-EAC2C6BB8D80}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E07714D8-5006-492B-A2B1-B433949D6B1D}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{394E9A2F-F433-43F1-9A2E-EAC2C6BB8D80}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E07714D8-5006-492B-A2B1-B433949D6B1D}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{6c227856-d369-4b3f-a317-89e4b1cd1a83}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ThirdPartyInstaller.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ThirdPartyInstaller, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ThirdPartyInstaller, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ThirdPartyInstaller.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{50066DBF-71B9-4489-B62E-4188D3048DB2}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0c7d2cd6-27fb-46c4-8311-de0905048f1a}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.UrlAlertButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.UrlAlertButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.UrlAlertButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.UrlAlertButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5806dc83-95c8-4120-a305-cbce6260adf1}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{154690a0-7778-41b5-a3ab-eb51e2482b74}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3C6E6F5A-8105-423A-AD2C-892FDAC11F49}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{499616EC-7C3D-499E-95ED-5D37D7FC7A3F}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3C6E6F5A-8105-423A-AD2C-892FDAC11F49}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{499616EC-7C3D-499E-95ED-5D37D7FC7A3F}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{154690a0-7778-41b5-a3ab-eb51e2482b74}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLPanel.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLPanel, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLPanel, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLPanel.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5806DC83-95C8-4120-A305-CBCE6260ADF1}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 8
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89, Delete-on-Reboot, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar, Delete-on-Reboot, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin, Delete-on-Reboot, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\chrome, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\gen1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\IE9Mesg, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Message, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Settings, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
Files: 58
PUP.Optional.AudioToAudioToolBar.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89barsvc.exe, Delete-on-Reboot, [c216d38b037981b53bcb9f97ab557090],
PUP.Optional.FunWebProducts.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89sknlcr.dll, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89bar.dll, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.Bandoo.A, C:\Users\uzivatel\Downloads\iMeshSetup-r1354-n-bf.exe, Quarantined, [22b669f5b9c366d009a3301923de6e92],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89auxstb.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89bprtct.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89brmon.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89brstub.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89datact.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89dlghk.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89dyn.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89feedmg.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89highin.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89hkstub.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89htmlmu.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89httpct.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89idle.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89ieovr.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89impipe.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89medint.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89mlbtn.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89msg.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89Plugin.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89radio.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89regfft.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89reghk.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89regiet.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89script.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89skin.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89skplay.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89SrcAs.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89SrchMn.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89tpinst.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89uabtn.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\AppIntegrator64.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\AppIntegratorStub64.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\BOOTSTRAP.JS, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\CHROME.MANIFEST, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\CREXT.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\CrExtP89.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\DPNMNGR.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\EXEMANAGER.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\Hpg64.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\INSTALL.RDF, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\installKeys.js, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\LOGO.BMP, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\NP89Stub.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8EXTEX.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8EXTPEX.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8HTML.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8RES.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8TICKER.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\VERIFY.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\chrome\89ffxtbr.jar, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\gen1\COMMON.T8S, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\IE9Mesg\COMMON.T8S, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Message\COMMON.T8S, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Settings\s_pid.dat, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
Physical Sectors: 0
(No malicious items detected)
(end)
# AdwCleaner v4.103 - Report created 04/12/2014 at 20:11:23
# Updated 01/12/2014 by Xplode
# Database : 2014-12-03.1 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : uzivatel - VLK3
# Running from : C:\Users\uzivatel\Desktop\Cisteni pc\adwcleaner_4.103.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\iolo
Folder Deleted : C:\Program Files (x86)\ICQ6Toolbar
Folder Deleted : C:\Program Files (x86)\SafePCRepair
Folder Deleted : C:\Users\uzivatel\AppData\Local\iolo
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{065C1A21-97F8-45FB-A9F0-861B60FACEC8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3204358F-5904-46A6-841F-D6B5BE3EF4E3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3AE67737-0E3E-44AA-AA5E-46A68BF017FF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3EE5B726-044A-48D2-AA7B-049BD9A0F62A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{60FBBE03-57FF-49D8-B38E-053D3F489825}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6A5182F1-C0B8-42B8-96CC-7F329CD46913}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6C153418-8E4D-4FAF-AF27-5201E38463A7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A26A2F05-AC4D-4A1E-9531-9125F7309B78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5D6240-7DF0-435D-9B9B-F8586A99DE86}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F343045E-E20A-46E1-82D8-9962C43EFC9E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FBB360DC-CB6C-4D6A-808A-2C773151BFFF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FFD7DDAC-EC28-42A5-8D39-917B9078604B}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DCA50CB4-6A78-4465-8A4C-EEEFE15DA7C8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Key Deleted : HKLM\SOFTWARE\ICQ\ICQToolbar
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17420
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v33.1 (x86 cs)
*************************
AdwCleaner[R0].txt - [4948 octets] - [03/12/2014 20:44:41]
AdwCleaner[R1].txt - [3851 octets] - [04/12/2014 20:06:06]
AdwCleaner[R2].txt - [3911 octets] - [04/12/2014 20:09:14]
AdwCleaner[S0].txt - [3136 octets] - [04/12/2014 20:11:23]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3196 octets] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Professional x64
Ran by uzivatel on źt 04.12.2014 at 20:18:53,05
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\uzivatel\AppData\Roaming\mozilla\firefox\profiles\neeurwhm.default\minidumps [35 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 04.12.2014 at 20:23:39,16
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
RogueKiller V10.0.8.0 (x64) [Nov 20 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : uzivatel [Práva správce]
Mód : Prohledat -- Datum : 12/04/2014 20:34:43
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 16 ¤¤¤
[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms} -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{BB1C490A-7BF1-4860-81F8-27BC56DEBA77} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{BB1C490A-7BF1-4860-81F8-27BC56DEBA77} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{BB1C490A-7BF1-4860-81F8-27BC56DEBA77} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
¤¤¤ Úlohy : 1 ¤¤¤
[Suspicious.Path] \\Registration -- "C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe" (Registration ShowMessageTask2D) -> Nalezeno
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 14 ¤¤¤
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 practivate.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 ereg.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate.wip3.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 wip3.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 3dns-3.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 3dns-2.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 adobe-dns.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 adobe-dns-2.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 adobe-dns-3.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 ereg.wip3.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate-sea.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 wwis-dubc1-vip60.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate-sjc0.adobe.com
¤¤¤ Antirootkit : 1 (Driver: Nahrán) ¤¤¤
[Filter(Kernel.Filter)] \Driver\Disk @ Unknown : \Driver\MfeEpeOpal @ Unknown (\SystemRoot\System32\Drivers\MfeEpeOpal.sys)
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS725050A9A364 +++++
--- User ---
[MBR] 3cf7a82bea6e45de68be95a1734b3b34
[BSP] ab099ab106e808ad63dece2a6da147cf : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 300 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 616448 | Size: 455772 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 934037504 | Size: 15744 MB
3 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 966281216 | Size: 5115 MB
User = LL1 ... OK
User = LL2 ... OK
www.malwarebytes.org
Scan Date: 4.12.2014
Scan Time: 19:42:12
Logfile: 2014_12_04.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2014.12.04.08
Rootkit Database: v2014.12.03.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: uzivatel
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 377090
Time Elapsed: 15 min, 10 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 184
PUP.Optional.AudioToAudioToolBar.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SafePCRepair_89Service, Quarantined, [c216d38b037981b53bcb9f97ab557090],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{33119133-0854-469d-807A-171568457991}, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{13119113-0854-469d-807A-171568457991}, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncher.1, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncher, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncher, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncher.1, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{03119103-0854-469d-807A-171568457991}, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{23119123-0854-469D-807A-171568457991}, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{23119123-0854-469D-807A-171568457991}, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{03119103-0854-469d-807A-171568457991}, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncherSettings.1, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SkinLauncherSettings, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncherSettings, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SkinLauncherSettings.1, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{a9d9ea68-5d09-43ef-a0c5-6f6a6f82a0e1}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{e81003f0-8f21-4a23-8142-403d821198ac}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{0bc5607d-dc04-410a-b137-73f2ee733596}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2438F6B7-0532-4C8C-9C5C-B34935DD3D70}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{34930B93-003D-4FF8-BF64-6A6F27547B0E}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{535062C7-0E84-4CD0-BEB2-59F41DD1A8F5}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A5935A23-63D1-4216-B6B3-7B392880EB21}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A983B26D-76CB-41C6-947E-4EEFF0906747}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B98BE44D-266A-45FE-814D-DB708279E238}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2438F6B7-0532-4C8C-9C5C-B34935DD3D70}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{34930B93-003D-4FF8-BF64-6A6F27547B0E}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{535062C7-0E84-4CD0-BEB2-59F41DD1A8F5}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A5935A23-63D1-4216-B6B3-7B392880EB21}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A983B26D-76CB-41C6-947E-4EEFF0906747}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B98BE44D-266A-45FE-814D-DB708279E238}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{0bc5607d-dc04-410a-b137-73f2ee733596}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SettingsPlugin.1, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.SettingsPlugin, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SettingsPlugin, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.SettingsPlugin.1, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{E81003F0-8F21-4A23-8142-403D821198AC}, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SafePCRepair_89bar Uninstall Firefox, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\SafePCRepair_89, Quarantined, [fedae27c354747ef502d0e6524df669a],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@SafePCRepair_89.com/Plugin, Quarantined, [6276005e2e4e9c9a94e65221689b40c0],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1674423443-3875478260-2121563268-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SafePCRepair_89, Quarantined, [55838fcfd0acee48d0a4f87be1220ff1],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1674423443-3875478260-2121563268-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Mindspark, Quarantined, [fddb6df10e6e7abc084df2d10ef6d12f],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1674423443-3875478260-2121563268-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\SafePCRepair_89, Quarantined, [e3f5c09e90ec9d993dc3d299659ecb35],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{b6de1d4c-f21b-4056-a99c-1727fd6400ce}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{63498647-b3ef-4a8a-8c98-163ecf8048fe}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{356E8E19-4DEB-4F01-8DB4-1A0C99129CE7}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5AB21B6C-9EAA-465D-9C21-A1F75981773C}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C62485E9-50DB-4F12-AE49-5D0A9B8BAC2C}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{356E8E19-4DEB-4F01-8DB4-1A0C99129CE7}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5AB21B6C-9EAA-465D-9C21-A1F75981773C}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C62485E9-50DB-4F12-AE49-5D0A9B8BAC2C}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{63498647-b3ef-4a8a-8c98-163ecf8048fe}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ToolbarProtector.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ToolbarProtector, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ToolbarProtector, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ToolbarProtector.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{fe617740-9986-4a5b-a4a8-a66d64ce5e7d}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{f7b9f27c-2e1a-429c-972a-da83f1165b74}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2E685A5C-6D12-4C22-AA7B-32E7467FD7A0}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{590CFF64-4C98-4B32-887C-4F6BC8C89899}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{6E2A759A-C5FC-45BA-92B8-85A6131B1324}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2E685A5C-6D12-4C22-AA7B-32E7467FD7A0}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{590CFF64-4C98-4B32-887C-4F6BC8C89899}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6E2A759A-C5FC-45BA-92B8-85A6131B1324}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{f7b9f27c-2e1a-429c-972a-da83f1165b74}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{79223c67-251e-4447-94fe-762be858d73e}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{b2a921d8-e831-468f-bbc6-16416342c0a7}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B4BCF535-178F-43C9-98B3-1C5447AAF153}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B4BCF535-178F-43C9-98B3-1C5447AAF153}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{b2a921d8-e831-468f-bbc6-16416342c0a7}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{b5d376a7-0327-4265-bbcd-b8e3326e39c7}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.DynamicBarButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.DynamicBarButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.DynamicBarButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.DynamicBarButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{76816fb7-2009-45ec-a3d7-0d45c67d5bd7}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{c78cce0d-f991-44f4-b450-33c4fd189e38}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{41A55DD5-AF6C-482F-9FED-0F3326D71800}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E07DD2E8-0B35-4F00-B311-1F079B94A1B4}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{41A55DD5-AF6C-482F-9FED-0F3326D71800}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E07DD2E8-0B35-4F00-B311-1F079B94A1B4}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{c78cce0d-f991-44f4-b450-33c4fd189e38}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.FeedManager.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.FeedManager, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.FeedManager, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.FeedManager.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{816098C9-EC16-4106-9FF7-E19580B2C338}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLMenu.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLMenu, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLMenu, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLMenu.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{816098C9-EC16-4106-9FF7-E19580B2C338}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{43223489-51e1-4e5c-bbc4-3645dce39afe}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{ccb31621-e2c6-43e7-b5d8-2b161973d5c3}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{35C03DE9-8BA0-4B87-B3D1-51944C349FF1}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7E84E65B-E911-4DC3-B316-E2E854343D1B}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{35C03DE9-8BA0-4B87-B3D1-51944C349FF1}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7E84E65B-E911-4DC3-B316-E2E854343D1B}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{ccb31621-e2c6-43e7-b5d8-2b161973d5c3}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{2accb327-7218-4979-8eb7-0e653bc0ea66}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.MultipleButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.MultipleButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.MultipleButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.MultipleButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9e256edc-b241-4c5b-b949-c347f3b614fd}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{0abe162e-a121-4f56-a7df-a94c95300943}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{457C8D0E-3805-4860-B2CF-DC1CD664AD6B}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{943BEEA6-4A9B-4BBD-A3A4-9EE530425941}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9E0E974B-5E9C-4850-89AB-F7B9F189CCAD}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{457C8D0E-3805-4860-B2CF-DC1CD664AD6B}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{943BEEA6-4A9B-4BBD-A3A4-9EE530425941}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9E0E974B-5E9C-4850-89AB-F7B9F189CCAD}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{0abe162e-a121-4f56-a7df-a94c95300943}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.XMLSessionPlugin.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.XMLSessionPlugin, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.XMLSessionPlugin, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.XMLSessionPlugin.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{9E256EDC-B241-4C5B-B949-C347F3B614FD}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{2f8ae8d5-8f22-40e8-9c9d-b14f5fa9fbcf}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{88a26450-768b-4c55-bdca-d5830e5856dd}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{898E0428-E588-4945-8438-1CC2920D99F1}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{898E0428-E588-4945-8438-1CC2920D99F1}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{88a26450-768b-4c55-bdca-d5830e5856dd}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.RadioSettings.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.RadioSettings, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.RadioSettings, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.RadioSettings.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{99e2e307-a956-4d7d-b1c2-b7448af6b33f}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.Radio.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.Radio, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.Radio, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.Radio.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{a8d7fcf9-a855-449b-aa9f-230ba62c4b4e}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ScriptButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ScriptButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ScriptButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ScriptButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{10019e3c-1039-4c6a-8231-0c657afc4bc4}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{95cd0b4b-5782-435e-993d-ba07b30710a6}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{565ABC73-E8CB-4261-8FDE-C281445CA53D}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{59B4F810-41AC-40F0-9FF1-703EAD14C290}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A42FD199-B78F-452F-B31F-5755D6105704}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B24F3E66-6E22-456F-85F0-43BEF5784F6C}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{565ABC73-E8CB-4261-8FDE-C281445CA53D}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{59B4F810-41AC-40F0-9FF1-703EAD14C290}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A42FD199-B78F-452F-B31F-5755D6105704}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B24F3E66-6E22-456F-85F0-43BEF5784F6C}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{95cd0b4b-5782-435e-993d-ba07b30710a6}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5ed1334e-4e55-40cd-accb-05ce52ad981d}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5ED1334E-4E55-40CD-ACCB-05CE52AD981D}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{fe97fe9a-ef03-47e0-9df9-8ebb728c5d93}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.PseudoTransparentPlugin.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{FE97FE9A-EF03-47E0-9DF9-8EBB728C5D93}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{50066dbf-71b9-4489-b62e-4188d3048db2}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{6c227856-d369-4b3f-a317-89e4b1cd1a83}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{394E9A2F-F433-43F1-9A2E-EAC2C6BB8D80}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E07714D8-5006-492B-A2B1-B433949D6B1D}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{394E9A2F-F433-43F1-9A2E-EAC2C6BB8D80}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E07714D8-5006-492B-A2B1-B433949D6B1D}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{6c227856-d369-4b3f-a317-89e4b1cd1a83}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ThirdPartyInstaller.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.ThirdPartyInstaller, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ThirdPartyInstaller, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.ThirdPartyInstaller.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{50066DBF-71B9-4489-B62E-4188D3048DB2}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0c7d2cd6-27fb-46c4-8311-de0905048f1a}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.UrlAlertButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.UrlAlertButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.UrlAlertButton, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.UrlAlertButton.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5806dc83-95c8-4120-a305-cbce6260adf1}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{154690a0-7778-41b5-a3ab-eb51e2482b74}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3C6E6F5A-8105-423A-AD2C-892FDAC11F49}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{499616EC-7C3D-499E-95ED-5D37D7FC7A3F}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3C6E6F5A-8105-423A-AD2C-892FDAC11F49}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{499616EC-7C3D-499E-95ED-5D37D7FC7A3F}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{154690a0-7778-41b5-a3ab-eb51e2482b74}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLPanel.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\SafePCRepair_89.HTMLPanel, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLPanel, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SafePCRepair_89.HTMLPanel.1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5806DC83-95C8-4120-A305-CBCE6260ADF1}, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 8
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89, Delete-on-Reboot, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar, Delete-on-Reboot, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin, Delete-on-Reboot, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\chrome, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\gen1, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\IE9Mesg, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Message, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Settings, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
Files: 58
PUP.Optional.AudioToAudioToolBar.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89barsvc.exe, Delete-on-Reboot, [c216d38b037981b53bcb9f97ab557090],
PUP.Optional.FunWebProducts.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89sknlcr.dll, Quarantined, [0fc948164e2e3600dace847d5aa94eb2],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89bar.dll, Quarantined, [08d0322c91eb52e47a6d7751936ff50b],
PUP.Optional.Bandoo.A, C:\Users\uzivatel\Downloads\iMeshSetup-r1354-n-bf.exe, Quarantined, [22b669f5b9c366d009a3301923de6e92],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89auxstb.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89bprtct.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89brmon.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89brstub.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89datact.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89dlghk.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89dyn.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89feedmg.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89highin.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89hkstub.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89htmlmu.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89httpct.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89idle.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89ieovr.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89impipe.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89medint.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89mlbtn.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89msg.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89Plugin.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89radio.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89regfft.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89reghk.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89regiet.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89script.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89skin.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89skplay.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89SrcAs.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89SrchMn.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89tpinst.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\89uabtn.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\AppIntegrator64.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\AppIntegratorStub64.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\BOOTSTRAP.JS, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\CHROME.MANIFEST, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\CREXT.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\CrExtP89.exe, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\DPNMNGR.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\EXEMANAGER.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\Hpg64.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\INSTALL.RDF, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\installKeys.js, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\LOGO.BMP, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\NP89Stub.dll, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8EXTEX.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8EXTPEX.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8HTML.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8RES.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\T8TICKER.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\VERIFY.DLL, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\1.bin\chrome\89ffxtbr.jar, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\gen1\COMMON.T8S, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\IE9Mesg\COMMON.T8S, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Message\COMMON.T8S, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\SafePCRepair_89\bar\Settings\s_pid.dat, Quarantined, [26b26df1c6b60e2857a437e7cc372fd1],
Physical Sectors: 0
(No malicious items detected)
(end)
# AdwCleaner v4.103 - Report created 04/12/2014 at 20:11:23
# Updated 01/12/2014 by Xplode
# Database : 2014-12-03.1 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : uzivatel - VLK3
# Running from : C:\Users\uzivatel\Desktop\Cisteni pc\adwcleaner_4.103.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\iolo
Folder Deleted : C:\Program Files (x86)\ICQ6Toolbar
Folder Deleted : C:\Program Files (x86)\SafePCRepair
Folder Deleted : C:\Users\uzivatel\AppData\Local\iolo
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{065C1A21-97F8-45FB-A9F0-861B60FACEC8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3204358F-5904-46A6-841F-D6B5BE3EF4E3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3AE67737-0E3E-44AA-AA5E-46A68BF017FF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3EE5B726-044A-48D2-AA7B-049BD9A0F62A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{60FBBE03-57FF-49D8-B38E-053D3F489825}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6A5182F1-C0B8-42B8-96CC-7F329CD46913}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6C153418-8E4D-4FAF-AF27-5201E38463A7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A26A2F05-AC4D-4A1E-9531-9125F7309B78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5D6240-7DF0-435D-9B9B-F8586A99DE86}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F343045E-E20A-46E1-82D8-9962C43EFC9E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FBB360DC-CB6C-4D6A-808A-2C773151BFFF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FFD7DDAC-EC28-42A5-8D39-917B9078604B}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DCA50CB4-6A78-4465-8A4C-EEEFE15DA7C8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Key Deleted : HKLM\SOFTWARE\ICQ\ICQToolbar
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17420
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v33.1 (x86 cs)
*************************
AdwCleaner[R0].txt - [4948 octets] - [03/12/2014 20:44:41]
AdwCleaner[R1].txt - [3851 octets] - [04/12/2014 20:06:06]
AdwCleaner[R2].txt - [3911 octets] - [04/12/2014 20:09:14]
AdwCleaner[S0].txt - [3136 octets] - [04/12/2014 20:11:23]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3196 octets] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Professional x64
Ran by uzivatel on źt 04.12.2014 at 20:18:53,05
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\uzivatel\AppData\Roaming\mozilla\firefox\profiles\neeurwhm.default\minidumps [35 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 04.12.2014 at 20:23:39,16
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
RogueKiller V10.0.8.0 (x64) [Nov 20 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : uzivatel [Práva správce]
Mód : Prohledat -- Datum : 12/04/2014 20:34:43
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 16 ¤¤¤
[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms} -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{BB1C490A-7BF1-4860-81F8-27BC56DEBA77} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{BB1C490A-7BF1-4860-81F8-27BC56DEBA77} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{BB1C490A-7BF1-4860-81F8-27BC56DEBA77} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
¤¤¤ Úlohy : 1 ¤¤¤
[Suspicious.Path] \\Registration -- "C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe" (Registration ShowMessageTask2D) -> Nalezeno
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 14 ¤¤¤
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 practivate.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 ereg.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate.wip3.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 wip3.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 3dns-3.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 3dns-2.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 adobe-dns.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 adobe-dns-2.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 adobe-dns-3.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 ereg.wip3.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate-sea.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 wwis-dubc1-vip60.adobe.com
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate-sjc0.adobe.com
¤¤¤ Antirootkit : 1 (Driver: Nahrán) ¤¤¤
[Filter(Kernel.Filter)] \Driver\Disk @ Unknown : \Driver\MfeEpeOpal @ Unknown (\SystemRoot\System32\Drivers\MfeEpeOpal.sys)
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS725050A9A364 +++++
--- User ---
[MBR] 3cf7a82bea6e45de68be95a1734b3b34
[BSP] ab099ab106e808ad63dece2a6da147cf : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 300 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 616448 | Size: 455772 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 934037504 | Size: 15744 MB
3 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 966281216 | Size: 5115 MB
User = LL1 ... OK
User = LL2 ... OK
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Vypni antivir
Stáhni
Zoek.exe
a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:
klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Vypni antivir
Stáhni
Zoek.exe
a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:
Kód: Vybrat vše
autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;
klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu
RogueKiller V10.0.8.0 (x64) [Nov 20 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : uzivatel [Práva správce]
Mód : Smazat -- Datum : 12/05/2014 16:06:11
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 16 ¤¤¤
[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms} -> Nahrazeno (http://go.microsoft.com/fwlink/?LinkId=54896)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{BB1C490A-7BF1-4860-81F8-27BC56DEBA77} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{BB1C490A-7BF1-4860-81F8-27BC56DEBA77} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{BB1C490A-7BF1-4860-81F8-27BC56DEBA77} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nahrazeno ()
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nahrazeno (1)
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nahrazeno (1)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nahrazeno (0)
¤¤¤ Úlohy : 1 ¤¤¤
[Suspicious.Path] \\Registration -- "C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe" (Registration ShowMessageTask2D) -> Smazáno
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 14 ¤¤¤
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 practivate.adobe.com -> ERROR [4c8]
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 ereg.adobe.com -> ERROR [4c8]
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate.wip3.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 wip3.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 3dns-3.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 3dns-2.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 adobe-dns.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 adobe-dns-2.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 adobe-dns-3.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 ereg.wip3.adobe.com -> ERROR [4c8]
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate-sea.adobe.com -> ERROR [4c8]
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 wwis-dubc1-vip60.adobe.com -> ERROR [4c8]
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate-sjc0.adobe.com -> ERROR [4c8]
¤¤¤ Antirootkit : 102 (Driver: Nahrán) ¤¤¤
[Filter(Kernel.Filter)] \Driver\Disk @ Unknown : \Driver\MfeEpeOpal @ Unknown (\SystemRoot\System32\Drivers\MfeEpeOpal.sys)
[IAT:Inl] (explorer.exe) ntdll.dll - NtSetSystemInformation : Unknown @ 0x701f0 (jmp 0xffffffff8914d850)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtWriteVirtualMemory : Unknown @ 0x703b0 (jmp 0xffffffff8914ed60)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtDuplicateObject : Unknown @ 0x70390 (jmp 0xffffffff8914ed20)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtNotifyChangeKey : Unknown @ 0x70490 (jmp 0xffffffff8914e300)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtAssignProcessToJobObject : Unknown @ 0x703a0 (jmp 0xffffffff8914e870)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtSetContextThread : Unknown @ 0x70400 (jmp 0xffffffff8914dc20)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x70370 (jmp 0xffffffff8914ee60)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtSetSystemInformation : Unknown @ 0x701f0 (jmp 0xffffffff8914d850)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtNotifyChangeMultipleKeys : Unknown @ 0x704a0 (jmp 0xffffffff8914e300)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateIoCompletion : Unknown @ 0x70350 (jmp 0xffffffff8914e730)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtDuplicateObject : Unknown @ 0x70390 (jmp 0xffffffff8914ed20)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenSection : Unknown @ 0x70320 (jmp 0xffffffff8914ed00)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtWriteVirtualMemory : Unknown @ 0x703b0 (jmp 0xffffffff8914ed60)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x70370 (jmp 0xffffffff8914ee60)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateSemaphore : Unknown @ 0x702b0 (jmp 0xffffffff8914e5a0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenSemaphore : Unknown @ 0x702c0 (jmp 0xffffffff8914e030)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateMutant : Unknown @ 0x70290 (jmp 0xffffffff8914e610)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenMutant : Unknown @ 0x702a0 (jmp 0xffffffff8914e060)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateTimer : Unknown @ 0x70330 (jmp 0xffffffff8914e5f0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenTimer : Unknown @ 0x70340 (jmp 0xffffffff8914e070)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateThreadEx : Unknown @ 0x703d0 (jmp 0xffffffff8914e6a0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtTerminateThread : Unknown @ 0x703f0 (jmp 0xffffffff8914ec10)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenThread : Unknown @ 0x70380 (jmp 0xffffffff8914e0c0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtSuspendThread : Unknown @ 0x70430 (jmp 0xffffffff8914d9a0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtNotifyChangeKey : Unknown @ 0x70490 (jmp 0xffffffff8914e300)
[IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtTerminateThread : Unknown @ 0x703f0 (jmp 0xffffffff8914ec10)
[IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtDuplicateObject : Unknown @ 0x70390 (jmp 0xffffffff8914ed20)
[IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtSetSystemInformation : Unknown @ 0x701f0 (jmp 0xffffffff8914d850)
[IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ sechost.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ RPCRT4.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x70480 (jmp 0xffffffff8914e980)
[IAT:Inl] (explorer.exe @ RPCRT4.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ RPCRT4.dll) ntdll.dll - NtQueueApcThreadEx : Unknown @ 0x70440 (jmp 0xffffffff8914de80)
[IAT:Inl] (explorer.exe @ GDI32.dll) ntdll.dll - NtVdmControl : Unknown @ 0x70280 (jmp 0xffffffff8914d700)
[IAT:Inl] (explorer.exe @ GDI32.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ USER32.dll) ntdll.dll - NtVdmControl : Unknown @ 0x70280 (jmp 0xffffffff8914d700)
[IAT:Inl] (explorer.exe @ SHELL32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ ole32.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ ole32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ MSCTF.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x70480 (jmp 0xffffffff8914e980)
[IAT:Inl] (explorer.exe @ UxTheme.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ SETUPAPI.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ dwmapi.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ Secur32.dll) ntdll.dll - NtOpenSection : Unknown @ 0x70320 (jmp 0xffffffff8914ed00)
[IAT:Inl] (explorer.exe @ SSPICLI.DLL) ntdll.dll - NtDuplicateObject : Unknown @ 0x70390 (jmp 0xffffffff8914ed20)
[IAT:Inl] (explorer.exe @ SSPICLI.DLL) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ WINSTA.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x70370 (jmp 0xffffffff8914ee60)
[IAT:Inl] (explorer.exe @ WINSTA.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ apphelp.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ apphelp.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ CLBCatQ.DLL) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ CSCDLL.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ CSCAPI.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenTimer : Unknown @ 0x70340 (jmp 0xffffffff8914e070)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenThread : Unknown @ 0x70380 (jmp 0xffffffff8914e0c0)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenSemaphore : Unknown @ 0x702c0 (jmp 0xffffffff8914e030)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenSection : Unknown @ 0x70320 (jmp 0xffffffff8914ed00)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x70370 (jmp 0xffffffff8914ee60)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenMutant : Unknown @ 0x702a0 (jmp 0xffffffff8914e060)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenEventPair : Unknown @ 0x70300 (jmp 0xffffffff8914e130)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ tiptsf.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x70480 (jmp 0xffffffff8914e980)
[IAT:Inl] (explorer.exe @ authui.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x70370 (jmp 0xffffffff8914ee60)
[IAT:Inl] (explorer.exe @ authui.dll) ntdll.dll - NtSetSystemInformation : Unknown @ 0x701f0 (jmp 0xffffffff8914d850)
[IAT:Inl] (explorer.exe @ CRYPT32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ gameux.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ wer.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ wer.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x70480 (jmp 0xffffffff8914e980)
[IAT:Inl] (explorer.exe @ WINMM.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ WINMM.dll) ntdll.dll - NtCreateTimer : Unknown @ 0x70330 (jmp 0xffffffff8914e5f0)
[IAT:Inl] (explorer.exe @ AVRT.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ AVRT.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x70480 (jmp 0xffffffff8914e980)
[IAT:Inl] (explorer.exe @ AVRT.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ AVRT.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ AUDIOSES.DLL) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x70480 (jmp 0xffffffff8914e980)
[IAT:Inl] (explorer.exe @ es.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ NSI.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ WS2_32.dll) ntdll.dll - NtLoadDriver : Unknown @ 0x701e0 (jmp 0xffffffff8914e140)
[IAT:Inl] (explorer.exe @ dsrole.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwOpenProcess : Unknown @ 0x70370 (jmp 0xffffffff8914ee60)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwCreateSemaphore : Unknown @ 0x702b0 (jmp 0xffffffff8914e5a0)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwDuplicateObject : Unknown @ 0x70390 (jmp 0xffffffff8914ed20)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwOpenSection : Unknown @ 0x70320 (jmp 0xffffffff8914ed00)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwOpenMutant : Unknown @ 0x702a0 (jmp 0xffffffff8914e060)
[IAT:Inl] (explorer.exe @ avgsea.dll) ntdll.dll - ZwCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
¤¤¤ Webové prohlížeče : 3 ¤¤¤
[FIREFX:Addon] neeurwhm.default : avast! Online Security [wrc@avast.com] -> Smazáno
[FIREFX:Addon] neeurwhm.default : Mozilla Firefox hotfix [firefox-hotfix@mozilla.org] -> Smazáno
[FIREFX:Addon] neeurwhm.default : DigitalPersona Extension [otis@digitalpersona.com] -> Smazáno
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS725050A9A364 +++++
--- User ---
[MBR] 3cf7a82bea6e45de68be95a1734b3b34
[BSP] ab099ab106e808ad63dece2a6da147cf : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 300 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 616448 | Size: 455772 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 934037504 | Size: 15744 MB
3 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 966281216 | Size: 5115 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_12042014_203443.log - RKreport_SCN_12052014_160356.log
Zoek.exe v5.0.0.0 Updated 29-11-2014
Tool run by uzivatel on p 05.12.2014 at 16:11:11,72.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\uzivatel\Desktop\Cisteni pc\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
5.12.2014 16:13:47 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\COMMON~1\MicroWorld deleted successfully
C:\PROGRA~3\ALM deleted successfully
C:\PROGRA~3\Oracle deleted successfully
C:\PROGRA~3\Validity deleted successfully
C:\Users\M\AppData\Local\VirtualStore deleted successfully
C:\Users\uzivatel\AppData\Local\PDFC deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{1E73965B-8B48-48be-9C8D-68B920ABC1C4} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\neeurwhm.default\prefs.js:
Added to C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\neeurwhm.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
==== Deleting Files \ Folders ======================
C:\Users\uzivatel\AppData\Roaming\varicad-work.ini deleted
C:\PROGRA~3\hpeBB72.dll deleted
C:\PROGRA~3\ICQ deleted
C:\windows\SysNative\config\systemprofile\Searches deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [14.11.2014 20:13]
==== Firefox Extensions ======================
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\neeurwhm.default
8303B3CEC05500F763B4FA75210598BB - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll - Shockwave Flash
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[15.09.2014 20:41]
jmfkcklnlgedgbglfkkgedjfmejoahla - C:\Program Files (x86)\AVG\AVG2012\Chrome\safesearch.crx[26.07.2012 02:23]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Search Page"="http://www.google.com"
"ICQ Search"="http://www.google.com"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}] not found
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"ICQ Search"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Reset Google Chrome ======================
Nothing found to reset
==== Empty IE Cache ======================
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\M\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\uzivatel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\uzivatel\AppData\Local\Mozilla\Firefox\Profiles\neeurwhm.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=13 folders=4 162610 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\M\AppData\Local\Temp emptied successfully
C:\Users\uzivatel\AppData\Local\Temp will be emptied at reboot
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\windows\Temp successfully emptied
C:\Users\uzivatel\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on p 05.12.2014 at 16:38:37,04 ======================
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : uzivatel [Práva správce]
Mód : Smazat -- Datum : 12/05/2014 16:06:11
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 16 ¤¤¤
[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms} -> Nahrazeno (http://go.microsoft.com/fwlink/?LinkId=54896)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{BB1C490A-7BF1-4860-81F8-27BC56DEBA77} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{BB1C490A-7BF1-4860-81F8-27BC56DEBA77} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{BB1C490A-7BF1-4860-81F8-27BC56DEBA77} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> Nahrazeno ()
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nahrazeno (1)
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-1674423443-3875478260-2121563268-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nahrazeno (1)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nahrazeno (0)
¤¤¤ Úlohy : 1 ¤¤¤
[Suspicious.Path] \\Registration -- "C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe" (Registration ShowMessageTask2D) -> Smazáno
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 14 ¤¤¤
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 practivate.adobe.com -> ERROR [4c8]
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 ereg.adobe.com -> ERROR [4c8]
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate.wip3.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 wip3.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 3dns-3.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 3dns-2.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 adobe-dns.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 adobe-dns-2.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 adobe-dns-3.adobe.com -> Smazáno
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 ereg.wip3.adobe.com -> ERROR [4c8]
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate-sea.adobe.com -> ERROR [4c8]
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 wwis-dubc1-vip60.adobe.com -> ERROR [4c8]
[C:\windows\System32\drivers\etc\hosts] 127.0.0.1 activate-sjc0.adobe.com -> ERROR [4c8]
¤¤¤ Antirootkit : 102 (Driver: Nahrán) ¤¤¤
[Filter(Kernel.Filter)] \Driver\Disk @ Unknown : \Driver\MfeEpeOpal @ Unknown (\SystemRoot\System32\Drivers\MfeEpeOpal.sys)
[IAT:Inl] (explorer.exe) ntdll.dll - NtSetSystemInformation : Unknown @ 0x701f0 (jmp 0xffffffff8914d850)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtWriteVirtualMemory : Unknown @ 0x703b0 (jmp 0xffffffff8914ed60)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtDuplicateObject : Unknown @ 0x70390 (jmp 0xffffffff8914ed20)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtNotifyChangeKey : Unknown @ 0x70490 (jmp 0xffffffff8914e300)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtAssignProcessToJobObject : Unknown @ 0x703a0 (jmp 0xffffffff8914e870)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtSetContextThread : Unknown @ 0x70400 (jmp 0xffffffff8914dc20)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x70370 (jmp 0xffffffff8914ee60)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtSetSystemInformation : Unknown @ 0x701f0 (jmp 0xffffffff8914d850)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtNotifyChangeMultipleKeys : Unknown @ 0x704a0 (jmp 0xffffffff8914e300)
[IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateIoCompletion : Unknown @ 0x70350 (jmp 0xffffffff8914e730)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtDuplicateObject : Unknown @ 0x70390 (jmp 0xffffffff8914ed20)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenSection : Unknown @ 0x70320 (jmp 0xffffffff8914ed00)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtWriteVirtualMemory : Unknown @ 0x703b0 (jmp 0xffffffff8914ed60)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x70370 (jmp 0xffffffff8914ee60)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateSemaphore : Unknown @ 0x702b0 (jmp 0xffffffff8914e5a0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenSemaphore : Unknown @ 0x702c0 (jmp 0xffffffff8914e030)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateMutant : Unknown @ 0x70290 (jmp 0xffffffff8914e610)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenMutant : Unknown @ 0x702a0 (jmp 0xffffffff8914e060)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateTimer : Unknown @ 0x70330 (jmp 0xffffffff8914e5f0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenTimer : Unknown @ 0x70340 (jmp 0xffffffff8914e070)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateThreadEx : Unknown @ 0x703d0 (jmp 0xffffffff8914e6a0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtTerminateThread : Unknown @ 0x703f0 (jmp 0xffffffff8914ec10)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenThread : Unknown @ 0x70380 (jmp 0xffffffff8914e0c0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtSuspendThread : Unknown @ 0x70430 (jmp 0xffffffff8914d9a0)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtNotifyChangeKey : Unknown @ 0x70490 (jmp 0xffffffff8914e300)
[IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtTerminateThread : Unknown @ 0x703f0 (jmp 0xffffffff8914ec10)
[IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtDuplicateObject : Unknown @ 0x70390 (jmp 0xffffffff8914ed20)
[IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtSetSystemInformation : Unknown @ 0x701f0 (jmp 0xffffffff8914d850)
[IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ sechost.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ RPCRT4.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x70480 (jmp 0xffffffff8914e980)
[IAT:Inl] (explorer.exe @ RPCRT4.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ RPCRT4.dll) ntdll.dll - NtQueueApcThreadEx : Unknown @ 0x70440 (jmp 0xffffffff8914de80)
[IAT:Inl] (explorer.exe @ GDI32.dll) ntdll.dll - NtVdmControl : Unknown @ 0x70280 (jmp 0xffffffff8914d700)
[IAT:Inl] (explorer.exe @ GDI32.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ USER32.dll) ntdll.dll - NtVdmControl : Unknown @ 0x70280 (jmp 0xffffffff8914d700)
[IAT:Inl] (explorer.exe @ SHELL32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ ole32.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ ole32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ MSCTF.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x70480 (jmp 0xffffffff8914e980)
[IAT:Inl] (explorer.exe @ UxTheme.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ SETUPAPI.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ dwmapi.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ Secur32.dll) ntdll.dll - NtOpenSection : Unknown @ 0x70320 (jmp 0xffffffff8914ed00)
[IAT:Inl] (explorer.exe @ SSPICLI.DLL) ntdll.dll - NtDuplicateObject : Unknown @ 0x70390 (jmp 0xffffffff8914ed20)
[IAT:Inl] (explorer.exe @ SSPICLI.DLL) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ WINSTA.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x70370 (jmp 0xffffffff8914ee60)
[IAT:Inl] (explorer.exe @ WINSTA.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ apphelp.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ apphelp.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ CLBCatQ.DLL) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ CSCDLL.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ CSCAPI.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenTimer : Unknown @ 0x70340 (jmp 0xffffffff8914e070)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenThread : Unknown @ 0x70380 (jmp 0xffffffff8914e0c0)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenSemaphore : Unknown @ 0x702c0 (jmp 0xffffffff8914e030)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenSection : Unknown @ 0x70320 (jmp 0xffffffff8914ed00)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x70370 (jmp 0xffffffff8914ee60)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenMutant : Unknown @ 0x702a0 (jmp 0xffffffff8914e060)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenEventPair : Unknown @ 0x70300 (jmp 0xffffffff8914e130)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ tiptsf.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x70480 (jmp 0xffffffff8914e980)
[IAT:Inl] (explorer.exe @ authui.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x70370 (jmp 0xffffffff8914ee60)
[IAT:Inl] (explorer.exe @ authui.dll) ntdll.dll - NtSetSystemInformation : Unknown @ 0x701f0 (jmp 0xffffffff8914d850)
[IAT:Inl] (explorer.exe @ CRYPT32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ gameux.dll) ntdll.dll - NtCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ wer.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ wer.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x70480 (jmp 0xffffffff8914e980)
[IAT:Inl] (explorer.exe @ WINMM.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ WINMM.dll) ntdll.dll - NtCreateTimer : Unknown @ 0x70330 (jmp 0xffffffff8914e5f0)
[IAT:Inl] (explorer.exe @ AVRT.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ AVRT.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x70480 (jmp 0xffffffff8914e980)
[IAT:Inl] (explorer.exe @ AVRT.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ AVRT.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ AUDIOSES.DLL) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x70480 (jmp 0xffffffff8914e980)
[IAT:Inl] (explorer.exe @ es.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ NSI.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ WS2_32.dll) ntdll.dll - NtLoadDriver : Unknown @ 0x701e0 (jmp 0xffffffff8914e140)
[IAT:Inl] (explorer.exe @ dsrole.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x702e0 (jmp 0xffffffff8914ec30)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwQueryObject : Unknown @ 0x70450 (jmp 0xffffffff8914f0a0)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwCreateEvent : Unknown @ 0x702d0 (jmp 0xffffffff8914eba0)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwOpenProcess : Unknown @ 0x70370 (jmp 0xffffffff8914ee60)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwTerminateProcess : Unknown @ 0x703e0 (jmp 0xffffffff8914ee70)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwCreateSemaphore : Unknown @ 0x702b0 (jmp 0xffffffff8914e5a0)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwDuplicateObject : Unknown @ 0x70390 (jmp 0xffffffff8914ed20)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwOpenSection : Unknown @ 0x70320 (jmp 0xffffffff8914ed00)
[IAT:Inl] (explorer.exe @ avgsysa.dll) ntdll.dll - ZwOpenMutant : Unknown @ 0x702a0 (jmp 0xffffffff8914e060)
[IAT:Inl] (explorer.exe @ avgsea.dll) ntdll.dll - ZwCreateSection : Unknown @ 0x70310 (jmp 0xffffffff8914ebc0)
¤¤¤ Webové prohlížeče : 3 ¤¤¤
[FIREFX:Addon] neeurwhm.default : avast! Online Security [wrc@avast.com] -> Smazáno
[FIREFX:Addon] neeurwhm.default : Mozilla Firefox hotfix [firefox-hotfix@mozilla.org] -> Smazáno
[FIREFX:Addon] neeurwhm.default : DigitalPersona Extension [otis@digitalpersona.com] -> Smazáno
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS725050A9A364 +++++
--- User ---
[MBR] 3cf7a82bea6e45de68be95a1734b3b34
[BSP] ab099ab106e808ad63dece2a6da147cf : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 300 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 616448 | Size: 455772 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 934037504 | Size: 15744 MB
3 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 966281216 | Size: 5115 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_12042014_203443.log - RKreport_SCN_12052014_160356.log
Zoek.exe v5.0.0.0 Updated 29-11-2014
Tool run by uzivatel on p 05.12.2014 at 16:11:11,72.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\uzivatel\Desktop\Cisteni pc\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
5.12.2014 16:13:47 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\COMMON~1\MicroWorld deleted successfully
C:\PROGRA~3\ALM deleted successfully
C:\PROGRA~3\Oracle deleted successfully
C:\PROGRA~3\Validity deleted successfully
C:\Users\M\AppData\Local\VirtualStore deleted successfully
C:\Users\uzivatel\AppData\Local\PDFC deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{1E73965B-8B48-48be-9C8D-68B920ABC1C4} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\neeurwhm.default\prefs.js:
Added to C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\neeurwhm.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
==== Deleting Files \ Folders ======================
C:\Users\uzivatel\AppData\Roaming\varicad-work.ini deleted
C:\PROGRA~3\hpeBB72.dll deleted
C:\PROGRA~3\ICQ deleted
C:\windows\SysNative\config\systemprofile\Searches deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [14.11.2014 20:13]
==== Firefox Extensions ======================
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\neeurwhm.default
8303B3CEC05500F763B4FA75210598BB - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll - Shockwave Flash
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[15.09.2014 20:41]
jmfkcklnlgedgbglfkkgedjfmejoahla - C:\Program Files (x86)\AVG\AVG2012\Chrome\safesearch.crx[26.07.2012 02:23]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Search Page"="http://www.google.com"
"ICQ Search"="http://www.google.com"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}] not found
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"ICQ Search"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Reset Google Chrome ======================
Nothing found to reset
==== Empty IE Cache ======================
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\M\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\uzivatel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\uzivatel\AppData\Local\Mozilla\Firefox\Profiles\neeurwhm.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=13 folders=4 162610 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\M\AppData\Local\Temp emptied successfully
C:\Users\uzivatel\AppData\Local\Temp will be emptied at reboot
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\windows\Temp successfully emptied
C:\Users\uzivatel\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on p 05.12.2014 at 16:38:37,04 ======================
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu
ComboFix 14-12-04.01 - uzivatel 05.12.2014 20:10:42.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4070.2124 [GMT 1:00]
Spuštěný z: c:\users\uzivatel\Desktop\Cisteni pc\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AV: AVG Anti-Virus Business Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: AVG Anti-Virus Business Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-11-05 do 2014-12-05 )))))))))))))))))))))))))))))))
.
.
2014-12-05 19:19 . 2014-12-05 19:19 -------- d-----w- c:\users\M\AppData\Local\temp
2014-12-05 19:19 . 2014-12-05 19:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-12-05 15:35 . 2014-12-05 15:35 -------- d-----w- c:\programdata\Validity
2014-12-05 15:34 . 2014-12-05 15:11 24064 ----a-w- c:\windows\zoek-delete.exe
2014-12-05 15:34 . 2014-12-05 19:23 -------- d-----w- c:\users\uzivatel\AppData\Local\Temp
2014-12-05 15:11 . 2014-12-05 15:28 -------- d-----w- C:\zoek_backup
2014-12-05 07:55 . 2014-12-05 07:55 -------- d-----w- c:\users\uzivatel\AppData\Local\ATI
2014-12-04 19:27 . 2014-12-05 14:58 37624 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-12-04 19:27 . 2014-12-04 19:27 -------- d-----w- c:\programdata\RogueKiller
2014-12-04 19:18 . 2014-12-04 19:18 -------- d-----w- c:\windows\ERUNT
2014-12-03 19:49 . 2014-12-05 19:22 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-12-03 19:48 . 2014-12-03 19:48 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-12-03 19:48 . 2014-12-03 19:48 -------- d-----w- c:\programdata\Malwarebytes
2014-12-03 19:48 . 2014-11-21 05:14 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-12-03 19:48 . 2014-11-21 05:14 93400 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-12-03 19:48 . 2014-11-21 05:14 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-12-03 19:44 . 2014-12-04 19:11 -------- d-----w- C:\AdwCleaner
2014-12-02 18:17 . 2014-12-02 18:17 -------- d---a-w- c:\windows\VDLL.DLL
2014-12-02 18:17 . 2014-12-02 18:17 -------- d---a-w- c:\windows\SysWow64\runouce.exe
2014-12-02 18:17 . 2014-12-02 18:17 -------- d---a-w- c:\windows\rundll16.exe
2014-12-02 18:17 . 2014-12-02 18:17 -------- d---a-w- c:\windows\RUNDL132.EXE
2014-12-02 18:17 . 2014-12-02 18:17 -------- d---a-w- c:\windows\logo1_.exe
2014-12-02 18:17 . 2014-12-02 18:17 -------- d---a-w- c:\windows\logo_1.exe
2014-12-02 18:13 . 2014-12-02 18:13 632064 ----a-w- c:\windows\SysWow64\msvcr80.dll
2014-12-02 18:13 . 2014-12-02 18:13 554240 ----a-w- c:\windows\SysWow64\msvcp80.dll
2014-12-02 18:13 . 2014-12-02 18:13 34048 ----a-w- c:\windows\SysWow64\eEmpty.exe
2014-12-02 18:13 . 2014-12-02 18:13 -------- d-----w- c:\programdata\MicroWorld
2014-11-24 12:20 . 2014-11-24 12:20 -------- d-----w- C:\RECEPTY
2014-11-19 20:02 . 2014-11-19 20:02 -------- d-sh--w- c:\users\uzivatel\AppData\Local\EmieUserList
2014-11-19 20:02 . 2014-11-19 20:02 -------- d-sh--w- c:\users\uzivatel\AppData\Local\EmieSiteList
2014-11-19 20:02 . 2014-11-19 20:02 -------- d-sh--w- c:\users\uzivatel\AppData\Local\EmieBrowserModeList
2014-11-19 09:14 . 2014-11-11 03:08 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-11-19 09:14 . 2014-11-11 03:08 241152 ----a-w- c:\windows\system32\pku2u.dll
2014-11-19 09:14 . 2014-11-11 02:44 186880 ----a-w- c:\windows\SysWow64\pku2u.dll
2014-11-19 09:14 . 2014-11-11 02:44 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-11-16 18:08 . 2014-11-16 18:08 -------- d-----w- c:\users\uzivatel\AppData\Local\M-Photo_Ltd
2014-11-16 17:44 . 2014-11-16 17:44 -------- d-----w- c:\programdata\M-Photo
2014-11-16 17:40 . 2014-11-19 20:26 -------- d-----w- C:\MCL
2014-11-16 17:40 . 2014-11-16 17:40 19727753 ----a-w- c:\windows\SysWow64\FOTOKNIHY_FOTOKNIHY_uninstaller.exe
2014-11-14 19:27 . 2014-08-21 06:43 1882624 ----a-w- c:\windows\system32\msxml3.dll
2014-11-14 19:24 . 2014-10-25 01:57 77824 ----a-w- c:\windows\system32\packager.dll
2014-11-14 19:24 . 2014-10-25 01:32 67584 ----a-w- c:\windows\SysWow64\packager.dll
2014-11-14 19:24 . 2014-10-10 00:57 3198976 ----a-w- c:\windows\system32\win32k.sys
2014-11-14 19:23 . 2014-10-14 02:13 3241984 ----a-w- c:\windows\system32\msi.dll
2014-11-14 19:23 . 2014-10-14 01:50 2363904 ----a-w- c:\windows\SysWow64\msi.dll
2014-11-14 19:23 . 2014-10-18 02:05 861696 ----a-w- c:\windows\system32\oleaut32.dll
2014-11-14 19:23 . 2014-10-18 01:33 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2014-11-08 06:18 . 2014-05-02 11:02 495376 ----a-w- c:\windows\system32\drivers\e1c62x64.sys
2014-11-08 06:18 . 2013-07-25 02:08 73480 ----a-w- c:\windows\system32\e1cmsg.dll
2014-11-08 06:18 . 2013-07-11 02:27 89888 ----a-w- c:\windows\system32\NicInstC.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-11-26 07:15 . 2013-06-05 06:37 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-11-26 07:15 . 2011-10-21 07:44 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-11-23 06:15 . 2014-09-15 19:41 1041168 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-11-15 06:39 . 2011-10-21 09:46 103374192 ----a-w- c:\windows\system32\MRT.exe
2014-09-25 02:08 . 2014-10-01 09:30 371712 ----a-w- c:\windows\system32\qdvd.dll
2014-09-25 01:40 . 2014-10-01 09:30 519680 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-09-20 12:09 . 2014-09-20 12:10 555760 ----a-w- c:\windows\system32\drivers\SynTP.sys
2014-09-20 12:09 . 2014-09-20 12:10 422640 ----a-w- c:\windows\system32\SynTPCo19.dll
2014-09-20 12:09 . 2014-09-20 12:10 252144 ----a-w- c:\windows\system32\SynTPAPI.dll
2014-09-20 12:09 . 2014-09-20 12:10 169712 ----a-w- c:\windows\SysWow64\SynTPCom.dll
2014-09-20 12:09 . 2014-09-20 12:10 723184 ----a-w- c:\windows\system32\SynCOM.dll
2014-09-20 12:09 . 2014-09-20 12:10 400624 ----a-w- c:\windows\SysWow64\SynCom.dll
2014-09-19 09:23 . 2014-11-14 19:27 248832 ----a-w- c:\windows\SysWow64\schannel.dll
2014-09-15 19:41 . 2014-09-15 19:41 427360 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-09-15 19:41 . 2014-09-15 19:41 92008 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-09-15 19:41 . 2014-09-15 19:41 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-09-15 19:41 . 2014-09-15 19:41 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-09-15 19:41 . 2014-09-15 19:41 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-09-15 19:41 . 2014-09-15 19:41 224896 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-09-15 19:41 . 2014-09-15 19:41 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-09-15 19:41 . 2014-09-15 19:41 307344 ----a-w- c:\windows\system32\aswBoot.exe
2014-09-15 19:41 . 2014-09-15 19:41 43152 ----a-w- c:\windows\avastSS.scr
2014-09-09 22:11 . 2014-09-24 06:49 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-09 21:47 . 2014-09-24 06:49 2048 ----a-w- c:\windows\SysWow64\tzres.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-05-19 2736128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-05-30 642816]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-09-15 4085896]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
2011-02-03 23:09 75360 ----a-w- c:\windows\System32\DeviceNP.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ DPPassFilter scecli
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [x]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfiltera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsfiltera.sys [x]
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys;c:\windows\SYSNATIVE\DRIVERS\DAMDrv64.sys [x]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\SysWOW64\flcdlock.exe;c:\windows\SysWOW64\flcdlock.exe [x]
R3 hidkmdf;KMDF Driver;c:\windows\system32\DRIVERS\hidkmdf.sys;c:\windows\SYSNATIVE\DRIVERS\hidkmdf.sys [x]
R3 hpCMSrv;HP Connection Manager 4 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [x]
R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys;c:\windows\SYSNATIVE\DRIVERS\s1039bus.sys [x]
R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys;c:\windows\SYSNATIVE\DRIVERS\s1039mdfl.sys [x]
R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys;c:\windows\SYSNATIVE\DRIVERS\s1039mdm.sys [x]
R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys;c:\windows\SYSNATIVE\DRIVERS\s1039mgmt.sys [x]
R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys;c:\windows\SYSNATIVE\DRIVERS\s1039nd5.sys [x]
R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys;c:\windows\SYSNATIVE\DRIVERS\s1039obex.sys [x]
R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys;c:\windows\SYSNATIVE\DRIVERS\s1039unic.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 wacomrouterfilter;Wacom Router Filter Driver;c:\windows\system32\DRIVERS\wacomrouterfilter.sys;c:\windows\SYSNATIVE\DRIVERS\wacomrouterfilter.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S0 MfeEpeOpal;MfeEpeOpal; [x]
S0 MfeEpePc;MfeEpePc; [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
S1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\System32\drivers\psd.sys;c:\windows\SYSNATIVE\drivers\psd.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 HPDayStarterService;HP DayStarter Service;c:\program files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe;c:\program files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [x]
S2 hpHotkeyMonitor;hpHotkeyMonitor;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [x]
S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [x]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe;c:\program files (x86)\PDF Complete\pdfsvc.exe [x]
S2 uArcCapture;ArcCapture;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe;c:\windows\SYSNATIVE\vcsFPService.exe [x]
S2 WTabletServicePro;Wacom Professional Service;c:\program files\Tablet\Wacom\WTabletServicePro.exe;c:\program files\Tablet\Wacom\WTabletServicePro.exe [x]
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;c:\windows\system32\DRIVERS\ArcSoftVCapture.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftVCapture.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys;c:\windows\SYSNATIVE\DRIVERS\johci.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MBAMSWISSARMY
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-05-19 18:36 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-12-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-05 07:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-09-15 19:41 634872 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\program files\Broadcom\Broadcom 802.11\WLTRAY.exe" [2013-06-04 7177728]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2013-06-04 1664000]
"Network Configuration"="c:\program files (x86)\Okidata\ActKey\Network Configuration.exe" [2012-08-27 725280]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 213.46.172.37 213.46.172.36
FF - ProfilePath - c:\users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\neeurwhm.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-FOTOKNIHY_FOTOKNIHY - c:\windows\system32\FOTOKNIHY_FOTOKNIHY_uninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_239_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_239_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_239_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_239_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.15"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe
c:\program files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
c:\program files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\Tablet\Wacom\WacomHost.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Celkový čas: 2014-12-05 20:28:15 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-12-05 19:28
.
Před spuštěním: Volných bajtů: 167 496 515 584
Po spuštění: Volných bajtů: 166 814 986 240
.
- - End Of File - - 25CC3DA8F52294045E97013A098A7075
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4070.2124 [GMT 1:00]
Spuštěný z: c:\users\uzivatel\Desktop\Cisteni pc\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AV: AVG Anti-Virus Business Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: AVG Anti-Virus Business Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-11-05 do 2014-12-05 )))))))))))))))))))))))))))))))
.
.
2014-12-05 19:19 . 2014-12-05 19:19 -------- d-----w- c:\users\M\AppData\Local\temp
2014-12-05 19:19 . 2014-12-05 19:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-12-05 15:35 . 2014-12-05 15:35 -------- d-----w- c:\programdata\Validity
2014-12-05 15:34 . 2014-12-05 15:11 24064 ----a-w- c:\windows\zoek-delete.exe
2014-12-05 15:34 . 2014-12-05 19:23 -------- d-----w- c:\users\uzivatel\AppData\Local\Temp
2014-12-05 15:11 . 2014-12-05 15:28 -------- d-----w- C:\zoek_backup
2014-12-05 07:55 . 2014-12-05 07:55 -------- d-----w- c:\users\uzivatel\AppData\Local\ATI
2014-12-04 19:27 . 2014-12-05 14:58 37624 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-12-04 19:27 . 2014-12-04 19:27 -------- d-----w- c:\programdata\RogueKiller
2014-12-04 19:18 . 2014-12-04 19:18 -------- d-----w- c:\windows\ERUNT
2014-12-03 19:49 . 2014-12-05 19:22 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-12-03 19:48 . 2014-12-03 19:48 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-12-03 19:48 . 2014-12-03 19:48 -------- d-----w- c:\programdata\Malwarebytes
2014-12-03 19:48 . 2014-11-21 05:14 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-12-03 19:48 . 2014-11-21 05:14 93400 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-12-03 19:48 . 2014-11-21 05:14 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-12-03 19:44 . 2014-12-04 19:11 -------- d-----w- C:\AdwCleaner
2014-12-02 18:17 . 2014-12-02 18:17 -------- d---a-w- c:\windows\VDLL.DLL
2014-12-02 18:17 . 2014-12-02 18:17 -------- d---a-w- c:\windows\SysWow64\runouce.exe
2014-12-02 18:17 . 2014-12-02 18:17 -------- d---a-w- c:\windows\rundll16.exe
2014-12-02 18:17 . 2014-12-02 18:17 -------- d---a-w- c:\windows\RUNDL132.EXE
2014-12-02 18:17 . 2014-12-02 18:17 -------- d---a-w- c:\windows\logo1_.exe
2014-12-02 18:17 . 2014-12-02 18:17 -------- d---a-w- c:\windows\logo_1.exe
2014-12-02 18:13 . 2014-12-02 18:13 632064 ----a-w- c:\windows\SysWow64\msvcr80.dll
2014-12-02 18:13 . 2014-12-02 18:13 554240 ----a-w- c:\windows\SysWow64\msvcp80.dll
2014-12-02 18:13 . 2014-12-02 18:13 34048 ----a-w- c:\windows\SysWow64\eEmpty.exe
2014-12-02 18:13 . 2014-12-02 18:13 -------- d-----w- c:\programdata\MicroWorld
2014-11-24 12:20 . 2014-11-24 12:20 -------- d-----w- C:\RECEPTY
2014-11-19 20:02 . 2014-11-19 20:02 -------- d-sh--w- c:\users\uzivatel\AppData\Local\EmieUserList
2014-11-19 20:02 . 2014-11-19 20:02 -------- d-sh--w- c:\users\uzivatel\AppData\Local\EmieSiteList
2014-11-19 20:02 . 2014-11-19 20:02 -------- d-sh--w- c:\users\uzivatel\AppData\Local\EmieBrowserModeList
2014-11-19 09:14 . 2014-11-11 03:08 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-11-19 09:14 . 2014-11-11 03:08 241152 ----a-w- c:\windows\system32\pku2u.dll
2014-11-19 09:14 . 2014-11-11 02:44 186880 ----a-w- c:\windows\SysWow64\pku2u.dll
2014-11-19 09:14 . 2014-11-11 02:44 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-11-16 18:08 . 2014-11-16 18:08 -------- d-----w- c:\users\uzivatel\AppData\Local\M-Photo_Ltd
2014-11-16 17:44 . 2014-11-16 17:44 -------- d-----w- c:\programdata\M-Photo
2014-11-16 17:40 . 2014-11-19 20:26 -------- d-----w- C:\MCL
2014-11-16 17:40 . 2014-11-16 17:40 19727753 ----a-w- c:\windows\SysWow64\FOTOKNIHY_FOTOKNIHY_uninstaller.exe
2014-11-14 19:27 . 2014-08-21 06:43 1882624 ----a-w- c:\windows\system32\msxml3.dll
2014-11-14 19:24 . 2014-10-25 01:57 77824 ----a-w- c:\windows\system32\packager.dll
2014-11-14 19:24 . 2014-10-25 01:32 67584 ----a-w- c:\windows\SysWow64\packager.dll
2014-11-14 19:24 . 2014-10-10 00:57 3198976 ----a-w- c:\windows\system32\win32k.sys
2014-11-14 19:23 . 2014-10-14 02:13 3241984 ----a-w- c:\windows\system32\msi.dll
2014-11-14 19:23 . 2014-10-14 01:50 2363904 ----a-w- c:\windows\SysWow64\msi.dll
2014-11-14 19:23 . 2014-10-18 02:05 861696 ----a-w- c:\windows\system32\oleaut32.dll
2014-11-14 19:23 . 2014-10-18 01:33 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2014-11-08 06:18 . 2014-05-02 11:02 495376 ----a-w- c:\windows\system32\drivers\e1c62x64.sys
2014-11-08 06:18 . 2013-07-25 02:08 73480 ----a-w- c:\windows\system32\e1cmsg.dll
2014-11-08 06:18 . 2013-07-11 02:27 89888 ----a-w- c:\windows\system32\NicInstC.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-11-26 07:15 . 2013-06-05 06:37 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-11-26 07:15 . 2011-10-21 07:44 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-11-23 06:15 . 2014-09-15 19:41 1041168 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-11-15 06:39 . 2011-10-21 09:46 103374192 ----a-w- c:\windows\system32\MRT.exe
2014-09-25 02:08 . 2014-10-01 09:30 371712 ----a-w- c:\windows\system32\qdvd.dll
2014-09-25 01:40 . 2014-10-01 09:30 519680 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-09-20 12:09 . 2014-09-20 12:10 555760 ----a-w- c:\windows\system32\drivers\SynTP.sys
2014-09-20 12:09 . 2014-09-20 12:10 422640 ----a-w- c:\windows\system32\SynTPCo19.dll
2014-09-20 12:09 . 2014-09-20 12:10 252144 ----a-w- c:\windows\system32\SynTPAPI.dll
2014-09-20 12:09 . 2014-09-20 12:10 169712 ----a-w- c:\windows\SysWow64\SynTPCom.dll
2014-09-20 12:09 . 2014-09-20 12:10 723184 ----a-w- c:\windows\system32\SynCOM.dll
2014-09-20 12:09 . 2014-09-20 12:10 400624 ----a-w- c:\windows\SysWow64\SynCom.dll
2014-09-19 09:23 . 2014-11-14 19:27 248832 ----a-w- c:\windows\SysWow64\schannel.dll
2014-09-15 19:41 . 2014-09-15 19:41 427360 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-09-15 19:41 . 2014-09-15 19:41 92008 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-09-15 19:41 . 2014-09-15 19:41 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-09-15 19:41 . 2014-09-15 19:41 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-09-15 19:41 . 2014-09-15 19:41 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-09-15 19:41 . 2014-09-15 19:41 224896 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-09-15 19:41 . 2014-09-15 19:41 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-09-15 19:41 . 2014-09-15 19:41 307344 ----a-w- c:\windows\system32\aswBoot.exe
2014-09-15 19:41 . 2014-09-15 19:41 43152 ----a-w- c:\windows\avastSS.scr
2014-09-09 22:11 . 2014-09-24 06:49 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-09 21:47 . 2014-09-24 06:49 2048 ----a-w- c:\windows\SysWow64\tzres.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-05-19 2736128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-05-30 642816]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-09-15 4085896]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
2011-02-03 23:09 75360 ----a-w- c:\windows\System32\DeviceNP.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ DPPassFilter scecli
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [x]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfiltera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsfiltera.sys [x]
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys;c:\windows\SYSNATIVE\DRIVERS\DAMDrv64.sys [x]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\SysWOW64\flcdlock.exe;c:\windows\SysWOW64\flcdlock.exe [x]
R3 hidkmdf;KMDF Driver;c:\windows\system32\DRIVERS\hidkmdf.sys;c:\windows\SYSNATIVE\DRIVERS\hidkmdf.sys [x]
R3 hpCMSrv;HP Connection Manager 4 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [x]
R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys;c:\windows\SYSNATIVE\DRIVERS\s1039bus.sys [x]
R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys;c:\windows\SYSNATIVE\DRIVERS\s1039mdfl.sys [x]
R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys;c:\windows\SYSNATIVE\DRIVERS\s1039mdm.sys [x]
R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys;c:\windows\SYSNATIVE\DRIVERS\s1039mgmt.sys [x]
R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys;c:\windows\SYSNATIVE\DRIVERS\s1039nd5.sys [x]
R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys;c:\windows\SYSNATIVE\DRIVERS\s1039obex.sys [x]
R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys;c:\windows\SYSNATIVE\DRIVERS\s1039unic.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 wacomrouterfilter;Wacom Router Filter Driver;c:\windows\system32\DRIVERS\wacomrouterfilter.sys;c:\windows\SYSNATIVE\DRIVERS\wacomrouterfilter.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S0 MfeEpeOpal;MfeEpeOpal; [x]
S0 MfeEpePc;MfeEpePc; [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
S1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\System32\drivers\psd.sys;c:\windows\SYSNATIVE\drivers\psd.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 HPDayStarterService;HP DayStarter Service;c:\program files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe;c:\program files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [x]
S2 hpHotkeyMonitor;hpHotkeyMonitor;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [x]
S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [x]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe;c:\program files (x86)\PDF Complete\pdfsvc.exe [x]
S2 uArcCapture;ArcCapture;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe;c:\windows\SYSNATIVE\vcsFPService.exe [x]
S2 WTabletServicePro;Wacom Professional Service;c:\program files\Tablet\Wacom\WTabletServicePro.exe;c:\program files\Tablet\Wacom\WTabletServicePro.exe [x]
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;c:\windows\system32\DRIVERS\ArcSoftVCapture.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftVCapture.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys;c:\windows\SYSNATIVE\DRIVERS\johci.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MBAMSWISSARMY
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-05-19 18:36 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-12-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-05 07:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-09-15 19:41 634872 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\program files\Broadcom\Broadcom 802.11\WLTRAY.exe" [2013-06-04 7177728]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2013-06-04 1664000]
"Network Configuration"="c:\program files (x86)\Okidata\ActKey\Network Configuration.exe" [2012-08-27 725280]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 213.46.172.37 213.46.172.36
FF - ProfilePath - c:\users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\neeurwhm.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-FOTOKNIHY_FOTOKNIHY - c:\windows\system32\FOTOKNIHY_FOTOKNIHY_uninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_239_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_239_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_239_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_239_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.15"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe
c:\program files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
c:\program files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\Tablet\Wacom\WacomHost.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Celkový čas: 2014-12-05 20:28:15 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-12-05 19:28
.
Před spuštěním: Volných bajtů: 167 496 515 584
Po spuštění: Volných bajtů: 166 814 986 240
.
- - End Of File - - 25CC3DA8F52294045E97013A098A7075
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AV: AVG Anti-Virus Business Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-
dva antiviry , jeden odinstaluj.
Pak nový log z Combofixu.
AV: AVG Anti-Virus Business Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-
dva antiviry , jeden odinstaluj.
Pak nový log z Combofixu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu
AVG ma prošlou licenci a nejde mi odinstalovat. Chce to, abych nejdřív odinstaloval Avasta.
AVG není v PC aktivní. Můsím ho tedy odistalovávat? Budu jinka muset odstranit i avata.
AVG není v PC aktivní. Můsím ho tedy odistalovávat? Budu jinka muset odstranit i avata.
- Orcus
- člen Security týmu
-
Elite Level 10.5
- Příspěvky: 10645
- Registrován: duben 10
- Bydliště: Okolo rostou 3 růže =o)
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Použij AVG Remover z odkazu níže:
http://download.avg.com/filedir/util/su ... 5_5501.exe
Pokud nepůjde, použij jej v nouzovém režimu.
http://download.avg.com/filedir/util/su ... 5_5501.exe
Pokud nepůjde, použij jej v nouzovém režimu.
Láska hřeje, ale uhlí je uhlí.
Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.

Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 27 hostů