Pomalé stahování, načítání webu. Zasekaný chod systému.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:00:46, on 2.3.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17631)
Boot mode: Normal
Running processes:
C:\Users\Tom\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\SafeQ\SafeQ_cli.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\Users\Tom\Desktop\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [SafeQClient] C:\Program Files (x86)\SafeQ\SafeQ_cli.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [MSStp] C:\Windows\inf\msstp.vbe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKCU\..\Run: [Driver Detective] C:\Program Files (x86)\PC Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.exe /applicationMode:systemTray /showWelcome:false
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Tom\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Tom\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKCU\..\Run: [Spotify] "C:\Users\Tom\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Bluetooth Device Monitor - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth Media Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
O23 - Service: Bluetooth OBEX Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
--
End of file - 12563 bytes
Kontrola logu Vyřešeno
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Kontrola logu
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Kontrola logu
# AdwCleaner v4.111 - Logfile created 02/03/2015 at 22:04:43
# Updated 18/02/2015 by Xplode
# Database : 2015-03-02.1 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Tom - TOM-PC
# Running from : C:\Users\Tom\Desktop\adwcleaner_4.111.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage
File Found : C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage-journal
Folder Found : C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\Conduit
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\B506D6D57B4EB0947A492948CBD3A2B8
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\B506D6D57B4EB0947A492948CBD3A2B8
Key Found : HKLM\SOFTWARE\SPPDCOM
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B506D6D57B4EB0947A492948CBD3A2B8
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Driver Detective]
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17631
-\\ Mozilla Firefox v36.0 (x86 cs)
-\\ Google Chrome v40.0.2214.115
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://istart.webssearches.com/web/?typ ... CDJS7RX&q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://istart.webssearches.com/web/?typ ... CDJS7RX&q={searchTerms}
-\\ Opera v27.0.1689.76
*************************
AdwCleaner[R0].txt - [2354 bytes] - [02/03/2015 22:04:43]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2413 bytes] ##########
# Updated 18/02/2015 by Xplode
# Database : 2015-03-02.1 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Tom - TOM-PC
# Running from : C:\Users\Tom\Desktop\adwcleaner_4.111.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage
File Found : C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage-journal
Folder Found : C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\Conduit
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\B506D6D57B4EB0947A492948CBD3A2B8
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\B506D6D57B4EB0947A492948CBD3A2B8
Key Found : HKLM\SOFTWARE\SPPDCOM
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B506D6D57B4EB0947A492948CBD3A2B8
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Driver Detective]
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17631
-\\ Mozilla Firefox v36.0 (x86 cs)
-\\ Google Chrome v40.0.2214.115
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://istart.webssearches.com/web/?typ ... CDJS7RX&q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://istart.webssearches.com/web/?typ ... CDJS7RX&q={searchTerms}
-\\ Opera v27.0.1689.76
*************************
AdwCleaner[R0].txt - [2354 bytes] - [02/03/2015 22:04:43]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2413 bytes] ##########
Re: Kontrola logu
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2.3.2015
Scan Time: 22:12:09
Logfile: mbm.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.03.02.06
Rootkit Database: v2015.02.25.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Tom
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 335874
Time Elapsed: 23 min, 19 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 1
Trojan.Agent.SCR, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|MSStp, C:\Windows\inf\msstp.vbe, , [bd01a8980b7f94a2145d05d436cd7789]
Registry Data: 0
(No malicious items detected)
Folders: 71
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\dialog, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\dialog\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\dialog\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\extensions, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\extensions\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\extensions\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\guide, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\guide\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\lastVisited, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\lastVisited\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\lastVisited\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\notice, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\notice\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\played, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\played\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\played\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\de, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\en, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\es, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\es_419, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\fr, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\it, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\ja, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\pl, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\pt_BR, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\pt_PT, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\ru, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\tr, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\vi, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\zh_CN, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\zh_TW, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_metadata, , [ecd297a96d1df83e86414a1e867d04fc],
Files: 136
PUP.Optional.Bitcoin, C:\Windows\SysWOW64\acumncxtpso.exe, , [07b77dc3197167cfb50abf85ce3431cf],
Trojan.BitMiner, C:\Windows\SysWOW64\dcgmncxtpso.exe, , [c5f9063aef9b7cba4971ed688a78fe02],
PUP.BitCoinMiner, C:\Windows\SysWOW64\lcpmncxtpso.exe, , [308e1b25f09afc3ad7f839fe10f15da3],
Trojan.Agent.SCR, C:\Windows\inf\msstp.vbe, , [bd01a8980b7f94a2145d05d436cd7789],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage, , [b40a37092565cf67580d140c897c7e82],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage-journal, , [c3fbf64ad4b622144d1880a050b51ee2],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\background.html, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\index.html, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\jump.html, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\manifest.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks\bookmarks.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks\img\searchButton.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\classification.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\img\skin\del.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\img\skin\main.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\img\skin\selected.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\cloud.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\cloudApp.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\cloudWebsite.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\createWebsite.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\buttonBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\categoryBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\icons.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\searchBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\searchButton.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\searchLeft.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\selected.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\tabsBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\dialog\img\skin\headerBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\extensions\extensions.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\extensions\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\extensions\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\gameCenter.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\img\star.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\img\star_bg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\img\time.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\guide\guide.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\guide\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\lastVisited\lastVisited.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\lastVisited\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\lastVisited\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\notice\notice.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\notice\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\played\played.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\played\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\search.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\img\google-new-logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\img\searchicon.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\img\searchicon2.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\setup.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\img\skin\dialBoxStyle.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\img\skin\icons.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts\img\oBookmarks.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts\img\oDownloads.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts\img\oExtensions.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts\img\oHistory.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts\img\oNewtab.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\cloudWallpaper.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\skins.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\skin\categoryBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\skin\delete.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\skin\download.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\skin\icons.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\skin\loading.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\weather.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img\skin\line.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img\skin\locationIcon.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img\skin\searchButton.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img\skin\weather.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\css\all.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\game.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\icon_128.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\icon_16.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\icon_48.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\NEW.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\shopping.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\weather.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\webstore.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\default.jpg, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\iconsprite.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\idialog_s.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\ios5_button.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\left.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\loading.gif, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\loading2.gif, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\qBoxBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\q_bg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\q_bg0.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\q_left.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\q_left0.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\q_right.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\q_right0.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\right.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\selected.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\titleBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\all.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\background.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\ga.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\jq.mobi.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\jump.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\pop.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\redirect.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\xagainit.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\de\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\en\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\es\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\es_419\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\fr\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\it\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\ja\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\pl\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\pt_BR\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\pt_PT\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\ru\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\tr\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\vi\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\zh_CN\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\zh_TW\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_metadata\computed_hashes.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_metadata\verified_contents.json, , [ecd297a96d1df83e86414a1e867d04fc],
Physical Sectors: 0
(No malicious items detected)
(end)
www.malwarebytes.org
Scan Date: 2.3.2015
Scan Time: 22:12:09
Logfile: mbm.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.03.02.06
Rootkit Database: v2015.02.25.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Tom
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 335874
Time Elapsed: 23 min, 19 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 1
Trojan.Agent.SCR, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|MSStp, C:\Windows\inf\msstp.vbe, , [bd01a8980b7f94a2145d05d436cd7789]
Registry Data: 0
(No malicious items detected)
Folders: 71
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\dialog, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\dialog\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\dialog\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\extensions, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\extensions\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\extensions\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\guide, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\guide\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\lastVisited, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\lastVisited\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\lastVisited\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\notice, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\notice\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\played, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\played\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\played\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\de, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\en, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\es, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\es_419, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\fr, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\it, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\ja, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\pl, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\pt_BR, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\pt_PT, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\ru, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\tr, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\vi, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\zh_CN, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\zh_TW, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_metadata, , [ecd297a96d1df83e86414a1e867d04fc],
Files: 136
PUP.Optional.Bitcoin, C:\Windows\SysWOW64\acumncxtpso.exe, , [07b77dc3197167cfb50abf85ce3431cf],
Trojan.BitMiner, C:\Windows\SysWOW64\dcgmncxtpso.exe, , [c5f9063aef9b7cba4971ed688a78fe02],
PUP.BitCoinMiner, C:\Windows\SysWOW64\lcpmncxtpso.exe, , [308e1b25f09afc3ad7f839fe10f15da3],
Trojan.Agent.SCR, C:\Windows\inf\msstp.vbe, , [bd01a8980b7f94a2145d05d436cd7789],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage, , [b40a37092565cf67580d140c897c7e82],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage-journal, , [c3fbf64ad4b622144d1880a050b51ee2],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\background.html, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\index.html, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\jump.html, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\manifest.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks\bookmarks.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\bookmarks\img\searchButton.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\classification.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\img\skin\del.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\img\skin\main.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\classification\img\skin\selected.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\cloud.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\cloudApp.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\cloudWebsite.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\createWebsite.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\buttonBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\categoryBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\icons.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\searchBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\searchButton.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\searchLeft.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\selected.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\cloud\img\skin\tabsBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\dialog\img\skin\headerBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\extensions\extensions.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\extensions\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\extensions\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\gameCenter.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\img\star.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\img\star_bg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\gameCenter\img\time.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\guide\guide.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\guide\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\lastVisited\lastVisited.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\lastVisited\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\lastVisited\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\notice\notice.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\notice\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\played\played.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\played\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\search.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\img\google-new-logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\img\searchicon.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\search\img\searchicon2.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\setup.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\img\skin\dialBoxStyle.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\setup\img\skin\icons.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts\img\oBookmarks.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts\img\oDownloads.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts\img\oExtensions.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts\img\oHistory.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\shortcuts\img\oNewtab.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\cloudWallpaper.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\skins.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\skin\categoryBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\skin\delete.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\skin\download.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\skin\icons.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\skins\img\skin\loading.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\weather.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\css\style.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img\logo.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img\skin\line.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img\skin\locationIcon.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img\skin\searchButton.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\app\weather\img\skin\weather.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\css\all.css, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\game.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\icon_128.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\icon_16.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\icon_48.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\NEW.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\shopping.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\weather.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\webstore.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\default.jpg, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\iconsprite.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\idialog_s.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\ios5_button.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\left.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\loading.gif, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\loading2.gif, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\qBoxBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\q_bg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\q_bg0.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\q_left.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\q_left0.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\q_right.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\q_right0.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\right.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\selected.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\img\skin\titleBg.png, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\all.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\background.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\ga.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\jq.mobi.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\jump.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\pop.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\redirect.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\js\xagainit.js, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\de\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\en\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\es\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\es_419\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\fr\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\it\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\ja\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\pl\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\pt_BR\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\pt_PT\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\ru\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\tr\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\vi\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\zh_CN\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_locales\zh_TW\messages.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_metadata\computed_hashes.json, , [ecd297a96d1df83e86414a1e867d04fc],
PUP.Optional.QuickStart.A, C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\4.5.8_0\_metadata\verified_contents.json, , [ecd297a96d1df83e86414a1e867d04fc],
Physical Sectors: 0
(No malicious items detected)
(end)
- Orcus
- člen Security týmu
-
Elite Level 10.5
- Příspěvky: 10645
- Registrován: duben 10
- Bydliště: Okolo rostou 3 růže =o)
- Pohlaví:
- Stav:
Offline
Re: Kontrola logu
Znovu spusť MbAM a dej Skenovat nyní
Po proběhnutí programu se ti objeví hláška, tak klikni na „Vše do karantény“ -> „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a ulož na Plochu.
Zkopíruj sem celý obsah toho logu.
====================================================
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
Klikni na „ Smazat“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
====================================================
Stáhni si Junkware Removal Tool
na svojí plochu.
Deaktivuj si svůj antivirový program.
Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
====================================================
Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Po proběhnutí programu se ti objeví hláška, tak klikni na „Vše do karantény“ -> „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a ulož na Plochu.
Zkopíruj sem celý obsah toho logu.
====================================================
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
Klikni na „ Smazat“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
====================================================
Stáhni si Junkware Removal Tool
na svojí plochu.
Deaktivuj si svůj antivirový program.
Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
====================================================
Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Láska hřeje, ale uhlí je uhlí.
Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.

Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.
Re: Kontrola logu
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 3.3.2015
Scan Time: 16:47:58
Logfile: mbm.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.03.03.04
Rootkit Database: v2015.02.25.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Tom
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 336651
Time Elapsed: 25 min, 21 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
www.malwarebytes.org
Scan Date: 3.3.2015
Scan Time: 16:47:58
Logfile: mbm.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.03.03.04
Rootkit Database: v2015.02.25.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Tom
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 336651
Time Elapsed: 25 min, 21 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
Re: Kontrola logu
# AdwCleaner v4.111 - Logfile created 03/03/2015 at 17:53:46
# Updated 18/02/2015 by Xplode
# Database : 2015-03-02.3 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Tom - TOM-PC
# Running from : C:\Users\Tom\Desktop\adwcleaner_4.111.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Driver Detective]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKLM\SOFTWARE\SPPDCOM
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\B506D6D57B4EB0947A492948CBD3A2B8
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\B506D6D57B4EB0947A492948CBD3A2B8
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B506D6D57B4EB0947A492948CBD3A2B8
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17631
-\\ Mozilla Firefox v36.0 (x86 cs)
-\\ Google Chrome v40.0.2214.115
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://istart.webssearches.com/web/?typ ... CDJS7RX&q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://istart.webssearches.com/web/?typ ... CDJS7RX&q={searchTerms}
-\\ Opera v27.0.1689.76
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://istart.webssearches.com/web/?typ ... CDJS7RX&q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://istart.webssearches.com/web/?typ ... CDJS7RX&q={searchTerms}
*************************
AdwCleaner[R0].txt - [2500 bytes] - [02/03/2015 22:04:43]
AdwCleaner[R1].txt - [2128 bytes] - [03/03/2015 17:51:05]
AdwCleaner[S0].txt - [2790 bytes] - [03/03/2015 17:53:46]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2849 bytes] ##########
# Updated 18/02/2015 by Xplode
# Database : 2015-03-02.3 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Tom - TOM-PC
# Running from : C:\Users\Tom\Desktop\adwcleaner_4.111.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Driver Detective]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKLM\SOFTWARE\SPPDCOM
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\B506D6D57B4EB0947A492948CBD3A2B8
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\B506D6D57B4EB0947A492948CBD3A2B8
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B506D6D57B4EB0947A492948CBD3A2B8
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17631
-\\ Mozilla Firefox v36.0 (x86 cs)
-\\ Google Chrome v40.0.2214.115
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://istart.webssearches.com/web/?typ ... CDJS7RX&q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://istart.webssearches.com/web/?typ ... CDJS7RX&q={searchTerms}
-\\ Opera v27.0.1689.76
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://istart.webssearches.com/web/?typ ... CDJS7RX&q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://istart.webssearches.com/web/?typ ... CDJS7RX&q={searchTerms}
*************************
AdwCleaner[R0].txt - [2500 bytes] - [02/03/2015 22:04:43]
AdwCleaner[R1].txt - [2128 bytes] - [03/03/2015 17:51:05]
AdwCleaner[S0].txt - [2790 bytes] - [03/03/2015 17:53:46]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2849 bytes] ##########
Re: Kontrola logu
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.3 (03.01.2015:1)
OS: Windows 7 Ultimate x64
Ran by Tom on Łt 03.03.2015 at 18:16:54,33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Tom\AppData\Roaming\mozilla\firefox\profiles\3yy1f78m.default\minidumps [20 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 03.03.2015 at 18:21:30,86
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.3 (03.01.2015:1)
OS: Windows 7 Ultimate x64
Ran by Tom on Łt 03.03.2015 at 18:16:54,33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Tom\AppData\Roaming\mozilla\firefox\profiles\3yy1f78m.default\minidumps [20 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 03.03.2015 at 18:21:30,86
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Re: Kontrola logu
RogueKiller V10.5.0.0 (x64) [Mar 2 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : Tom [Práva správce]
Mód : Prohledat -- Datum : 03/03/2015 18:32:18
¤¤¤ Procesy : 1 ¤¤¤
[Suspicious.Path] SpotifyWebHelper.exe(4900) -- C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7] -> Zastaveno [TermProc]
¤¤¤ Registry : 15 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify : "C:\Users\Tom\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart -> Nalezeno
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify Web Helper : "C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" -> Nalezeno
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify : "C:\Users\Tom\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart -> Nalezeno
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify Web Helper : "C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" -> Nalezeno
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tsusbhub (system32\drivers\tsusbhub.sys) -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{359C9C4A-4DBB-4461-919B-DD1A3163AA8D} | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{359C9C4A-4DBB-4461-919B-DD1A3163AA8D} | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{359C9C4A-4DBB-4461-919B-DD1A3163AA8D} | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nalezeno
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS545032A7E380 +++++
--- User ---
[MBR] 87dd6e3ee0369ce8337e3e6f9d71e279
[BSP] fdb7a5cb8a758c20ba6f1bbda34c6426 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 305143 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_DEL_10282014_232025.log - RKreport_SCN_10282014_114406.log - RKreport_SCN_10282014_161539.log - RKreport_SCN_10282014_231722.log
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : Tom [Práva správce]
Mód : Prohledat -- Datum : 03/03/2015 18:32:18
¤¤¤ Procesy : 1 ¤¤¤
[Suspicious.Path] SpotifyWebHelper.exe(4900) -- C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7] -> Zastaveno [TermProc]
¤¤¤ Registry : 15 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify : "C:\Users\Tom\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart -> Nalezeno
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify Web Helper : "C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" -> Nalezeno
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify : "C:\Users\Tom\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart -> Nalezeno
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify Web Helper : "C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" -> Nalezeno
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tsusbhub (system32\drivers\tsusbhub.sys) -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{359C9C4A-4DBB-4461-919B-DD1A3163AA8D} | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{359C9C4A-4DBB-4461-919B-DD1A3163AA8D} | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{359C9C4A-4DBB-4461-919B-DD1A3163AA8D} | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nalezeno
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS545032A7E380 +++++
--- User ---
[MBR] 87dd6e3ee0369ce8337e3e6f9d71e279
[BSP] fdb7a5cb8a758c20ba6f1bbda34c6426 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 305143 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_DEL_10282014_232025.log - RKreport_SCN_10282014_114406.log - RKreport_SCN_10282014_161539.log - RKreport_SCN_10282014_231722.log
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Kontrola logu
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Vypni antivir
Stáhni
Zoek.exe
a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:
klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Vlož nový log z HJT + informuj o problémech.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Vypni antivir
Stáhni
Zoek.exe
a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:
Kód: Vybrat vše
autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;
klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Vlož nový log z HJT + informuj o problémech.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Kontrola logu
RogueKiller V10.5.0.0 (x64) [Mar 2 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : Tom [Práva správce]
Mód : Smazat -- Datum : 03/03/2015 18:57:59
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 15 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify : "C:\Users\Tom\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [7][x][x] -> Smazáno
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify Web Helper : "C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [7] -> Smazáno
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify : "C:\Users\Tom\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify Web Helper : "C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" -> ERROR [2]
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tsusbhub -> Smazáno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{359C9C4A-4DBB-4461-919B-DD1A3163AA8D} | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{359C9C4A-4DBB-4461-919B-DD1A3163AA8D} | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{359C9C4A-4DBB-4461-919B-DD1A3163AA8D} | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nahrazeno ()
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nahrazeno (0)
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 3 ¤¤¤
[FIREFX:Addon] 3yy1f78m.default : Quick Translator [{5C655500-E712-41e7-9349-CE462F844B19}] -> Smazáno
[FIREFX:Addon] 3yy1f78m.default : Adblock Plus [{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}] -> Smazáno
[FIREFX:Addon] 3yy1f78m.default : Skype Click to Call [{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}] -> Smazáno
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS545032A7E380 +++++
--- User ---
[MBR] 87dd6e3ee0369ce8337e3e6f9d71e279
[BSP] fdb7a5cb8a758c20ba6f1bbda34c6426 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 305143 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_DEL_10282014_232025.log - RKreport_SCN_03032015_183218.log - RKreport_SCN_10282014_114406.log - RKreport_SCN_10282014_161539.log
RKreport_SCN_10282014_231722.log - RKreport_SCN_03032015_185543.log
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : Tom [Práva správce]
Mód : Smazat -- Datum : 03/03/2015 18:57:59
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 15 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify : "C:\Users\Tom\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [7][x][x] -> Smazáno
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify Web Helper : "C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [7] -> Smazáno
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify : "C:\Users\Tom\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Run | Spotify Web Helper : "C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" -> ERROR [2]
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tsusbhub -> Smazáno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{359C9C4A-4DBB-4461-919B-DD1A3163AA8D} | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{359C9C4A-4DBB-4461-919B-DD1A3163AA8D} | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{359C9C4A-4DBB-4461-919B-DD1A3163AA8D} | DhcpNameServer : 158.196.149.9 158.196.162.8 [CZECH REPUBLIC (CZ)][EUROPEAN UNION (EU)] -> Nahrazeno ()
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-336169304-3127449335-4048730859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nahrazeno (0)
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 3 ¤¤¤
[FIREFX:Addon] 3yy1f78m.default : Quick Translator [{5C655500-E712-41e7-9349-CE462F844B19}] -> Smazáno
[FIREFX:Addon] 3yy1f78m.default : Adblock Plus [{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}] -> Smazáno
[FIREFX:Addon] 3yy1f78m.default : Skype Click to Call [{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}] -> Smazáno
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS545032A7E380 +++++
--- User ---
[MBR] 87dd6e3ee0369ce8337e3e6f9d71e279
[BSP] fdb7a5cb8a758c20ba6f1bbda34c6426 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 305143 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_DEL_10282014_232025.log - RKreport_SCN_03032015_183218.log - RKreport_SCN_10282014_114406.log - RKreport_SCN_10282014_161539.log
RKreport_SCN_10282014_231722.log - RKreport_SCN_03032015_185543.log
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Kontrola logu
Ještě poprosíme o ten Zoek
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 68 hostů