Kontrola logu (podezření na keylogger)

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Impra
Level 2
Level 2
Příspěvky: 160
Registrován: prosinec 14
Pohlaví: Muž
Stav:
Offline

Kontrola logu (podezření na keylogger)

Příspěvekod Impra » 11 úno 2016 16:11

Zdravím, mám podezření na keylogger. Mohl by se mě na to nějaký zdejší odborník mrknout prosím?:) Diky
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:09:27, on 11.2.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.17606)

FIREFOX: 31.0 (x86 cs)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\FILIP\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Overwolf\Overwolf.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
C:\Users\FILIP\AppData\Local\Temp\Rar$EX00.837\iBrightnessTray.exe
C:\Users\FILIP\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Users\FILIP\AppData\Roaming\Spotify\Spotify.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Inbox Toolbar\Inbox.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Program Files (x86)\BlueStacks\HD-Agent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\FILIP\AppData\Roaming\Spotify\Spotify.exe
C:\Program Files (x86)\EVOLVEO\Gaming Keyboard\Monitor.EXE
C:\Users\FILIP\AppData\Roaming\Spotify\Spotify.exe
C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
C:\Program Files (x86)\EVOLVEO\Gaming Keyboard\OSD.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Overwolf\0.92.3.0\Purplizer\Purplizer.exe
C:\Program Files (x86)\Overwolf\0.92.3.0\OverwolfBrowser.exe
C:\Program Files (x86)\Overwolf\0.92.3.0\OverwolfBrowser.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\cmd.exe
C:\Program Files (x86)\Spyware Terminator\STInternetGuard.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\FILIP\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hal3000.cz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... p=aus&qkw=%s&tbid=60341
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT3072253
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx ... 093&lng=cs
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://toolbar.inbox.com/help/sa_custom ... tbid=80093
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\10.9\iobitappsToolbarIE.dll
R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll
R3 - URLSearchHook: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
R3 - URLSearchHook: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
O1 - Hosts: ::1 localhost
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\10.9\iobitappsToolbarIE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
O2 - BHO: Slick Savings - {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO: uTorrentControl2 - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Spyware Terminator 2015 Internet Guard - {82A76710-4F98-4957-92BE-99648A4E2475} - C:\PROGRA~2\SPYWAR~1\STINTE~1.DLL
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Web TuneUp - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Web TuneUp\4.2.5.441\AVG Web TuneUp.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: DataMngr - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\PROGRA~2\IMESHA~1\Mediabar\Datamngr\BROWSE~1.DLL
O2 - BHO: Search-Results Toolbar - {bff6b2ca-366c-4a90-b685-d87776deb0d2} - C:\PROGRA~2\IMESHA~1\Mediabar\Datamngr\SRTOOL~1\searchresultsDx.dll
O2 - BHO: Ask Shopping Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ\Passport.dll" (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
O3 - Toolbar: Search-Results Toolbar - {bff6b2ca-366c-4a90-b685-d87776deb0d2} - C:\PROGRA~2\IMESHA~1\Mediabar\Datamngr\SRTOOL~1\searchresultsDx.dll
O3 - Toolbar: Ask Shopping Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ\Passport.dll" (file missing)
O3 - Toolbar: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\10.9\iobitappsToolbarIE.dll
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [InboxToolbar] "C:\Program Files (x86)\Inbox Toolbar\Inbox.exe" /STARTUP
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [GK-862 Driver] "C:\Program Files (x86)\EVOLVEO\Gaming Keyboard\Monitor.exe"
O4 - HKLM\..\Run: [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
O4 - HKLM\..\Run: [AvgUi] "C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe" /lps=fmw
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe"
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Google Update] "C:\Users\FILIP\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent
O4 - HKCU\..\Run: [WMFinishInstall] C:\Program Files (x86)\Videocharge Software\Watermark Master\FinishInstallation.exe
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [BackgroundContainerV2] "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\FILIP\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
O4 - HKCU\..\Run: [iBrightness Tray] C:\Users\FILIP\AppData\Local\Temp\Rar$EX00.837\iBrightnessTray.exe
O4 - HKCU\..\Run: [Dxtory Update Checker 2.0] C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\FILIP\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Spotify] "C:\Users\FILIP\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (file missing)
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Users\FILIP\AppData\Roaming\ICQ\Application\ICQ7.2\ICQ.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Users\FILIP\AppData\Roaming\ICQ\Application\ICQ7.2\ICQ.exe (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {6678BE91-1E04-4A4A-9C32-63145EA79C2A} (EAFO3AXLauncher Control) - http://www.fifa-online.easports.com/fo3 ... uncher.cab
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~2\INBOXT~1\Inbox.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~2\IMESHA~1\Mediabar\Datamngr\datamngr.dll C:\PROGRA~2\IMESHA~1\Mediabar\Datamngr\IEBHO.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ask Update Service (APNMCP) - APN LLC. - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\PROGRAM FILES (X86)\LOGMEIN HAMACHI\LMIGUARDIANSVC.EXE
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler Group, LLC - C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater40.2.5 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.5\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe

--
End of file - 21491 bytes

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu (podezření na keylogger)

Příspěvekod jaro3 » 11 úno 2016 17:10

Odinstaluj::
Spyware Terminator
Advanced SystemCare 7
Všechny toolbary


Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
http://www.geekstogo.com/forum/files/fi ... -oldtimer/
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu klikni na „Logfile“ ,objeví log ( jinak je uložen systémovem disku jako AdwCleaner[C?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na Kopírovat do schránky a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Impra
Level 2
Level 2
Příspěvky: 160
Registrován: prosinec 14
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu (podezření na keylogger)

Příspěvekod Impra » 11 úno 2016 18:16

AdwCleaner v5.033 - Logfile created 11/02/2016 at 18:12:44
# Updated 07/02/2016 by Xplode
# Database : 2016-02-07.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : FILIP - FILIP-PC
# Running from : C:\Users\FILIP\Desktop\adwcleaner_5.033.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****

Service Found : APNMCP
Service Found : Application Updater
Service Found : vToolbarUpdater40.2.5

***** [ Folders ] *****

Folder Found : C:\Program Files\Zrychleni Pocitace
Folder Found : C:\Program Files (x86)\Application Updater
Folder Found : C:\Program Files (x86)\Ask.com
Folder Found : C:\Program Files (x86)\AskPartnerNetwork
Folder Found : C:\Program Files (x86)\AVG Security Toolbar
Folder Found : C:\Program Files (x86)\Crawler
Folder Found : C:\Program Files (x86)\ICQ6Toolbar
Folder Found : C:\Program Files (x86)\iMesh Applications
Folder Found : C:\Program Files (x86)\Inbox Toolbar
Folder Found : C:\Program Files (x86)\IObit Apps Toolbar
Folder Found : C:\Program Files (x86)\uTorrentControl2
Folder Found : C:\Program Files (x86)\Mozilla Firefox\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Program Files (x86)\Common Files\Spigot
Folder Found : C:\Program Files\Common Files\AVG Secure Search
Folder Found : C:\ProgramData\apn
Folder Found : C:\ProgramData\Ask
Folder Found : C:\ProgramData\AskPartnerNetwork
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\Babylon
Folder Found : C:\ProgramData\BrowserDefender
Folder Found : C:\ProgramData\ICQ\ICQToolbar
Folder Found : C:\ProgramData\iMesh
Folder Found : C:\ProgramData\Avg_Update_0814tb
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inbox Toolbar
Folder Found : C:\Users\FILIP\AppData\Local\AskPartnerNetwork
Folder Found : C:\Users\FILIP\AppData\Local\AskToolbar
Folder Found : C:\Users\FILIP\AppData\Local\Conduit
Folder Found : C:\Users\FILIP\AppData\Local\PackageAware
Folder Found : C:\Users\FILIP\AppData\Local\Slick Savings
Folder Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
Folder Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
Folder Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Folder Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc
Folder Found : C:\Users\FILIP\AppData\Local\Temp\apn
Folder Found : C:\Users\FILIP\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\FILIP\AppData\LocalLow\AVG Security Toolbar
Folder Found : C:\Users\FILIP\AppData\LocalLow\Conduit
Folder Found : C:\Users\FILIP\AppData\LocalLow\ConduitEngine
Folder Found : C:\Users\FILIP\AppData\LocalLow\Inbox Toolbar
Folder Found : C:\Users\FILIP\AppData\LocalLow\PriceGong
Folder Found : C:\Users\FILIP\AppData\LocalLow\Search Settings
Folder Found : C:\Users\FILIP\AppData\LocalLow\searchresultstb
Folder Found : C:\Users\FILIP\AppData\LocalLow\uTorrentControl2
Folder Found : C:\Users\FILIP\AppData\LocalLow\Vuze_Remote
Folder Found : C:\Users\FILIP\AppData\LocalLow\xfirexo
Folder Found : C:\Users\FILIP\AppData\Roaming\Babylon
Folder Found : C:\Users\FILIP\AppData\Roaming\goforfiles
Folder Found : C:\Users\FILIP\AppData\Roaming\Slick Savings
Folder Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\Inbox Toolbar
Folder Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\Extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}
Folder Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\Extensions\inboxcomtoolbar@inbox.com
Folder Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\Extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}
Folder Found : C:\Users\Guest\AppData\Local\AVG Secure Search
Folder Found : C:\Users\Linux\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Linux\AppData\LocalLow\Conduit
Folder Found : C:\Users\Linux\AppData\LocalLow\Search Settings
Folder Found : C:\Users\Linux\AppData\LocalLow\searchresultstb
Folder Found : C:\Users\Linux\AppData\LocalLow\uTorrentControl2
Folder Found : C:\Users\Linux\AppData\Roaming\Mozilla\Firefox\Profiles\x87uq7d1.default\Extensions\{BFF6B2CA-366C-4A90-B685-D87776DEB0D2}
Folder Found : C:\Users\mamka\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\mamka\AppData\LocalLow\AVG Security Toolbar
Folder Found : C:\Users\mamka\AppData\LocalLow\Conduit
Folder Found : C:\Users\mamka\AppData\LocalLow\PriceGong
Folder Found : C:\Users\mamka\AppData\LocalLow\Search Settings
Folder Found : C:\Users\mamka\AppData\LocalLow\searchresultstb
Folder Found : C:\Users\mamka\AppData\LocalLow\uTorrentControl2
Folder Found : C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\66h8ul8p.default\Extensions\{BFF6B2CA-366C-4A90-B685-D87776DEB0D2}

***** [ Files ] *****

File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pacgpkgadgmibnhpdidcnfafllnmeomc_0.localstorage
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_pacgpkgadgmibnhpdidcnfafllnmeomc_0
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pacgpkgadgmibnhpdidcnfafllnmeomc
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\bprotector web data
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_facebook.conduitapps.com_0.localstorage
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_youtube.conduitapps.com_0.localstorage
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_app.mam.conduit.com_0.localstorage
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_facebook.conduitapps.com_0.localstorage
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_int.search-results.com_0.localstorage
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pricegong.conduitapps.com_0.localstorage
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.imesh.net_0.localstorage
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_storage.conduit.com_0.localstorage
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Found : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_youtube.conduitapps.com_0.localstorage
File Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\lqiggqkd.default-1353230452431\searchplugins\yahoo_ff.xml
File Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\Extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}.xpi
File Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\bprotector_extensions.sqlite
File Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\searchplugins\Askcom.xml
File Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\searchplugins\Babylon.xml
File Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\searchplugins\bingp.xml
File Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\searchplugins\BrowserDefender.xml
File Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\searchplugins\yahoo_ff.xml
File Found : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\user.js
File Found : C:\Users\Linux\AppData\Roaming\Mozilla\Firefox\Profiles\x87uq7d1.default\Extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}.xpi
File Found : C:\Users\Linux\AppData\Roaming\Mozilla\Firefox\Profiles\x87uq7d1.default\searchplugins\yahoo_ff.xml
File Found : C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\66h8ul8p.default\bprotector_extensions.sqlite
File Found : C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\66h8ul8p.default\searchplugins\yahoo_ff.xml

***** [ DLL ] *****


***** [ Shortcuts ] *****

Shortcut Infected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inbox Toolbar\Inbox.com.lnk ( /showurl hxxp://www.inbox.com/homepage.aspx?tbid ... 273&lng=cs )
Shortcut Infected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inbox Toolbar\NastavenĂ­.lnk ( /showurl hxxp://toolbar.inbox.com/settings/settings.aspx?lng=cs )
Shortcut Infected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inbox Toolbar\Nápověda.lnk ( /showurl hxxp://toolbar.inbox.com/faq.aspx )
Shortcut Infected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crawler lišta\Nápověda pro lištu.lnk ( /showurl hxxp://www.crawler.com/help/default.aspx?src=TbMenu )

***** [ Scheduled tasks ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Found : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search
Key Found : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
Key Found : HKLM\SOFTWARE\Classes\AppID\DiscoveryHelper.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\GIFAnimator.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\iMesh.exe
Key Found : HKLM\SOFTWARE\Classes\AppID\IMTrProgress.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\IMWeb.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Found : HKLM\SOFTWARE\Classes\Applications\iMesh_V11_en_Setup.exe
Key Found : HKLM\SOFTWARE\Classes\Applications\iMeshV11.exe
Key Found : HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithiMesh
Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\handler\inbox
Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\tbr
Key Found : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\IMPlayCDAudioOnArrival
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\IMRipCDAudioOnArrival
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\IMShowCDAudioOnArrival
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\IMShowVolumeOnArrival
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\Crawler
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [fmconverter@gmail.com]
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Key Found : HKCU\Software\Google\Chrome\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc
Key Found : HKCU\Software\Google\Chrome\Extensions\chfdnecihphmhljaaejmgoiahnihplgn
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FC41815-FA4C-4F8B-B143-2C045C8EA2FC}
Key Found : HKLM\SOFTWARE\Classes\AppID\{21493C1F-D071-496A-9C27-450578888291}
Key Found : HKLM\SOFTWARE\Classes\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7}
Key Found : HKLM\SOFTWARE\Classes\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48}
Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Key Found : HKCU\Software\Classes\CLSID\{16C8C46E-C811-4977-BF0A-B5CC1FA78D95}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{042DA63B-0933-403D-9395-B49307691690}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1DDA201E-5B42-4352-933E-21A92B297E3B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{37540F19-DD4C-478B-B2DF-C19281BCAF27}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{474597C5-AB09-49D6-A4D5-2E8D7341384E}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4D25FB7A-8902-4291-960E-9ADA051CFBBF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{612AD33D-9824-4E87-8396-92374E91C4BB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{950F80EF-32C2-47DD-9C35-9576E21EE66E}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BFF6B2CA-366C-4A90-B685-D87776DEB0D2}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DBDB6FAA-1F5F-4A18-B60B-7A905C7FF83F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
Key Found : HKLM\SOFTWARE\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
Key Found : HKLM\SOFTWARE\Classes\Interface\{28C3737A-32D1-492D-B76B-8D75EBBFB887}
Key Found : HKLM\SOFTWARE\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
Key Found : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\Interface\{CE057E0D-2D7E-4DFF-A890-07BA69B8C762}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
Key Found : HKLM\SOFTWARE\Classes\Interface\{884189CF-7C10-41E8-A014-F7B2BE40AADB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{BD125908-5F10-409F-9C01-F2207CA18887}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D15809AA-50CF-4EE0-BCC9-E91A681BEFD3}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{04006843-5199-4CE4-B3CD-8092CC91706E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{615E8AA1-6BB8-4A3D-A1CC-373194DB612C}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A147AA03-820F-4A0F-9F34-D6CB4004A2F9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{CBEF8724-D080-4737-88DA-111EEC6651AA}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E79BB61D-7F1A-41DF-8AD0-402795E3B566}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EEA63863-87BC-4DCA-A5B5-EB97E3B04806}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{687578B9-7132-4A7A-80E4-30EE31099E03}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BFF6B2CA-366C-4A90-B685-D87776DEB0D2}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA14329E-9550-4989-B3F2-9732E92D17CC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BFF6B2CA-366C-4A90-B685-D87776DEB0D2}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA14329E-9550-4989-B3F2-9732E92D17CC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BFF6B2CA-366C-4A90-B685-D87776DEB0D2}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7C3B01BC-53A5-48A0-A43B-0C67731134B9}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424C-BB9F-74C6899B9F92}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6F8DA9F-2696-419E-A8A3-19BE41EF51BD}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0ABE0FED-50E7-4E42-A125-57C0A11DBCDE}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{612AD33D-9824-4E87-8396-92374E91C4BB}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7459F1D0-9FB6-4D71-AA7B-9DECB34EB704}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BFF6B2CA-366C-4A90-B685-D87776DEB0D2}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FBF1B8D2-9A06-4174-A8B5-E38606DDB92B}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{687578B9-7132-4A7A-80E4-30EE31099E03}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{BFF6B2CA-366C-4A90-B685-D87776DEB0D2}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{687578B9-7132-4A7A-80E4-30EE31099E03}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{CCC7A320-B3CA-4199-B1A6-9F516DD69829}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{21FA44EF-376D-4D53-9B0F-8A89D3229068}]
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{474597C5-AB09-49D6-A4D5-2E8D7341384E}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{950F80EF-32C2-47DD-9C35-9576E21EE66E}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{28C3737A-32D1-492D-B76B-8D75EBBFB887}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{B37B4BA6-334E-72C1-B57E-6AFE8F8A5AF3}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{B77AD4AC-C1C2-B293-7737-71E13A11FFEA}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{CE057E0D-2D7E-4DFF-A890-07BA69B8C762}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{E773F2CF-5E6E-FF2B-81A1-AC581A26B2B2}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{596BB86E-F1E5-A1DE-3363-41AB634E77EF}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A3492A3A-6715-9371-F8DB-1C48CC4DAAA1}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{D15809AA-50CF-4EE0-BCC9-E91A681BEFD3}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Value Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{612AD33D-9824-4E87-8396-92374E91C4BB}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Key Found : HKCU\Software\1ClickDownload
Key Found : HKCU\Software\AskPartnerNetwork
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\CToolbar
Key Found : HKCU\Software\DataMngr_Toolbar
Key Found : HKCU\Software\eSupport.com
Key Found : HKCU\Software\ICQ\ICQToolbar
Key Found : HKCU\Software\IGearSettings
Key Found : HKCU\Software\Inbox Toolbar
Key Found : HKCU\Software\IObit Apps
Key Found : HKCU\Software\Myfree Codec
Key Found : HKCU\Software\Search Settings
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\AppDataLow\Software\AVG Security Toolbar
Key Found : HKCU\Software\AppDataLow\Software\BackgroundContainerV2
Key Found : HKCU\Software\AppDataLow\Software\Browser Extensions
Key Found : HKCU\Software\AppDataLow\Software\conduitEngine
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\IObit Apps
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\AppDataLow\Software\Search Settings
Key Found : HKCU\Software\AppDataLow\Software\Settings Manager
Key Found : HKLM\SOFTWARE\Application Updater
Key Found : HKLM\SOFTWARE\AskPartnerNetwork
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\CToolbar
Key Found : HKLM\SOFTWARE\DataMngr
Key Found : HKLM\SOFTWARE\dt soft\daemon tools toolbar
Key Found : HKLM\SOFTWARE\ICQ\ICQToolbar
Key Found : HKLM\SOFTWARE\iMeshSRTB
Key Found : HKLM\SOFTWARE\Inbox Toolbar
Key Found : HKLM\SOFTWARE\IObit Apps
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{612AD33D-9824-4E87-8396-92374E91C4BB}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FB495A1-4A3F-4C1D-BD27-3F3AB2E66763}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CToolbar_UNINSTALL
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Imesh
Key Found : [x64] HKLM\SOFTWARE\AskPartnerNetwork
Key Found : [x64] HKLM\SOFTWARE\DataMngr
Key Found : HKU\.DEFAULT\Software\AskPartnerNetwork
Key Found : HKU\.DEFAULT\Software\AVG Secure Search
Key Found : HKU\.DEFAULT\Software\CToolbar
Key Found : HKU\.DEFAULT\Software\IGearSettings
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\AskToolbar
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\AVG Security Toolbar
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\1A594BF8F3A4D1C4DB72F3A32B6E7636
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\1A594BF8F3A4D1C4DB72F3A32B6E7636
Key Found : HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02726A9FE166A194C977C43ED7918C7D
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\05990EE2A6ECB704AAE09A9F2B1D2690
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\05E320899AC5DFC4188992AF8FD5F0A9
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07AEB9989AC635A4C9AEC17C1D8C3F47
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0A167702A96FE1D4DA3296FCA77354D9
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0A7275BB60FCF7A44B07560596868F6F
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CE7E880681D8514BB74495CB9C7DB15
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\11918CE983E411A4499DB4F94B03988C
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1837B90D2D2A24E46BD078515E54606D
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18A2F79B8B5496548AFF6BFD951BA1D7
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1B342991F909BFE42BE3111FCC2A4FDF
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\26FB96B9D8A7BA641B9B403EFE5E352A
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30C16B15B255BD349A1157B8A83E2AF9
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\33F0A06A03D1BCD4C8478F57942EB382
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\35BF9777E7A71D24F9AE687C49A9D4AA
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3ADA836143C391140BC3A310A3887D76
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3B700104B595403438CF1766A17C7B43
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4419373400F2999449B449AD52A405C8
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\44D9E2201CBAF7F4AAB499F88F186793
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\48D113357373E7243987C715C2E237B7
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4C8E2B5D1AD75DC4D817D3245529FF8A
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\521C89BFD20682C4A8A3D09653B5754C
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\542FA3B1339B3C746BEA9030972B21A3
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5F51EFF1E682AEE419D5DC2C6991D96D
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\640077B237BDACF488907776FD0C94B7
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6516A7399D5B20C44A9D52C754D45AB0
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AD7464931533E54ABC4ED253F3AC7D4
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AFCF8185798D05489D1EC80833137BF
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6CB081BFE0546AA41851C5F201A5096D
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6D909061B36E74D439105FC6C46EE7E4
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\714E529913F2B11459D57CF5AB8ADE18
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71C1BAEDCFEE1F04787B3A1A88D61521
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\782CB3952651E1F498135CD5EAF62A3B
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\78DE8D4E317D831428E9B303110F5D4E
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86C6B9FDF7D548F4A8EA238724A95E8A
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9CB1EFBCC7DFCF546B4F590FF0D16CDC
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9EC1D63A26A49754AA21245669B6C050
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A1DB601AF179DDB4E8019CD5A8DC28D6
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5F1E13C84BF9EA429F900AC8DFE735D
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA3D949BCB89B41419ED62A7B59D5AB6
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA3ECDF0A5A3C1E449DEFA5067377C19
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AFFA280B59E7E964D97771E806E856D8
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B7A4D6202FAB59C4384AD98E156DF915
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B8A02A917B98BDD4F87CC68AE73FD13F
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B9B86DF9648E50F49B6FA80AA1817FFF
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAC4DFAF69F21D748AACDA4EB27D388E
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD951A01F6B5123489BFD25C37099539
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C306F1134D3402D4F85A227F3BA51922
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C56ADA40C7C79F649A24894B4C9E9855
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C99971F434D718E4E9233C967E3B6E9C
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CFF07BCFCF6853A4CBF566C5487566E5
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D0415D2B9FF39DE4BA389EC95BB4E5D1
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D45965CDA20AEED4A9D01FC74276005B
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBC7454A1DC1BB6498690C8A2271CD5C
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DCBA962DFC3BA354FAE45A2F6F865483
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E26591CEB9A2C8945AD3D8FE6FDD8A77
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4857DEE299B6FF47B34302A1B09D1FA
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E86AA401AA1EB164E873283056577F43
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC236841F203FA04CA286BDC54E6CECD
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1CAE30F47D14B41B5FC8FA53658044
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F5FEE537686A40D48A5155FD2702FF69
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F8C855FBD8CF09B45BE399B1191A41CD
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F92CB401299A0584CB95D5D656F79953
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F937787D1134BBA4B846D98011F78299
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDF4258FB4C3BC641B1F7A4FDD91AABA
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8036C72171EF4ba46856BF57969F6A36
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\89BB7852687BDC34B9A81E01C7FF9173
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CBC85D72B148084ABE8C2F072F781F4
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CC5A38A64D6098468BC8395BA0EFF03
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8DF9A1AC557F56c49B56F6B83E293C15
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A97C590397DCC454AA8923563BAB10E4
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B08932C78B697C244BE7BA3E6FF09B62
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CFA51B44D54927c4E9B7BC1D3FD1E49F
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D14A7F65792054F418578C78367D13F7
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DFE9F0BD163D827438CB6AD6B100EC48
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F739A19A8327dc64C9A8B641A9E89646
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\158D6D9E3FE81fa428925F22ACB3A965
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15E6C514FEFC09f45BAFAAE1D7546ED4
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DB42320A8525634AA089F0BEC86473B
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22468B0D6050b2e46B9C4B67A8F59577
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2251BF05A2F606d43BB064BD63CBD87E
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3255D95681398614190EDF0A4F3F77DB
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3CDF313E9B28c944FBC7579CF4949414
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71E54748EDD3dc1468548785DC856EDA
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\754590DD06DE8d249B526503432F99D4
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1A594BF8F3A4D1C4DB72F3A32B6E7636
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
Key Found : [x64] HKLM\SOFTWARE\Classes\Installer\Products\1A594BF8F3A4D1C4DB72F3A32B6E7636
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.conduit.com?SearchSource= ... =CT3072253
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar] - hxxp://www.crawler.com/search/dispatche ... p=aus&qkw=%s&tbid=60341
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] - hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [SearchAssistant] - hxxp://toolbar.inbox.com/search/ie.aspx ... 093&lng=cs
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [CustomizeSearch] - hxxp://toolbar.inbox.com/help/sa_custom ... tbid=80093
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1E5672EF-5D91-451A-A581-0B907CFED224}
Data Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {1E5672EF-5D91-451A-A581-0B907CFED224}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2BD8164E-AC71-4BCF-A404-F467A407F390}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
Key Found : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\IMESHA~1\Mediabar\Datamngr\datamngr.dll C:\PROGRA~2\IMESHA~1\Mediabar\Datamngr\IEBHO.dll
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\IMESHA~1\Mediabar\Datamngr\x64\datamngr.dll C:\PROGRA~2\IMESHA~1\Mediabar\Datamngr\x64\IEBHO.dll
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\icq.com
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BackgroundContainerV2]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTBMon]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [InboxToolbar]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]

***** [ Web browsers ] *****

[C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\lqiggqkd.default-1353230452431\prefs.js] [Preference] Found : user_pref("keyword.URL", "hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=");
[C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\prefs.js] [Preference] Found : user_pref("keyword.URL", "hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=");
[C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\prefs.js] [Preference] Found : user_pref("keyword.url", "hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=");
[C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\prefs.js] [Preference] Found : user_pref("network.hxxp.request.max-start-delay", 0);
[C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\66h8ul8p.default\prefs.js] [Preference] Found : user_pref("keyword.URL", "hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=");
[C:\Users\Linux\AppData\Roaming\Mozilla\Firefox\Profiles\x87uq7d1.default\prefs.js] [Preference] Found : user_pref("browser.search.defaultengine", "Ask.com");
[C:\Users\Linux\AppData\Roaming\Mozilla\Firefox\Profiles\x87uq7d1.default\prefs.js] [Preference] Found : user_pref("browser.search.order.1", "Ask.com");
[C:\Users\Linux\AppData\Roaming\Mozilla\Firefox\Profiles\x87uq7d1.default\prefs.js] [Preference] Found : user_pref("extensions.asktb.ff-original-keyword-url", "");
[C:\Users\Linux\AppData\Roaming\Mozilla\Firefox\Profiles\x87uq7d1.default\prefs.js] [Preference] Found : user_pref("keyword.URL", "hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=");
[C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : yahoo.com Search

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [48082 bytes] ##########

Uživatelský avatar
Impra
Level 2
Level 2
Příspěvky: 160
Registrován: prosinec 14
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu (podezření na keylogger)

Příspěvekod Impra » 11 úno 2016 18:42

Hned jak se dodělá ten druhý scan přidám log.

Uživatelský avatar
Impra
Level 2
Level 2
Příspěvky: 160
Registrován: prosinec 14
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu (podezření na keylogger)

Příspěvekod Impra » 11 úno 2016 19:21

Je to tak dlouhý, že to sem nejde ani vložit.

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu (podezření na keylogger)

Příspěvekod jerabina » 11 úno 2016 19:50

Nahraj to např. na www.leteckaposta.cz a odkaz na stažení sem vlož.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Uživatelský avatar
Impra
Level 2
Level 2
Příspěvky: 160
Registrován: prosinec 14
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu (podezření na keylogger)

Příspěvekod Impra » 11 úno 2016 20:01


Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu (podezření na keylogger)

Příspěvekod jerabina » 11 úno 2016 20:15

No je tam toho požehnaně :D

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Uživatelský avatar
Impra
Level 2
Level 2
Příspěvky: 160
Registrován: prosinec 14
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu (podezření na keylogger)

Příspěvekod Impra » 11 úno 2016 20:39

# AdwCleaner v5.033 - Logfile created 11/02/2016 at 20:23:46
# Updated 07/02/2016 by Xplode
# Database : 2016-02-07.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : FILIP - FILIP-PC
# Running from : C:\Users\FILIP\Downloads\adwcleaner_5.033.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : APNMCP
[-] Service Deleted : Application Updater
[-] Service Deleted : vToolbarUpdater40.2.5

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files\Zrychleni Pocitace
[-] Folder Deleted : C:\Program Files (x86)\Application Updater
[-] Folder Deleted : C:\Program Files (x86)\Ask.com
[-] Folder Deleted : C:\Program Files (x86)\AskPartnerNetwork
[-] Folder Deleted : C:\Program Files (x86)\AVG Security Toolbar
[-] Folder Deleted : C:\Program Files (x86)\Crawler
[-] Folder Deleted : C:\Program Files (x86)\ICQ6Toolbar
[-] Folder Deleted : C:\Program Files (x86)\iMesh Applications
[-] Folder Deleted : C:\Program Files (x86)\Inbox Toolbar
[-] Folder Deleted : C:\Program Files (x86)\IObit Apps Toolbar
[-] Folder Deleted : C:\Program Files (x86)\uTorrentControl2
[#] Folder Deleted : C:\Program Files (x86)\Mozilla Firefox\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
[-] Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
[-] Folder Deleted : C:\Program Files (x86)\Common Files\Spigot
[-] Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
[-] Folder Deleted : C:\ProgramData\apn
[-] Folder Deleted : C:\ProgramData\Ask
[-] Folder Deleted : C:\ProgramData\AskPartnerNetwork
[-] Folder Deleted : C:\ProgramData\AVG Secure Search
[-] Folder Deleted : C:\ProgramData\Babylon
[-] Folder Deleted : C:\ProgramData\BrowserDefender
[-] Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
[-] Folder Deleted : C:\ProgramData\iMesh
[-] Folder Deleted : C:\ProgramData\Avg_Update_0814tb
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inbox Toolbar
[-] Folder Deleted : C:\Users\FILIP\AppData\Local\AskPartnerNetwork
[-] Folder Deleted : C:\Users\FILIP\AppData\Local\AskToolbar
[-] Folder Deleted : C:\Users\FILIP\AppData\Local\Conduit
[-] Folder Deleted : C:\Users\FILIP\AppData\Local\PackageAware
[-] Folder Deleted : C:\Users\FILIP\AppData\Local\Slick Savings
[-] Folder Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
[-] Folder Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
[-] Folder Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
[-] Folder Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc
[-] Folder Deleted : C:\Users\FILIP\AppData\Local\Temp\apn
[-] Folder Deleted : C:\Users\FILIP\AppData\LocalLow\AVG Secure Search
[-] Folder Deleted : C:\Users\FILIP\AppData\LocalLow\AVG Security Toolbar
[-] Folder Deleted : C:\Users\FILIP\AppData\LocalLow\Conduit
[-] Folder Deleted : C:\Users\FILIP\AppData\LocalLow\ConduitEngine
[-] Folder Deleted : C:\Users\FILIP\AppData\LocalLow\Inbox Toolbar
[-] Folder Deleted : C:\Users\FILIP\AppData\LocalLow\PriceGong
[-] Folder Deleted : C:\Users\FILIP\AppData\LocalLow\Search Settings
[-] Folder Deleted : C:\Users\FILIP\AppData\LocalLow\searchresultstb
[-] Folder Deleted : C:\Users\FILIP\AppData\LocalLow\uTorrentControl2
[-] Folder Deleted : C:\Users\FILIP\AppData\LocalLow\Vuze_Remote
[-] Folder Deleted : C:\Users\FILIP\AppData\LocalLow\xfirexo
[-] Folder Deleted : C:\Users\FILIP\AppData\Roaming\Babylon
[-] Folder Deleted : C:\Users\FILIP\AppData\Roaming\goforfiles
[-] Folder Deleted : C:\Users\FILIP\AppData\Roaming\Slick Savings
[-] Folder Deleted : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\Inbox Toolbar
[-] Folder Deleted : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\Extensions\inboxcomtoolbar@inbox.com
[-] Folder Deleted : C:\Users\Guest\AppData\Local\AVG Secure Search
[-] Folder Deleted : C:\Users\Linux\AppData\LocalLow\AVG Secure Search
[-] Folder Deleted : C:\Users\Linux\AppData\LocalLow\Conduit
[-] Folder Deleted : C:\Users\Linux\AppData\LocalLow\Search Settings
[-] Folder Deleted : C:\Users\Linux\AppData\LocalLow\searchresultstb
[-] Folder Deleted : C:\Users\Linux\AppData\LocalLow\uTorrentControl2
[-] Folder Deleted : C:\Users\Linux\AppData\Roaming\Mozilla\Firefox\Profiles\x87uq7d1.default\Extensions\{BFF6B2CA-366C-4A90-B685-D87776DEB0D2}
[-] Folder Deleted : C:\Users\mamka\AppData\LocalLow\AVG Secure Search
[-] Folder Deleted : C:\Users\mamka\AppData\LocalLow\AVG Security Toolbar
[-] Folder Deleted : C:\Users\mamka\AppData\LocalLow\Conduit
[-] Folder Deleted : C:\Users\mamka\AppData\LocalLow\PriceGong
[-] Folder Deleted : C:\Users\mamka\AppData\LocalLow\Search Settings
[-] Folder Deleted : C:\Users\mamka\AppData\LocalLow\searchresultstb
[-] Folder Deleted : C:\Users\mamka\AppData\LocalLow\uTorrentControl2
[-] Folder Deleted : C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\66h8ul8p.default\Extensions\{BFF6B2CA-366C-4A90-B685-D87776DEB0D2}

***** [ Files ] *****

[-] File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml
[-] File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pacgpkgadgmibnhpdidcnfafllnmeomc_0.localstorage
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_pacgpkgadgmibnhpdidcnfafllnmeomc_0
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pacgpkgadgmibnhpdidcnfafllnmeomc
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\bprotector web data
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_facebook.conduitapps.com_0.localstorage
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_youtube.conduitapps.com_0.localstorage
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_facebook.conduitapps.com_0.localstorage
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_int.search-results.com_0.localstorage
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.conduit.com_0.localstorage
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.imesh.net_0.localstorage
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage
[-] File Deleted : C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_youtube.conduitapps.com_0.localstorage
[-] File Deleted : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\lqiggqkd.default-1353230452431\searchplugins\yahoo_ff.xml
[-] File Deleted : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\Extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC}.xpi
[-] File Deleted : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\Extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}.xpi
[-] File Deleted : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\bprotector_extensions.sqlite
[-] File Deleted : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\searchplugins\Askcom.xml
[-] File Deleted : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\searchplugins\Babylon.xml
[-] File Deleted : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\searchplugins\bingp.xml
[-] File Deleted : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\searchplugins\BrowserDefender.xml
[-] File Deleted : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\searchplugins\yahoo_ff.xml
[-] File Deleted : C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\user.js
[-] File Deleted : C:\Users\Linux\AppData\Roaming\Mozilla\Firefox\Profiles\x87uq7d1.default\Extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}.xpi
[-] File Deleted : C:\Users\Linux\AppData\Roaming\Mozilla\Firefox\Profiles\x87uq7d1.default\searchplugins\yahoo_ff.xml
[-] File Deleted : C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\66h8ul8p.default\bprotector_extensions.sqlite
[-] File Deleted : C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\66h8ul8p.default\searchplugins\yahoo_ff.xml

***** [ DLLs ] *****


***** [ Shortcuts ] *****

Uživatelský avatar
Impra
Level 2
Level 2
Příspěvky: 160
Registrován: prosinec 14
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu (podezření na keylogger)

Příspěvekod Impra » 11 úno 2016 22:12


Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu (podezření na keylogger)

Příspěvekod jerabina » 11 úno 2016 22:15

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni antivir
Stáhni
Zoek.exe

a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Uživatelský avatar
Impra
Level 2
Level 2
Příspěvky: 160
Registrován: prosinec 14
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu (podezření na keylogger)

Příspěvekod Impra » 11 úno 2016 22:20

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.2 (01.06.2016)
Operating System: Windows 7 Home Premium x64
Ran by FILIP (Administrator) on źt 11.02.2016 at 22:12:50,87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 211

Failed to delete: C:\Users\FILIP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\503SPHG1 (Folder)
Failed to delete: C:\Users\FILIP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BEIZ7HZZ (Folder)
Failed to delete: C:\Users\FILIP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M5VLN63F (Folder)
Failed to delete: C:\Users\FILIP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZWT1LUEJ (Folder)
Successfully deleted: C:\ProgramData\productdata (Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{021FF527-0253-4219-A960-A93C767A9F56} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{0297B259-5384-4BB1-8362-A3D0BC668704} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{02D5308E-E160-4E5C-A10F-B1687B2188D2} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{03BC7372-3A41-49E7-8397-B095013BB235} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{03C50363-401B-4EC7-981C-512267FD45F1} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{03E9BB8D-F7B4-42E4-BC83-DD0B8F0E63F9} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{040DF85D-0A2F-4CC7-9FA9-83F0238C73DB} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{04876D19-526E-4172-854C-5AAAFCEED512} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{0510A9D5-2F13-47B8-9D0F-F618F5968FA5} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{0564C2F7-CE43-4189-9F38-A26586265393} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{085AC7E8-81F9-405C-9DB1-A1367381285B} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{0949A4CE-9507-4F39-B1AA-CAAAF4821B0A} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{0B16C54F-340C-47AF-8EBE-CD4321E66CC6} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{0C2C917F-EA97-40E1-80B2-C79C747106C5} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{0D8397C9-DFA3-45A1-BFD7-FC760BD2E46B} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{0DCADAF1-EA34-41C3-9077-5B023CB44AF0} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{0F50F419-4074-437B-A326-F779DE13D3D4} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{116EBE04-2CD9-401B-BAC4-40796D321B32} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{12168026-D3AC-4417-A909-16F7754345BD} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{13E3DC24-2CD4-4E09-B782-40E6E9150138} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{150172AB-C8DA-4A58-BE55-F1CA962E12B5} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{1625554E-C41C-4CAF-9062-DA392C6532CF} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{164E0D5C-8F21-4B81-8608-160AD2F47A0A} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{16B3A4E8-D692-48C8-BBD5-F6C4AABBA8DC} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{199004B7-5B74-4CE4-BBD3-93843F2F1B33} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{19A0FBB0-3209-4995-B9CF-6DCBB4F7141E} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{1AD12D19-86E3-44F4-844D-9335D725FE41} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{1B0D6312-2C7C-489C-9E98-7A9626723DC5} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{1B85F122-AE5E-4C48-8D0F-879A5A0DBDE4} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{1BBED7DC-FA5D-4B77-84F4-6769E7E63E41} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{1C7BEFD9-8A69-42A8-80F5-36AD23C346CA} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{1C7DE8E1-81AA-4CB7-B700-BC18E6893D93} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{1CBA18AA-3A72-4142-A4AA-3F08ED121EF6} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{1E4AFCF9-B024-4829-AF1C-0930A729BC2B} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{1E89F34C-4FE1-4ABD-A694-139CE153B8DA} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{1F7891C7-FC70-4116-B12A-F69D1E6368CE} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{1FBD1BDC-9F2E-4B99-A126-6BE9657CAEFE} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{20956F11-0EB0-4F5F-BBF1-76C072BDF086} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{22C3E46A-2B05-486F-B48D-5149E5C34DE5} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{238E3A41-7D09-4E7B-8256-B67AA9F11FD0} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{23C964D9-565D-4E41-A1F1-66D314901EC0} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{247BADD6-AE58-439E-B0CD-BA69EF03FC68} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{2978E6CF-B3B2-41DA-A695-BC71928238FC} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{2A121311-6856-444C-A289-F6E47264ACBB} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{2B06B6FE-93CC-4BC1-9689-EA1DE664E132} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{2DD730DF-A117-4E46-BBE6-B03DF4703BA3} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{316D284D-A220-4107-AAA6-0DE4B02C42CB} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{318D1435-1C94-46CC-A879-3567398532B4} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{3329E08F-AAAC-4A62-B1E1-EA1D62F243F2} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{3563A1B3-3670-4BB7-A009-B5B79274419C} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{35AEC28B-AA7B-47A7-AF99-9BCF1B85947B} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{35D03A7F-B7D5-4344-9816-F0885FB0F4BB} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{35DA8014-6110-4C50-90AA-F57C6FDFEE09} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{367DB1F8-FB49-4406-A74F-D1161B05AEEA} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{3A785C11-EDD7-4A68-AEE2-D557CBBA764B} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{3B411FBF-8033-4412-A08E-11EBBD05FB1E} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{3B65322B-DE76-4734-B496-C66A3A89F87D} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{3BE397D6-B811-416C-B8E0-CFE237BC0DC9} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{3CB45056-FCB4-4282-A337-01CD7BF946FA} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{3CD5A295-0FE0-4D49-9A5A-530FAD654EAA} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{3CF1FF99-5000-4AA4-B370-2BFAA0C8C64B} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{3D6BF085-AA84-47C5-B2A1-1564075A7233} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{3DE6DE50-E12C-4DBE-82C2-0115058E8D73} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{4042E2A9-7DBD-4198-84EF-309A72087BCD} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{4050F097-D0D4-4832-97D1-D6EBE19576DA} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{40A548BD-7F52-4C2C-B104-7AF9DC1D448A} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{41DA37A8-3CBA-4180-B7B1-1E2A42926020} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{43C98EF1-E699-49DA-8B5C-D5AFE8E90144} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{475CAEAE-C882-4EDF-A010-A579C7C97186} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{4A72C220-C54A-40DA-BEF9-035187B2AC94} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{4F91B85D-38FF-4BDB-A501-3357AEE6827D} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{503406EE-12FB-46E3-8108-C5ED17403B35} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{517606AD-FA02-4E60-BF06-EFFA8B586C40} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{522C5D99-824B-414E-9415-E4BCF0628B44} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{538E7594-701D-4B6D-BB10-2366BFC23679} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{53B8F920-2098-4603-83B8-9A2F447AA909} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{547CF427-2BE3-45F7-80D0-523C71A039B3} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{55B56F5F-60F9-4959-8670-56E016B3106F} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{57075E57-E3CC-4151-B2FE-26CD1EA44CF8} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{59E2B587-9F7D-4D3B-847A-1C87681BEB5A} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{5A0D20DA-81F7-4440-AAD7-B0DE0C871C32} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{5BA2F567-D561-49B6-9EB9-5179B07FD481} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{5C96E706-03B1-42B5-8E50-C6861DEAF245} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{5D3C2ECE-4F27-43AF-9759-B99F1E074546} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{5D3CE84E-AE5F-4EB5-8540-8272C192C8F4} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{5DF1B8BD-464F-49BD-9EA0-E40930CE15C0} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{5E13A3E4-E593-49BE-8695-CB4539FA8C18} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{5FB36561-65BB-462D-A9FC-39D1D0F54A43} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{5FE724CF-2990-4882-9D1D-0543F862F8A1} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{6199FF33-490A-43D5-83E7-014DE41810ED} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{6373A401-D3CF-4199-AAB4-B3ED137C4DE1} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{65C0BC6C-93B6-4859-9E28-A02A07883D3A} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{673C340C-BE69-4485-AE68-5E668F6B3EB1} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{674C692E-0E46-40A1-A9C5-A70CEDDA5900} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{6C4962A4-FAFB-47EB-B79B-0E0F7F9BB540} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{6D187CCE-110C-4A28-9F20-DB3CB757FCAC} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{6E8BCB45-6D61-4F20-9F9E-46E58D9ED697} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{6EE23C1A-9079-4F0B-AE22-F2F5DDD6CCC7} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{6FECBCF9-4A13-4403-80F7-993DF7FF0F2F} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{7050DCBF-68A5-46DA-AFA8-FBFDA824E223} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{71873F4D-52FB-49D8-94D4-D6C1E04C9931} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{736A0006-0F68-44E9-9452-E99FFD47CE8D} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{73822DE9-0F58-47EA-83D3-53FE40DE92BD} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{7524FA2A-23B8-4BF0-87B1-6874F56361B3} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{754DCEE5-B2A1-406C-AECC-3F038B5527C5} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{7858624A-43B4-4A47-A54B-FC73ABA4B978} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{7927CEC6-064A-4B6B-8431-7AD2B34B5606} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{793A81E7-10AA-4714-AD35-E9FC46BC44B9} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{7AB20E57-B4AB-475E-AC68-82359E7D43A9} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{7C245F0C-DC69-46F1-BA85-397A3C754EF3} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{7D07D4CC-E639-4C84-8836-3B1E034B56BB} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{7E0714EA-15D7-4423-9702-5E14455A614C} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{7FDDCB75-7BFC-4826-B8C3-7F3AC5755C46} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{801F2815-CF3A-486D-8CE7-D2FE992D1921} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{81E6FED5-AA81-4CCB-B1A9-EB23C59D01BF} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{84964876-C55C-42FA-A460-8510A2EEAB86} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{862E3BBD-FEE3-4CE9-9987-2B8097D7A3AB} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{88882456-BAAC-45FC-85AC-7BA9A1ED3576} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{8C0842F5-9256-4242-A4B3-38DF0375BCE2} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{8D13BDE5-0507-46A7-9592-CEBCAC10343E} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{8E0A6828-AA54-4E78-B0C5-59671B563D0F} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{907AEAF9-9884-45D5-B090-66D6C31902AC} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{919141B8-6CA7-44BA-8829-ECE6E794F84F} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{91CBF435-3AF6-469E-B699-F7A1B7CE5F6A} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{952ED459-DCF9-45FC-A36A-BD5BC4835232} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{97364277-1B76-4DFE-8896-35F30E219928} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{97A2BA98-26AF-4E84-A763-66A77355139F} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{98FD9AEE-C217-438E-A8D7-02E6700292CD} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{99D72A71-63D7-45B2-85E4-3E2B625B3D37} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{9C0B62C5-8386-4EB0-86FA-97201042A9FE} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{9EC09B35-BCF6-4B9C-BC7C-61C99A7F7F88} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{A0542AD1-5919-4796-B9B0-3225310C36E8} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{A132C7CA-B371-4023-8570-B9E769754E03} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{A466CFAB-337B-42DE-B338-70203E5EE8C3} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{A5313427-75AD-49DE-B270-F6C9E571BB2B} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{A54D0969-5D6C-4808-A79B-ED4C230465B3} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{A832E170-DC15-467B-B764-366DADAA93BB} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{AB1FC1D5-D69C-467A-BE1A-C1CF89693E4E} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{ADC56E47-510A-46ED-8785-C2ECF3ED62DD} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{AEDFF61D-CD24-48A8-996E-9452C69DED03} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{AFB323DA-B26F-42A8-A7DE-1E0397A3748C} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{B0483027-6CB2-48CB-B633-A59CF5D58EFF} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{B06C18DA-28B7-444A-A82A-2104CDC4C129} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{B28CCB86-E1FD-4E14-8DDC-EA14F9FC6443} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{B2D9A1CE-E14C-48CD-A11B-DFA8879EB851} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{B3518B25-42E0-48F0-8554-E85801D90AC5} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{B4A471BC-F29D-4B14-9EE0-31D93E7CB72C} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{BA9257B4-5B86-44BE-8366-852EADBB9E18} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{BBC7E5F0-03A0-473F-9CBC-FFA96CBD68F5} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{BD1EA64F-504D-4C00-A3A9-E70016373CAB} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{BD88714D-E3B7-4FAD-86EB-42EE51BA9B01} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{BE7FDBE8-BACF-48DD-9CE4-65F2AE508CC6} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{BF4A81BE-1B77-42C2-A995-0E24233A12C1} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{C10FED15-0898-43A7-B580-00F90A4919D3} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{C3D160EF-C361-4F26-B953-52A0D742BC51} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{D00C068F-F88A-4FD6-86DE-0159B8F54E34} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{D2CAAA29-74CF-4CD0-A4B3-3CEDCA0363DB} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{D413E12B-0B6D-4112-B749-9CCBCA7ABE29} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{D5072C6F-6494-4EDB-B7B1-26D486096E73} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{D58E39A3-655B-4B83-A475-04409800F6A7} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{D61A7D8F-F639-4B94-AC98-23195A5E9A48} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{D9CC147B-5B1E-425A-870F-0B1F75B02967} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{DA5D7C25-9258-4BE9-A496-EA2C1B2FA086} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{DB3CD798-CD1E-477B-8992-F0D9B6DA359C} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{DBE1974C-F110-4D69-AF3D-B6C15828D612} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{DD0582BA-91E2-450F-A7D9-81EC8D30810B} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{DE9D9456-6136-4CD0-976D-E21A9806933E} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{DF97A1AA-70A3-4B45-BFFC-9A1BD87B40D4} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{DFC5E79F-4C31-4BA8-A2FD-23F6C8795719} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{E267850F-70F4-4908-B58D-2BA534578D72} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{E3678659-36C2-4E00-8C1A-38ABCB54CF49} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{E3E8A26A-5640-4508-8729-34A59DA2E77A} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{E4E9F870-90AE-4E69-B7BE-3DFDFE4B443F} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{E695FE45-6906-4E8E-ACC0-3DE53B529CA1} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{E6A0D091-73A6-4DFA-9F66-6A71447DDECD} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{E7DE4C78-6F49-4CED-AC94-6D271CDCF9E5} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{E8694B57-84A4-4573-A7CD-88F7DB1F1B13} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{E9480D1B-50CA-4D62-9096-0221CC3F1D75} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{EB375FC2-1003-48BB-99DF-88C492D77003} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{EB56C219-A460-422E-8CC9-8E26E4BEAD3D} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{EBFD4A8C-0028-4F75-A633-B968DAE59B87} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{EC1D15BB-C186-4C3E-9953-0420E41EABC5} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{ED294D9A-9CE5-48E0-9EA6-53BFC97D0E68} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{ED534B5B-1D38-4E41-9265-1EE1B5D37C71} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{F0960230-CE29-4659-9881-C202B7C5585A} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{F0BC6398-BE3C-461D-AC38-C391D54734A5} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{F167976E-834E-484E-B655-871DF9A4CEAE} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{F1BF35E5-CFB9-41B1-9C81-B571FF13B916} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{F34BC624-DFD0-4333-A405-91D01FA99930} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{F4FEDB2F-E680-477D-A6F1-B88A705CB710} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{F5386D5C-FF5C-44F6-A873-914F1CAFEB47} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{F60EBFDF-F99C-462B-A6D4-2C758C9802DB} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{F669FB9E-6839-4482-BDD6-0AAB19D63E06} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{F9F442B1-1389-4AEB-932D-9FA8636439BF} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{FB3F1FD0-287A-4C84-B4A3-60202707393D} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{FB5563AE-AFE7-432C-9240-CBE960330B93} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{FC61952D-64B3-4DC3-AFD5-2038226B6077} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{FCBB7EF3-3E5F-4F5E-BCD7-EBDC1A8509DC} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{FF758140-E5C5-4DF3-B225-AB96FA42ADE2} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\{FFB8CB19-4F2A-4EBB-8FD0-4546288A758D} (Empty Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\crashrpt (Folder)
Successfully deleted: C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.ak.facebook.com_0.localstorage (File)
Successfully deleted: C:\Users\FILIP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_toolbar.utorrent.com_0.localstorage (File)
Successfully deleted: C:\Users\FILIP\Appdata\LocalLow\imeshtoolbar2 (Folder)
Successfully deleted: C:\Users\FILIP\AppData\Roaming\Mozilla\Firefox\Profiles\yv23j9g4.default-1356541827888\searchplugins\inbox-search.xml (File)
Successfully deleted: C:\Users\FILIP\AppData\Roaming\productdata (Folder)



Registry: 22

Successfully deleted: HKLM\Software\Google\Chrome\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj (Registry Key)
Successfully deleted: HKLM\Software\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\InboxToolbar (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\ICQ Search (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2BD8164E-AC71-4BCF-A404-F467A407F390} (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Main\\CustomizeSearch (Registry Value)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Main\\SearchAssistant (Registry Value)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{03EB0E9C-7A91-4381-A220-9B52B641CDB1} (Registry Value)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} (Registry Value)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 11.02.2016 at 22:18:22,35
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 128 hostů