Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Potrzebny plik fixlist.txt

Robert__zak 27 Lip 2015 20:51 1023 6
  • CControls
  • #2 27 Lip 2015 21:18
    Kolobos
    Spec od komputerów

    Odinstaluj:
    agederar (HKLM-x32\...\{9f58a80e-3c37-4557-0e9d-4857a20ed324}) (Version: 1.0.0 - ryofward) <==== ATTENTION!
    AnyProtect (HKLM-x32\...\AnyProtect) (Version: 1.0.0.4 - CMI Limited) <==== ATTENTION
    AnySend (HKLM-x32\...\ASPackage) (Version: - CMI Limited) <==== ATTENTION!
    CinemaP-1.9cV27.07 (HKLM-x32\...\CinemaP-1.9cV27.07) (Version: 1.36.01.22 - Cinema PlusV27.07) <==== ATTENTION
    CinemaPlus-3.2cV27.07 (HKLM-x32\...\CinemaPlus-3.2cV27.07) (Version: 1.36.01.22 - Cinema PlusV27.07) <==== ATTENTION
    Crossbrowse (HKLM-x32\...\Crossbrowse) (Version: 39.6.2171.95 - The Crossbrowse Authors) <==== ATTENTION!
    GamesDesktop 008.005010043 (HKLM-x32\...\gmsd_pl_005010043_is1) (Version: - GAMESDESKTOP) <==== ATTENTION
    McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
    MyBestOffersToday 008.014010043 (HKLM-x32\...\mbot_pl_014010043_is1) (Version: - MYBESTOFFERSTODAY) <==== ATTENTION
    mystartsearch uninstall (HKLM-x32\...\mystartsearch uninstall) (Version: - mystartsearch) <==== ATTENTION
    oursurfing uninstall (HKLM-x32\...\oursurfing uninstall) (Version: - oursurfing) <==== ATTENTION
    RegClean-Pro (HKLM-x32\...\RegClean-Pro_is1) (Version: 6.21 - systweak.com) <==== ATTENTION
    Search App by Ask (HKLM-x32\...\{4F524A2D-5350-4500-76A7-A758B70C1D00}) (Version: 12.29.0.197 - APN, LLC) <==== ATTENTION
    SmartWeb (HKLM-x32\...\SmartWeb) (Version: 8.0.9 - SoftBrain Technologies Ltd.) <==== ATTENTION
    Software Version Updater (HKLM-x32\...\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}) (Version: 1.1.4.2 - ) <==== ATTENTION
    WordSurfer

    Uzyj AdwCleaner, opcja Scan i Clean/Szukaj i Usun: https://toolslib.net/downloads/viewdownload/1-adwcleaner/

    Obok frst.exe utworz plik fixlist.txt z zawartoscia:
    CustomCLSID: HKU\S-1-5-21-104773140-1717761600-546702795-1000_Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InprocServer32 -> C:\Users\Filip\AppData\Roaming\agederar\fortetri.dll () <==== ATTENTION
    Task: {0770BBFF-F582-4C06-B52B-CEF000385EA3} - System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-5 => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-5.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {0D197968-AA01-4804-9C56-9B2BB1382B7C} - System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-7 => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-7.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {0D43DF93-15A1-4672-A5A6-9F2D9BD7F8B7} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-07-27] (globalUpdate) <==== ATTENTION
    Task: {123990CD-2617-4C43-996E-9A69BEA875FC} - System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-5 => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-5.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION




    Task: {160795EA-0127-4D87-9B64-2ABB1374F431} - System32\Tasks\Crossbrowse => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe [2015-07-27] () <==== ATTENTION
    Task: {24A873F6-E577-46B0-95B1-06E8B206E9D7} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RCP\RegCleanPro.exe [2015-07-02] () <==== ATTENTION
    Task: {261145C2-E308-4666-B3A2-583ED8489021} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RCP\RegCleanPro.exe [2015-07-02] () <==== ATTENTION
    Task: {2AA42CCD-0010-4533-ACE9-7EDA023F5EBE} - System32\Tasks\WordSurfer Auto Updater 1.10.0.19 Core => C:\Program Files (x86)\WordSurfer_1.10.0.19\Update\WordSurferAutoUpdateClient.exe [2015-06-16] (Word Surfer)
    Task: {2AC361D9-D973-46FD-8368-2CC683B09144} - System32\Tasks\kZQDX8QDE7prDgHMKejoHU => C:\Users\Filip\AppData\Roaming\kZQDX8QDE7prDgHMKejoHU.exe [2015-04-20] () <==== ATTENTION
    Task: {3644BA00-80AB-4B42-9412-D242A2CA3DEF} - System32\Tasks\{F89E1EE4-91F0-460B-9BC5-9D73EEE18930} => pcalua.exe -a C:\Users\Filip\Desktop\Setup.exe -d C:\Users\Filip\Desktop
    Task: {3AF5AF86-B259-4D8B-B4BA-1909D3BBE248} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\Filip\AppData\Local\SmartWeb\SmartWebHelper.exe [2015-02-17] (SoftBrain Technologies Ltd.) <==== ATTENTION
    Task: {3F7F5FDC-0829-4C27-99E0-E5AA96F0F782} - System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-3 => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-3.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {5063AF9A-4580-4FDC-B02D-E0DA7E3DE02D} - System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-6 => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-6.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {51158B5F-71AC-46F6-BE70-0A930A8EF337} - System32\Tasks\az3uxeLrncSj15Vwi99YRRv5d => C:\Users\Filip\AppData\Roaming\az3uxeLrncSj15Vwi99YRRv5d.exe [2015-04-20] () <==== ATTENTION
    Task: {5F3CB37F-29CE-49B3-93F1-F50A94625972} - System32\Tasks\{62285F84-5F3F-493F-AB6E-E215A6CF533F} => pcalua.exe -a "F:\UWAGA !!! GRATIS !!! #DJManiac#\Zestaw Gier #DJManiac#\Super Mario Clone FX.exe" -d "F:\UWAGA !!! GRATIS !!! #DJManiac#\Zestaw Gier #DJManiac#"
    Task: {5F53D521-472C-4851-A706-980326030865} - System32\Tasks\F3WCYac => C:\Users\Filip\AppData\Roaming\F3WCYac.exe [2015-04-20] () <==== ATTENTION
    Task: {5FEFE06D-E4CE-47AA-8E6F-8CE82F124B1C} - System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-6 => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-6.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {67E59AFA-433F-4417-8F1C-0B58C06C7900} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2015-07-27] (AnyProtect.com) <==== ATTENTION
    Task: {738BF57E-D2ED-4EE1-B907-912AE81D49F8} - System32\Tasks\2tNIwZbrMeND47GqCK3TE => C:\Users\Filip\AppData\Roaming\2tNIwZbrMeND47GqCK3TE.exe [2015-04-20] () <==== ATTENTION
    Task: {741E9970-F13B-433F-B7FA-973F49861BD9} - System32\Tasks\{11F4893B-3594-4FB6-BDA2-C1B5B5316211} => Iexplore.exe http://ui.skype.com/ui/0/5.9.0.123.259/pl/aba...rce=lightinstaller&amp;page=tsProgressBar
    Task: {74DC5829-1BAD-4763-BD69-0A4334CADBE1} - System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-4 => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-4.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {80787304-B346-43FE-B387-B95E75A485AC} - System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-5_user => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-5.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {8C7CC8ED-07BC-4F73-B907-4E038EABC41C} - System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-3 => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-3.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {8FF621F0-5845-4A7E-BA9D-22987ADC38DD} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-07-27] (globalUpdate) <==== ATTENTION
    Task: {9BB9B803-3D5A-4508-BA21-B5AE2B41A5F9} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2015-07-27] (AnyProtect.com) <==== ATTENTION
    Task: {9C65421C-E0D4-44A7-9C09-F1219B4AB5AA} - System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-1-7 => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-1-7.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {9C706A70-C3A8-4ABD-B45D-19FD35AFD065} - System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-7 => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-7.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {A83D8CD1-CB75-4581-A7B0-191DA473CDE2} - System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-1-6 => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-1-6.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {A91C5AC6-757F-44FA-9D3F-EDF323F0B185} - System32\Tasks\{2691FAD4-9994-420E-B841-F1DA4D9A458A} => pcalua.exe -a "C:\Program Files\AVAST Software\Avast\aswRunDll.exe" -c "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
    Task: {AB6D146D-5D02-4D8B-8CA4-39EA5BA94CEE} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2015-07-27] (AnyProtect.com) <==== ATTENTION
    Task: {B3FAA2CE-F407-46D3-A5CA-BBF9A29826CC} - System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-6 => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-6.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {D4D07CD0-6A4C-476D-99B1-AF3CD4EB6537} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RCP\RegCleanPro.exe [2015-07-02] () <==== ATTENTION
    Task: {D9D3289C-D178-41CF-ACDB-9C66A3ABC0F9} - System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-10_user => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-10.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {E39A9522-234A-4D1C-912B-6C1E0BF17FDB} - System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-5_user => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-5.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {E5F5B67D-070F-4450-A4A7-5EEDF2643A2D} - System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-7 => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-7.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {E6D76BE8-5578-4A27-B749-859A6DFABA19} - System32\Tasks\AmiUpdXp => C:\Users\Filip\AppData\Local\8018\Updater.exe [2015-07-27] () <==== ATTENTION
    Task: {E9DB6E29-5DE6-4552-BDA9-39B9F0E7DDAD} - System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-4 => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-4.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {F4085291-32D1-4211-A809-19E8D4A2CF7F} - System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-10_user => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-10.exe [2015-07-27] (Cinema PlusV27.07) <==== ATTENTION
    Task: {F9BE78F8-CAAD-4349-A60E-A8FB11C352CB} - System32\Tasks\WordSurfer Auto Updater 1.10.0.19 Pending Update => C:\Program Files (x86)\WordSurfer_1.10.0.19\Update\WordSurferAutoUpdateClient.exe [2015-06-16] (Word Surfer)
    Task: {FADE57AD-BE6D-482F-B281-D3A0E290B9DE} - System32\Tasks\{451BA7F8-1AB4-4F84-8DCC-E8846E83B6A2} => C:\Program Files (x86)\THQ\Disney-Pixar\Auta - Przygody w Chlodnicy Gorskiej\Cars.exe [2006-06-25] ()
    Task: C:\Windows\Tasks\2tNIwZbrMeND47GqCK3TE.job => C:\Users\Filip\AppData\Roaming\2tNIwZbrMeND47GqCK3TE.exe <==== ATTENTION
    Task: C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-1-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-1-6.exe <==== ATTENTION
    Task: C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-1-7.job => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-1-7.exe <==== ATTENTION
    Task: C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-10_user.job => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-10.exe <==== ATTENTION
    Task: C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-3.job => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-3.exe <==== ATTENTION
    Task: C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-4.job => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-4.exe <==== ATTENTION
    Task: C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-5.job => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-5.exe <==== ATTENTION
    Task: C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-5_user.job => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-5.exe <==== ATTENTION
    Task: C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-6.exe <==== ATTENTION
    Task: C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-7.job => C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-7.exe <==== ATTENTION
    Task: C:\Windows\Tasks\AmiUpdXp.job => C:\Users\Filip\AppData\Local\8018\Updater.exe <==== ATTENTION
    Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
    Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
    Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
    Task: C:\Windows\Tasks\az3uxeLrncSj15Vwi99YRRv5d.job => C:\Users\Filip\AppData\Roaming\az3uxeLrncSj15Vwi99YRRv5d.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Crossbrowse.job => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
    Task: C:\Windows\Tasks\F3WCYac.job => C:\Users\Filip\AppData\Roaming\F3WCYac.exe <==== ATTENTION
    Task: C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-6.job => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-6.exe <==== ATTENTION
    Task: C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-7.job => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-7.exe <==== ATTENTION
    Task: C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-10_user.job => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-10.exe <==== ATTENTION
    Task: C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-3.job => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-3.exe <==== ATTENTION
    Task: C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-4.job => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-4.exe <==== ATTENTION
    Task: C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-5.job => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-5.exe <==== ATTENTION
    Task: C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-5_user.job => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-5.exe <==== ATTENTION
    Task: C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-6.job => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-6.exe <==== ATTENTION
    Task: C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-7.job => C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-7.exe <==== ATTENTION
    Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
    Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
    Task: C:\Windows\Tasks\kZQDX8QDE7prDgHMKejoHU.job => C:\Users\Filip\AppData\Roaming\kZQDX8QDE7prDgHMKejoHU.exe <==== ATTENTION
    Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
    Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
    (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
    () C:\Program Files (x86)\10319C20-1438015455-11DC-9CEE-5404A6D90BF7\hnsc8C98.tmp
    (XTab system) C:\Program Files (x86)\MiuiTab\ProtectService.exe
    () C:\Program Files (x86)\10319C20-1438015455-11DC-9CEE-5404A6D90BF7\knsm465D.tmpfs
    (SearchProtect) C:\Program Files (x86)\MiuiTab\CmdShell.exe
    (XTab system) C:\Program Files (x86)\MiuiTab\HPNotify.exe
    (Cinema PlusV27.07) C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-10.exe
    (Cinema PlusV27.07) C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-6.exe
    (Cinema PlusV27.07) C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-1-6.exe
    (Cinema PlusV27.07) C:\Program Files (x86)\CinemaP-1.9cV27.07\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-6.exe
    (Cinema PlusV27.07) C:\Program Files (x86)\CinemaPlus-3.2cV27.07\5fd930fc-d85c-478b-94de-7508b2c986c0-6.exe
    (Word Surfer) C:\Program Files (x86)\WordSurfer_1.10.0.19\Service\wsasvc.exe
    () C:\Users\Filip\AppData\Local\mbot_pl_014010043\upmbot_pl_014010043.exe
    (Crossbrowse) C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe
    (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
    (SoftBrain Technologies Ltd.) C:\Users\Filip\AppData\Local\SmartWeb\SmartWebHelper.exe
    (SoftBrain Technologies Ltd.) C:\Users\Filip\AppData\Local\SmartWeb\SmartWebApp.exe
    (Crossbrowse) C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe
    (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
    () C:\Program Files (x86)\mbot_pl_014010043\mbot_pl_014010043.exe
    () C:\Program Files (x86)\gmsd_pl_005010043\gmsd_pl_005010043.exe
    HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1684360 2015-05-26] (APN)
    HKLM-x32\...\Run: [mbot_pl_014010043] => C:\Program Files (x86)\mbot_pl_014010043\mbot_pl_014010043.exe [3979408 2015-07-27] ()
    HKLM-x32\...\Run: [SmartWeb] => C:\Users\Filip\AppData\Local\SmartWeb\SmartWebHelper.exe [270368 2015-02-17] (SoftBrain Technologies Ltd.)
    HKLM-x32\...\Run: [gmsd_pl_005010043] => C:\Program Files (x86)\gmsd_pl_005010043\gmsd_pl_005010043.exe [3976848 2015-07-27] ()
    HKLM-x32\...\RunOnce: [upmbot_pl_014010043.exe] => C:\Users\Filip\AppData\Local\mbot_pl_014010043\upmbot_pl_014010043.exe [3323536 2015-07-27] ()
    HKU\S-1-5-21-104773140-1717761600-546702795-1000\...\Run: [GoogleChromeAutoLaunch_6495E1029E6D15BFF636ECFC5D36A15E] => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe [637440 2015-05-12] (Crossbrowse)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2012-10-08]
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
    Startup: C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk [2015-07-27]
    ShortcutTarget: crossbrowse.lnk -> C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (Crossbrowse)
    Startup: C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk [2015-07-27]
    ShortcutTarget: SmartWeb.lnk -> C:\Users\Filip\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oursurfing.com/?type=hppp&ts=1...id=WDCXWD5000AAKS-00V6A0_WD-WCAWFE19400094000
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.oursurfing.com/?type=hppp&ts=1...id=WDCXWD5000AAKS-00V6A0_WD-WCAWFE19400094000
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&...WD5000AAKS-00V6A0_WD-WCAWFE19400094000&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/?type=hppp&ts=1...id=WDCXWD5000AAKS-00V6A0_WD-WCAWFE19400094000
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/?type=hppp&ts=1...id=WDCXWD5000AAKS-00V6A0_WD-WCAWFE19400094000
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&...WD5000AAKS-00V6A0_WD-WCAWFE19400094000&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKU\S-1-5-21-104773140-1717761600-546702795-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oursurfing.com/web/?type=ds&ts...WD5000AAKS-00V6A0_WD-WCAWFE19400094000&q={searchTerms}
    HKU\S-1-5-21-104773140-1717761600-546702795-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oursurfing.com/web/?type=ds&ts...WD5000AAKS-00V6A0_WD-WCAWFE19400094000&q={searchTerms}
    HKU\S-1-5-21-104773140-1717761600-546702795-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oursurfing.com/?type=hppp&ts=1...id=WDCXWD5000AAKS-00V6A0_WD-WCAWFE19400094000
    HKU\S-1-5-21-104773140-1717761600-546702795-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/?type=hppp&ts=1...id=WDCXWD5000AAKS-00V6A0_WD-WCAWFE19400094000
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&...WD5000AAKS-00V6A0_WD-WCAWFE19400094000&q={searchTerms}
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&...WD5000AAKS-00V6A0_WD-WCAWFE19400094000&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&...WD5000AAKS-00V6A0_WD-WCAWFE19400094000&q={searchTerms}
    SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&...WD5000AAKS-00V6A0_WD-WCAWFE19400094000&q={searchTerms}
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-104773140-1717761600-546702795-1000 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.mystartsearch.com/web/?utm_source=...000&ts=1438016184&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-104773140-1717761600-546702795-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.mystartsearch.com/web/?utm_source=...000&ts=1438016184&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-104773140-1717761600-546702795-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.mystartsearch.com/web/?utm_source=...000&ts=1438016184&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-104773140-1717761600-546702795-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.oursurfing.com/web/?type=dspp&...WD5000AAKS-00V6A0_WD-WCAWFE19400094000&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-104773140-1717761600-546702795-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.mystartsearch.com/web/?utm_source=...000&ts=1438016184&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-104773140-1717761600-546702795-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.mystartsearch.com/web/?utm_source=...000&ts=1438016184&type=default&q={searchTerms}
    BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
    BHO-x32: GoodTab Class -> {1F91A9A1-01BA-4c81-863D-3BA0751E1419} -> C:\Program Files (x86)\MiuiTab\SupTab.dll [2015-07-23] (Thinkgood Co. Limited)
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.oursurfing.com/?type=sc&ts=143...id=WDCXWD5000AAKS-00V6A0_WD-WCAWFE19400094000
    FF NewTab: chrome://quick_start/content/index.html
    FF DefaultSearchEngine: oursurfing
    FF SelectedSearchEngine: oursurfing
    FF Homepage: hxxp://www.oursurfing.com/?type=hppp&ts=1...id=WDCXWD5000AAKS-00V6A0_WD-WCAWFE19400094000
    FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-07-27] (globalUpdate)
    FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-07-27] (globalUpdate)
    FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mystartsearch.xml [2015-07-27]
    FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\oursurfing.xml [2015-07-27]
    FF Extension: CinemaP-1.9cV27.07 - C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\gpn57a9p.default-1424492849014\Extensions\AVJYFVOD75109374@HCDE39471360.com [2015-07-27]
    FF Extension: CinemaPlus-3.2cV27.07 - C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\gpn57a9p.default-1424492849014\Extensions\d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.com [2015-07-27]
    FF Extension: deskCut - C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\gpn57a9p.default-1424492849014\Extensions\deskCutv2@gmail.com [2015-07-27]
    FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\gpn57a9p.default-1424492849014\extensions\deskCutv2@gmail.com
    StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.mystartsearch.com/?type=sc&ts=...id=WDCXWD5000AAKS-00V6A0_WD-WCAWFE19400094000
    CHR Extension: (Ask Search) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf [2015-04-30]
    CHR Extension: (CinemaP-1.9cV27.07) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-07-27]
    CHR Extension: (CinemaPlus-3.2cV27.07) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\papbadoldddalgcjcicnikcfenodpghp [2015-07-27]
    CHR HKLM\...\Chrome\Extension: [aaaaaiabcopkplhgaedhbloeejhhankf] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaaiabcopkplhgaedhbloeejhhankf.crx [Not Found]
    CHR HKLM-x32\...\Chrome\Extension: [aaaaaiabcopkplhgaedhbloeejhhankf] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaaiabcopkplhgaedhbloeejhhankf.crx [Not Found]
    StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.mystartsearch.com/?type=sc&ts=...id=WDCXWD5000AAKS-00V6A0_WD-WCAWFE19400094000
    R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [178568 2015-04-28] (APN LLC.)
    R2 comyninu; C:\Program Files (x86)\10319C20-1438015455-11DC-9CEE-5404A6D90BF7\hnsc8C98.tmp [161792 2015-07-27] () [File not signed]
    S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-07-27] (globalUpdate) [File not signed] <==== ATTENTION
    S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-07-27] (globalUpdate) [File not signed] <==== ATTENTION
    R2 IHProtect Service; C:\Program Files (x86)\MiuiTab\ProtectService.exe [125112 2015-07-23] (XTab system)
    R2 wsasvc_1.10.0.19; C:\Program Files (x86)\WordSurfer_1.10.0.19\Service\wsasvc.exe [299608 2015-06-16] (Word Surfer)
    R2 jomubyge; C:\Program Files (x86)\10319C20-1438015455-11DC-9CEE-5404A6D90BF7\knsm465D.tmpfs [X]
    R1 wsafd_1_10_0_19; C:\Windows\System32\drivers\wsafd_1_10_0_19.sys [61312 2015-06-16] (Word Surfer)
    2015-07-27 19:58 - 2015-07-27 19:58 - 00000000 ____D C:\Users\Filip\AppData\Local\mybestofferstoday
    2015-07-27 19:16 - 2015-07-27 19:16 - 00613255 _____ (CMI Limited) C:\Users\Filip\AppData\Local\nsyB7DD.tmp
    2015-07-27 19:04 - 2015-07-27 19:04 - 00000000 ____D C:\Users\Filip\AppData\Local\8018
    2015-07-27 18:59 - 2015-07-27 20:02 - 00000376 _____ C:\Windows\Tasks\APSnotifierPP3.job
    2015-07-27 18:59 - 2015-07-27 20:02 - 00000376 _____ C:\Windows\Tasks\APSnotifierPP2.job
    2015-07-27 18:59 - 2015-07-27 19:49 - 00000378 _____ C:\Windows\Tasks\APSnotifierPP1.job
    2015-07-27 18:59 - 2015-07-27 19:17 - 00002828 _____ C:\Windows\System32\Tasks\APSnotifierPP1
    2015-07-27 18:59 - 2015-07-27 19:17 - 00002826 _____ C:\Windows\System32\Tasks\APSnotifierPP3
    2015-07-27 18:59 - 2015-07-27 19:17 - 00002826 _____ C:\Windows\System32\Tasks\APSnotifierPP2
    2015-07-27 18:58 - 2015-07-27 20:02 - 00002446 _____ C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-5_user.job
    2015-07-27 18:58 - 2015-07-27 20:02 - 00001022 _____ C:\Windows\Tasks\az3uxeLrncSj15Vwi99YRRv5d.job
    2015-07-27 18:58 - 2015-07-27 20:02 - 00001016 _____ C:\Windows\Tasks\kZQDX8QDE7prDgHMKejoHU.job
    2015-07-27 18:58 - 2015-07-27 19:17 - 00001045 _____ C:\Users\Filip\Desktop\AnyProtect.lnk
    2015-07-27 18:58 - 2015-07-27 18:58 - 00004060 _____ C:\Windows\System32\Tasks\az3uxeLrncSj15Vwi99YRRv5d
    2015-07-27 18:58 - 2015-07-27 18:58 - 00004054 _____ C:\Windows\System32\Tasks\kZQDX8QDE7prDgHMKejoHU
    2015-07-27 18:58 - 2015-07-27 18:58 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
    2015-07-27 18:57 - 2015-07-27 20:02 - 00004494 _____ C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-4.job
    2015-07-27 18:57 - 2015-07-27 20:02 - 00003474 _____ C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-1-7.job
    2015-07-27 18:57 - 2015-07-27 20:02 - 00003138 _____ C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-1-6.job
    2015-07-27 18:57 - 2015-07-27 20:02 - 00002446 _____ C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-5.job
    2015-07-27 18:57 - 2015-07-27 18:58 - 00005476 _____ C:\Windows\System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-5
    2015-07-27 18:57 - 2015-07-27 18:57 - 00007524 _____ C:\Windows\System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-4
    2015-07-27 18:57 - 2015-07-27 18:57 - 00006504 _____ C:\Windows\System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-1-7
    2015-07-27 18:57 - 2015-07-27 18:57 - 00006166 _____ C:\Windows\System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-1-6
    2015-07-27 18:56 - 2015-07-27 20:09 - 00003090 _____ C:\Windows\System32\Tasks\RegClean Pro
    2015-07-27 18:56 - 2015-07-27 20:06 - 00002112 _____ C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-10_user.job
    2015-07-27 18:56 - 2015-07-27 20:02 - 00005862 _____ C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-6.job
    2015-07-27 18:56 - 2015-07-27 20:02 - 00005518 _____ C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-7.job
    2015-07-27 18:56 - 2015-07-27 20:02 - 00004494 _____ C:\Windows\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-3.job
    2015-07-27 18:56 - 2015-07-27 20:02 - 00000266 _____ C:\Windows\Tasks\RegClean Pro_UPDATES.job
    2015-07-27 18:56 - 2015-07-27 20:02 - 00000258 _____ C:\Windows\Tasks\RegClean Pro_DEFAULT.job
    2015-07-27 18:56 - 2015-07-27 18:59 - 00000000 ____D C:\Program Files (x86)\AnyProtectEx
    2015-07-27 18:56 - 2015-07-27 18:58 - 00000000 ____D C:\Program Files (x86)\CinemaPlus-3.2cV27.07
    2015-07-27 18:56 - 2015-07-27 18:57 - 00000000 ____D C:\Program Files (x86)\c3245dd2-5e29-4a85-a04d-d24e48769739
    2015-07-27 18:56 - 2015-07-27 18:56 - 00613255 _____ (CMI Limited) C:\Users\Filip\AppData\Local\nsb8DAB.tmp
    2015-07-27 18:56 - 2015-07-27 18:56 - 00008890 _____ C:\Windows\System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-6
    2015-07-27 18:56 - 2015-07-27 18:56 - 00008548 _____ C:\Windows\System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-7
    2015-07-27 18:56 - 2015-07-27 18:56 - 00007524 _____ C:\Windows\System32\Tasks\5fd930fc-d85c-478b-94de-7508b2c986c0-3
    2015-07-27 18:56 - 2015-07-27 18:56 - 00003020 _____ C:\Windows\System32\Tasks\RegClean Pro_UPDATES
    2015-07-27 18:56 - 2015-07-27 18:56 - 00002864 _____ C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
    2015-07-27 18:56 - 2015-07-27 18:56 - 00000981 _____ C:\Users\Public\Desktop\RegClean Pro.lnk
    2015-07-27 18:56 - 2015-07-27 18:56 - 00000000 __SHD C:\Users\Filip\AppData\Roaming\AnyProtectEx
    2015-07-27 18:56 - 2015-07-27 18:56 - 00000000 ____D C:\Users\Filip\AppData\Roaming\systweak
    2015-07-27 18:56 - 2015-07-27 18:56 - 00000000 ____D C:\ProgramData\WindowsMangerProtect
    2015-07-27 18:56 - 2015-07-27 18:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
    2015-07-27 18:56 - 2015-07-27 18:56 - 00000000 ____D C:\Program Files (x86)\RCP
    2015-07-27 18:56 - 2015-07-02 14:14 - 00020248 _____ () C:\Windows\system32\roboot64.exe
    2015-07-27 18:55 - 2015-07-27 19:16 - 00000000 ____D C:\Program Files (x86)\gmsd_pl_005010043
    2015-07-27 18:55 - 2015-07-27 18:55 - 00004046 _____ C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task
    2015-07-27 18:55 - 2015-07-27 18:55 - 00002269 _____ C:\Users\Public\Desktop\Facebook.lnk
    2015-07-27 18:55 - 2015-07-27 18:55 - 00000000 ____D C:\Users\Filip\AppData\Roaming\mystartsearch
    2015-07-27 18:55 - 2015-07-27 18:55 - 00000000 ____D C:\Users\Filip\AppData\Local\SmartWeb
    2015-07-27 18:55 - 2015-07-27 18:55 - 00000000 ____D C:\Users\Filip\AppData\Local\gmsd_pl_005010043
    2015-07-27 18:54 - 2015-07-27 18:54 - 00004180 _____ C:\Windows\System32\Tasks\WordSurfer Auto Updater 1.10.0.19 Pending Update
    2015-07-27 18:54 - 2015-07-27 18:54 - 00004170 _____ C:\Windows\System32\Tasks\WordSurfer Auto Updater 1.10.0.19 Core
    2015-07-27 18:54 - 2015-07-27 18:54 - 00000000 ____D C:\Program Files (x86)\WordSurfer_1.10.0.19
    2015-07-27 18:48 - 2015-07-27 20:02 - 00001056 _____ C:\Windows\Tasks\Crossbrowse.job
    2015-07-27 18:48 - 2015-07-27 18:55 - 00004094 _____ C:\Windows\System32\Tasks\Crossbrowse
    2015-07-27 18:48 - 2015-07-27 18:55 - 00002400 _____ C:\Users\Public\Desktop\Crossbrowse.lnk
    2015-07-27 18:48 - 2015-07-27 18:48 - 00000000 ____D C:\Users\Filip\AppData\Local\Crossbrowse
    2015-07-27 18:48 - 2015-07-27 18:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossbrowse
    2015-07-27 18:48 - 2015-07-27 18:48 - 00000000 ____D C:\Program Files (x86)\Crossbrowse
    2015-07-27 18:47 - 2015-07-27 20:02 - 00002440 _____ C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-5_user.job
    2015-07-27 18:47 - 2015-07-27 20:02 - 00002440 _____ C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-5.job
    2015-07-27 18:47 - 2015-07-27 20:02 - 00001014 _____ C:\Windows\Tasks\2tNIwZbrMeND47GqCK3TE.job
    2015-07-27 18:47 - 2015-07-27 20:02 - 00000986 _____ C:\Windows\Tasks\F3WCYac.job
    2015-07-27 18:47 - 2015-07-27 18:47 - 00005470 _____ C:\Windows\System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-5
    2015-07-27 18:47 - 2015-07-27 18:47 - 00004052 _____ C:\Windows\System32\Tasks\2tNIwZbrMeND47GqCK3TE
    2015-07-27 18:47 - 2015-07-27 18:47 - 00004024 _____ C:\Windows\System32\Tasks\F3WCYac
    2015-07-27 18:46 - 2015-07-27 20:02 - 00005856 _____ C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-6.job
    2015-07-27 18:46 - 2015-07-27 20:02 - 00005512 _____ C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-7.job
    2015-07-27 18:46 - 2015-07-27 20:02 - 00004488 _____ C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-4.job
    2015-07-27 18:46 - 2015-07-27 20:02 - 00004488 _____ C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-3.job
    2015-07-27 18:46 - 2015-07-27 20:02 - 00003468 _____ C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-7.job
    2015-07-27 18:46 - 2015-07-27 20:02 - 00003132 _____ C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-6.job
    2015-07-27 18:46 - 2015-07-27 20:02 - 00002106 _____ C:\Windows\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-10_user.job
    2015-07-27 18:46 - 2015-07-27 20:02 - 00000970 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
    2015-07-27 18:46 - 2015-07-27 20:02 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
    2015-07-27 18:46 - 2015-07-27 19:01 - 00000974 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
    2015-07-27 18:46 - 2015-07-27 18:57 - 00000000 ____D C:\Program Files (x86)\8c17b8e1-0127-4fd3-abc9-83f67b3b896c
    2015-07-27 18:46 - 2015-07-27 18:56 - 00003972 _____ C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
    2015-07-27 18:46 - 2015-07-27 18:56 - 00003718 _____ C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
    2015-07-27 18:46 - 2015-07-27 18:47 - 00000000 ____D C:\Program Files (x86)\CinemaP-1.9cV27.07
    2015-07-27 18:46 - 2015-07-27 18:46 - 00008884 _____ C:\Windows\System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-6
    2015-07-27 18:46 - 2015-07-27 18:46 - 00008542 _____ C:\Windows\System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-7
    2015-07-27 18:46 - 2015-07-27 18:46 - 00007518 _____ C:\Windows\System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-4
    2015-07-27 18:46 - 2015-07-27 18:46 - 00007518 _____ C:\Windows\System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-3
    2015-07-27 18:46 - 2015-07-27 18:46 - 00006498 _____ C:\Windows\System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-7
    2015-07-27 18:46 - 2015-07-27 18:46 - 00006160 _____ C:\Windows\System32\Tasks\ff2aad10-8de3-4fad-92cb-cf251ddbb443-1-6
    2015-07-27 18:46 - 2015-07-27 18:46 - 00000000 ____D C:\Users\Filip\AppData\Local\globalUpdate
    2015-07-27 18:46 - 2015-07-27 18:46 - 00000000 ____D C:\ProgramData\IHProtectUpDate
    2015-07-27 18:46 - 2015-07-27 18:46 - 00000000 ____D C:\Program Files (x86)\globalUpdate
    2015-07-27 18:45 - 2015-07-27 19:47 - 00000000 ____D C:\ProgramData\rWinManPror
    2015-07-27 18:45 - 2015-07-27 18:57 - 00000000 ____D C:\Program Files (x86)\MiuiTab
    2015-07-27 18:45 - 2015-07-27 18:45 - 00000000 ____D C:\Users\Filip\AppData\Roaming\oursurfing
    2015-07-27 18:45 - 2015-07-27 18:45 - 00000000 _____ C:\Windows\prleth.sys
    2015-07-27 18:45 - 2015-07-27 18:45 - 00000000 _____ C:\Windows\hgfs.sys
    2015-07-27 18:44 - 2015-07-27 20:32 - 00000000 ____D C:\Program Files (x86)\10319C20-1438015455-11DC-9CEE-5404A6D90BF7
    2015-07-27 18:44 - 2015-07-27 18:44 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASPackage
    2015-07-27 18:44 - 2015-07-27 18:44 - 00000000 ____D C:\Users\Filip\AppData\Roaming\ASPackage
    2015-07-27 18:44 - 2015-07-27 18:44 - 00000000 ____D C:\Users\Filip\AppData\Roaming\agederar
    2015-07-27 18:43 - 2015-07-27 20:05 - 00000000 ____D C:\Users\Filip\AppData\Local\mbot_pl_014010043
    2015-07-27 18:43 - 2015-07-27 18:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MYBESTOFFERSTODAY
    2015-07-27 18:43 - 2015-07-27 18:43 - 00000000 ____D C:\Program Files (x86)\mbot_pl_014010043
    2015-07-27 18:42 - 2015-07-27 18:42 - 01009140 _____ C:\Users\Filip\Downloads\Hack Tool Update 3 2 Downloader__3687_i1566779553_il134587.exe.zip
    2013-06-27 22:41 - 2014-06-23 21:21 - 0003730 _____ () C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
    2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Filip\AppData\Roaming\2tNIwZbrMeND47GqCK3TE
    2015-04-20 16:05 - 2015-04-20 16:05 - 1246720 _____ () C:\Users\Filip\AppData\Roaming\2tNIwZbrMeND47GqCK3TE.exe
    2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Filip\AppData\Roaming\az3uxeLrncSj15Vwi99YRRv5d
    2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Users\Filip\AppData\Roaming\az3uxeLrncSj15Vwi99YRRv5d.exe
    2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Filip\AppData\Roaming\F3WCYac
    2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Users\Filip\AppData\Roaming\F3WCYac.exe
    2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Filip\AppData\Roaming\kZQDX8QDE7prDgHMKejoHU
    2015-04-20 16:05 - 2015-04-20 16:05 - 1246720 _____ () C:\Users\Filip\AppData\Roaming\kZQDX8QDE7prDgHMKejoHU.exe
    2015-07-27 18:56 - 2015-07-27 18:56 - 0613255 _____ (CMI Limited) C:\Users\Filip\AppData\Local\nsb8DAB.tmp
    2015-07-27 19:16 - 2015-07-27 19:16 - 0613255 _____ (CMI Limited) C:\Users\Filip\AppData\Local\nsyB7DD.tmp
    EmptyTemp:

    W FRST wybierz Fix.

    Zrob pelny skan przy pomocy Mbam i usun to co wykryje:
    http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/

    Po wykonaniu daj nowe logi z FRST, ze skanowania.

    1
  • CControls
  • #3 27 Lip 2015 23:25
    Robert__zak
    Poziom 5  

    Nie napisałem, że problem dot. niechcianych reklam i zakładek. Prawdopodobnie wszystkie "śmieci" zostały zainstalowane dzisiaj z jakimiś darmowymi grami z internetu - tych też chciałbym się pozbyć.

    pozdrawiam,
    Robert

    Dodano po 2 [godziny] 6 [minuty]:

    Dziękuję za pomoc, w załączeniu nowy plik FRST.
    Proszę o sprawdzenie.

    0
  • #4 28 Lip 2015 08:40
    Acorus 20
    Spec od komputerów

    Otwórz notatnik systemowy i wklej:

    Cytat:
    SearchScopes: HKU\S-1-5-21-104773140-1717761600-546702795-1000 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
    SearchScopes: HKU\S-1-5-21-104773140-1717761600-546702795-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
    2015-07-27 22:25 - 2015-07-27 22:27 - 00000000 ____D C:\AdwCleaner
    2015-07-27 21:50 - 2015-07-27 21:50 - 00003164 _____ C:\Windows\System32\Tasks\{7FA3AE12-05EE-4B9E-A788-EA84049300C2}
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix. Reset Chrome: https://support.google.com/chrome/answer/3296214?hl=pl

    0
  • Pomocny post
    #6 08 Sty 2016 23:38
    krzychupar
    Poziom 41  

    Otwórz notatnik systemowy i wklej:
    Task: {68C3016C-6F37-4DED-9617-BE3054E7300D} - System32\Tasks\FilipDaggerNatalV2 => Rundll32.exe EthylSophistic.dll,main 7 1 <==== UWAGA
    Task: C:\Windows\Tasks\Price Fountain.job => C:\Users\Filip\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== UWAGA
    HKU\S-1-5-21-3698421322-1535131535-2162105096-1001\...\MountPoints2: {127816a1-8021-11e5-bda3-806e6f6e6963} - F:\win\CDSplash.exe
    AppInit_DLLs: C:\ProgramData\Lightzap\Zotlam.dll => C:\ProgramData\Lightzap\Zotlam.dll [805376 2016-01-03] ()
    AppInit_DLLs-x32: C:\ProgramData\Lightzap\Qvoandom.dll => C:\ProgramData\Lightzap\Qvoandom.dll [257536 2016-01-03] ()
    HKU\S-1-5-21-3698421322-1535131535-2162105096-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...uKQR5_AldqB-ndK0FqajC0p-pYd6BPT1MPfw,,&q={searchTerms}
    HKU\S-1-5-21-3698421322-1535131535-2162105096-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...uKQR5_AldqB-ndK0FqajC0p-pYd6BPT1MPfw,,&q={searchTerms}
    HKU\S-1-5-21-3698421322-1535131535-2162105096-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...uKQR5_AldqB-ndK0FqajC0p-pYd6BPT1MPfw,,&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
    SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...uKQR5_AldqB-ndK0FqajC0p-pYd6BPT1MPfw,,&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3698421322-1535131535-2162105096-1001 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...uKQR5_AldqB-ndK0FqajC0p-pYd6BPT1MPfw,,&q={searchTerms}
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-20] (Google Inc.)
    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-20] (Google Inc.)
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-20] (Google Inc.)
    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-20] (Google Inc.)
    Toolbar: HKU\S-1-5-21-3698421322-1535131535-2162105096-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-20] (Google Inc.)
    FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku]
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku]
    CHR HomePage: Default -> hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F...s0CmvmDE3AuJuRbsCP-3o2uhckojC_egoWiraguUY9Q,,,,
    CHR DefaultSearchURL: Default -> hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...8iZzJYkd9fAlFQlOgkksAKKBEmih_rHmMPVw,,&q={searchTerms}
    CHR DefaultSearchKeyword: Default -> feed.sonic-search.com_
    CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms}
    CHR Extension: (Papas Cupcakeria Game) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgafdfbeilmpdipkccdjddlbmnblkldf [2015-11-06]
    CHR Extension: (Avast Online Security) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-01-05]
    CHR Extension: (Happy Wheels) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\hpljdpjoahbnnfilkiilnfdkdbfiabfc [2015-11-06]
    CHR Extension: (Cut the Rope) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfbadlndcminbkfojhlimnkgaackjmdo [2015-11-06]
    2016-01-03 19:08 - 2016-01-04 21:05 - 00000000 ____D C:\ProgramData\Lightzap
    2016-01-03 19:08 - 2016-01-03 19:08 - 00000000 ____D C:\ProgramData\Lightzaps

    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.

    0