# AdwCleaner v4.206 - Utworzono raport 04/06/2015 o 22:19:13 # Ostatnia aktualizacja 01/06/2015 przez Xplode # Baza danych : 2015-06-01.1 [Serwer] # System operacyjny : Windows 7 Professional Service Pack 1 (x64) # Nazwa użytkownika : JARO - JARO-DELL # Uruchomiony z : C:\Users\JARO\Downloads\AdwCleaner.exe # Działanie : Skanuj ***** [ Usługi ] ***** Usługa znaleziono : globalUpdate Usługa znaleziono : globalUpdatem Usługa znaleziono : IHProtect Service Usługa znaleziono : Update Edu App Usługa znaleziono : Util Edu App Usługa znaleziono : {ab573ef7-acd0-4715-a5c0-420d2ee2cd93}Gw64 Usługa znaleziono : {eb01aed1-bba3-4e72-8323-a77bb027b1d4}Gw64 ***** [ Pliki / Foldery ] ***** Folder znaleziono : C:\Program Files (x86)\AnyProtectEx Folder znaleziono : C:\Program Files (x86)\Edu App Folder znaleziono : C:\Program Files (x86)\Edu App Folder znaleziono : C:\Program Files (x86)\globalUpdate Folder znaleziono : C:\Program Files (x86)\gmsd_pl_125 Folder znaleziono : C:\Program Files (x86)\GUPlayer Folder znaleziono : C:\Program Files (x86)\predm Folder znaleziono : C:\Program Files (x86)\RCP Folder znaleziono : C:\Program Files (x86)\XTab Folder znaleziono : C:\ProgramData\IHProtectUpDate Folder znaleziono : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP Folder znaleziono : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro Folder znaleziono : C:\ProgramData\WindowsMangerProtect Folder znaleziono : C:\Users\Administrator\AppData\Local\Crossbrowse Folder znaleziono : C:\Users\JARO\AppData\Local\globalUpdate Folder znaleziono : C:\Users\JARO\AppData\Local\gmsd_pl_125 Folder znaleziono : C:\Users\JARO\AppData\Local\SmartWeb Folder znaleziono : C:\Users\JARO\AppData\Local\Temp\Edu App Folder znaleziono : C:\Users\JARO\AppData\Local\Temp\Edu App Folder znaleziono : C:\Users\JARO\AppData\Local\Windesk_Winsearch Folder znaleziono : C:\Users\JARO\AppData\LocalLow\SmartWeb Folder znaleziono : C:\Users\JARO\AppData\Roaming\AnyProtectEx Folder znaleziono : C:\Users\JARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup Folder znaleziono : C:\Users\JARO\AppData\Roaming\mystartsearch Folder znaleziono : C:\Users\JARO\AppData\Roaming\Systweak Folder znaleziono : C:\Users\JARO\SupTab Plik znaleziono : C:\Users\JARO\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jhjjdgbhohaallcimgcmakfiobacimkm Plik znaleziono : C:\Users\JARO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage Plik znaleziono : C:\Users\JARO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage-journal Plik znaleziono : C:\Users\JARO\AppData\Local\Temp\Uninstall.exe Plik znaleziono : C:\Users\JARO\AppData\Roaming\kaqJ2NA0pWw5OqUmFeUoj0B Plik znaleziono : C:\Users\JARO\AppData\Roaming\kaqJ2NA0pWw5OqUmFeUoj0B.exe Plik znaleziono : C:\Users\JARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk Plik znaleziono : C:\Users\Public\Desktop\RegClean Pro.lnk Plik znaleziono : C:\Windows\System32\drivers\{ab573ef7-acd0-4715-a5c0-420d2ee2cd93}Gw64.sys Plik znaleziono : C:\Windows\System32\drivers\{eb01aed1-bba3-4e72-8323-a77bb027b1d4}Gw64.sys Plik znaleziono : C:\Windows\System32\roboot64.exe ***** [ Zaplanowane zadania ] ***** Zadanie znaleziono : APSnotifierPP1 Zadanie znaleziono : APSnotifierPP2 Zadanie znaleziono : APSnotifierPP3 Zadanie znaleziono : globalUpdateUpdateTaskMachineCore Zadanie znaleziono : globalUpdateUpdateTaskMachineUA Zadanie znaleziono : RegClean Pro Zadanie znaleziono : RegClean Pro_DEFAULT Zadanie znaleziono : RegClean Pro_UPDATES Zadanie znaleziono : SmartWeb Upgrade Trigger Task Zadanie znaleziono : kaqJ2NA0pWw5OqUmFeUoj0B Zadanie znaleziono : kaqJ2NA0pWw5OqUmFeUoj0B ***** [ Skróty ] ***** Skrót Zainfekowany : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk Skrót Zainfekowany : C:\Users\JARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Skrót Zainfekowany : C:\Users\JARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Skrót Zainfekowany : C:\Users\JARO\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ***** [ Rejestr ] ***** Dane znaleziono : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1433330049&z=df625f8667777d12d81894bg5z7cdcbc4cee9edz7q&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975 Klucz znaleziono : HKCU\Software\AnyProtect Klucz znaleziono : HKCU\Software\APN PIP Klucz znaleziono : HKCU\Software\AppDataLow\Software\Crossrider Klucz znaleziono : HKCU\Software\AppDataLow\Software\SmartWeb Klucz znaleziono : HKCU\Software\ArenaHD Klucz znaleziono : HKCU\Software\Crossbrowse Klucz znaleziono : HKCU\Software\Edu App Klucz znaleziono : HKCU\Software\GAMESDESKTOP Klucz znaleziono : HKCU\Software\GlobalUpdate Klucz znaleziono : HKCU\Software\HighDefAction Klucz znaleziono : HKCU\Software\HomeTab Klucz znaleziono : HKCU\Software\Linkey Klucz znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Klucz znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} Klucz znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Klucz znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C} Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBFBDD44-C0E0-4F63-A8E6-EE5F34765238} Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ebfbdd44-c0e0-4f63-a8e6-ee5f34765238} Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBFBDD44-C0E0-4F63-A8E6-EE5F34765238} Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ebfbdd44-c0e0-4f63-a8e6-ee5f34765238} Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Linkey Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance Klucz znaleziono : HKCU\Software\RST Klucz znaleziono : HKCU\Software\SearchProtectWS Klucz znaleziono : HKCU\Software\simplytech Klucz znaleziono : HKCU\Software\systweak Klucz znaleziono : HKCU\Software\TNT2 Klucz znaleziono : HKCU\Software\Tutorials Klucz znaleziono : HKCU\Software\TutoTag Klucz znaleziono : HKCU\Software\WajIntEnhance Klucz znaleziono : HKCU\Software\YorkNewCin Klucz znaleziono : [x64] HKCU\Software\AnyProtect Klucz znaleziono : [x64] HKCU\Software\APN PIP Klucz znaleziono : [x64] HKCU\Software\ArenaHD Klucz znaleziono : [x64] HKCU\Software\Crossbrowse Klucz znaleziono : [x64] HKCU\Software\Edu App Klucz znaleziono : [x64] HKCU\Software\GAMESDESKTOP Klucz znaleziono : [x64] HKCU\Software\GlobalUpdate Klucz znaleziono : [x64] HKCU\Software\HighDefAction Klucz znaleziono : [x64] HKCU\Software\HomeTab Klucz znaleziono : [x64] HKCU\Software\Linkey Klucz znaleziono : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Klucz znaleziono : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} Klucz znaleziono : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} Klucz znaleziono : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Klucz znaleziono : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C} Klucz znaleziono : [x64] HKCU\Software\RST Klucz znaleziono : [x64] HKCU\Software\SearchProtectWS Klucz znaleziono : [x64] HKCU\Software\simplytech Klucz znaleziono : [x64] HKCU\Software\systweak Klucz znaleziono : [x64] HKCU\Software\TNT2 Klucz znaleziono : [x64] HKCU\Software\Tutorials Klucz znaleziono : [x64] HKCU\Software\TutoTag Klucz znaleziono : [x64] HKCU\Software\WajIntEnhance Klucz znaleziono : [x64] HKCU\Software\YorkNewCin Klucz znaleziono : HKLM\SOFTWARE\AIM Toolbar Klucz znaleziono : HKLM\SOFTWARE\ArenaHD Klucz znaleziono : HKLM\SOFTWARE\AskPartnerNetwork Klucz znaleziono : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} Klucz znaleziono : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} Klucz znaleziono : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{EBFBDD44-C0E0-4F63-A8E6-EE5F34765238} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{ebfbdd44-c0e0-4f63-a8e6-ee5f34765238} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78} Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0 Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc Klucz znaleziono : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0 Klucz znaleziono : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Klucz znaleziono : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8} Klucz znaleziono : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Klucz znaleziono : HKLM\SOFTWARE\Classes\TypeLib\{1317e5f7-3acf-4d74-a9ae-4ce526026e3f} Klucz znaleziono : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66} Klucz znaleziono : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66} Klucz znaleziono : HKLM\SOFTWARE\Conduit Klucz znaleziono : HKLM\SOFTWARE\Crossbrowse Klucz znaleziono : HKLM\SOFTWARE\Edu App Klucz znaleziono : HKLM\SOFTWARE\GAMESDESKTOP Klucz znaleziono : HKLM\SOFTWARE\GlobalUpdate Klucz znaleziono : HKLM\SOFTWARE\HighDefAction Klucz znaleziono : HKLM\SOFTWARE\IHProtect Klucz znaleziono : HKLM\SOFTWARE\Iminent Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298} Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\globalupdate.exe Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EBFBDD44-C0E0-4F63-A8E6-EE5F34765238} Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ebfbdd44-c0e0-4f63-a8e6-ee5f34765238} Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298} Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AnyProtect Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_pl_125_is1 Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1 Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean-Pro_is1 Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartWeb Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance Klucz znaleziono : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10 Klucz znaleziono : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4 Klucz znaleziono : HKLM\SOFTWARE\mystartsearchSoftware Klucz znaleziono : HKLM\SOFTWARE\SearchProtect Klucz znaleziono : HKLM\SOFTWARE\SpeedBit Klucz znaleziono : HKLM\SOFTWARE\SupDp Klucz znaleziono : HKLM\SOFTWARE\SupTab Klucz znaleziono : HKLM\SOFTWARE\supWindowsMangerProtect Klucz znaleziono : HKLM\SOFTWARE\systweak Klucz znaleziono : HKLM\SOFTWARE\Tutorials Klucz znaleziono : HKLM\SOFTWARE\WajIntEnhance Klucz znaleziono : HKLM\SOFTWARE\YorkNewCin Klucz znaleziono : HKLM\SYSTEM\CurrentControlSet\Control\Class\{0014298C-A9BA-440D-AAA8-AD12C7010EE5} Klucz znaleziono : HKLM\SYSTEM\CurrentControlSet\Control\Class\{181A06EA-B82C-47DE-B851-E20FD0E1CC7D} Klucz znaleziono : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update Edu App Klucz znaleziono : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Util Edu App Klucz znaleziono : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect Klucz znaleziono : [x64] HKLM\SOFTWARE\ArenaHD Klucz znaleziono : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Klucz znaleziono : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Klucz znaleziono : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Klucz znaleziono : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Klucz znaleziono : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8} Klucz znaleziono : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Klucz znaleziono : [x64] HKLM\SOFTWARE\HighDefAction Klucz znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Klucz znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Edu App Klucz znaleziono : [x64] HKLM\SOFTWARE\YorkNewCin Wartość znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_pl_125] Wartość znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SmartWeb] ***** [ Przeglądarki internetowe ] ***** -\\ Internet Explorer v11.0.9600.17801 Ustawienia znaleziono : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.mystartsearch.com/web/?type=dspp&ts=1433330073&z=9ca7c0da71ee4c298e1c4bdg8zfcbc4cec6e2e4mae&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975&q={searchTerms} Ustawienia znaleziono : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.mystartsearch.com/?type=hppp&ts=1433330073&z=9ca7c0da71ee4c298e1c4bdg8zfcbc4cec6e2e4mae&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975 Ustawienia znaleziono : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.mystartsearch.com/?type=hppp&ts=1433330073&z=9ca7c0da71ee4c298e1c4bdg8zfcbc4cec6e2e4mae&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975 Ustawienia znaleziono : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.mystartsearch.com/web/?type=dspp&ts=1433330073&z=9ca7c0da71ee4c298e1c4bdg8zfcbc4cec6e2e4mae&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975&q={searchTerms} Ustawienia znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.mystartsearch.com/?type=hppp&ts=1433330073&z=9ca7c0da71ee4c298e1c4bdg8zfcbc4cec6e2e4mae&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975 Ustawienia znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.mystartsearch.com/?type=hppp&ts=1433330073&z=9ca7c0da71ee4c298e1c4bdg8zfcbc4cec6e2e4mae&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975 Ustawienia znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.mystartsearch.com/web/?type=ds&ts=1433416434&z=898731903967539f7680e51g3zccbc9zdg9q6z0c3e&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975&q={searchTerms} Ustawienia znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.mystartsearch.com/?type=hppp&ts=1433330073&z=9ca7c0da71ee4c298e1c4bdg8zfcbc4cec6e2e4mae&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975 Ustawienia znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.mystartsearch.com/?type=hppp&ts=1433330073&z=9ca7c0da71ee4c298e1c4bdg8zfcbc4cec6e2e4mae&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975 Ustawienia znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.mystartsearch.com/web/?type=ds&ts=1433416434&z=898731903967539f7680e51g3zccbc9zdg9q6z0c3e&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975&q={searchTerms} -\\ Google Chrome v43.0.2357.81 [C:\Users\JARO\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - znaleziono [Homepage] : hxxps://www.google.pl/","homepage_changed":true,"pinned_tabs":[],"protection":{"macs":{"browser":{"show_home_button":"0BDD2B0C4B2AF376EB5AE0A9A9D79AD3A0980A3E131BB22F852A133D0A8501CE"},"default_search_provider":{"keyword":"F7CAAB776193BFB4462823EFCF266DD5BD3D7FC162BA144CAFC9AC2FA59AB1E3","name":"E14B0CCBB8B07CC83398895CE306EB5A166CDC995FCFC215350B76843B59EF84","search_url":"9F5879D80725BE7A14CFDB5ACF0905925AD24940A2B43ED7A11612DCC3535AFC"},"default_search_provider_data":{"template_url_data":"947338C2A63A8AA7BC32D32385F7669FF8275D35C971007BFAD38CB60C27BA13"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":"F9CDA5FF3792761ACD22B53DF82CBF6096339FE80CB5C45732F125E59FA46DE3","apdfllckaahabafndbhieahigkjlhalf":"DC0C0AE8E65D2D168056A5AC8F2D65A9CF9C385B72B404659DC27E2D71AC780A","bepbmhgboaologfdajaanbcjmnhjmhfn":"FFEF36791E27CBB6A79DB5D071180B49A80C89B2F08CC864C51CDDB1640A608D","blpcfgokakmgnkcojhhkbfbldkacnbeo":"AD8E886228F5EFA374B77AD67ED64C973F1A1EB47036E11232195FDDA70F357F","coobgpohoikkiipiblmjeljniedjpjpf":"75A9E9F79144D41CDFAEC4899A3B1CEB515151CB5104EB5A72BD7396FD40B2D3","dpenanfkbgnimkndjpeohkjbhbfkfkhn":"449D8FFDD2CEFEBF927C2B8BDCF2E0A0CDDB425BA0B7C2245142AAA6E2DE299D","eemcgdkfndhakfknompkggombfjjjeno":"644940C38FD87798A1B5C32E95B07CB4DF579BDB7F371498628DD28E81C10936","ennkphjdgehloodpbhlhldgbnhmacadg":"04BE70301000DD58F89564F2670F90925CCE7DC3D5899AB6F58B39B0C90953E6","gfdkimpbcpahaombhbimeihdjnejgicl":"7FCA6FC44A9D170897976C8A5E2A10F04A8EE2D197285F6592D8171EF3F3FC99","gmlllbghnfkpflemihljekbapjopfjik":"FF67ED97EA4B8F0458EC2E703F505D834310EF6A7FD44A27DEBD158EFC569D4F","kmendfapggjehodndflmmgagdbamhnfd":"2C70B8F3A7DEAD02A4C391E8C6FBB6ADB7FA39E8B0D31D265338647D8B212D81","mfehgcgbbipciphmccgaenjidiccnmng":"BE35E2E9F6B80AFFED8253C869812DEB0ED4AFEA6288088B7DC869AD698F8C18","mgndgikekgjfcpckkfioiadnlibdjbkf":"E139BA6DEF57762CA1C347EE938FAF905496246BC773F3F8D354B69BF800E2FB","mhjfbmdgcfjbbpaeojofohoefgiehjai":"036F42FD08E7C293D3C220FCDC4BC72E6A46660D604437627A1CD745E7A98B8D","neajdppkdcdipfabeoofebfddakdcjhd":"3324FD009E850AFD21FB08C1B127AA475E2A42CF847FFEC2330145448F351805","nkeimhogjdpnpccoofpliimaahmaaome":"E05523B944D1CDB9F38E544CEF3AE2571A73861AD8088F877936D129B036C0D3","nmmhkkegccagdldgiimedpiccmgmieda":"A263E79F5B661E77C359E5082D18D136F876DF9CE035E94403E5B6442F997657","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"A716EC3E065F0274E45AC82B477213BCA9A326DE7B77D40F4AA1E03EE1EEC553","pjkljhegncpnkpknbcohdijeoejaedia":"7A5474E611ED97222ECC833ED70CD6268352FB41794D9428B1B184ADBA2353AF"}},"google":{"services":{"last_username":"18832137CA9E89A56D56F406FC8D87EA8119CD5CE1DA43C25DBE31689C7C08D8","username":"44C3303FDD3923FE9103703F277F4B79343A50EF1D6A22A0C5355C8ABC4B0D2F"}},"homepage":"05F5D644436888425B7296B736C9343BA35BB1E8ED4DB5A5D7F4F7279C4CD713","homepage_is_newtabpage":"BAF7695465FEDA69B33C10873AC7E781FEC00261EDE9A4C1DD62664E977F3ACE","pinned_tabs":"6C16720D4CEA0BBBA2C8D80542B0E890F7154266997F1538B0894DC6E64413A8","prefs":{"preference_reset_time":"50BA7BE3CA03A62828D5194311599996C8FE1600CCC1E01B12A65628CA163759"},"profile":{"reset_prompt_memento":"B9FC075A594CEA55AC1A86EACC052D547B77B0E0BEA4A2D11E6FC3D3A6AF86B9"},"safebrowsing":{"incidents_sent":"72FA45AC2ABE1C69A52C981EA21307E80387A6F3B2EAF2C4F52E44F569215EAC"},"search_provider_overrides":"6F481DE8F96DDF242DF1F89CABC6AF0881EC3E87F97CEE10C94AD6233658D455","session":{"restore_on_startup":"3B915EF287F8B0E55D8CA60BA43F2EE43C0873C239252AE047FAEAA199CEDD9D","startup_urls":"CDDEF7CFA8C95B9D7DB50D63AE13FA713804C27EB0BD15E773378E45DB52C56B"},"software_reporter":{"prompt_reason":"45EEEBC7DA6140381543DBE6771367B215A5C133D472805056F9643EE605D56D","prompt_seed":"EB82783B5686F9AFBC47FFA9C0B83DAC193622972AE731262DDB2AFA4AD22F33","prompt_version":"BEDCC0DC15EAFC743BD275638C43E5821A18B2B92C97E7C113A757622F44047C"},"sync":{"remaining_rollback_tries":"96BC6CF753670C7DE29F9BA096225CD822F94A40F0AA4D0CFD41AB1CEA4EABF1"}},"super_mac":"F04C2D38ABD5A773C1CB828936E6700D323F2445459A281BFD79C87E65225215"},"session":{"startup_urls":["hxxp://www.mystartsearch.com/?type=hppp&ts=1433330073&z=9ca7c0da71ee4c298e1c4bdg8zfcbc4cec6e2e4mae&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975 [C:\Users\JARO\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - znaleziono [Startup_URLs] : CDDEF7CFA8C95B9D7DB50D63AE13FA713804C27EB0BD15E773378E45DB52C56B"},"software_reporter":{"prompt_reason":"45EEEBC7DA6140381543DBE6771367B215A5C133D472805056F9643EE605D56D","prompt_seed":"EB82783B5686F9AFBC47FFA9C0B83DAC193622972AE731262DDB2AFA4AD22F33","prompt_version":"BEDCC0DC15EAFC743BD275638C43E5821A18B2B92C97E7C113A757622F44047C"},"sync":{"remaining_rollback_tries":"96BC6CF753670C7DE29F9BA096225CD822F94A40F0AA4D0CFD41AB1CEA4EABF1"}},"super_mac":"F04C2D38ABD5A773C1CB828936E6700D323F2445459A281BFD79C87E65225215"},"session":{"startup_urls":["hxxp://www.mystartsearch.com/?type=hppp&ts=1433330073&z=9ca7c0da71ee4c298e1c4bdg8zfcbc4cec6e2e4mae&from=cmi&uid=WDCXWD2500AAKX-753CA1_WD-WCAYV114997549975 -\\ Opera v0.0.0.0 ************************* AdwCleaner[R5].txt - [27134 bajty] - [04/06/2015 22:19:13] ########## EOF - C:\AdwCleaner\AdwCleaner[R5].txt - [27194 bajty] ##########