Scan Log Version of virus signature database: 12630 (20151126) Date: 26.11.2015 Time: 21:54:49 Scanned disks, folders and files: Operating memory;C:\Boot sector;D:\Boot sector;C:\;D:\ Operating memory C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\~FontCache-System.dat - error opening [4] Operating memory C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\~FontCache-FontFace.dat - error opening [4] Operating memory C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\~FontCache-S-1-5-21-2238440515-2062330631-3741975613-1001.dat - error opening [4] Boot sector of disk C: - error opening [4] Boot sector of disk D: - error opening [4] C:\hiberfil.sys - error opening [4] C:\pagefile.sys - error opening [4] C:\swapfile.sys - error opening [4] C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\bdrescue.exe RAR bdrescue\data\bdrescue.gz GZIP bdrescue CPIO - archive damaged C:\Program Files\WinRAR\Default.SFX WINRARSFX - archive damaged C:\Program Files\WinRAR\Zip.SFX WINRARSFX - archive damaged C:\Program Files (x86)\gmsd_pl_005010158\gamesdesktop_widget.exe - a variant of Win32/AdWare.EoRezo.AU application - cleaned by deleting - quarantined [1] C:\Program Files (x86)\gmsd_pl_005010158\predm.exe INNO - a variant of Win32/Adware.EoRezo.BD application - cleaned by deleting - quarantined [1] C:\Program Files (x86)\ospd_us_013010158\onesoftperday_widget.exe - a variant of Win32/AdWare.EoRezo.AU application - cleaned by deleting - quarantined [1] C:\Program Files (x86)\ospd_us_013010158\predm.exe INNO - a variant of Win32/Adware.EoRezo.BD application - cleaned by deleting - quarantined [1] C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\447f329dc0907e12473ea29e88b71de4_05f3cc61-e25f-433b-b4f6-9ec94b7b9f6e - error opening [4] C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4def7c6ceb72b555e11a5682d187f103_05f3cc61-e25f-433b-b4f6-9ec94b7b9f6e - error opening [4] C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\65a626b1836abb8e3ecf6689d8e7d47c_05f3cc61-e25f-433b-b4f6-9ec94b7b9f6e - error opening [4] C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\670cf5cde21cd629395366511b7d1217_05f3cc61-e25f-433b-b4f6-9ec94b7b9f6e - error opening [4] C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7217c13c9d447395c792e16601c1441f_05f3cc61-e25f-433b-b4f6-9ec94b7b9f6e - error opening [4] C:\ProgramData\Microsoft\User Account Pictures\defaultuser0.dat - error opening [4] C:\ProgramData\Microsoft\Windows\RetailDemo\OfflineContent\Packages\Microsoft.BasicAttractLoop_8wekyb3d8bbwe\Microsoft.BasicAttractLoop_8wekyb3d8bbwe.appx ZIP - archive damaged C:\ProgramData\Microsoft\Windows\RetailDemo\OfflineContent\Packages\Microsoft.BasicAttractLoop_8wekyb3d8bbwe\Microsoft.NET.Native.Runtime.1.1.BasicAttractLoop.appx ZIP - archive damaged C:\ProgramData\Microsoft\Windows\RetailDemo\OfflineContent\Packages\Microsoft.BasicAttractLoop_8wekyb3d8bbwe\Microsoft.VCLibs.x64.14.00.BasicAttractLoop.appx ZIP - archive damaged C:\ProgramData\Microsoft\Windows\RetailDemo\OfflineContent\Packages\Microsoft.MicrosoftRetailDemoProvisioning_8wekyb3d8bbwe\Microsoft.MicrosoftRetailDemoProvisioning_8wekyb3d8bbwe.appx ZIP - archive damaged C:\ProgramData\Microsoft\Windows\RetailDemo\OfflineContent\Packages\Microsoft.MicrosoftRetailDemoProvisioning_8wekyb3d8bbwe\Microsoft.NET.Native.Runtime.1.1.DemoProvisioning.appx ZIP - archive damaged C:\ProgramData\Microsoft\Windows\RetailDemo\OfflineContent\Packages\Microsoft.MicrosoftRetailDemoProvisioning_8wekyb3d8bbwe\Microsoft.VCLibs.x64.14.00.DemoProvisioning.appx ZIP - archive damaged C:\SWTOOLS\DRIVERS\PhotoMaster\pm3330\LenovoPhotoMaster_2.1.3330_Patch.exe RAR Setup.exe NSIS ilesDir - archive damaged - the file could not be extracted. C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\447f329dc0907e12473ea29e88b71de4_05f3cc61-e25f-433b-b4f6-9ec94b7b9f6e - error opening [4] C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\4def7c6ceb72b555e11a5682d187f103_05f3cc61-e25f-433b-b4f6-9ec94b7b9f6e - error opening [4] C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\65a626b1836abb8e3ecf6689d8e7d47c_05f3cc61-e25f-433b-b4f6-9ec94b7b9f6e - error opening [4] C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\670cf5cde21cd629395366511b7d1217_05f3cc61-e25f-433b-b4f6-9ec94b7b9f6e - error opening [4] C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\7217c13c9d447395c792e16601c1441f_05f3cc61-e25f-433b-b4f6-9ec94b7b9f6e - error opening [4] C:\Users\All Users\Microsoft\User Account Pictures\defaultuser0.dat - error opening [4] C:\Users\Mateusz H\NTUSER.DAT - error opening [4] C:\Users\Mateusz H\ntuser.dat.LOG1 - error opening [4] C:\Users\Mateusz H\ntuser.dat.LOG2 - error opening [4] C:\Users\Mateusz H\AppData\Local\255A1767-1448572303-E411-A26A-F0761C597D36\onsj4F1D.tmp - a variant of Win32/Adware.ConvertAd.PD application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\255A1767-1448572303-E411-A26A-F0761C597D36\rnsj4F1C.exe - a variant of Win32/Adware.ConvertAd.ACZ application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Comms\UnistoreDB\store.vol - error opening [4] C:\Users\Mateusz H\AppData\Local\Comms\UnistoreDB\tmp.edb - error opening [4] C:\Users\Mateusz H\AppData\Local\Comms\UnistoreDB\USS.log - error opening [4] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\465.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\602.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\564.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_secureprotect_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\607.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\596.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\609.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\493.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\623.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\443.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_BubbleSound_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_bobrowser_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\610.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_speedup_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\600.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\381.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_bubblefoot_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\382.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\657.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\581.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_boxore_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_wajam_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_polacarita_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\666.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\577.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\631.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\660.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_SByoutube_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_pwebbar_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_oursurfing_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_pcrossbrowser_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_iminent_p_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\455.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\491.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_pzombie_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_istartsurfp_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\420.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\557.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\473.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_superpc_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_AnySend_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\537.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\569.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_airwebbar_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\11.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\380.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\436.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_bubbledock_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\583.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_csdi_oursurfing_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\611.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\613.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\644.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\591.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\648.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\643.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\653.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\688.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\697.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\GetHomepage.exe - a variant of MSIL/Adware.EoRezo.A application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\gmsd_pl_005010158\Download\majmp_gentleeu.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Image Touch\{F1D83F68-363D-80BA-CA4B-E1FC08728F98}\c.dat - error opening [4] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\UsrClass.dat - error opening [4] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - error opening [4] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - error opening [4] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\WebCacheLock.dat - error opening [4] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\aaLSB[1] NSIS ӝ NSIS - a variant of Win32/Adware.ConvertAd.ABO application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\SmartWebInstaller[1].exe NSIS SmartWebInstallerHelperDll.dll - a variant of Win32/PriceGong.C potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\SmartWebInstaller[1].exe NSIS SmartWebApp.exe - a variant of Win32/PriceGong.C potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\SmartWebInstaller[1].exe NSIS swhk.dll - a variant of Win32/PriceGong.C potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\SmartWebInstaller[1].exe NSIS SmartWebHelper.exe - Win32/PriceGong.C potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\SmartWebInstaller[1].exe NSIS NSIS SmartWebInstallerHelperDll.dll - a variant of Win32/PriceGong.C potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\Update_Notifier[1].exe - a variant of Win32/Adware.ConvertAd.PD application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\VuuPC_VO2_8907[1].exe NSIS Script.nsi - Win32/InstallMonetizer.BJ potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\AS1VNPDD\9YAgvis[1] - a variant of Win32/Adware.ConvertAd.ACA.gen application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\AS1VNPDD\BiTool[1].dll - a variant of Win32/Somoto.K potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\AS1VNPDD\runasu[1].exe - a variant of Win32/Adware.ConvertAd.ACZ application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\AS1VNPDD\SU_Srv[1].exe - a variant of Win32/Adware.ConvertAd.ACK application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\AS1VNPDD\VOPackage[1].exe NSIS χ - a variant of Win32/Adware.ConvertAd.ACN application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\fXvvEo[1].exe - a variant of Win32/Adware.ConvertAd.ACO application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\Hr8BBXq[1].exe - Win32/TrojanClicker.Agent.NXU trojan - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\install[1].exe - a variant of MSIL/Amonetize.AC.gen potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\setup_ospd_us[1].exe INNO {tmp}\ospd_us_013010158.7z 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\setup_ospd_us[1].exe INNO {tmp}\upospd_us_013010158.7z 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\setup_ospd_us[1].exe INNO {tmp}\predm.7z 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\setup_ospd_us[1].exe INNO {tmp}\onesoftperday_widget.7z 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\setup_ospd_us[1].exe INNO - a variant of Win32/Adware.EoRezo.BD application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\swse-setup-1.10.0.25[1].exe NSIS SwiftSearchAutoUpdateClient.exe - a variant of MSIL/Adware.Vitruvian.A application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\swse-setup-1.10.0.25[1].exe NSIS .sys - is OK C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\swse-setup-1.10.0.25[1].exe NSIS .sys - is OK C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\swse-setup-1.10.0.25[1].exe NSIS .sys - is OK C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\swse-setup-1.10.0.25[1].exe NSIS .sys - is OK C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\swse-setup-1.10.0.25[1].exe NSIS swsesrvc.exe - a variant of Win32/Adware.Vitruvian.F application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\Cdn[1].exe NSIS cpm.exe - is OK C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\Cdn[1].exe NSIS cpm.exe - is OK C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\Cdn[1].exe NSIS gpuminer-setup.exe NSIS sgminer.7z 7ZIP sgminer/start.cmd - is OK C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\Cdn[1].exe NSIS gpuminer-setup.exe NSIS sgminer.7z 7ZIP sgminer/sgm.exe - is OK C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\JOSrv[1].exe - a variant of Win32/Adware.ConvertAd.ABM application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\setup[1].exe NSIS Script.nsi - Win32/Somoto.G potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\setup[1].exe NSIS [RANDOM_STRING].7z 7ZIP - archive damaged C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\setup_gmsd_pl[1].exe INNO {tmp}\gmsd_pl_005010158.7z 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\setup_gmsd_pl[1].exe INNO {tmp}\upgmsd_pl_005010158.7z 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\setup_gmsd_pl[1].exe INNO {tmp}\predm.7z 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\setup_gmsd_pl[1].exe INNO {tmp}\gamesdesktop_widget.7z 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\setup_gmsd_pl[1].exe INNO - a variant of Win32/Adware.EoRezo.BD application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\Notifications\WPNPRMRY.tmp - error opening [4] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\UPPS\UPPS.bin - error opening [4] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\WebCache\V01.log - error opening [4] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat - error opening [4] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\465.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\602.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\564.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_secureprotect_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\607.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\596.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\609.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\493.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\623.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\443.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_BubbleSound_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_bobrowser_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\610.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_speedup_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\600.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\381.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_bubblefoot_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\382.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\657.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\581.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_boxore_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_wajam_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_polacarita_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\666.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\577.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\631.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\660.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_SByoutube_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_pwebbar_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_oursurfing_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_pcrossbrowser_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_iminent_p_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\455.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\491.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_pzombie_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_istartsurfp_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\420.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\557.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\473.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_superpc_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_AnySend_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\537.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\569.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_airwebbar_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\11.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\380.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\436.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_bubbledock_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\583.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\package_csdi_oursurfing_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\611.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\613.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\644.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\591.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\648.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\643.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\653.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\688.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\697.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO {tmp}\GetHomepage.exe - a variant of MSIL/Adware.EoRezo.A application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO {tmp}\gentlemjmp_ieu.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\ospd_us_013010158\Download\majmp_gentleeu.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Messaging_8wekyb3d8bbwe\LocalState\DataRv\offline-storage-ecs.data - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Messaging_8wekyb3d8bbwe\LocalState\DataRv\offline-storage.data - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Messaging_8wekyb3d8bbwe\LocalState\live#3amathaladyj\bistats.lock - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Messaging_8wekyb3d8bbwe\LocalState\live#3amathaladyj\eascache.lock - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Messaging_8wekyb3d8bbwe\LocalState\live#3amathaladyj\main.lock - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Messaging_8wekyb3d8bbwe\LocalState\live#3amathaladyj\statistics.lock - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Messaging_8wekyb3d8bbwe\Settings\settings.dat - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Messaging_8wekyb3d8bbwe\Settings\settings.dat.LOG1 - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Messaging_8wekyb3d8bbwe\Settings\settings.dat.LOG2 - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat.LOG1 - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat.LOG2 - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG1 - error opening [4] C:\Users\Mateusz H\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG2 - error opening [4] C:\Users\Mateusz H\AppData\Local\SmartWeb\__u.exe NSIS SmartWebInstallerHelperDll.dll - a variant of Win32/PriceGong.C potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\SmartWeb\swhk.dll - a variant of Win32/PriceGong.C potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Temp\bitool.dll - a variant of Win32/Somoto.K potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Temp\JtiJp.tmp ZIP xrc.exe - a variant of MSIL/Smeazymo.A trojan - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Temp\nsh715C.tmp - a variant of Win32/Adware.ConvertAd.ACA.gen application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\nsi73E6.tmp - Win32/TrojanClicker.Agent.NXU trojan - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\nsq9BBF.exe - a variant of MSIL/Amonetize.AB potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Temp\nsrA20E.tmp NSIS Script.nsi - Win32/InstallMonetizer.BJ potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Temp\nsrA417.tmp NSIS ӝ NSIS - a variant of Win32/Adware.ConvertAd.ABO application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\nsw1CF7.exe NSIS Script.nsi - is OK C:\Users\Mateusz H\AppData\Local\Temp\nsw1CF7.exe NSIS OCSetupHlp.dll - is OK C:\Users\Mateusz H\AppData\Local\Temp\nsx32C8.tmp NSIS Script.nsi - Win32/Somoto.G potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Temp\nsyDB95.tmp INNO {tmp}\gmsd_pl_005010158.7z 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Temp\nsyDB95.tmp INNO {tmp}\upgmsd_pl_005010158.7z 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Temp\nsyDB95.tmp INNO {tmp}\predm.7z 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Temp\nsyDB95.tmp INNO {tmp}\gamesdesktop_widget.7z 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Temp\nsyDB95.tmp INNO - a variant of Win32/Adware.EoRezo.BD application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\SetupVLCPlayer.exe NSIS beeieiijdf.exe - a variant of Win32/OutBrowse.CL potentially unwanted application - action selection postponed until scan completion C:\Users\Mateusz H\AppData\Local\Temp\HYD4812.tmp.1448565294\HTA\install.1448565294.zip ZIP 3rdparty/OCSetupHlp.dll - is OK C:\Users\Mateusz H\AppData\Local\Temp\is-0SK5E.tmp\465.exe NSIS SwiftSearchAutoUpdateClient.exe - a variant of MSIL/Adware.Vitruvian.A application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-0SK5E.tmp\465.exe NSIS .sys - is OK C:\Users\Mateusz H\AppData\Local\Temp\is-0SK5E.tmp\465.exe NSIS .sys - is OK C:\Users\Mateusz H\AppData\Local\Temp\is-0SK5E.tmp\465.exe NSIS .sys - is OK C:\Users\Mateusz H\AppData\Local\Temp\is-0SK5E.tmp\465.exe NSIS .sys - is OK C:\Users\Mateusz H\AppData\Local\Temp\is-0SK5E.tmp\465.exe NSIS swsesrvc.exe - a variant of Win32/Adware.Vitruvian.F application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-0SK5E.tmp\465_.exe 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\465.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\602.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\564.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_secureprotect_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\607.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\596.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\609.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\493.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\623.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\443.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_BubbleSound_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_bobrowser_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\610.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_speedup_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\600.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\381.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_bubblefoot_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\382.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\657.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\581.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_boxore_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_wajam_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_polacarita_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\666.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\577.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\631.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\660.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_SByoutube_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_pwebbar_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_oursurfing_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_pcrossbrowser_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_iminent_p_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\455.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\491.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_pzombie_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_istartsurfp_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\420.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\557.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\473.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_superpc_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_AnySend_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\537.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\569.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_airwebbar_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\11.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\380.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\436.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_bubbledock_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\583.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_csdi_oursurfing_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\611.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\613.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\644.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\591.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\648.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\643.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\653.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\688.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\697.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO {tmp}\GetHomepage.exe - a variant of MSIL/Adware.EoRezo.A application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-1M377.tmp\gentlemjmp_ieu.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-49GTE.tmp\465.exe INNO {tmp}\465_.exe 7ZIP - Incorrect file checksum (CRC); the file is probably password protected. C:\Users\Mateusz H\AppData\Local\Temp\is-49GTE.tmp\465.exe INNO - a variant of Win32/Adware.AdInstaller.E application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\465.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\602.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\564.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_secureprotect_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\607.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\596.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\609.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\493.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\623.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\443.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_BubbleSound_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_bobrowser_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\610.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_speedup_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\600.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\381.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_bubblefoot_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\382.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\657.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\581.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_boxore_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_wajam_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_polacarita_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\666.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\577.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\631.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\660.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_SByoutube_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_pwebbar_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_oursurfing_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_pcrossbrowser_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_iminent_p_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\455.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\491.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_pzombie_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_istartsurfp_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\420.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\557.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\473.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_superpc_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_AnySend_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\537.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\569.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_airwebbar_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\11.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\380.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\436.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_bubbledock_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\583.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\package_csdi_oursurfing_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\611.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\613.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\644.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\591.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\648.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\643.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\653.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\688.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\697.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO {tmp}\GetHomepage.exe - a variant of MSIL/Adware.EoRezo.A application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-6QHV6.tmp\gentlemjmp_ieu.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-FV32J.tmp\465.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-FV32J.tmp\473.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-FV32J.tmp\package_oursurfing_installer_multilang.exe INNO - a variant of Win32/Adware.EoRezo.AY application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-H6S1K.tmp\473.exe NSIS SwiftSearchAutoUpdateClient.exe - a variant of MSIL/Adware.Vitruvian.A application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\is-H6S1K.tmp\473.exe NSIS .sys - is OK C:\Users\Mateusz H\AppData\Local\Temp\is-H6S1K.tmp\473.exe NSIS .sys - is OK C:\Users\Mateusz H\AppData\Local\Temp\is-H6S1K.tmp\473.exe NSIS .sys - is OK C:\Users\Mateusz H\AppData\Local\Temp\is-H6S1K.tmp\473.exe NSIS .sys - is OK C:\Users\Mateusz H\AppData\Local\Temp\is-H6S1K.tmp\473.exe NSIS swsesrvc.exe - a variant of Win32/Adware.Vitruvian.F application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\TileDataLayer\Database\EDB.log - error opening [4] C:\Users\Mateusz H\AppData\Local\TileDataLayer\Database\vedatamodel.edb - error opening [4] C:\Users\Mateusz H\OneDrive\.849C9593-D756-4E56-8D6E-42412F2A707B - error opening [4] C:\Windows\Logs\DPX\setupact.log - error opening [4] C:\Windows\Logs\DPX\setuperr.log - error opening [4] C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config - error opening [4] C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe.config - error opening [4] C:\Windows\Panther\UnattendGC\diagerr.xml - error opening [4] C:\Windows\Panther\UnattendGC\diagwrn.xml - error opening [4] C:\Windows\Panther\UnattendGC\setupact.log - error opening [4] C:\Windows\Panther\UnattendGC\setuperr.log - error opening [4] C:\Windows\PLA\System\System Diagnostics.xml - error opening [4] C:\Windows\PLA\System\System Performance.xml - error opening [4] C:\Windows\security\database\secedit.sdb - error opening [4] C:\Windows\System32\catroot2\edb.log - error opening [4] C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - error opening [4] C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - error opening [4] C:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat - error opening [4] C:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat.LOG1 - error opening [4] C:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat.LOG2 - error opening [4] C:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat{3009c410-9396-11e5-b9f5-b01041f3ea56}.TM.blf - error opening [4] C:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat{3009c410-9396-11e5-b9f5-b01041f3ea56}.TMContainer00000000000000000001.regtrans-ms - error opening [4] C:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat{3009c410-9396-11e5-b9f5-b01041f3ea56}.TMContainer00000000000000000002.regtrans-ms - error opening [4] C:\Windows\System32\Sysprep\Panther\IE\diagerr.xml - error opening [4] C:\Windows\System32\Sysprep\Panther\IE\diagwrn.xml - error opening [4] C:\Windows\System32\Sysprep\Panther\IE\setupact.log - error opening [4] C:\Windows\System32\Sysprep\Panther\IE\setuperr.log - error opening [4] C:\Windows\System32\winevt\Logs\Application.evtx - error opening [4] C:\Windows\System32\winevt\Logs\HardwareEvents.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Internet Explorer.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Key Management Service.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-All-User-Install-Agent%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Troubleshooter.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Inventory.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Steps-Recorder.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Audio%4CaptureMonitor.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Audio%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Audio%4PlaybackManager.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-CertificateServicesClient-Lifecycle-System%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-CertificateServicesClient-Lifecycle-User%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-PCW%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-Scheduled%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-Scripted%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-Scripted%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Fault-Tolerant-Heap%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-FileHistory-Core%4WHC.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-HomeGroup Control Panel%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-IKE%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-LiveId%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-NCSI%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkLocationWizard%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Ntfs%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Ntfs%4WHC.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-PowerShell%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-PowerShell%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-PrintService%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-PushNotification-Platform%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-PushNotification-Platform%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Regsvr32%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Security-SPP-UX-Notifications%4ActionCenter.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-SettingSync%4Debug.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-SettingSync%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Shell-ConnectedAccountState%4ActionCenter.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-SMBClient%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-SmbClient%4Security.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-SMBServer%4Audit.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-SMBServer%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-SMBServer%4Security.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-StateRepository%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-StateRepository%4Restricted.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-ClassPnP%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-Storport%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-StorageSpaces-ManagementAgent%4WHC.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Store%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-TWinUI%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-VPN%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-WFP%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsBackup%4ActionCenter.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-Winlogon%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-Windows-WorkFolders%4WHC.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Microsoft-WindowsPhone-Connectivity-WiFiConnSvc-Channel.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Security.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Setup.evtx - error opening [4] C:\Windows\System32\winevt\Logs\System.evtx - error opening [4] C:\Windows\System32\winevt\Logs\Windows PowerShell.evtx - error opening [4] C:\Windows\WinSxS\amd64_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_10.0.10586.0_none_5db42904e056ea84\dnary.xsd - error opening [4] C:\Windows\WinSxS\amd64_microsoft-windows-r..demo-offlinecontent_31bf3856ad364e35_10.0.10586.0_none_868976b3e0d0e7cc\Microsoft.NET.Native.Runtime.1.1.BasicAttractLoop.appx ZIP - archive damaged C:\Windows\WinSxS\amd64_microsoft-windows-r..demo-offlinecontent_31bf3856ad364e35_10.0.10586.0_none_868976b3e0d0e7cc\Microsoft.NET.Native.Runtime.1.1.DemoProvisioning.appx ZIP - archive damaged C:\Windows\WinSxS\amd64_microsoft-windows-r..demo-offlinecontent_31bf3856ad364e35_10.0.10586.0_none_868976b3e0d0e7cc\Microsoft.VCLibs.x64.14.00.BasicAttractLoop.appx ZIP - archive damaged C:\Windows\WinSxS\amd64_microsoft-windows-r..demo-offlinecontent_31bf3856ad364e35_10.0.10586.0_none_868976b3e0d0e7cc\Microsoft.VCLibs.x64.14.00.DemoProvisioning.appx ZIP - archive damaged C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\SmartWebInstaller[1].exe NSIS SmartWebInstallerHelperDll.dll - a variant of Win32/PriceGong.C potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\SmartWebInstaller[1].exe NSIS SmartWebApp.exe - a variant of Win32/PriceGong.C potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\SmartWebInstaller[1].exe NSIS swhk.dll - a variant of Win32/PriceGong.C potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\SmartWebInstaller[1].exe NSIS SmartWebHelper.exe - Win32/PriceGong.C potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\SmartWebInstaller[1].exe NSIS NSIS SmartWebInstallerHelperDll.dll - a variant of Win32/PriceGong.C potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\7336700B\VuuPC_VO2_8907[1].exe NSIS Script.nsi - Win32/InstallMonetizer.BJ potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\AS1VNPDD\BiTool[1].dll - a variant of Win32/Somoto.K potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\E2FJCWL3\install[1].exe - a variant of MSIL/Amonetize.AC.gen potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Microsoft\Windows\INetCache\IE\P9S2WCX9\setup[1].exe NSIS Script.nsi - Win32/Somoto.G potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\SmartWeb\__u.exe NSIS SmartWebInstallerHelperDll.dll - a variant of Win32/PriceGong.C potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\SmartWeb\swhk.dll - a variant of Win32/PriceGong.C potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\bitool.dll - a variant of Win32/Somoto.K potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\JtiJp.tmp ZIP xrc.exe - a variant of MSIL/Smeazymo.A trojan - deleted - quarantined C:\Users\Mateusz H\AppData\Local\Temp\nsq9BBF.exe - a variant of MSIL/Amonetize.AB potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\nsrA20E.tmp NSIS Script.nsi - Win32/InstallMonetizer.BJ potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\nsx32C8.tmp NSIS Script.nsi - Win32/Somoto.G potentially unwanted application - cleaned by deleting - quarantined [1] C:\Users\Mateusz H\AppData\Local\Temp\SetupVLCPlayer.exe NSIS beeieiijdf.exe - a variant of Win32/OutBrowse.CL potentially unwanted application - cleaned by deleting - quarantined [1] Number of scanned objects: 273020 Number of threats found: 304 Number of cleaned objects: 304 Time of completion: 22:31:02 Total scanning time: 2173 sec (00:36:13) Notes: [1] Object has been deleted as it only contained the virus body. [4] Object cannot be opened. It may be in use by another application or operating system.