Provera

Provera

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2634
  • Gde živiš: Milan, Italy

Poz ljudi.

Neke sam (zabranjeno)-ove skidao za programe pa je nesto bilo sto ne valja. Pa eto ako moze provera da nisam sta zakacio jer je bilo nekih toolbarova i smarackih programa sto sam unistal. Pa jedna provera zbog toga a i inace ako ima sta da se ocisti jer nisam dugo radio proveru a OS je od 2012.

Hvala

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Springfieldz0r (administrator) on ANDROID-19C7E46 (09-04-2016 10:43:33)
Running from C:\Users\Springfieldz0r\Desktop
Loaded Profiles: Springfieldz0r (Available Profiles: Springfieldz0r)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
(MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe
() C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(MyCity) C:\Program Files (x86)\MCShield\MCShieldRTM.exe
(Flux Software LLC) C:\Users\Springfieldz0r\AppData\Local\FluxSoftware\Flux\flux.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Vimicro) C:\Windows\VM305_STI.EXE
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(mIRC Co. Ltd.) D:\program files\ACMilan-Script 4.5 white\ACMilan-Script 4.5 white\Mirc.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winamp.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-23] (AVAST Software)
HKLM-x32\...\Run: [BigDog305] => C:\Windows\VM305_STI.EXE USB PC Camera VC305
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [912920 2016-03-05] (BlueStack Systems, Inc.)
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\...\Run: [MCShield Monitor] => C:\Program Files (x86)\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\...\Run: [F.lux] => C:\Users\Springfieldz0r\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-24] (Flux Software LLC)
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [912920 2016-03-05] (BlueStack Systems, Inc.)
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\...\RunOnce: [Uninstall C:\Users\Springfieldz0r\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Springfieldz0r\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910"
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\...\MountPoints2: F - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\...\MountPoints2: {57ccab62-873a-11e2-94f3-6c626d84b408} - F:\autorun.exe
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\...\MountPoints2: {8404849c-4413-11e5-ba04-6c626d84b408} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\...\MountPoints2: {a6714d5b-f884-11e4-802b-6c626d84b408} - F:\Lenovo_Suite.exe
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\...\MountPoints2: {add5721a-ee48-11e4-aff1-6c626d84b408} - F:\Lenovo_Suite.exe
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\...\MountPoints2: {add5723b-ee48-11e4-aff1-6c626d84b408} - F:\Lenovo_Suite.exe
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\...\MountPoints2: {fc5b303d-ee8c-11e4-9fe9-6c626d84b408} - F:\Lenovo_Suite.exe
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-03-21] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Springfieldz0r\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Springfieldz0r\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Springfieldz0r\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Springfieldz0r\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Springfieldz0r\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Springfieldz0r\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Springfieldz0r\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Springfieldz0r\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{FAFABC99-746E-4865-8021-13F67C4B4BEF}: [DhcpNameServer] 192.168.1.254

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2145776392-1472050533-324974990-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2145776392-1472050533-324974990-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-11-18] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-10-21] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-03-21] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-02-09] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-21] (Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-11-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-21] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-03-21] (AVAST Software)
BHO-x32: No Name -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> No File
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL => No File
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-02-09] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-21] (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-03-12] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-02-01] (Skype Technologies)
Handler: WSISVCUchrome - No CLSID Value
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\\mscoree.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\\mscoree.dll [2010-11-21] (Microsoft Corporation)
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\\mscoree.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\\mscoree.dll [2010-11-21] (Microsoft Corporation)
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\\mscoree.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\\mscoree.dll [2010-11-21] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF NewTab: www.google.com
FF DefaultSearchEngine: hohosearch
FF DefaultSearchEngine.US:
FF SelectedSearchEngine: hohosearch
FF Homepage: hxxp://www.google.com/
FF Keyword.URL: hxxp://www.hohosearch.com/chrome.php?uid=31B422787E95B03884E174EB6F99026D&ptid=amz&ts=AHEqA34lBn0mAU..&v=20160405&mode=ffexttoolbar&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-21] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-21] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-21] (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-18] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2014-07-16] (Nitro PDF)
FF Plugin-x32: @nitropdf.com/NitroPDF.PrevVerNPR -> C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll [2013-03-26] (Nitro PDF)
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2014-07-07] ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-10] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-11-18] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2012-06-28] (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\searchplugins\bing-avast.xml [2014-07-21]
FF SearchPlugin: C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\searchplugins\bing-avast.xml [2014-07-21]
FF SearchPlugin: C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\searchplugins\DD1B66D4.xml [2016-04-08]
FF SearchPlugin: C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\bing-avast.xml [2014-07-21]
FF Extension: Firebug - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\Extensions\firebug@software.joehewitt.com.xpi [2016-03-31]
FF Extension: MEGA - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\Extensions\firefox@mega.co.nz.xpi [2016-04-05]
FF Extension: Valence - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\Extensions\fxdevtools-adapters@mozilla.org [2016-02-23]
FF Extension: Awesome screenshot: Capture and Annotate - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2015-10-16]
FF Extension: Qualys BrowserCheck - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\Extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D} [2015-12-10] [not signed]
FF Extension: Web Developer - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2015-05-29]
FF Extension: Adblock Plus - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]
FF Extension: Firebug - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\Extensions\firebug@software.joehewitt.com.xpi [2015-10-26]
FF Extension: Valence - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\Extensions\fxdevtools-adapters@mozilla.org [2015-12-10]
FF Extension: Awesome screenshot: Capture and Annotate - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2015-10-16]
FF Extension: Qualys BrowserCheck - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\Extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D} [2015-12-10] [not signed]
FF Extension: Web Developer - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2015-05-29]
FF Extension: Adblock Plus - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-25]
FF Extension: Firebug - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\firebug@software.joehewitt.com.xpi [2016-03-31]
FF Extension: MEGA - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\firefox@mega.co.nz.xpi [2016-04-05]
FF Extension: Valence - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\fxdevtools-adapters@mozilla.org [2016-04-08]
FF Extension: Awesome screenshot: Capture and Annotate - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2015-10-16]
FF Extension: Qualys BrowserCheck - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D} [2016-04-08] [not signed]
FF Extension: Web Developer - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2015-05-29]
FF Extension: Adblock Plus - C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-19] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-03-21]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-03-21]
StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Firefox Developer Edition\firefox.exe

Chrome:
=======
CHR HomePage: Default -> hxxp://www.hohosearch.com/?mode=nnnb&ptid=amz&uid=31B422787E95B03884E174EB6F99026D&v=20160405&ts=AHEqA34lBn0mAU..
CHR StartupUrls: Default -> "hxxp://www.hohosearch.com/?mode=nnnb&ptid=amz&uid=31B422787E95B03884E174EB6F99026D&v=20160405&ts=AHEqA34lBn0mAU.."
CHR DefaultSearchURL: Default -> hxxp://www.hohosearch.com/chrome.php?q={searchTerms}&ts=AHEqA34lBn0mAU..&v=20160405&uid=31B422787E95B03884E174EB6F99026D&ptid=amz&mode=nnnb
CHR DefaultSearchKeyword: Default -> hohosearch
CHR Profile: C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-04-06]
CHR Extension: (Плаћања у Chrome веб-продавници) - C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-06]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-03-21]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [351944 2015-11-03] (Advanced Micro Devices, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-03-21] (AVAST Software)
S4 AXIS Camera Management; C:\Program Files (x86)\Axis Communications\AXIS Camera Management 4\AcmService.exe [17920 2013-09-05] (Axis Communications) [File not signed]
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [437784 2016-03-05] (BlueStack Systems, Inc.)
S3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [417304 2016-03-05] (BlueStack Systems, Inc.)
S3 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [880152 2016-03-05] (BlueStack Systems, Inc.)
S2 ggbugreport; C:\Program Files (x86)\SearchesToYesbnd\bugreport.exe [1609744 2016-04-06] ()
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [1779664 2015-10-07] (Micro-Star INT'L CO., LTD.)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [163280 2015-05-18] (MSI)
S4 MTel_ontenegro Imola Modem Device Helper; C:\Program Files (x86)\HSPA USB MODEM\BackgroundService\ServiceManager.exe [53312 2012-03-14] ()
R2 NitroDriverReadSpool9; C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe [230920 2014-07-16] (Nitro PDF Software)
S4 NitroReaderDriverReadSpool3; C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [230416 2013-03-26] (Nitro PDF Software)
R2 NitroUpdateService; C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe [417800 2014-07-16] ()
S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [741640 2014-06-16] (DEVGURU Co., LTD.)
S4 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6887696 2015-11-30] (TeamViewer GmbH)
S4 UI Assistant Service; C:\Program Files (x86)\Join Air\AssistantServices.exe [252784 2010-07-14] ()
S4 UleadBurningHelper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-12-13] (Ulead Systems, Inc.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R3 WinHttpAutoProxySvc; C:\Windows\System32\\winhttp.dll [444416 2010-11-21] (Microsoft Corporation)
R3 WinHttpAutoProxySvc; C:\Windows\SysWOW64\\winhttp.dll [351232 2010-11-21] (Microsoft Corporation)
S2 Winsere; C:\Program Files (x86)\Winsere\Winsere\Winsere.exe [316400 2016-04-06] ()
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [X]
U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [62152 2014-10-28] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-03-21] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-22] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-03-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-03-21] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-03-21] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-03-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-03-21] (AVAST Software)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [154680 2016-03-05] (BlueStack Systems)
S2 BT848; C:\Windows\System32\drivers\BT848.sys [421248 2009-12-27] (Illusion & Hope. Porting to AMD64 by Sergey Sakharov.) [File not signed]
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-07-11] (DT Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [30112 2013-03-08] (REALiX(tm))
S3 jrdusbser; C:\Windows\System32\DRIVERS\jrdusbser.sys [120832 2011-06-20] (TCT International Mobile Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
S3 MODEMCSA; C:\Windows\System32\drivers\MODEMCSA.sys [24064 2009-07-14] (Microsoft Corporation)
S3 NTIOLib_1_0_2; C:\Program Files (x86)\MSI\BIOS Code Unlocked Technology\NTIOLib_X64.sys [14136 2010-04-21] (MSI)
S3 pfc; C:\Windows\SysWOW64\drivers\pfc.sys [10368 2013-02-17] (Padus, Inc.) [File not signed]
S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [926824 2014-04-08] (Realtek Semiconductor Corporation )
S3 s116bus; C:\Windows\System32\DRIVERS\s116bus.sys [108296 2007-04-03] (MCCI Corporation)
S3 s116mgmt; C:\Windows\System32\DRIVERS\s116mgmt.sys [126216 2007-04-03] (MCCI Corporation)
S3 s116nd5; C:\Windows\System32\DRIVERS\s116nd5.sys [31496 2007-04-03] (MCCI Corporation)
S3 s116unic; C:\Windows\System32\DRIVERS\s116unic.sys [130824 2007-04-03] (MCCI Corporation)
S3 smserial; C:\Windows\System32\DRIVERS\smserial.sys [1202688 2009-10-26] (Motorola Inc.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2013-07-17] () [File not signed]
S3 TS_AR5416; C:\Windows\System32\DRIVERS\ts_athwx.sys [2157672 2013-07-23] (TamoSoft)
S3 TS_ARN5416; C:\Windows\System32\DRIVERS\ts_athrx.sys [3543752 2013-08-16] (TamoSoft)
S3 ULCDRHlp; C:\Windows\SysWOW64\Drivers\ULCDRHlp.sys [27392 2004-12-23] (Ulead Systems, Inc.) [File not signed]
R0 vsock; C:\Windows\System32\drivers\vsock.sys [75512 2015-11-05] (VMware, Inc.)
S3 vvftav; C:\Windows\System32\drivers\vvftav.sys [300800 2007-02-02] (Vimicro Corporation)
S3 ZSMC0305; C:\Windows\System32\Drivers\usbVM305.sys [1541120 2007-03-08] (Vimicro Corporation)
S2 AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X]
S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-04-09 10:43 - 2016-04-09 10:44 - 00029945 _____ C:\Users\Springfieldz0r\Desktop\FRST.txt
2016-04-09 10:42 - 2016-04-09 10:42 - 02374144 _____ (Farbar) C:\Users\Springfieldz0r\Desktop\FRST64.exe
2016-04-08 23:38 - 2016-04-08 23:39 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\pvr2000_vista32
2016-04-08 23:38 - 2016-04-08 23:38 - 04626515 _____ C:\Users\Springfieldz0r\Desktop\pvr2000_vista32.zip
2016-04-08 19:30 - 2016-04-08 19:30 - 00002003 _____ C:\Users\Springfieldz0r\Desktop\sah.egn
2016-04-08 14:40 - 2016-04-08 14:40 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\VOPackage
2016-04-08 14:40 - 2016-04-08 14:40 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2016-04-08 14:40 - 2016-04-08 14:40 - 00000000 ____D C:\Program Files (x86)\00000000-1460119255-0000-0000-6C626D84B408
2016-04-08 14:39 - 2016-04-08 14:39 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\Keygen_1.2
2016-04-08 14:32 - 2016-04-08 14:32 - 00001144 _____ C:\Users\Springfieldz0r\Desktop\Live PC Help.lnk
2016-04-08 14:31 - 2016-04-08 14:31 - 00000000 ___HD C:\Users\Springfieldz0r\AppData\Local\.Chess 2013
2016-04-08 14:27 - 2016-04-08 14:27 - 00000000 ____D C:\Program Files (x86)\RelevantKnowledge
2016-04-08 14:24 - 2016-04-08 14:32 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\systweak
2016-04-08 14:24 - 2016-03-17 13:54 - 00019888 _____ () C:\Windows\system32\roboot64.exe
2016-04-08 14:03 - 2016-04-09 09:06 - 00000000 ____D C:\Program Files (x86)\SearchesToYesbnd
2016-04-08 14:03 - 2016-04-08 14:04 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-04-08 14:03 - 2016-04-08 14:03 - 00015168 _____ C:\Windows\System32\Tasks\WinTaske
2016-04-08 14:03 - 2016-04-08 14:03 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-04-08 14:03 - 2016-04-08 14:03 - 00000000 ____D C:\Program Files (x86)\WinTaske
2016-04-08 14:03 - 2016-04-08 14:03 - 00000000 ____D C:\Program Files (x86)\Winsere
2016-04-08 14:02 - 2016-04-08 15:03 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\Software Tool
2016-04-08 14:01 - 2016-04-08 14:32 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Local\Chess 2013
2016-04-08 14:01 - 2016-04-08 14:01 - 00001105 _____ C:\Users\Springfieldz0r\Desktop\Chess 2013.lnk
2016-04-08 14:01 - 2016-04-08 14:01 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chess 2013
2016-04-08 13:54 - 2016-04-08 13:55 - 69374525 _____ C:\Users\Springfieldz0r\Desktop\chess2013_setup.exe
2016-04-08 13:41 - 2016-04-08 13:42 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\Chess King
2016-04-08 03:45 - 2016-04-08 03:46 - 42971214 _____ C:\Users\Springfieldz0r\Desktop\chess2012_setup.exe
2016-04-07 17:30 - 2016-04-07 17:30 - 00001868 _____ C:\Users\Springfieldz0r\Desktop\Chessmaster - Shortcut.lnk
2016-04-07 16:51 - 2016-04-07 16:52 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\Chessmate 11th - Chessmaster Grandmaster Edition
2016-04-07 15:14 - 2016-04-07 16:33 - 2170028032 _____ C:\Users\Springfieldz0r\Desktop\Chessmate 11th - Chessmaster Grandmaster Edition.iso
2016-04-07 11:20 - 2016-04-07 11:27 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\Zizu5
2016-04-05 15:11 - 2016-04-05 15:11 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\SpotlightImages
2016-04-05 00:48 - 2016-04-05 00:49 - 41496629 _____ C:\Users\Springfieldz0r\Desktop\SpotlightImages.zip
2016-03-31 16:10 - 2016-03-31 16:10 - 00001892 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Pro 9.lnk
2016-03-31 16:10 - 2016-03-31 16:10 - 00001880 _____ C:\Users\Public\Desktop\Nitro Pro 9.lnk
2016-03-31 16:10 - 2016-03-31 16:10 - 00000000 ____D C:\Program Files\Nitro
2016-03-31 16:10 - 2014-07-16 15:08 - 00017928 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalui9.dll
2016-03-31 16:10 - 2014-07-16 15:07 - 00029704 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalmon9.dll
2016-03-31 12:23 - 2016-03-31 12:23 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\slike
2016-03-29 12:54 - 2016-03-29 09:54 - 07058954 _____ C:\Users\Springfieldz0r\Desktop\Predmjer i Predračun Kl-Kos (ugovor).pdf
2016-03-28 16:24 - 2016-03-28 16:24 - 00000065 _____ C:\Users\Springfieldz0r\Desktop\WinWin radio.pls
2016-03-28 12:41 - 2016-03-28 12:41 - 00000000 ____D C:\Program Files\SAMSUNG
2016-03-28 12:40 - 2016-03-28 12:40 - 00000000 ____D C:\ProgramData\Samsung
2016-03-28 12:39 - 2016-04-09 10:29 - 00000376 _____ C:\Windows\Tasks\DriverToolkit Autorun.job
2016-03-28 12:39 - 2016-04-04 13:25 - 00002764 _____ C:\Windows\System32\Tasks\DriverToolkit Autorun
2016-03-28 12:37 - 2016-04-04 17:45 - 00000000 ____D C:\Program Files (x86)\DriverToolkit
2016-03-28 12:37 - 2016-03-28 12:37 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Local\DriverToolkit
2016-03-24 19:16 - 2016-03-24 19:16 - 00067746 _____ C:\Users\Springfieldz0r\Desktop\mirc.7.x-patch-XenoCoder.rar
2016-03-24 19:16 - 2016-03-24 19:16 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\mirc.7.x-patch-XenoCoder
2016-03-24 19:00 - 2016-03-24 19:00 - 00000951 _____ C:\Users\Public\Desktop\mIRC.lnk
2016-03-24 19:00 - 2016-03-24 19:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mIRC
2016-03-24 18:58 - 2016-03-24 18:58 - 02471168 _____ (mIRC Co. Ltd.) C:\Users\Springfieldz0r\Desktop\mirc743.exe
2016-03-24 02:21 - 2016-03-24 02:39 - 00001537 _____ C:\Users\Public\Desktop\Start Andy.lnk
2016-03-24 02:21 - 2016-03-24 02:21 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Andy
2016-03-24 02:21 - 2016-03-24 02:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Andy
2016-03-24 02:20 - 2015-11-25 19:10 - 00066752 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmx86.sys
2016-03-24 02:20 - 2015-11-25 19:10 - 00033472 _____ (VMware, Inc.) C:\Windows\system32\Drivers\VMkbd.sys
2016-03-24 02:20 - 2015-11-05 20:25 - 00075512 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vsock.sys
2016-03-24 02:20 - 2015-11-05 20:25 - 00068288 _____ (VMware, Inc.) C:\Windows\system32\vsocklib.dll
2016-03-24 02:20 - 2015-11-05 20:25 - 00064192 _____ (VMware, Inc.) C:\Windows\SysWOW64\vsocklib.dll
2016-03-24 02:19 - 2016-03-24 02:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
2016-03-24 02:19 - 2016-03-24 02:19 - 00000000 ____D C:\Program Files\Common Files\VMware
2016-03-24 02:19 - 2015-11-25 19:10 - 00934080 _____ (VMware, Inc.) C:\Windows\system32\vnetlib64.dll
2016-03-24 02:19 - 2015-11-25 19:10 - 00392896 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
2016-03-24 02:19 - 2015-11-06 12:57 - 00057536 _____ (VMware, Inc.) C:\Windows\system32\Drivers\hcmon.sys
2016-03-24 02:18 - 2016-04-09 09:11 - 00000000 ____D C:\ProgramData\VMware
2016-03-24 02:15 - 2016-03-24 02:22 - 00000000 ____D C:\Program Files\Andy
2016-03-24 02:15 - 2016-03-24 02:15 - 00000000 ____D C:\Program Files\AndyOfflineInstaller46.2
2016-03-24 01:49 - 2016-03-24 02:01 - 446508624 _____ C:\Users\Springfieldz0r\Desktop\Andy_v46.2_86_x64bit.exe
2016-03-23 12:50 - 2016-03-23 12:50 - 00006362 _____ C:\Users\Springfieldz0r\Desktop\fordlawnmower_+_raz_youtube_script_length_mod_v2.txt
2016-03-23 12:22 - 2016-03-23 14:28 - 00000201 _____ C:\Users\Springfieldz0r\Desktop\New Text Document (2).txt
2016-03-23 02:34 - 2016-03-23 02:34 - 00006468 _____ C:\Users\Springfieldz0r\Desktop\20140528135355-KYoutube.tcl
2016-03-23 01:32 - 2016-03-23 01:32 - 00002438 _____ C:\Users\Springfieldz0r\Desktop\KYoutube_v1.4.zip
2016-03-23 01:32 - 2016-03-23 01:32 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\KYoutube_v1.4
2016-03-22 19:07 - 2016-03-23 00:31 - 00001125 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-03-22 19:07 - 2016-03-22 19:07 - 00003062 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1458666430
2016-03-22 19:07 - 2016-03-22 19:07 - 00000997 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-03-22 19:06 - 2016-03-22 19:06 - 00037144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2016-03-22 02:00 - 2016-03-22 02:00 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\tcllib-1.18
2016-03-22 01:54 - 2016-03-22 01:58 - 14752759 _____ C:\Users\Springfieldz0r\Desktop\tcllib-1.18.zip
2016-03-22 01:38 - 2016-03-22 01:38 - 00006036 _____ C:\Users\Springfieldz0r\Desktop\json.tcl
2016-03-22 01:30 - 2016-03-22 01:30 - 00300648 _____ C:\Users\Springfieldz0r\Desktop\bwidget-1.9.10.zip
2016-03-22 01:30 - 2016-03-22 01:30 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\bwidget-1.9.10
2016-03-22 01:07 - 2016-03-22 01:12 - 02993419 _____ C:\Users\Springfieldz0r\Desktop\tcllib-trunk.zip.part
2016-03-22 01:00 - 2016-03-22 01:06 - 02180343 _____ C:\Users\Springfieldz0r\Desktop\tarball.tgz.part
2016-03-21 11:34 - 2016-03-21 11:34 - 00398152 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-03-21 11:34 - 2016-03-21 11:34 - 00052184 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-03-19 19:59 - 2016-03-19 19:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-03-18 18:32 - 2016-03-18 18:32 - 00000000 _____ C:\Users\Springfieldz0r\Desktop\New Text Document.txt
2016-03-18 15:35 - 2016-03-18 15:35 - 00001418 _____ C:\Users\Springfieldz0r\Desktop\Professional Script v.5.lnk
2016-03-16 15:07 - 2016-03-16 15:07 - 00123211 _____ C:\Users\Springfieldz0r\Desktop\Zahtjev za registraciju gazdinstava pcelara i pcelinjaka.pdf
2016-03-16 14:58 - 2016-03-16 14:58 - 00647929 _____ C:\Users\Springfieldz0r\Desktop\Uputstvo za držaoce životinja.pdf
2016-03-14 22:36 - 2016-03-14 22:36 - 00000000 _____ C:\Windows\ViewNX2.INI
2016-03-14 22:29 - 2016-03-15 14:28 - 00000000 ____D C:\ProgramData\Nikon
2016-03-14 22:27 - 2016-03-14 22:27 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\Nikon
2016-03-14 22:27 - 2016-03-14 22:27 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Local\Nikon
2016-03-14 22:14 - 2016-03-14 22:14 - 00002043 _____ C:\Users\Public\Desktop\Picture Control Utility 2.lnk
2016-03-14 22:14 - 2016-03-14 22:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picture Control Utility 2
2016-03-14 22:14 - 2016-03-14 22:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nikon Message Center 2
2016-03-14 22:13 - 2016-03-14 22:13 - 00000268 ___RH C:\Users\Springfieldz0r\AppData\Roaming\Distortion
2016-03-14 22:13 - 2016-03-14 22:13 - 00000268 ___RH C:\ProgramData\Drums
2016-03-14 22:13 - 2016-03-14 22:13 - 00000020 ____H C:\ProgramData\PKP_DLes.DAT
2016-03-14 22:13 - 2016-03-14 22:13 - 00000012 ___RH C:\ProgramData\Filesystems
2016-03-14 22:12 - 2016-03-14 22:44 - 00000020 ____H C:\ProgramData\PKP_DLet.DAT
2016-03-14 22:12 - 2016-03-14 22:14 - 00000000 ____D C:\Program Files\Nikon
2016-03-14 22:12 - 2016-03-14 22:14 - 00000000 ____D C:\Program Files\Common Files\Nikon
2016-03-14 22:12 - 2016-03-14 22:14 - 00000000 ____D C:\Program Files (x86)\Nikon
2016-03-14 22:12 - 2016-03-14 22:13 - 00000000 ____D C:\ProgramData\Ultima_T15
2016-03-14 22:12 - 2016-03-14 22:13 - 00000000 ____D C:\ProgramData\EnterNHelp
2016-03-14 22:12 - 2016-03-14 22:12 - 00002009 _____ C:\Users\Public\Desktop\ViewNX 2.lnk
2016-03-14 22:12 - 2016-03-14 22:12 - 00000268 ___RH C:\Users\Springfieldz0r\AppData\Roaming\Documentation
2016-03-14 22:12 - 2016-03-14 22:12 - 00000268 ___RH C:\Users\Springfieldz0r\AppData\Roaming\Displays
2016-03-14 22:12 - 2016-03-14 22:12 - 00000268 ___RH C:\ProgramData\Dynamic Library
2016-03-14 22:12 - 2016-03-14 22:12 - 00000268 ___RH C:\ProgramData\Drum Kits
2016-03-14 22:12 - 2016-03-14 22:12 - 00000020 ____H C:\ProgramData\PKP_DLev.DAT
2016-03-14 22:12 - 2016-03-14 22:12 - 00000012 ___RH C:\ProgramData\Filters
2016-03-14 22:12 - 2016-03-14 22:12 - 00000012 ___RH C:\ProgramData\External Build System
2016-03-14 22:12 - 2016-03-14 22:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ViewNX 2
2016-03-14 22:11 - 2016-03-14 22:13 - 00000000 ____D C:\ProgramData\54F3DE4E-B7BA-4EBD-8B3B-385D272CC583
2016-03-14 22:11 - 2016-03-14 22:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Link to Nikon
2016-03-14 22:10 - 2016-03-14 22:10 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\S-VNX2__-021003WF-NSAEN-64BIT_
2016-03-14 20:47 - 2016-03-14 20:49 - 113952560 _____ C:\Users\Springfieldz0r\Desktop\S-VNX2__-021003WF-NSAEN-64BIT_.exe
2016-03-14 20:02 - 2016-03-15 19:05 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\POBORI
2016-03-14 20:01 - 2016-03-14 20:02 - 32059479 _____ C:\Users\Springfieldz0r\Desktop\POBORI.zip
2016-03-14 14:02 - 2016-03-15 19:07 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\Milica Vranic
2016-03-12 12:55 - 2016-03-12 12:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlaysTV
2016-03-10 20:25 - 2016-03-10 21:41 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\Muzikaa

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-04-09 10:43 - 2015-10-15 12:16 - 00000000 ____D C:\FRST
2016-04-09 10:37 - 2012-10-09 21:15 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-04-09 10:34 - 2009-07-14 06:45 - 00026544 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-09 10:34 - 2009-07-14 06:45 - 00026544 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-09 10:29 - 2016-01-15 19:16 - 00000360 _____ C:\Windows\Tasks\Health-Check-auto.job
2016-04-09 10:29 - 2014-01-11 18:19 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-09 10:29 - 2012-10-09 20:36 - 00000000 ____D C:\ProgramData\MCShield
2016-04-09 09:55 - 2014-01-11 18:19 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-09 09:07 - 2016-01-15 19:16 - 00000362 _____ C:\Windows\Tasks\Health-Check-deep.job
2016-04-09 09:07 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-09 02:58 - 2014-03-15 09:12 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\Slike Mikan
2016-04-09 01:35 - 2016-01-15 03:59 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\Andy
2016-04-09 00:33 - 2016-01-15 04:12 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\VMware
2016-04-08 19:07 - 2016-03-07 15:44 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2016-04-08 18:15 - 2016-01-15 19:16 - 00000354 _____ C:\Windows\Tasks\Health-Check.job
2016-04-08 14:34 - 2013-03-04 14:05 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Local\CrashDumps
2016-04-08 14:31 - 2015-08-31 19:32 - 00000000 ____D C:\Users\Springfieldz0r\.oracle_jre_usage
2016-04-08 14:17 - 2012-10-10 07:54 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\uTorrent
2016-04-08 01:37 - 2012-10-09 21:15 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-08 01:37 - 2012-10-09 21:15 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-08 01:37 - 2012-10-09 21:15 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-04-07 19:07 - 2012-10-25 15:52 - 00000000 ____D C:\Program Files (x86)\Medjed-Skript v1.5 Black
2016-04-07 17:20 - 2012-10-09 22:22 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-04-07 17:18 - 2013-01-24 14:24 - 00000000 ____D C:\ProgramData\Media Center Programs
2016-04-07 11:12 - 2013-03-14 02:26 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-04-06 00:27 - 2012-10-10 19:33 - 00000600 _____ C:\Users\Springfieldz0r\AppData\Roaming\winscp.rnd
2016-04-04 17:55 - 2016-02-24 16:47 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Local\Viber
2016-04-04 17:55 - 2015-03-06 19:43 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\ViberPC
2016-04-04 17:52 - 2014-05-22 21:14 - 00000000 ____D C:\Users\Springfieldz0r\Documents\ViberDownloads
2016-04-04 03:38 - 2012-10-14 07:47 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\Skype
2016-04-02 00:04 - 2016-03-06 14:35 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\PlaysTV
2016-04-01 14:08 - 2013-10-20 23:52 - 00000000 ____D C:\Windows\pss
2016-04-01 12:10 - 2014-05-16 22:07 - 00722228 _____ C:\Windows\system32\perfh019.dat
2016-04-01 12:10 - 2014-05-16 22:07 - 00153000 _____ C:\Windows\system32\perfc019.dat
2016-04-01 12:10 - 2009-07-14 07:13 - 01666324 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-01 12:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-04-01 12:03 - 2014-03-19 12:47 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\Raptr
2016-03-31 17:12 - 2013-01-21 14:14 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\Nitro
2016-03-31 16:10 - 2014-04-13 13:36 - 00000000 ____D C:\Program Files\Common Files\Nitro
2016-03-31 16:10 - 2014-04-13 13:36 - 00000000 ____D C:\Program Files (x86)\Nitro
2016-03-31 16:10 - 2013-01-21 14:13 - 00000000 ____D C:\ProgramData\Nitro
2016-03-31 16:09 - 2014-04-13 13:33 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\Downloaded Installations
2016-03-31 12:05 - 2014-08-07 18:23 - 00003860 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1382109612
2016-03-31 12:05 - 2013-02-12 15:30 - 00000000 ____D C:\Program Files (x86)\Opera
2016-03-30 22:57 - 2014-01-11 18:21 - 00002197 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-30 19:36 - 2015-08-26 16:24 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\mIRC
2016-03-30 19:34 - 2015-08-26 16:24 - 00000000 ____D C:\Program Files (x86)\mIRC
2016-03-27 15:37 - 2012-11-08 19:21 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Roaming\TeamViewer
2016-03-25 01:30 - 2015-08-25 20:30 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-03-25 01:30 - 2012-10-14 07:47 - 00000000 ____D C:\ProgramData\Skype
2016-03-25 01:03 - 2012-11-18 21:40 - 01632072 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-03-25 01:00 - 2015-04-04 16:23 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2016-03-25 01:00 - 2015-04-04 16:23 - 00000000 ___SD C:\Windows\system32\GWX
2016-03-24 02:24 - 2016-01-15 04:02 - 00000000 ____D C:\Users\Springfieldz0r\Andy
2016-03-23 13:34 - 2012-11-01 18:10 - 00000600 _____ C:\Users\Springfieldz0r\AppData\Local\PUTTY.RND
2016-03-22 19:06 - 2012-10-09 20:52 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-22 19:06 - 2012-10-09 20:52 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-22 02:05 - 2012-10-10 19:30 - 00000000 ____D C:\Program Files (x86)\WinSCP
2016-03-21 11:35 - 2013-03-14 02:26 - 01070904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2016-03-21 11:35 - 2013-03-14 02:26 - 00463744 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2016-03-21 11:35 - 2013-03-14 02:26 - 00287016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-03-21 11:35 - 2013-03-14 02:26 - 00107792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2016-03-21 11:34 - 2014-04-30 02:23 - 00037656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-03-21 11:34 - 2014-01-03 16:19 - 00165344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-03-21 11:34 - 2013-03-14 02:26 - 00103064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-03-21 11:34 - 2013-03-14 02:26 - 00074544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-03-20 14:15 - 2012-10-09 20:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-03-18 18:14 - 2012-12-03 08:04 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Local\Eclipse
2016-03-18 15:45 - 2012-12-27 22:16 - 00000000 ____D C:\PScript5
2016-03-15 19:04 - 2013-02-14 17:26 - 00001456 _____ C:\Users\Springfieldz0r\AppData\Local\Adobe Save for Web 13.0 Prefs
2016-03-15 01:11 - 2012-12-22 20:49 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2016-03-14 22:14 - 2014-02-17 18:29 - 00000000 ____D C:\Users\Springfieldz0r\AppData\Local\Downloaded Installations
2016-03-14 22:13 - 2013-02-17 19:39 - 00000000 ____D C:\Windows\Downloaded Installations
2016-03-14 22:12 - 2011-09-05 19:05 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ATL71.DLL
2016-03-13 14:38 - 2015-07-15 18:34 - 00000000 ____D C:\Windows\rescache
2016-03-12 18:45 - 2014-01-21 22:28 - 00001041 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk
2016-03-12 16:28 - 2016-01-31 01:15 - 00000000 ____D C:\Users\Springfieldz0r\Desktop\telefon
2016-03-11 12:39 - 2015-11-01 13:14 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-03-11 12:26 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2016-03-10 22:15 - 2009-07-14 06:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-03-10 02:30 - 2009-07-14 06:45 - 05089336 _____ C:\Windows\system32\FNTCACHE.DAT
2016-03-10 01:11 - 2009-07-14 04:34 - 00000842 _____ C:\Windows\win.ini
2016-03-10 01:08 - 2013-10-18 00:56 - 00000000 ____D C:\Windows\system32\MRT
2016-03-10 01:00 - 2014-12-11 03:17 - 00000000 ____D C:\Windows\system32\appraiser
2016-03-10 01:00 - 2012-10-11 07:34 - 143659408 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== Files in the root of some directories =======

2014-04-21 20:06 - 2014-04-21 20:06 - 0000288 _____ () C:\Users\Springfieldz0r\AppData\Roaming\.backup.dm
2013-02-13 02:27 - 2014-05-31 16:11 - 0000132 _____ () C:\Users\Springfieldz0r\AppData\Roaming\Adobe BMP Format CS6 Prefs
2013-01-20 16:52 - 2013-12-07 05:19 - 0000132 _____ () C:\Users\Springfieldz0r\AppData\Roaming\Adobe GIF Format CS6 Prefs
2014-01-22 03:39 - 2016-02-29 18:30 - 0000132 _____ () C:\Users\Springfieldz0r\AppData\Roaming\Adobe IllExport Filter CS6 Prefs
2013-01-15 15:47 - 2016-02-29 18:32 - 0000132 _____ () C:\Users\Springfieldz0r\AppData\Roaming\Adobe PNG Format CS6 Prefs
2016-03-14 22:12 - 2016-03-14 22:12 - 0000268 ___RH () C:\Users\Springfieldz0r\AppData\Roaming\Displays
2016-03-14 22:13 - 2016-03-14 22:13 - 0000268 ___RH () C:\Users\Springfieldz0r\AppData\Roaming\Distortion
2016-03-14 22:12 - 2016-03-14 22:12 - 0000268 ___RH () C:\Users\Springfieldz0r\AppData\Roaming\Documentation
2014-02-02 05:22 - 2014-02-12 01:22 - 0000079 _____ () C:\Users\Springfieldz0r\AppData\Roaming\WB.CFG
2012-10-10 19:33 - 2016-04-06 00:27 - 0000600 _____ () C:\Users\Springfieldz0r\AppData\Roaming\winscp.rnd
2013-02-14 17:26 - 2016-03-15 19:04 - 0001456 _____ () C:\Users\Springfieldz0r\AppData\Local\Adobe Save for Web 13.0 Prefs
2015-12-17 17:24 - 2015-12-17 17:24 - 0003584 _____ () C:\Users\Springfieldz0r\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-26 02:51 - 2014-01-26 02:51 - 0000001 _____ () C:\Users\Springfieldz0r\AppData\Local\llftool.4.25.agreement
2012-11-01 18:10 - 2016-03-23 13:34 - 0000600 _____ () C:\Users\Springfieldz0r\AppData\Local\PUTTY.RND
2013-03-08 00:33 - 2015-11-07 20:36 - 0007597 _____ () C:\Users\Springfieldz0r\AppData\Local\Resmon.ResmonCfg
2015-04-18 13:08 - 2015-04-18 13:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2016-03-14 22:12 - 2016-03-14 22:12 - 0000268 ___RH () C:\ProgramData\Drum Kits
2016-03-14 22:13 - 2016-03-14 22:13 - 0000268 ___RH () C:\ProgramData\Drums
2016-03-14 22:12 - 2016-03-14 22:12 - 0000268 ___RH () C:\ProgramData\Dynamic Library
2016-03-14 22:12 - 2016-03-14 22:12 - 0000012 ___RH () C:\ProgramData\External Build System
2016-03-14 22:13 - 2016-03-14 22:13 - 0000012 ___RH () C:\ProgramData\Filesystems
2016-03-14 22:12 - 2016-03-14 22:12 - 0000012 ___RH () C:\ProgramData\Filters
2016-03-14 22:13 - 2016-03-14 22:13 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT
2016-03-14 22:12 - 2016-03-14 22:44 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT
2016-03-14 22:12 - 2016-03-14 22:12 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT

Some files in TEMP:
====================
C:\Users\Springfieldz0r\AppData\Local\Temp\AMDCleanupUtility.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\Cleanup.dll
C:\Users\Springfieldz0r\AppData\Local\Temp\ddu.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\Font__19312_il531781.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\HD-Logger-Native.dll
C:\Users\Springfieldz0r\AppData\Local\Temp\HD-ShortcutHandler.dll
C:\Users\Springfieldz0r\AppData\Local\Temp\hib7DF7.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\mirc743.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\msvcm80.dll
C:\Users\Springfieldz0r\AppData\Local\Temp\msvcp80.dll
C:\Users\Springfieldz0r\AppData\Local\Temp\msvcr80.dll
C:\Users\Springfieldz0r\AppData\Local\Temp\playstv_patch.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\raptrpatch.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\raptr_stub.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\s11575.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\s21541.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\Setup.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Springfieldz0r\AppData\Local\Temp\sfextra.dll
C:\Users\Springfieldz0r\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\tasklisten.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\tmp67A8.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\tmpE6F6.exe
C:\Users\Springfieldz0r\AppData\Local\Temp\uninstall.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-04-08 13:23

==================== End of FRST.txt ============================

https://www.mycity.rs/must-login.png

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Pozdrav,

Deinstaliraj RelevantKnowledge i Remote Desktop Access (od VuuPC-a ). Potom idemo na prvu fazu...





Preuzmi smeenk-ov zoek.zip ili zoek.rar () sa ovog linka i sačuvaj ga na Desktop.

Raspakuj arhivu u neki folder (uputstvo), a zatim:

zatvori browser i ostale pokrenute programe;
privremeno deaktiviraj zaštitni softver ( ukoliko je to potrebno ) Uputstvo ;
dvoklikom pokreni zoek na ikonicu programa ;
pričekaj da se alat startuje ...


U beli okvir prozora iskopiraj sledeći tekst:

hohosearch;a
C:\Users\Springfieldz0r\AppData\Roaming\Software Tool;vs
FFDefaults;
CHRDefaults;
VOPackage;u
C:\Users\Springfieldz0r\AppData\Roaming\VOPackage;fs
C:\Users\Springfieldz0r\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage;fs
C:\Program Files (x86)\00000000-1460119255-0000-0000-6C626D84B408;fs
C:\Users\Springfieldz0r\Desktop\Live PC Help.lnk;f
C:\Program Files (x86)\SearchesToYesbnd;fs
C:\Windows\System32\Tasks\WinTaske;fs
C:\Program Files (x86)\WinTaske;fs
C:\Program Files (x86)\Winsere;fs
EmptyFoldersCheck;Delete
EmptyAllTemp;
Reboot;


Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2634
  • Gde živiš: Milan, Italy

Ovaj Remote Desktop Access (od VuuPC-a ) sam valjda deinstalirao nisam bas siguran...

A ovaj RelevantKnowledge nesto cini mi se nece kad krenem da unistal otvori mi samo ovo



Ja restartujem racunar ono opet isto.

Da nastavim sa zoek?

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Da, da. Nastavi slobodno, vidim ja sve po logovima. Wink

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2634
  • Gde živiš: Milan, Italy

Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Springfieldz0r on sub 09.04.2016 at 23:25:40,30.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Springfieldz0r\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

9.4.2016 23:28:25 Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\PROGRA~2\Avira deleted successfully
C:\PROGRA~2\GUM78AE.tmp deleted successfully
C:\PROGRA~2\GUMEEB5.tmp deleted successfully
C:\PROGRA~2\iSkysoft deleted successfully
C:\PROGRA~2\Raptr deleted successfully
C:\PROGRA~2\Ray Adams deleted successfully
C:\PROGRA~2\Tensons deleted successfully
C:\PROGRA~2\VideoLAN deleted successfully
C:\Program Files\WinFast deleted successfully
C:\PROGRA~3\ALM deleted successfully
C:\PROGRA~3\HTC deleted successfully
C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) deleted successfully
C:\PROGRA~3\TamoSoft deleted successfully
C:\Users\Springfieldz0r\AppData\Roaming\Axis Communications deleted successfully
C:\Users\Springfieldz0r\AppData\Roaming\HeidiSQL deleted successfully
C:\Users\Springfieldz0r\AppData\Roaming\Opera deleted successfully
C:\Users\Springfieldz0r\AppData\Roaming\Publish Providers deleted successfully
C:\Users\Springfieldz0r\AppData\Roaming\systweak deleted successfully
C:\Users\Springfieldz0r\AppData\Roaming\VMware deleted successfully
C:\Users\Springfieldz0r\AppData\Roaming\VOPackage deleted successfully
C:\Users\Springfieldz0r\AppData\Roaming\Windows Live Writer deleted successfully
C:\Users\Springfieldz0r\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A} deleted successfully
C:\Users\Springfieldz0r\AppData\Local\.Chess 2013 deleted successfully
C:\Users\Springfieldz0r\AppData\Local\DriverToolkit deleted successfully
C:\Users\Springfieldz0r\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\Springfieldz0r\AppData\Local\EmieSiteList deleted successfully
C:\Users\Springfieldz0r\AppData\Local\EmieUserList deleted successfully
C:\Users\Springfieldz0r\AppData\Local\Opera deleted successfully
C:\Users\Springfieldz0r\AppData\Local\PACE Anti-Piracy deleted successfully
C:\Users\Springfieldz0r\AppData\Local\PokerStars deleted successfully
C:\Users\Springfieldz0r\AppData\Local\Skype deleted successfully
C:\Users\Springfieldz0r\AppData\Local\WMTools Downloaded Files deleted successfully

==== FireFox Fix ======================

Deleted from C:\Users\SPRING~1\AppData\Roaming\KompoZer\Profiles\1o1xsch7.default\prefs.js:

Added to C:\Users\SPRING~1\AppData\Roaming\KompoZer\Profiles\1o1xsch7.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com/");
user_pref("browser.newtab.url", "www.google.com");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.defaultenginename.US", "");
user_pref("browser.search.selectedEngine", "hohosearch");
user_pref("keyword.URL", "http://www.hohosearch.com/chrome.php?uid=31B422787E95B03884E174EB6F99026D&ptid=amz&ts=AHEqA34lBn0mAU..&v=20160405&mode=ffexttoolbar&q=");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "http://www.hohosearch.com/?ts=AHEqA34lBn0mAU..&v=20160405&uid=31B422787E95B03884E174EB6F99026D&ptid=amz&mode=ffseng");
user_pref("browser.newtab.url", "http://www.hohosearch.com/?ts=AHEqA34lBn0mAU..&v=20160405&uid=31B422787E95B03884E174EB6F99026D&ptid=amz&mode=ffseng");
user_pref("browser.search.defaultenginename", "hohosearch");
user_pref("browser.search.defaultenginename.US", "data:text/plain,browser.search.defaultenginename.US=hohosearch");
user_pref("browser.search.selectedEngine", "hohosearch");
user_pref("keyword.URL", "http://www.hohosearch.com/chrome.php?uid=31B422787E95B03884E174EB6F99026D&ptid=amz&ts=AHEqA34lBn0mAU..&v=20160405&mode=ffexttoolbar&q=");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com/");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\prefs.js:
user_pref("browser.startup.homepage", "http://www.hohosearch.com/?ts=AHEqA34lBn0mAU..&v=20160405&uid=31B422787E95B03884E174EB6F99026D&ptid=amz&mode=ffseng");
user_pref("browser.newtab.url", "http://www.hohosearch.com/?ts=AHEqA34lBn0mAU..&v=20160405&uid=31B422787E95B03884E174EB6F99026D&ptid=amz&mode=ffseng");
user_pref("browser.search.defaultenginename", "hohosearch");
user_pref("browser.search.selectedEngine", "hohosearch");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\urh1dwro.default-1406026697443\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com/");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\urh1dwro.default-1406026697443\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\SPRING~1\AppData\Roaming\Thunderbird\Profiles\tc0883kq.default\prefs.js:

Added to C:\Users\SPRING~1\AppData\Roaming\Thunderbird\Profiles\tc0883kq.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\Users\Springfieldz0r\AppData\Roaming\VOPackage not found
"C:\Users\Springfieldz0r\Desktop\Live PC Help.lnk" not found
C:\Users\Springfieldz0r\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage deleted
C:\Program Files (x86)\00000000-1460119255-0000-0000-6C626D84B408 deleted
C:\Program Files (x86)\SearchesToYesbnd deleted
C:\windows\SysNative\Tasks\WinTaske deleted
C:\Program Files (x86)\WinTaske deleted
C:\Program Files (x86)\Winsere deleted

==== Files Found In C:\Users\Springfieldz0r\AppData\Roaming\Software Tool ======================

2016-04-08 12:03:15 1 ----a-w- 5058F1AF8388633F609CADB75A75DC9D C:\Users\SPRING~1\AppData\Roaming\SOFTWA~1\ksp8 --- C:\Users\Springfieldz0r\AppData\Roaming\Software Tool\ksp8
2016-04-08 12:22:58 93396 ----a-w- 9820B16869218F09D3FD20C8A59BC38B C:\Users\SPRING~1\AppData\Roaming\SOFTWA~1\Update.exe --- C:\Users\Springfieldz0r\AppData\Roaming\Software Tool\Update.exe
2016-04-08 12:23:18 1 ----a-w- 5058F1AF8388633F609CADB75A75DC9D C:\Users\SPRING~1\AppData\Roaming\SOFTWA~1\kup8 --- C:\Users\Springfieldz0r\AppData\Roaming\Software Tool\kup8

==== Registry Search Results for "hohosearch" ======================


[HKEY_LOCAL_MACHINE\SOFTWARE\hohosearchSoftware]

[HKEY_LOCAL_MACHINE\SOFTWARE\hohosearchSoftware\hohosearchhp]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}]
"hp"="http://www.hohosearch.com/?ts=AHEqA34lBn0mAU..&v=20160405&uid=31B422787E95B03884E174EB6F99026D&ptid=amz&mode=ffsengext"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}]
"tab"="http://www.hohosearch.com/?ts=AHEqA34lBn0mAU..&v=20160405&uid=31B422787E95B03884E174EB6F99026D&ptid=amz&mode=ffsengext"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}]
"sp"="http://www.hohosearch.com/chrome.php?uid=31B422787E95B03884E174EB6F99026D&ptid=amz&q={searchTerms}&ts=AHEqA34lBn0mAU..&v=20160405&mode=ffsengext"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}]
"surl"="http://www.hohosearch.com/chrome.php?uid=31B422787E95B03884E174EB6F99026D&ptid=amz&ts=AHEqA34lBn0mAU..&v=20160405&mode=ffexttoolbar&q="

[HKEY_USERS\S-1-5-21-2145776392-1472050533-324974990-1000\Software\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}]
"hp"="http://www.hohosearch.com/?ts=AHEqA34lBn0mAU..&v=20160405&uid=31B422787E95B03884E174EB6F99026D&ptid=amz&mode=ffsengext"

[HKEY_USERS\S-1-5-21-2145776392-1472050533-324974990-1000\Software\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}]
"tab"="http://www.hohosearch.com/?ts=AHEqA34lBn0mAU..&v=20160405&uid=31B422787E95B03884E174EB6F99026D&ptid=amz&mode=ffsengext"

[HKEY_USERS\S-1-5-21-2145776392-1472050533-324974990-1000\Software\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}]
"sp"="http://www.hohosearch.com/chrome.php?uid=31B422787E95B03884E174EB6F99026D&ptid=amz&q={searchTerms}&ts=AHEqA34lBn0mAU..&v=20160405&mode=ffsengext"

[HKEY_USERS\S-1-5-21-2145776392-1472050533-324974990-1000\Software\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}]
"surl"="http://www.hohosearch.com/chrome.php?uid=31B422787E95B03884E174EB6F99026D&ptid=amz&ts=AHEqA34lBn0mAU..&v=20160405&mode=ffexttoolbar&q="

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\KompoZer\Profiles\1o1xsch7.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\urh1dwro.default-1406026697443
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Thunderbird\Profiles\tc0883kq.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [21.03.2016 12:53]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [21.03.2016 12:53]

==== Firefox Extensions ======================

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\KompoZer\Profiles\1o1xsch7.default
- Undetermined - %ProfilePath%\extensions\installed-extensions.txt
- KompoZer classic - %ProfilePath%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
- Valence - %ProfilePath%\extensions\fxdevtools-adapters@mozilla.org
- Qualys BrowserCheck - %ProfilePath%\extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D}
- Firebug - %ProfilePath%\extensions\firebug@software.joehewitt.com.xpi
- Undetermined - %ProfilePath%\extensions\firefox@mega.co.nz.xpi
- Awesome screenshot: Capture and Annotate - %ProfilePath%\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
- Web Developer - %ProfilePath%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
- Valence - %ProfilePath%\extensions\fxdevtools-adapters@mozilla.org
- Qualys BrowserCheck - %ProfilePath%\extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D}
- Firebug - %ProfilePath%\extensions\firebug@software.joehewitt.com.xpi
- Undetermined - %ProfilePath%\extensions\firefox@mega.co.nz.xpi
- Awesome screenshot: Capture and Annotate - %ProfilePath%\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
- Web Developer - %ProfilePath%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default
- Valence - %ProfilePath%\extensions\fxdevtools-adapters@mozilla.org
- Qualys BrowserCheck - %ProfilePath%\extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D}
- Firebug - %ProfilePath%\extensions\firebug@software.joehewitt.com.xpi
- Undetermined - %ProfilePath%\extensions\firefox@mega.co.nz.xpi
- Awesome screenshot: Capture and Annotate - %ProfilePath%\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
- Web Developer - %ProfilePath%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726
- Valence - %ProfilePath%\extensions\fxdevtools-adapters@mozilla.org
- Qualys BrowserCheck - %ProfilePath%\extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D}
- Firebug - %ProfilePath%\extensions\firebug@software.joehewitt.com.xpi
- Awesome screenshot: Capture and Annotate - %ProfilePath%\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
- Web Developer - %ProfilePath%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\urh1dwro.default-1406026697443
- Valence - %ProfilePath%\extensions\fxdevtools-adapters@mozilla.org
- Qualys BrowserCheck - %ProfilePath%\extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D}
- Firebug - %ProfilePath%\extensions\firebug@software.joehewitt.com.xpi
- Awesome screenshot: Capture and Annotate - %ProfilePath%\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
- Web Developer - %ProfilePath%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Thunderbird\Profiles\tc0883kq.default
- Undetermined - %ProfilePath%\extensions\staged

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
57C7E359ED8D049132EED23EFA444C63 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll - Shockwave Flash

Profilepath: C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
57C7E359ED8D049132EED23EFA444C63 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll - Shockwave Flash

Profilepath: C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default
57C7E359ED8D049132EED23EFA444C63 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll - Shockwave Flash


==== Reset Google Chrome ======================

C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Preferences_backup was reset successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences.bad was reset successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Secure Preferencesgbak was reset successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences_backup was reset successfully
C:\Users\Springfieldz0r\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Web Datagbak was reset successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Web Data_backup was reset successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data_backup was reset successfully
C:\Users\Springfieldz0r\AppData\Roaming\Opera Software\Opera Stable\Web Data was reset successfully
C:\Users\Springfieldz0r\AppData\Roaming\Opera Software\Opera Stable\Web Data-journal was reset successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2145776392-1472050533-324974990-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF} deleted successfully
HKEY_USERS\S-1-5-21-2145776392-1472050533-324974990-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B4F3A835-0E21-4959-BA22-42B3008E02FF} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Springfieldz0r\AppData\Local\Mozilla\Firefox\Profiles\41A66E7E5EE1\cache2 emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\cache2 emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\Cache emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\cache2 emptied successfully
C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\storage\default\https+++plus.google.com\cache will be emptied at reboot
C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\storage\default\https+++plus.google.com\cache emptied successfully
C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\cache2 emptied successfully
C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\storage\default\https+++plus.google.com\cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Springfieldz0r\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache is not empty, a reboot is needed

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=12 folders=13 4920058 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\SPRING~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Springfieldz0r\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\4JX7JG6A\player.foxfdm.com" not found
"C:\Users\Springfieldz0r\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\4JX7JG6A\static-hw.xvideos.com" not found
"C:\Users\Springfieldz0r\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\4JX7JG6A\static.miniclipcdn.com" not found
"C:\Users\Springfieldz0r\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\4JX7JG6A\test-script.dotmetrics.net" not found
"C:\Users\Springfieldz0r\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\4JX7JG6A\www.miniclip.com" not found
"C:\Users\Springfieldz0r\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\4JX7JG6A\www.navidiku.rs" not found
"C:\Users\Springfieldz0r\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\4JX7JG6A\www.shockwave.com" not found
"C:\Users\Springfieldz0r\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\4JX7JG6A\www8.agame.com" not found

==== EOF on sub 09.04.2016 at 23:42:20,22 ======================

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Izvrsi sada ovaj Zoek script i postavi sveze formiran izvestaj;

Uninstall-List;
[-HKEY_LOCAL_MACHINE\SOFTWARE\hohosearchSoftware];r
[-HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}];r
[-HKEY_USERS\S-1-5-21-2145776392-1472050533-324974990-1000\Software\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}];r
AutoClean;
Reboot;



Potom, postavi Firefox browser na podrazumevana (default) podesavanja.
https://support.mozilla.org/en-US/kb/make-firefox-your-default-browser



Je l' sada bolje?

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2634
  • Gde živiš: Milan, Italy

Pa da sad se cini da je sve ok. Very Happy Je l' bilo previse gamadi? Very Happy


Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Springfieldz0r on ned 10.04.2016 at 12:21:49,26.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Springfieldz0r\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2016-04-09-214220.log 23535 bytes

==== Empty Folders Check ======================

C:\Users\Springfieldz0r\AppData\Local\Viber Media S.a r.l

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\KompoZer\Profiles\1o1xsch7.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_09.04.2016_2330_.backup
prefs_10.04.2016_1246_.backup

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1

user.js not found
---- Lines mindspark removed from prefs.js ----
user_pref("extensions.toolbar.mindspark._brMembers_.BUTTON_STRUCTURE", "[{\"b\":224520315,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":224520316,
user_pref("extensions.toolbar.mindspark._brMembers_.browser.version.last", "45.0");
user_pref("extensions.toolbar.mindspark._brMembers_.firstKnownVersion", "7.38.8.45986");
user_pref("extensions.toolbar.mindspark._brMembers_.homepage", "/index.jhtml?n=782a576e");
user_pref("extensions.toolbar.mindspark._brMembers_.hp.enabled", false);
user_pref("extensions.toolbar.mindspark._brMembers_.initialized", true);
user_pref("extensions.toolbar.mindspark._brMembers_.installation.installDate", "2016040814");
user_pref("extensions.toolbar.mindspark._brMembers_.installation.success", true);
user_pref("extensions.toolbar.mindspark._brMembers_.lastActivePing", "1460117750455");
user_pref("extensions.toolbar.mindspark._brMembers_.lastKnownVersion", "7.38.8.45986");
user_pref("extensions.toolbar.mindspark._brMembers_.lssState", "{\"previousLocales\":[\"en-US\",\"en\"],\"supportedLocales\":[\"de\",\"es\",\"pt\",\"j
user_pref("extensions.toolbar.mindspark._brMembers_.options.defaultSearch", false);
user_pref("extensions.toolbar.mindspark._brMembers_.options.homePageEnabled", false);
user_pref("extensions.toolbar.mindspark._brMembers_.options.keywordEnabled", true);
user_pref("extensions.toolbar.mindspark._brMembers_.options.tabEnabled", false);
user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.language", "en");
user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.type", "Toolbar");
user_pref("extensions.toolbar.mindspark._brMembers_.shownUninstall", true);
user_pref("extensions.toolbar.mindspark._brMembers_.startupTasks", "{\"clearPrefs\":[\"extensions.toolbar.mindspark._brMembers_.shownUninstall\"],\"un
user_pref("extensions.toolbar.mindspark._brMembers_.successUrl", "http://www.hohosearch.com/chrome.php?uid=31B422787E95B03884E174EB6F99026D&ptid=amz&t
user_pref("extensions.toolbar.mindspark._brMembers_.toolbarCollapsed", false);
user_pref("extensions.toolbar.mindspark._brMembers_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._brMembers_.\"],\"file
user_pref("extensions.toolbar.mindspark.hp.enabled", false);
user_pref("extensions.toolbar.mindspark.lastInstalled", "yourGSearchfinder@GSearch.com");
---- Lines search.com removed from prefs.js ----
user_pref("browser.search.searchengine.hp", "http://www.hohosearch.com/?ts=AHEqA34lBn0mAU..&v=20160405&uid=31B422787E95B03884E174EB6F99026D&ptid=amz&m
user_pref("browser.search.searchengine.sp", "http://www.hohosearch.com/chrome.php?mode=ffsengext&ptid=amz&q={searchTerms}&ts=AHEqA34lBn0mAU..&uid=31B4
user_pref("browser.search.searchengine.url", "http://www.hohosearch.com/chrome.php?mode=ffsengext&ptid=amz&q={searchTerms}&ts=AHEqA34lBn0mAU..&uid=31B
---- Lines searchengine removed from prefs.js ----
user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine");
user_pref("browser.search.searchengine.ptid", "cor");
user_pref("browser.search.searchengine.uid", "ST500DM002-1BD142_Z2A9AEZLXXXXZ2A9AEZL");
---- Lines searches removed from prefs.js ----
user_pref("browser.urlbar.suggest.searches", true);
---- Lines offers removed from prefs.js ----
user_pref("fbsidebardisabler.au_script_cache", "{\"data\":\"/*\\n * SocialReviver - AutoUpdate JS code\\n * Copyright (C) 2013 VittGam.net. All rights
---- FireFox user.js and prefs.js backups ----

prefs_09.04.2016_2330_.backup
prefs_10.04.2016_1246_.backup

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F

user.js not found
---- Lines mindspark removed from prefs.js ----
user_pref("extensions.toolbar.mindspark._brMembers_.browser.version.last", "45.0");
user_pref("extensions.toolbar.mindspark._brMembers_.BUTTON_STRUCTURE", "[{\"b\":224520315,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":224520316,
user_pref("extensions.toolbar.mindspark._brMembers_.firstKnownVersion", "7.38.8.45986");
user_pref("extensions.toolbar.mindspark._brMembers_.homepage", "/index.jhtml?n=782a576e");
user_pref("extensions.toolbar.mindspark._brMembers_.hp.enabled", false);
user_pref("extensions.toolbar.mindspark._brMembers_.initialized", true);
user_pref("extensions.toolbar.mindspark._brMembers_.installation.installDate", "2016040814");
user_pref("extensions.toolbar.mindspark._brMembers_.installation.success", true);
user_pref("extensions.toolbar.mindspark._brMembers_.lastActivePing", "1460117143803");
user_pref("extensions.toolbar.mindspark._brMembers_.lastKnownVersion", "7.38.8.45986");
user_pref("extensions.toolbar.mindspark._brMembers_.lssState", "{\"previousLocales\":[\"en-US\",\"en\"],\"supportedLocales\":[\"de\",\"es\",\"pt\",\"j
user_pref("extensions.toolbar.mindspark._brMembers_.options.defaultSearch", false);
user_pref("extensions.toolbar.mindspark._brMembers_.options.homePageEnabled", false);
user_pref("extensions.toolbar.mindspark._brMembers_.options.keywordEnabled", true);
user_pref("extensions.toolbar.mindspark._brMembers_.options.tabEnabled", false);
user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.language", "en");
user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.type", "Toolbar");
user_pref("extensions.toolbar.mindspark._brMembers_.shownUninstall", true);
user_pref("extensions.toolbar.mindspark._brMembers_.startupTasks", "{\"clearPrefs\":[\"extensions.toolbar.mindspark._brMembers_.shownUninstall\"],\"un
user_pref("extensions.toolbar.mindspark._brMembers_.successUrl", "http://www.hohosearch.com/chrome.php?uid=31B422787E95B03884E174EB6F99026D&ptid=amz&t
user_pref("extensions.toolbar.mindspark._brMembers_.toolbarCollapsed", false);
user_pref("extensions.toolbar.mindspark._brMembers_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._brMembers_.\"],\"file
user_pref("extensions.toolbar.mindspark.hp.enabled", false);
user_pref("extensions.toolbar.mindspark.lastInstalled", "yourGSearchfinder@GSearch.com");
---- Lines search.com removed from prefs.js ----
user_pref("browser.search.searchengine.hp", "http://www.hohosearch.com/?ts=AHEqA34lBn0mAU..&v=20160405&uid=31B422787E95B03884E174EB6F99026D&ptid=amz&m
user_pref("browser.search.searchengine.sp", "http://www.hohosearch.com/chrome.php?mode=ffsengext&ptid=amz&q={searchTerms}&ts=AHEqA34lBn0mAU..&uid=31B4
user_pref("browser.search.searchengine.url", "http://www.hohosearch.com/chrome.php?mode=ffsengext&ptid=amz&q={searchTerms}&ts=AHEqA34lBn0mAU..&uid=31B
---- Lines searchengine removed from prefs.js ----
user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine");
user_pref("browser.search.searchengine.ptid", "cor");
user_pref("browser.search.searchengine.uid", "ST500DM002-1BD142_Z2A9AEZLXXXXZ2A9AEZL");
---- Lines searches removed from prefs.js ----
user_pref("browser.urlbar.suggest.searches", true);
---- Lines offers removed from prefs.js ----
user_pref("fbsidebardisabler.au_script_cache", "{\"data\":\"/*\\n * SocialReviver - AutoUpdate JS code\\n * Copyright (C) 2013 VittGam.net. All rights
---- FireFox user.js and prefs.js backups ----

prefs_09.04.2016_2330_.backup
prefs_10.04.2016_1246_.backup

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default

user.js not found
---- Lines searchengine removed from prefs.js ----
user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine");
user_pref("browser.search.searchengine.ptid", "cor");
user_pref("browser.search.searchengine.uid", "ST500DM002-1BD142_Z2A9AEZLXXXXZ2A9AEZL");
---- Lines searches removed from prefs.js ----
user_pref("browser.urlbar.suggest.searches", true);
---- Lines offers removed from prefs.js ----
user_pref("fbsidebardisabler.au_script_cache", "{\"data\":\"/*\\n * SocialReviver - AutoUpdate JS code\\n * Copyright (C) 2013 VittGam.net. All rights
---- FireFox user.js and prefs.js backups ----

prefs_09.04.2016_2330_.backup
prefs_10.04.2016_1246_.backup

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726

user.js not found
---- Lines search.com removed from prefs.js ----
user_pref("browser.search.searchengine.hp", "http://www.hohosearch.com/?ts=AHEqA34lBn0mAU..&v=20160405&uid=31B422787E95B03884E174EB6F99026D&ptid=amz&m
user_pref("browser.search.searchengine.sp", "http://www.hohosearch.com/chrome.php?mode=ffsengext&ptid=amz&q={searchTerms}&ts=AHEqA34lBn0mAU..&uid=31B4
user_pref("browser.search.searchengine.url", "http://www.hohosearch.com/chrome.php?mode=ffsengext&ptid=amz&q={searchTerms}&ts=AHEqA34lBn0mAU..&uid=31B
---- Lines searchengine removed from prefs.js ----
user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine");
user_pref("browser.search.searchengine.ptid", "cor");
user_pref("browser.search.searchengine.uid", "ST500DM002-1BD142_Z2A9AEZLXXXXZ2A9AEZL");
---- Lines searches removed from prefs.js ----
user_pref("browser.urlbar.suggest.searches", true);
---- Lines offers removed from prefs.js ----
user_pref("fbsidebardisabler.au_script_cache", "{\"data\":\"/*\\n * SocialReviver - AutoUpdate JS code\\n * Copyright (C) 2013 VittGam.net. All rights
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 1);
---- FireFox user.js and prefs.js backups ----

prefs_09.04.2016_2330_.backup
prefs_10.04.2016_1246_.backup

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\urh1dwro.default-1406026697443

user.js not found
---- Lines searchengine removed from prefs.js ----
user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine");
user_pref("browser.search.searchengine.ptid", "cor");
user_pref("browser.search.searchengine.uid", "ST500DM002-1BD142_Z2A9AEZLXXXXZ2A9AEZL");
---- Lines offers removed from prefs.js ----
user_pref("fbsidebardisabler.au_script_cache", "{\"data\":\"/*\\n * SocialReviver - AutoUpdate JS code\\n * Copyright (C) 2013 VittGam.net. All rights
---- FireFox user.js and prefs.js backups ----

prefs_09.04.2016_2330_.backup
prefs_10.04.2016_1246_.backup

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Thunderbird\Profiles\tc0883kq.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_09.04.2016_2330_.backup
prefs_10.04.2016_1246_.backup

==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\hohosearchSoftware]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}]
[-HKEY_USERS\S-1-5-21-2145776392-1472050533-324974990-1000\Software\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}]

==== Deleting Files \ Folders ======================

C:\PROGRA~3\DivX deleted
C:\Users\Springfieldz0r\.android deleted
C:\PROGRA~2\GUM9247.tmp deleted
C:\PROGRA~2\RelevantKnowledge deleted
C:\NetworkCfg.xml deleted
C:\install.exe deleted
C:\found.000 deleted
C:\found.001 deleted
C:\Users\Springfieldz0r\AppData\Roaming\WB.CFG deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Springfieldz0r\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108 deleted
C:\Users\Springfieldz0r\AppData\Local\Software deleted
C:\Users\Springfieldz0r\AppData\Local\CrashRpt deleted
C:\Windows\SysNative\roboot64.exe deleted
C:\Users\Public\Documents\dmp deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Windows\Syswow64\lMMLDeleteUserData42107612FX.tmp deleted
C:\Windows\Syswow64\RENBD9E.tmp deleted
C:\Windows\SysWow64\AI_RecycleBin deleted
C:\Users\Springfieldz0r\Documents\Add-in Express deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\firefox@mega.co.nz.xpi deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\YourGSearchFinder_br deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\jetpack deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\firefox@mega.co.nz.xpi deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\YourGSearchFinder_br deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\jetpack deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\extensions\firefox@mega.co.nz.xpi deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\jetpack deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\jetpack deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\urh1dwro.default-1406026697443\jetpack deleted
C:\Users\SPRING~1\AppData\Roaming\Thunderbird\Profiles\tc0883kq.default\extensions\staged deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\fxdevtools-adapters@mozilla.org deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\fxdevtools-adapters@mozilla.org deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\extensions\fxdevtools-adapters@mozilla.org deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\extensions\fxdevtools-adapters@mozilla.org deleted
C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\urh1dwro.default-1406026697443\extensions\fxdevtools-adapters@mozilla.org deleted
"C:\Users\Springfieldz0r\AppData\Roaming\Displays" deleted
"C:\Users\Springfieldz0r\AppData\Roaming\Distortion" deleted
"C:\Users\Springfieldz0r\AppData\Roaming\Documentation" deleted
"C:\ProgramData\Drum Kits" deleted
"C:\ProgramData\Drums" deleted
"C:\ProgramData\Dynamic Library" deleted
"C:\ProgramData\External Build System" deleted
"C:\ProgramData\Filesystems" deleted
"C:\ProgramData\Filters" deleted
"C:\PROGRA~2\Firefox Developer Edition" deleted
"C:\PROGRA~2\Pro Evolution Soccer 2015" deleted

==== Orphaned Tasks deleted from Registry ======================

avast Emergency Update deleted
WinTaske deleted
{0B46DCB2-BAB3-445C-9FAD-DC88DBD31730} deleted
{40EA4C14-4399-4F8E-ACC2-8F4F407B5DA8} deleted
{8198D5AF-3598-455E-853C-26E0D45AEC29} deleted
{8905A320-EBF6-4345-8A5A-467374127DBA} deleted
{B349D370-2AA9-4C4A-8F7D-5691CA207040} deleted
{DD339D37-EBA3-40D0-8DCF-AAA0E4960E8D} deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\KompoZer\Profiles\1o1xsch7.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\urh1dwro.default-1406026697443
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Thunderbird\Profiles\tc0883kq.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [21.03.2016 12:53]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [21.03.2016 12:53]

==== Firefox Extensions ======================

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\KompoZer\Profiles\1o1xsch7.default
- Undetermined - %ProfilePath%\extensions\installed-extensions.txt
- KompoZer classic - %ProfilePath%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
- Qualys BrowserCheck - %ProfilePath%\extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D}
- Firebug - %ProfilePath%\extensions\firebug@software.joehewitt.com.xpi
- Awesome screenshot: Capture and Annotate - %ProfilePath%\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
- Web Developer - %ProfilePath%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
- Qualys BrowserCheck - %ProfilePath%\extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D}
- Firebug - %ProfilePath%\extensions\firebug@software.joehewitt.com.xpi
- Awesome screenshot: Capture and Annotate - %ProfilePath%\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
- Web Developer - %ProfilePath%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default
- Qualys BrowserCheck - %ProfilePath%\extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D}
- Firebug - %ProfilePath%\extensions\firebug@software.joehewitt.com.xpi
- Awesome screenshot: Capture and Annotate - %ProfilePath%\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
- Web Developer - %ProfilePath%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726
- Qualys BrowserCheck - %ProfilePath%\extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D}
- Firebug - %ProfilePath%\extensions\firebug@software.joehewitt.com.xpi
- Awesome screenshot: Capture and Annotate - %ProfilePath%\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
- Web Developer - %ProfilePath%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\SPRING~1\AppData\Roaming\Mozilla\Firefox\Profiles\urh1dwro.default-1406026697443
- Qualys BrowserCheck - %ProfilePath%\extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D}
- Firebug - %ProfilePath%\extensions\firebug@software.joehewitt.com.xpi
- Awesome screenshot: Capture and Annotate - %ProfilePath%\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
- Web Developer - %ProfilePath%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
57C7E359ED8D049132EED23EFA444C63 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll - Shockwave Flash

Profilepath: C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
57C7E359ED8D049132EED23EFA444C63 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll - Shockwave Flash

Profilepath: C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default
57C7E359ED8D049132EED23EFA444C63 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll - Shockwave Flash


==== Chromium Look ======================

Google Chrome Version: 46.0.2490.86

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[21.03.2016 11:34]

Avast Online Security - Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki

==== Chromium Fix ======================

C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_land.pckeeper.software_0.localstorage deleted successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_land.pckeeper.software_0.localstorage-journal deleted successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.safesidetabplussearch.com_0.localstorage deleted successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.safesidetabplussearch.com_0.localstorage-journal deleted successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.tv-newtabsearch.com_0.localstorage deleted successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.tv-newtabsearch.com_0.localstorage-journal deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] not found

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} - http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKCU\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

==== Uninstall List x64 ======================

ACDSee Pro [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F99F74B4-972B-4B06-B893-6B3B0DB0128B}]
Adobe Acrobat Reader DC [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}]
Adobe AIR [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7B77622E-DE90-48EA-B2C7-227B1DE58A01}]
Adobe AIR [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe AIR]
Adobe Creative Suite 6 Master Collection [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}]
Adobe Flash Player 21 NPAPI [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI]
Adobe Help Manager [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AF37176A-78CA-545B-34EF-8B6A21514DD1}]
Adobe Help Manager [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1]
Adobe Refresh Manager [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824166751}]
Adobe Widget Browser [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EFBE6DD5-B224-96E5-72B9-68D328CB12A6}]
Adobe Widget Browser [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\com.adobe.WidgetBrowser]
AMD Drag and Drop Transcoding [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{21A91999-0771-6ACA-BE64-23945C393CC0}]
AMD Fuel [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3F1E7228-4332-DC73-E002-7B2BA92CC744}]
AMD Install Manager [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F389A14F-B924-E628-4E4F-8D93AFB0215F}]
AMD Install Manager [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\AMD Catalyst Install Manager]
AMD Radeon Settings [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A239C6BD-191D-63FF-32C1-7832EC2BBBFF}]
AMD Settings - Branding [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{78ACE60E-0CB7-4935-BCD4-F33422105607}]
AMD Settings [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF2BFC1C-F47F-F92D-FC47-68281F76E707}]
AMD Wireless Display v3.0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{450F8249-9100-5CF2-1E65-72560F31CF2C}]
AMD Wireless Display v3.0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B2C674EE-E9C5-5360-DCF1-7318BB8B1E30}]
Andy OS [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Andy OS]
Apple Application Support [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{46F044A5-CE8B-4196-984E-5BD6525E361D}]
Apple Software Update [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}]
Aptana Studio 3 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Aptana Studio 3]
Avast Free Antivirus [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\avast]
AXIS Camera Management 4.00 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DB5112F7-9C59-4cc0-B10F-119FE07D38E8}_is1]
BIOS Code Unlocked Technology [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9B5FC5B-815A-4EE9-B7BF-08165F2A6A36}_is1]
Bit Che [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9DA5C41-964F-455F-B5E7-3664519440E8}_is1]
bl [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2A075BB4-E976-4278-BF3F-E5C6945D84C0}]
BlueStacks App Player [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3ED354A3-6E95-4EB3-B6D3-3120FDFAC1F1}]
Camtasia Studio 8 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DB93E2C2-851F-44B2-B09C-351D2C624AE1}]
Catalyst Control Center - Branding [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{11087D24-567D-7D88-69C6-D7A08B5F4C47}]
Catalyst Control Center Graphics Previews Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0242875E-C3AA-890C-DCAA-1277753843F0}]
Catalyst Control Center Localization All [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{344F42CB-1EA1-C4EF-CD05-D7E8C0E60950}]
Catalyst Control Center Next Localization BR [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{585A6A74-1DED-8DA0-32F1-F5EFA485DFB1}]
Catalyst Control Center Next Localization CHS [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A0649E20-C57C-DCFA-AE1B-1CE1CB9D98A8}]
Catalyst Control Center Next Localization CHT [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{35F79A5D-00E2-8C19-D929-2E85DEA4252D}]
Catalyst Control Center Next Localization CS [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2CEBB6AA-EC39-DFF2-1F5B-9A98301C4DAB}]
Catalyst Control Center Next Localization DA [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F05F0B6E-9999-55D0-C323-D06DF0E2B59F}]
Catalyst Control Center Next Localization DE [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CBABB5FD-BD69-8969-729A-5659E11D9518}]
Catalyst Control Center Next Localization EL [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{98527BF3-A8E0-B8CF-7297-436B714FC576}]
Catalyst Control Center Next Localization ES [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D6CD1B25-53E6-C2F8-FA99-F89138A9C86F}]
Catalyst Control Center Next Localization FI [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{487C3865-3005-F04A-FBA4-F4239E02A847}]
Catalyst Control Center Next Localization FR [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D80AD200-548C-B62B-32AE-BF3CD7AA7EA2}]
Catalyst Control Center Next Localization HU [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D21BFF5C-51AA-4C15-1C91-6A1087FDC373}]
Catalyst Control Center Next Localization IT [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{04F0FFCB-D9A5-2332-2697-CA47C0424AF2}]
Catalyst Control Center Next Localization JA [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{47F2FFDC-3D6A-CED6-0B54-6E7082D5B29B}]
Catalyst Control Center Next Localization KO [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5608D1B6-6483-9FA3-7297-C2CFC3FCE747}]
Catalyst Control Center Next Localization NL [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1FCA484A-5A9E-9C91-F050-257D1F311A0C}]
Catalyst Control Center Next Localization NO [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D8FB03AE-A326-0C12-AC47-B898FE73FA94}]
Catalyst Control Center Next Localization PL [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F7876D2E-CDCD-CE53-0E88-995B57A94B58}]
Catalyst Control Center Next Localization RU [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3BAB5AC8-EF35-FED0-BCEB-9306D05EDE1C}]
Catalyst Control Center Next Localization SV [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{746E086C-023A-A79C-DBE1-062E773FF6C8}]
Catalyst Control Center Next Localization TH [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1C44BB26-1941-DB44-D5E8-C455F89EE6E6}]
Catalyst Control Center Next Localization TR [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{BE7F26CB-6E91-7673-7130-80C36FBF13DE}]
ccc-utility64 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AB523759-18A4-A6BC-A362-5B0F018C7AED}]
CCC Help Chinese Standard [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D8A907CC-8BED-446F-DDC4-B91745EA3F2C}]
CCC Help Chinese Traditional [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4FF20269-9740-033E-E0D5-4A7442E3DD83}]
CCC Help Czech [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8A4C6664-7E90-2351-418E-9C405FE36CEE}]
CCC Help Danish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{19F67EF3-6A70-DBA0-50BF-53D3283F7A4B}]
CCC Help Dutch [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4EF08451-3646-8D00-661D-48C23DDB9BDC}]
CCC Help English [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{99E3762D-6928-8685-8397-DF0233A97A3F}]
CCC Help Finnish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{34354493-F94C-8820-660E-4FB1D8B2DB61}]
CCC Help French [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{83BF90EE-9829-76AF-B293-0D33286DB3AE}]
CCC Help German [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0E8A0593-66CA-A0C2-A5BE-FBBCA847EBFF}]
CCC Help Greek [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C1EDF12F-00D2-591A-5A68-9913F7E0DFE1}]
CCC Help Hungarian [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8F70CD84-C72E-3C40-3A0B-3A8A6A233D6B}]
CCC Help Italian [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D2DF4E94-60CF-4987-B12C-929E9BABFC18}]
CCC Help Japanese [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C249B794-3B22-8A1A-2131-8A9443EAE628}]
CCC Help Korean [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D43BE293-9E4F-73C9-B4AC-9AE8637DD57B}]
CCC Help Norwegian [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{123042AD-D0C1-7817-744B-FB6025A944D3}]
CCC Help Polish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5F71F763-7EF9-AB05-EDB2-0ABBF1494B97}]
CCC Help Portuguese [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92C148B-BE69-0F50-C8EB-E51444A07249}]
CCC Help Russian [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{475C262B-946E-7D71-7C59-68D3A35EA305}]
CCC Help Spanish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DB5FE0F8-1043-12BC-C960-7A7E6980EC48}]
CCC Help Swedish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{20B10861-44BD-813A-E5F4-8C6B2F2D27F3}]
CCC Help Thai [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E35DAC70-DEB6-4010-7A85-0AD54DD911CB}]
CCC Help Turkish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{314417F6-F1F3-A2F4-B7B0-90B9A372852D}]
CCleaner [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\CCleaner]
CDBurnerXP [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1]
Chess 2013 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Chess2013]
Chessmaster 10th Edition Demo [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9111CCEF-1675-48BC-BC5A-BD787A15713B}]
Chessmaster 10th Edition Demo [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{9111CCEF-1675-48BC-BC5A-BD787A15713B}]
Chessmaster Grandmaster Edition [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{27614800-84A9-484E-9CCB-43ED2F1205F5}]
Chessmaster Grandmaster Edition [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{27614800-84A9-484E-9CCB-43ED2F1205F5}]
Counter Strike v42 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Counter Strike v42]
CPUID CPU-Z 1.74 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\CPUID CPU-Z_is1]
CSS3 Menu [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CSS3 Menu_is1]
CureROM Pro 1.3.1 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CureROM]
D3DX10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E09C4DB7-630C-4F06-A631-8EA7239923AF}]
Dragonball Xenoverse [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Dragonball Xenoverse_is1]
Dropbox [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox]
EasyBCD 2.2 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD]
Extension Changer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Extension Changer]
f.lux [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Flux]
Farming Simulator 2013 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Farming Simulator 20132.0.0.9]
Firefox Developer Edition 44.0a2 (x86 en-US) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Developer Edition 44.0a2 (x86 en-US)]
Fraps (remove only) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Fraps]
Freemake Video Converter version 4.1.7 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Freemake Video Converter_is1]
GlassFish Server Open Source Edition 4.0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\nbi-glassfish-mod-4.0.0.89.0]
Google Chrome [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome]
Google Earth Pro [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{44FC61F0-2F8A-11E3-8CAE-B8AC6F97B88E}]
Google Update Helper [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}]
Google Update Helper [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}]
GRID Autosport [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GRID Autosport_R.G. Mechanics_is1]
HP USB Disk Storage Format Tool [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}]
HSPA USB MODEM [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MTel_ontenegro Imola HSPA USB MODEM_is1]
HWiNFO32 Version 4.12 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HWiNFO32_is1]
HxD Hex Editor version 1.7.7.0 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HxD Hex Editor_is1]
ICCup Launcher [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ICCup Launcher_is1]
ImgBurn [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ImgBurn]
IPTInstaller [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{08208143-777D-4A06-BB54-71BF0AD1BB70}]
Java 8 Update 65 (64-bit) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F86418065F0}]
Java 8 Update 65 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83218065F0}]
Java SE Development Kit 8 Update 31 (64-bit) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{64A3A4F4-B792-11D6-A78A-00B0D0180310}]
Java SE Development Kit 8 Update 5 (64-bit) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{64A3A4F4-B792-11D6-A78A-00B0D0180050}]
JDownloader 0.9 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\5513-1208-7298-9440]
JDownloader 2 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\jdownloader2]
Join Air [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}]
Junk Mail filter update [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{400C31E4-796F-4E86-8FDC-C3C4FACC6847}]
K-Lite Mega Codec Pack 11.3.6 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\KLiteCodecPack_is1]
Lenovo Smart Assistant 1.03 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VibeRomFlash]
LenovoUsbDriver 1.0.12 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\LenovoUsbDriver]
Malwarebytes Anti-Malware version 2.2.0.1024 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Malwarebytes Anti-Malware_is1]
MCShield ::Anti-Malware Tool:: [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MCShield]
Medieval 2 Total War Gold version 1.05 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8241AE65-BF38-4C3F-B0AF-6E9983A4516C}_is1]
Medjed-Skript [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Medjed-Skriptv1.5]
Microsoft .NET Framework 4.6.1 (???????) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1049]
Microsoft .NET Framework 4.6.1 (RUS) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{395723E7-7D0C-3045-BC96-5FCA1EEFCD11}]
Microsoft .NET Framework 4.6.1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033]
Microsoft .NET Framework 4.6.1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{BD6F5371-DAC1-30F0-9DDE-CAC6791E28C3}]
Microsoft Office Professional Plus 2013 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Office15.PROPLUS]
Microsoft Silverlight [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}]
Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}]
Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}]
Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}]
Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}]
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8220EEFE-38CD-377E-8595-13398D740ACE}]
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}]
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}]
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}]
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}]
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}]
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}]
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}]
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}]
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15134cb0-b767-4960-a911-f2d16ae54797}]
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}]
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{22154f09-719a-4619-bb71-5b3356999fbf}]
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}]
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}]
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{37B8F9C7-03FB-3253-8781-2517C99D7C00}]
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}]
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}]
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}]
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9}]
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}]
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}]
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{050d4fc8-5d48-4b8f-8972-47c82c46020f}]
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{929FBD26-9020-399B-9A7A-751D61F0B942}]
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}]
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}]
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}]
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}]
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)]
Microsoft_VC80_CRT_x86 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}]
Microsoft_VC90_CRT_x86 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{08D2E121-7F6A-43EB-97FD-629B44903403}]
Microsoft_VC90_MFC_x86 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}]
Microsoft_VC90_MFCLOC_x86 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B6D38690-755E-4F40-A35A-23F8BC2B86AC}]
mIRC [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\mIRC]
Motorola SM56 Speakerphone Modem [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\SMSERIAL]
Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5BABDA39-61CF-41EE-992D-4054B6649A9B}]
Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ED6C77F9-4D7E-447C-9EC0-9A212D075535}]
Mozilla Firefox 45.0.1 (x86 en-US) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 45.0.1 (x86 en-US)]
Mozilla Maintenance Service [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MozillaMaintenanceService]
Mozilla Thunderbird 38.6.0 (x86 en-US) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Thunderbird 38.6.0 (x86 en-US)]
MSI Live Update 6 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1]
MSI Super Charger [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1]
MSVCRT [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}]
MSVCRT Redists [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{24DB3A5E-0BC8-11E5-9A27-F04DA23A5C58}]
MSVCRT Redists [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6B00F0E1-2680-11E3-95F5-F04DA23A5C58}]
MSVCRT_amd64 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D0B44725-3666-492D-BEF6-587A14BD9BD9}]
MSVCRT110 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}]
MSVCRT110_amd64 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E9FA781F-3E80-4399-825A-AD3E11C28C77}]
MSXML 4.0 SP2 (KB954430) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}]
MSXML 4.0 SP2 (KB973688) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}]
MSXML 4.0 SP3 Parser (KB2758694) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}]
MSXML 4.0 SP3 Parser [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{196467F1-C11F-4F76-858B-5812ADC83B94}]
NetBeans IDE 7.4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\nbi-nb-base-7.4.0.0.201310111528]
Nik Collection [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Nik Collection]
Nikon Message Center 2 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B014EE44-9197-4513-9613-71E6EB1B514E}]
Nikon Movie Editor [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}]
Nitro Pro 9 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1325EE91-6AB4-4250-9780-8713FABBBD9A}]
Nitro Reader 3 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4436B9BD-CA66-4D69-9091-2D2EB62F09AD}]
Notepad++ [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++]
Opera Stable 36.0.2130.46 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Opera 36.0.2130.46]
PCSX2 - Playstation 2 Emulator [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\pcsx2-r5875]
PDF Settings CS6 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}]
ph [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{185F9795-9663-4F13-9EF9-307A282ADB5A}]
Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D888F114-7537-4D48-AF03-5DA9C82D7540}]
Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{30F99474-EBE3-4134-A02B-F6CD38CFE243}]
Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FC6C7107-7D72-41A1-A031-3CE751159BAB}]
Picture Control Utility 2 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D4893C47-704F-4B84-8486-9DE4974ACA6F}]
PlaysTV [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PlaysTV]
Pro Evolution Soccer 2015 Update v1.05 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\UHJvRXZvbHV0aW9uU29jY2VyMjAxNQ==_is1]
Pro Evolution Soccer 2016 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\UHJvRXZvbHV0aW9uU29jY2VyMjAxNg==_is1]
Professional Script v.5 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Professional Script v.5]
QuickTime 7 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}]
Raptr [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Raptr]
Realtek Ethernet Controller Driver [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}]
Realtek High Definition Audio Driver [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}]
RelevantKnowledge [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831}]
Rockstar Games Social Club [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Rockstar Games Social Club]
RT 7 Lite (64-Bit) [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\RT 7 Lite x64]
RT 7 Lite x64 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{DDEBB7D6-671C-468D-98EB-EF9F1A1BC524}]
Ruby 2.2.3-p173-x64 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A98E44F8-6401-400F-830E-B1A2919C22BD}_is1]
SafeZone Stable 1.48.2066.44 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SafeZone 1.48.2066.44]
SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\01_Simmental]
SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\02_Siberian]
SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\03_Swallowtail]
SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\04_semseyite]
SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\07_Schorl]
SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\09_Hsp]
SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\11_HSP_Plus_Default]
SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\16_Shrewsbury]
SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\20_NXP_Driver]
SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\24_flashusbdriver]
SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\25_escape]
SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}]
Setup - Pro Evolution Soccer 2015 (c) Konami ... [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Setup - Pro Evolution Soccer 2015 (c) Konami ...]
Skypet 7.21 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FC965A47-4839-40CA-B618-18F486F042C6}]
SpeedFan (remove only) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SpeedFan]
Steam [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Steam]
TeamSpeak 3 Client [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\TeamSpeak 3 Client]
TeamViewer 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\TeamViewer]
Teleport Pro [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Teleport Pro]
Topaz Adjust 5 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz Adjust 5]
Topaz B&W Effects [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz BW Effects 2]
Topaz Clarity [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz Clarity]
Topaz Clean 3 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz Clean 3]
Topaz DeJpeg 4 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz DeJpeg 4]
Topaz DeNoise 5 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz DeNoise 5]
Topaz Detail 3 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz Detail 3]
Topaz Fusion Express 2 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz Fusion Express 2]
Topaz InFocus [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz InFocus]
Topaz Lens Effects [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz Lens Effects]
Topaz ReMask 3 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz ReMask 3]
Topaz ReStyle [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz ReStyle]
Topaz Simplify 4 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz Simplify 4]
Topaz Star Effects [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Topaz Star Effects]
Total Commander 64-bit (Remove or Repair) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Totalcmd64]
TP-LINK Kablosuz ístemci Hizmet Programě [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{12C19B8A-992F-4BC9-8CB9-F19AE49C9DF4}]
TP-LINK Wireless Client Utility [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{71BF8787-A67D-4CBC-9155-22927199F4BB}]
USB Game Controller [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D3DF3D05-DE2A-476A-A384-08FCD58D9FE7}]
USB PC Camera VC305 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0305}]
UTFCast Express 1.0.5.22 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\UTFCast Express]
uTorrent [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
Vegas Pro 13.0 (64-bit) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1EEE0BEE-0BC8-11E5-A19E-F04DA23A5C58}]
Viber [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Viber]
ViewNX 2 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{635BE602-BB9C-4C59-8CC5-93F9366E8A21}]
VMware Player [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{57AA4E8A-E2C9-4F1C-B3F1-762C36E34472}]
VMware VIX [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F99FC179-EA67-4BBC-8955-BDDA0CB94B88}]
Winamp [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Winamp]
Windows 7 USB/DVD Download Tool [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CCF298AF-9CE1-4B26-B251-486E98A34789}]
Windows Live Communications Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0454BB9A-2A7A-4214-BDFF-937F7A711A44}]
Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C034A6F9-6569-491B-B3BF-F5D15221A708}]
Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite]
Windows Live Family Safety [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5F611ADA-B98C-4DBB-ADDE-414F08457ECF}]
Windows Live Family Safety [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7B0C5EF6-DE4C-4E20-8889-C17604FFE5CD}]
Windows Live ID Sign-in Assistant [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CE52672C-A0E9-4450-8875-88A221D5CD50}]
Windows Live Installer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}]
Windows Live Mail [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{70854FE6-3BF1-4C69-94D0-BEB821102E34}]
Windows Live Mail [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B80D3EA9-A252-4AE5-AC51-81729F5C586F}]
Windows Live Messenger [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1EA7C505-E6DA-4B85-9432-EBD3C70D510D}]
Windows Live Messenger [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F2235E5E-7881-4293-9B6F-04B2609FBFF0}]
Windows Live MIME IFilter [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F6822EFD-3F7D-4B35-8845-757A26AEC8E2}]
Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}]
Windows Live PIMT Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}]
Windows Live SOXE [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FE7C0B3D-50B9-4951-BE78-A321CBF86552}]
Windows Live SOXE Definitions [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}]
Windows Live UX Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4CCBD1F4-CEEC-452A-9CB8-46564B501315}]
Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{18272881-CFC0-434D-A975-E5BE44206AA0}]
Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86C40513-B5A4-476E-9EAB-EC118DCF4502}]
Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{97C79BEC-43F7-4BD8-A6A7-85C0257E488A}]
Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D2C146B1-948D-47EF-8387-5D1C6B980F7C}]
Windows Live Writer Resources [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{23A3E560-069F-4CFC-8F6C-1B526EC735FC}]
Windows Mobile Device Center [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}]
Windows Movie Maker 2.6 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}]
WinHTTrack Website Copier 3.48-6 (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinHTTrack Website Copier_is1]
WinRAR 5.20 (64-bit) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver]
WinSCP 5.7.7 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\winscp3_is1]
XAMPP [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\xampp]
Xilisoft Video Converter Ultimate [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Xilisoft Video Converter Ultimate]

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avichannel deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DelaypluginInstall deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MagicPlus_helper deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinFast Schedule deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinFastDTV deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Springfieldz0r\AppData\Local\Mozilla\Firefox\Profiles\41A66E7E5EE1\cache2 emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\cache2 emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\Cache emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Mozilla\Firefox\Profiles\n6br6t04.default-1449779373726\cache2 emptied successfully
C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\storage\default\https+++plus.google.com\cache emptied successfully
C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\storage\default\https+++plus.google.com\cache emptied successfully
C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\cache2 emptied successfully
C:\Users\Springfieldz0r\AppData\Roaming\Mozilla\Firefox\Profiles\ezmvm3rx.dev-edition-default\storage\default\https+++plus.google.com\cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Springfieldz0r\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=1596 folders=759 15415697924 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Springfieldz0r\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\SPRING~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on ned 10.04.2016 at 13:11:50,72 ======================

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Samo vremenom nagomilani ostatci, nista aktivno osim par unosa u prefs.js (Firefox).

Ovo sada izgleda cisto kao bebina guza. Ako je sve u redu, mozes uzdignute glave da napustis Ambulantu. Razz



Sledeća procedura će implementirati završno čišćenje.



Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.

Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;
Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.

Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Ukoliko neki alat ili izveštaj nije uklonjen, slobodno ih obriši ručno.


Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)
- Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
- DelFix briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2634
  • Gde živiš: Milan, Italy

Hvala, to je to. Very Happy

Ko je trenutno na forumu
 

Ukupno su 769 korisnika na forumu :: 32 registrovanih, 4 sakrivenih i 733 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Andrija357, antonije64, Apok, Arahne, aramis s, Areal84, ArmyBoss, Atomski čoban, ccoogg123, debeli, FileFinder, hologram, Kubovac, mercedesamg, Mercury, Metanoja, Miloskec, MiroslavD, Nemanja.M, nemkea71, NoOneEver Dreams, nuke92, operniki, panzerwaffe, pein, procesor, RJ, robert1979, Smiljke, vathra, |_MeD_|