[code] HitmanPro 3.7.15.281 www.hitmanpro.com Computer name . . . . : MARTYNA-MARTYNA Windows . . . . . . . : 6.1.1.7601.X64/4 User name . . . . . . : martyna-martyna\martyna UAC . . . . . . . . . : Enabled License . . . . . . . : Free Scan date . . . . . . : 2017-01-25 00:35:39 Scan mode . . . . . . : Normal Scan duration . . . . : 11m 20s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 4 Traces . . . . . . . : 79 Objects scanned . . . : 2 194 574 Files scanned . . . . : 52 771 Remnants scanned . . : 421 842 files / 1 719 961 keys Malware _____________________________________________________________________ C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\win32cert.dll Size . . . . . . . : 7 168 bytes Age . . . . . . . : 2.5 days (2017-01-22 13:19:03) Entropy . . . . . : 5.0 SHA-256 . . . . . : 667985D140FF2E4AB20FDF12F1F5195693E0AB32318827D446CA182CC311F1EE > Kaspersky . . . . : not-a-virus:WebToolbar.Win32.SearchSuite.a Fuzzy . . . . . . : 108.0 Forensic Cluster -7.1s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\igt9EFE.tmp.dir\ -7.1s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\igtA0DF.tmp.dir\ -7.1s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\ -7.1s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\config.dat -7.1s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\igtA0DF.tmp.dir\IEToolbar.dll -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\ -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\apnuserid.dat -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\appid.dat -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\dtx.ini -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\geodata.xml -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\guid.dat -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\setupCfg.xml -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\sysid.dat -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\trackid.dat -6.5s C:\AdwCleaner\quarantine\files\pedqmoxdfexvnelnkvgigdqtualgwxpr\ -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\installer\ -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\installer\ab.test.json -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\ -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\installer\tempfile.t -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\language\ -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\language\de.xml -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\language\en.xml -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\language\fr.xml -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\logs\ -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\scan_results\ -6.1s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\scan_results\aps.scan.quick.results -6.1s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\scan_results\aps.scan.results -6.1s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\swf\ -6.1s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\swf\mov01.swf -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\ -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\Shared\ -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\Shared\Delta.ico -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\CR\ -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\Shared\SetupParams.ini -3.9s C:\AdwCleaner\quarantine\files\bauvpxpdegkjfkymrrmdabucxvzpiypd\ -3.9s C:\AdwCleaner\quarantine\files\bauvpxpdegkjfkymrrmdabucxvzpiypd\log_file.txt -3.7s C:\AdwCleaner\quarantine\files\kcfqfjzvuxhvallpoyjwvqytiaekliif\ -3.7s C:\AdwCleaner\quarantine\files\kcfqfjzvuxhvallpoyjwvqytiaekliif\data -3.7s C:\AdwCleaner\quarantine\files\kcfqfjzvuxhvallpoyjwvqytiaekliif\license.rtf -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\ -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\UpdateProc\ -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\UpdateProc\config.dat -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\UpdateProc\info.dat -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\UpdateProc\src.dat -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\ -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\config.dat -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\gup_dt.dat -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\ -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\info.dat -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\STTL.DAT -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\TTL.DAT -3.1s C:\AdwCleaner\quarantine\files\muhmdvapasfsfbeazbsonrrgqhgqoyki\ -3.1s C:\AdwCleaner\quarantine\files\muhmdvapasfsfbeazbsonrrgqhgqoyki\995d85f6d641fe6a4151bb7353f4784e.logic.db -2.9s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\ -2.9s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\nengine.cookie -2.7s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\NENGINE.DLL -2.7s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\cache\ -2.7s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\cache\spark.bin -2.4s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\9B8EB9D39A324125BA571DA397070421\ -2.4s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\ -2.4s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\ADA4E2B058024DF0AD533B304E8BACDF\ -2.4s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\ADA4E2B058024DF0AD533B304E8BACDF\TuneUpUtilities2013_2200266_pl-PL.exe -2.0s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\B475FB05243643E394B1C833B7CA7CD8\ -2.0s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\OpenCandy_9B8EB9D39A324125BA571DA397070421\ -1.8s C:\AdwCleaner\quarantine\files\roefxxzuqpvduaxqvajiikdqxokgurso\ -1.6s C:\AdwCleaner\quarantine\files\xivpevzbmajyurgetsxfzewtigjshold\ -1.6s C:\AdwCleaner\quarantine\files\xivpevzbmajyurgetsxfzewtigjshold\995d85f6d641fe6a4151bb7353f4784e.data.db -1.6s C:\AdwCleaner\quarantine\files\xivpevzbmajyurgetsxfzewtigjshold\995d85f6d641fe6a4151bb7353f4784e.events.db -1.6s C:\AdwCleaner\quarantine\files\xivpevzbmajyurgetsxfzewtigjshold\995d85f6d641fe6a4151bb7353f4784e.user.db -1.5s C:\AdwCleaner\quarantine\files\htkgixdmfuiantrceqmkouyjqxxdywhq\ -1.0s C:\AdwCleaner\quarantine\files\amiaislgnprnvoqqqxchsuplogpzwukn\ -1.0s C:\AdwCleaner\quarantine\files\amiaislgnprnvoqqqxchsuplogpzwukn\APN-Stub\ -0.5s C:\AdwCleaner\quarantine\files\khsbhkwostkvwkrhkjwmnxozkafmrtvv\ -0.5s C:\AdwCleaner\quarantine\files\khsbhkwostkvwkrhkjwmnxozkafmrtvv\APN-Stub\ -0.4s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\ -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\osd.xml -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\Languages\ -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\Languages\en.ini -0.2s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\Languages\languages.cfg -0.2s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\Update\ -0.2s C:\AdwCleaner\quarantine\files\smlrhkhqrgtgteuuzkztvoumibxrbhay\ -0.1s C:\AdwCleaner\quarantine\files\zawfnkkzkpefauoaruuoskbnbcfchagr\ -0.1s C:\AdwCleaner\quarantine\files\hjncjhfrqrcmiofbkuxgaglmipaovqyy\ -0.0s C:\AdwCleaner\quarantine\files\eiibvdbdnzlxfrkufvnslskysqjnxrjl\ 0.0s C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\ 0.0s C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\win32cert.dll 0.0s C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\win32prop.dll 0.0s C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\win64prop.dll 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\ 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\products\FileFinder\uninstall\ 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\products\FileFinder\uninstall\uninstall.exe 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\products\FileFinder\ 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\products\ 0.4s C:\AdwCleaner\quarantine\files\peloflwaniejfgbmizspcxdblmmbqwkx\ 0.4s C:\AdwCleaner\quarantine\files\peloflwaniejfgbmizspcxdblmmbqwkx\CrashReports\ 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\ 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_AlphaFS.dll 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_GetText.dll 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_InstMgr.dll 0.8s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_LinqBridge.dll 0.8s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_MPCBClient.dll 0.9s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_Newtonsoft.Json.dll 1.0s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_ObjectListView.dll 1.0s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_Shared Stack.dll 1.4s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_Signup Wizard.exe 1.4s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_SignupWizard.dll 1.5s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_System.Data.SQLite.DLL 1.5s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_UnRegisterExtensions.exe 1.5s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\x64\ 1.5s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\x64\SQLite.Interop.dll 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\ 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\09300b3557168d79.fb 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\ 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\12cf70ec74eb3a36.fb 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\26c630d098e22dd5.fb 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\272512937d9e61a4.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\287204568329e189.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\28bc8f716fd76a47.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\2c53092c95605355.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\31a0997e9a5b5eb3.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\32c84fe32bb74d60.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\38bade7ddf884a44.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\3917078cb68ec657.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\45cf5d2512a4e923.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\4864606a6ccf1516.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\50557b302433e4e2.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\5432cde375cd99ac.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\590ba23ce359fd0c.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\5c87df8d04acbfbe.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\5f8564f9a80741b1.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\605c18c507a6eb5e.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\610289e025a3ee9a.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\651c5d3cdbfb8bd1.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\6c59ac5e7e7a3ad0.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\6d03dad1035885d3.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\8c8582f3690f8dc4.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\95f567698be8a182.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\9a5072c53cfb5ee2.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\a8556537add6dfc5.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\aa86d770685495b0.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\ad10a52aff5e038d.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\adb6d1f34514a611.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\ae543077a59ca096.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\c1fa887b03019701.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\c4d28dca2e7648be.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\c792bb43917c8dfd.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\c8f106ca16238b6b.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d201ef9910cd39de.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d2e94710a5708128.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d49e9a539b07ddcd.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d79b9dfe81484ec4.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d8b59175ed2a94b0.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\deff26ed26dcc2d8.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\e087b4009f1b83ee.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\e0de16f883bea794.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\f998975c9cc711ee.fb 2.7s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\fcc0d4a4e6d31c63.fb 2.8s C:\AdwCleaner\quarantine\files\tggqfwoibuqcqwivgmemetwbhjdcqieo.back 3.6s C:\AdwCleaner\quarantine\files\umzpjftndxsrmvshtilvkxjrqrpxhydj.back 3.7s C:\AdwCleaner\quarantine\files\uumvtjvwkxtymdeuimjpbdpgmqghmqkq.back 3.7s C:\AdwCleaner\quarantine\files\tlhzwjqzgmrlftsgrmylosrwcwnauxxj.back 3.7s C:\AdwCleaner\quarantine\files\ldsqeyuzokhaniluqnadyvggkrhytsdn.back 3.8s C:\AdwCleaner\quarantine\files\lwowdcvpazduccaiemnnhuzcllfnsydl.back 3.9s C:\AdwCleaner\quarantine\files\irqcjrsycmzxutgqhohaccgifxjuekmr.back C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\win32prop.dll Size . . . . . . . : 78 336 bytes Age . . . . . . . : 2.5 days (2017-01-22 13:19:03) Entropy . . . . . : 6.2 SHA-256 . . . . . : 9C12CB71E3DE326F71B2C64BFCC80E971BD0299CE36CD403563D69032ACBFFE1 > Kaspersky . . . . : not-a-virus:WebToolbar.Win32.SearchSuite.b Fuzzy . . . . . . : 108.0 Forensic Cluster -7.2s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\igt9EFE.tmp.dir\ -7.2s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\igtA0DF.tmp.dir\ -7.2s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\ -7.2s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\config.dat -7.1s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\igtA0DF.tmp.dir\IEToolbar.dll -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\ -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\apnuserid.dat -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\appid.dat -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\dtx.ini -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\geodata.xml -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\guid.dat -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\setupCfg.xml -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\sysid.dat -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\trackid.dat -6.5s C:\AdwCleaner\quarantine\files\pedqmoxdfexvnelnkvgigdqtualgwxpr\ -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\installer\ -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\installer\ab.test.json -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\ -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\installer\tempfile.t -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\language\ -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\language\de.xml -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\language\en.xml -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\language\fr.xml -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\logs\ -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\scan_results\ -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\scan_results\aps.scan.quick.results -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\scan_results\aps.scan.results -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\swf\ -6.1s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\swf\mov01.swf -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\ -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\Shared\ -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\Shared\Delta.ico -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\CR\ -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\Shared\SetupParams.ini -3.9s C:\AdwCleaner\quarantine\files\bauvpxpdegkjfkymrrmdabucxvzpiypd\ -3.9s C:\AdwCleaner\quarantine\files\bauvpxpdegkjfkymrrmdabucxvzpiypd\log_file.txt -3.8s C:\AdwCleaner\quarantine\files\kcfqfjzvuxhvallpoyjwvqytiaekliif\ -3.7s C:\AdwCleaner\quarantine\files\kcfqfjzvuxhvallpoyjwvqytiaekliif\data -3.7s C:\AdwCleaner\quarantine\files\kcfqfjzvuxhvallpoyjwvqytiaekliif\license.rtf -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\ -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\UpdateProc\ -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\UpdateProc\config.dat -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\UpdateProc\info.dat -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\UpdateProc\src.dat -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\ -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\config.dat -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\gup_dt.dat -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\ -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\info.dat -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\STTL.DAT -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\TTL.DAT -3.2s C:\AdwCleaner\quarantine\files\muhmdvapasfsfbeazbsonrrgqhgqoyki\ -3.1s C:\AdwCleaner\quarantine\files\muhmdvapasfsfbeazbsonrrgqhgqoyki\995d85f6d641fe6a4151bb7353f4784e.logic.db -3.0s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\ -3.0s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\nengine.cookie -2.7s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\NENGINE.DLL -2.7s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\cache\ -2.7s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\cache\spark.bin -2.5s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\9B8EB9D39A324125BA571DA397070421\ -2.5s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\ -2.4s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\ADA4E2B058024DF0AD533B304E8BACDF\ -2.4s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\ADA4E2B058024DF0AD533B304E8BACDF\TuneUpUtilities2013_2200266_pl-PL.exe -2.1s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\B475FB05243643E394B1C833B7CA7CD8\ -2.1s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\OpenCandy_9B8EB9D39A324125BA571DA397070421\ -1.8s C:\AdwCleaner\quarantine\files\roefxxzuqpvduaxqvajiikdqxokgurso\ -1.7s C:\AdwCleaner\quarantine\files\xivpevzbmajyurgetsxfzewtigjshold\ -1.7s C:\AdwCleaner\quarantine\files\xivpevzbmajyurgetsxfzewtigjshold\995d85f6d641fe6a4151bb7353f4784e.data.db -1.7s C:\AdwCleaner\quarantine\files\xivpevzbmajyurgetsxfzewtigjshold\995d85f6d641fe6a4151bb7353f4784e.events.db -1.7s C:\AdwCleaner\quarantine\files\xivpevzbmajyurgetsxfzewtigjshold\995d85f6d641fe6a4151bb7353f4784e.user.db -1.6s C:\AdwCleaner\quarantine\files\htkgixdmfuiantrceqmkouyjqxxdywhq\ -1.1s C:\AdwCleaner\quarantine\files\amiaislgnprnvoqqqxchsuplogpzwukn\ -1.0s C:\AdwCleaner\quarantine\files\amiaislgnprnvoqqqxchsuplogpzwukn\APN-Stub\ -0.6s C:\AdwCleaner\quarantine\files\khsbhkwostkvwkrhkjwmnxozkafmrtvv\ -0.6s C:\AdwCleaner\quarantine\files\khsbhkwostkvwkrhkjwmnxozkafmrtvv\APN-Stub\ -0.4s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\ -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\osd.xml -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\Languages\ -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\Languages\en.ini -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\Languages\languages.cfg -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\Update\ -0.2s C:\AdwCleaner\quarantine\files\smlrhkhqrgtgteuuzkztvoumibxrbhay\ -0.1s C:\AdwCleaner\quarantine\files\zawfnkkzkpefauoaruuoskbnbcfchagr\ -0.1s C:\AdwCleaner\quarantine\files\hjncjhfrqrcmiofbkuxgaglmipaovqyy\ -0.1s C:\AdwCleaner\quarantine\files\eiibvdbdnzlxfrkufvnslskysqjnxrjl\ -0.0s C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\ -0.0s C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\win32cert.dll 0.0s C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\win32prop.dll 0.0s C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\win64prop.dll 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\ 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\products\FileFinder\uninstall\ 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\products\FileFinder\uninstall\uninstall.exe 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\products\FileFinder\ 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\products\ 0.4s C:\AdwCleaner\quarantine\files\peloflwaniejfgbmizspcxdblmmbqwkx\ 0.4s C:\AdwCleaner\quarantine\files\peloflwaniejfgbmizspcxdblmmbqwkx\CrashReports\ 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\ 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_AlphaFS.dll 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_GetText.dll 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_InstMgr.dll 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_LinqBridge.dll 0.8s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_MPCBClient.dll 0.8s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_Newtonsoft.Json.dll 0.9s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_ObjectListView.dll 1.0s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_Shared Stack.dll 1.3s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_Signup Wizard.exe 1.4s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_SignupWizard.dll 1.4s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_System.Data.SQLite.DLL 1.5s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_UnRegisterExtensions.exe 1.5s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\x64\ 1.5s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\x64\SQLite.Interop.dll 2.0s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\ 2.0s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\09300b3557168d79.fb 2.0s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\ 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\12cf70ec74eb3a36.fb 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\26c630d098e22dd5.fb 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\272512937d9e61a4.fb 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\287204568329e189.fb 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\28bc8f716fd76a47.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\2c53092c95605355.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\31a0997e9a5b5eb3.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\32c84fe32bb74d60.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\38bade7ddf884a44.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\3917078cb68ec657.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\45cf5d2512a4e923.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\4864606a6ccf1516.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\50557b302433e4e2.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\5432cde375cd99ac.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\590ba23ce359fd0c.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\5c87df8d04acbfbe.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\5f8564f9a80741b1.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\605c18c507a6eb5e.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\610289e025a3ee9a.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\651c5d3cdbfb8bd1.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\6c59ac5e7e7a3ad0.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\6d03dad1035885d3.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\8c8582f3690f8dc4.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\95f567698be8a182.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\9a5072c53cfb5ee2.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\a8556537add6dfc5.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\aa86d770685495b0.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\ad10a52aff5e038d.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\adb6d1f34514a611.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\ae543077a59ca096.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\c1fa887b03019701.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\c4d28dca2e7648be.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\c792bb43917c8dfd.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\c8f106ca16238b6b.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d201ef9910cd39de.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d2e94710a5708128.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d49e9a539b07ddcd.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d79b9dfe81484ec4.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d8b59175ed2a94b0.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\deff26ed26dcc2d8.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\e087b4009f1b83ee.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\e0de16f883bea794.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\f998975c9cc711ee.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\fcc0d4a4e6d31c63.fb 2.8s C:\AdwCleaner\quarantine\files\tggqfwoibuqcqwivgmemetwbhjdcqieo.back 3.6s C:\AdwCleaner\quarantine\files\umzpjftndxsrmvshtilvkxjrqrpxhydj.back 3.6s C:\AdwCleaner\quarantine\files\uumvtjvwkxtymdeuimjpbdpgmqghmqkq.back 3.7s C:\AdwCleaner\quarantine\files\tlhzwjqzgmrlftsgrmylosrwcwnauxxj.back 3.7s C:\AdwCleaner\quarantine\files\ldsqeyuzokhaniluqnadyvggkrhytsdn.back 3.7s C:\AdwCleaner\quarantine\files\lwowdcvpazduccaiemnnhuzcllfnsydl.back 3.9s C:\AdwCleaner\quarantine\files\irqcjrsycmzxutgqhohaccgifxjuekmr.back C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\win64prop.dll Size . . . . . . . : 99 328 bytes Age . . . . . . . : 2.5 days (2017-01-22 13:19:03) Entropy . . . . . : 5.8 SHA-256 . . . . . : 21F70DD88AB67C3BA0A11F69DDA2BDBE58E7600F8393DF9B3D292F7DEFE8E7AF > Kaspersky . . . . : not-a-virus:WebToolbar.Win64.SearchSuite.b Fuzzy . . . . . . : 108.0 Forensic Cluster -7.2s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\igt9EFE.tmp.dir\ -7.2s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\igtA0DF.tmp.dir\ -7.2s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\ -7.2s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\config.dat -7.1s C:\AdwCleaner\quarantine\files\fofiojmbmhwdciiwqorjybzibctfnptm\igtA0DF.tmp.dir\IEToolbar.dll -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\ -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\apnuserid.dat -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\appid.dat -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\dtx.ini -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\geodata.xml -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\guid.dat -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\setupCfg.xml -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\sysid.dat -6.6s C:\AdwCleaner\quarantine\files\adwdmizyvnaeuloyabiwfamgahcycjvl\trackid.dat -6.5s C:\AdwCleaner\quarantine\files\pedqmoxdfexvnelnkvgigdqtualgwxpr\ -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\installer\ -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\installer\ab.test.json -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\ -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\installer\tempfile.t -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\language\ -6.3s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\language\de.xml -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\language\en.xml -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\language\fr.xml -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\logs\ -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\scan_results\ -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\scan_results\aps.scan.quick.results -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\scan_results\aps.scan.results -6.2s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\swf\ -6.1s C:\AdwCleaner\quarantine\files\bhoyhniuhsznezpxquoraaoguqypsyzs\swf\mov01.swf -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\ -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\Shared\ -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\Shared\Delta.ico -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\CR\ -4.1s C:\AdwCleaner\quarantine\files\wspzszmuhrudszlyldldfggazgtgqonm\Shared\SetupParams.ini -3.9s C:\AdwCleaner\quarantine\files\bauvpxpdegkjfkymrrmdabucxvzpiypd\ -3.9s C:\AdwCleaner\quarantine\files\bauvpxpdegkjfkymrrmdabucxvzpiypd\log_file.txt -3.8s C:\AdwCleaner\quarantine\files\kcfqfjzvuxhvallpoyjwvqytiaekliif\ -3.7s C:\AdwCleaner\quarantine\files\kcfqfjzvuxhvallpoyjwvqytiaekliif\data -3.7s C:\AdwCleaner\quarantine\files\kcfqfjzvuxhvallpoyjwvqytiaekliif\license.rtf -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\ -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\UpdateProc\ -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\UpdateProc\config.dat -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\UpdateProc\info.dat -3.5s C:\AdwCleaner\quarantine\files\ayzdqcrepfnonwhzkddsufzbgnvwkjey\UpdateProc\src.dat -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\ -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\config.dat -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\gup_dt.dat -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\ -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\info.dat -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\STTL.DAT -3.3s C:\AdwCleaner\quarantine\files\ownfpahrkmvrftkhxfuodowefkjiibeu\UpdateProc\TTL.DAT -3.2s C:\AdwCleaner\quarantine\files\muhmdvapasfsfbeazbsonrrgqhgqoyki\ -3.1s C:\AdwCleaner\quarantine\files\muhmdvapasfsfbeazbsonrrgqhgqoyki\995d85f6d641fe6a4151bb7353f4784e.logic.db -3.0s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\ -3.0s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\nengine.cookie -2.7s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\NENGINE.DLL -2.7s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\cache\ -2.7s C:\AdwCleaner\quarantine\files\tcodcwlprcdfbvsxvczteadanmupioku\cache\spark.bin -2.5s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\9B8EB9D39A324125BA571DA397070421\ -2.5s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\ -2.4s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\ADA4E2B058024DF0AD533B304E8BACDF\ -2.4s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\ADA4E2B058024DF0AD533B304E8BACDF\TuneUpUtilities2013_2200266_pl-PL.exe -2.1s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\B475FB05243643E394B1C833B7CA7CD8\ -2.1s C:\AdwCleaner\quarantine\files\xnisrvnqddeyoeyanjltonseamzohcxi\OpenCandy_9B8EB9D39A324125BA571DA397070421\ -1.8s C:\AdwCleaner\quarantine\files\roefxxzuqpvduaxqvajiikdqxokgurso\ -1.7s C:\AdwCleaner\quarantine\files\xivpevzbmajyurgetsxfzewtigjshold\ -1.7s C:\AdwCleaner\quarantine\files\xivpevzbmajyurgetsxfzewtigjshold\995d85f6d641fe6a4151bb7353f4784e.data.db -1.7s C:\AdwCleaner\quarantine\files\xivpevzbmajyurgetsxfzewtigjshold\995d85f6d641fe6a4151bb7353f4784e.events.db -1.7s C:\AdwCleaner\quarantine\files\xivpevzbmajyurgetsxfzewtigjshold\995d85f6d641fe6a4151bb7353f4784e.user.db -1.6s C:\AdwCleaner\quarantine\files\htkgixdmfuiantrceqmkouyjqxxdywhq\ -1.1s C:\AdwCleaner\quarantine\files\amiaislgnprnvoqqqxchsuplogpzwukn\ -1.0s C:\AdwCleaner\quarantine\files\amiaislgnprnvoqqqxchsuplogpzwukn\APN-Stub\ -0.6s C:\AdwCleaner\quarantine\files\khsbhkwostkvwkrhkjwmnxozkafmrtvv\ -0.6s C:\AdwCleaner\quarantine\files\khsbhkwostkvwkrhkjwmnxozkafmrtvv\APN-Stub\ -0.4s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\ -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\osd.xml -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\Languages\ -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\Languages\en.ini -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\Languages\languages.cfg -0.3s C:\AdwCleaner\quarantine\files\jlfhhogakzyymnkxfqzapgdxovvhwvjb\Update\ -0.2s C:\AdwCleaner\quarantine\files\smlrhkhqrgtgteuuzkztvoumibxrbhay\ -0.1s C:\AdwCleaner\quarantine\files\zawfnkkzkpefauoaruuoskbnbcfchagr\ -0.1s C:\AdwCleaner\quarantine\files\hjncjhfrqrcmiofbkuxgaglmipaovqyy\ -0.1s C:\AdwCleaner\quarantine\files\eiibvdbdnzlxfrkufvnslskysqjnxrjl\ -0.0s C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\ -0.0s C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\win32cert.dll 0.0s C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\win32prop.dll 0.0s C:\AdwCleaner\quarantine\files\eaqpjbllwlrtycyzzokmmrgtjobbzmwl\win64prop.dll 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\ 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\products\FileFinder\uninstall\ 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\products\FileFinder\uninstall\uninstall.exe 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\products\FileFinder\ 0.2s C:\AdwCleaner\quarantine\files\djqaabvmvekpwpbovejcnwsefhnrjzle\products\ 0.4s C:\AdwCleaner\quarantine\files\peloflwaniejfgbmizspcxdblmmbqwkx\ 0.4s C:\AdwCleaner\quarantine\files\peloflwaniejfgbmizspcxdblmmbqwkx\CrashReports\ 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\ 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_AlphaFS.dll 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_GetText.dll 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_InstMgr.dll 0.7s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_LinqBridge.dll 0.8s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_MPCBClient.dll 0.8s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_Newtonsoft.Json.dll 0.9s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_ObjectListView.dll 1.0s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_Shared Stack.dll 1.3s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_Signup Wizard.exe 1.4s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_SignupWizard.dll 1.4s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_System.Data.SQLite.DLL 1.5s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\DEL_UnRegisterExtensions.exe 1.5s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\x64\ 1.5s C:\AdwCleaner\quarantine\files\bewsitafspxhreoviwvrgalpubcnoyjl\x64\SQLite.Interop.dll 2.0s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\ 2.0s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\09300b3557168d79.fb 2.0s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\ 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\12cf70ec74eb3a36.fb 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\26c630d098e22dd5.fb 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\272512937d9e61a4.fb 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\287204568329e189.fb 2.1s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\28bc8f716fd76a47.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\2c53092c95605355.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\31a0997e9a5b5eb3.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\32c84fe32bb74d60.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\38bade7ddf884a44.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\3917078cb68ec657.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\45cf5d2512a4e923.fb 2.2s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\4864606a6ccf1516.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\50557b302433e4e2.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\5432cde375cd99ac.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\590ba23ce359fd0c.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\5c87df8d04acbfbe.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\5f8564f9a80741b1.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\605c18c507a6eb5e.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\610289e025a3ee9a.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\651c5d3cdbfb8bd1.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\6c59ac5e7e7a3ad0.fb 2.3s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\6d03dad1035885d3.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\8c8582f3690f8dc4.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\95f567698be8a182.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\9a5072c53cfb5ee2.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\a8556537add6dfc5.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\aa86d770685495b0.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\ad10a52aff5e038d.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\adb6d1f34514a611.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\ae543077a59ca096.fb 2.4s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\c1fa887b03019701.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\c4d28dca2e7648be.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\c792bb43917c8dfd.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\c8f106ca16238b6b.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d201ef9910cd39de.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d2e94710a5708128.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d49e9a539b07ddcd.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d79b9dfe81484ec4.fb 2.5s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\d8b59175ed2a94b0.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\deff26ed26dcc2d8.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\e087b4009f1b83ee.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\e0de16f883bea794.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\f998975c9cc711ee.fb 2.6s C:\AdwCleaner\quarantine\files\flpoudpjjofgmkutglwyfnrxmxlinvap\cache\fcc0d4a4e6d31c63.fb 2.8s C:\AdwCleaner\quarantine\files\tggqfwoibuqcqwivgmemetwbhjdcqieo.back 3.6s C:\AdwCleaner\quarantine\files\umzpjftndxsrmvshtilvkxjrqrpxhydj.back 3.6s C:\AdwCleaner\quarantine\files\uumvtjvwkxtymdeuimjpbdpgmqghmqkq.back 3.7s C:\AdwCleaner\quarantine\files\tlhzwjqzgmrlftsgrmylosrwcwnauxxj.back 3.7s C:\AdwCleaner\quarantine\files\ldsqeyuzokhaniluqnadyvggkrhytsdn.back 3.7s C:\AdwCleaner\quarantine\files\lwowdcvpazduccaiemnnhuzcllfnsydl.back 3.9s C:\AdwCleaner\quarantine\files\irqcjrsycmzxutgqhohaccgifxjuekmr.back C:\Users\martyna\AppData\Local\nsd24B6.tmp Size . . . . . . . : 628 496 bytes Age . . . . . . . : 728.3 days (2015-01-27 17:20:37) Entropy . . . . . : 7.9 SHA-256 . . . . . : BC1CAD335E1C72FE30330E6B6E0FFFE653185AC30A2DBDF7585E527CD3F37008 Product . . . . . : Online Backup! Publisher . . . . : CMI Limited Description . . . : Setup Version . . . . . : 1.0.0.4 RSA Key Size . . . : 2048 LanguageID . . . . : 0 Authenticode . . . : Valid > Kaspersky . . . . : not-a-virus:AdWare.NSIS.AnProt.b Fuzzy . . . . . . : 105.0 Suspicious files ____________________________________________________________ C:\Users\martyna\Downloads\FRST-OlderVersion\FRST64.exe Size . . . . . . . : 2 419 712 bytes Age . . . . . . . : 4.4 days (2017-01-20 14:48:00) Entropy . . . . . : 7.6 SHA-256 . . . . . : A6F5705974D580CD90356F383715E682E824FFE3E81E121AA97181C7CD7414AC Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Forensic Cluster -11.9s C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e85575b7ebdec2dd82c3116cbe4490a0_a80bf666-24ee-41df-bf36-494fc7368692 -11.9s C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c3da599de98c04641b38e65ce65d1765_a80bf666-24ee-41df-bf36-494fc7368692 -10.4s C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8c9e020d0291efc7e704e909c784c43a_a80bf666-24ee-41df-bf36-494fc7368692 -6.3s C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9fa19a156a7a701164a95017c5e4bc41_a80bf666-24ee-41df-bf36-494fc7368692 -3.3s C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6ccb648676d72d06575086ea11f03c91_a80bf666-24ee-41df-bf36-494fc7368692 -1.7s C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\efa5a5f48ba887d1955319b254d356cd_a80bf666-24ee-41df-bf36-494fc7368692 0.0s C:\Users\martyna\Downloads\FRST-OlderVersion\FRST64.exe C:\Users\martyna\Downloads\FRST64.exe Size . . . . . . . : 2 420 736 bytes Age . . . . . . . : 2.5 days (2017-01-22 13:29:18) Entropy . . . . . : 7.6 SHA-256 . . . . . : 945C56ADCD33C43D4D6954E99B4427C92C0528C797B08783CD9BE3E9D95A5299 Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Forensic Cluster 0.0s C:\Users\martyna\Downloads\FRST64.exe 1.4s C:\Users\martyna\Downloads\FRST-OlderVersion\ Potential Unwanted Programs _________________________________________________ C:\ProgramData\Datamngr\ (SearchQU) C:\ProgramData\Datamngr\coordinator.cfg (SearchQU) C:\ProgramData\Datamngr\general.cfg (SearchQU) C:\ProgramData\Datamngr\S-1-5-21-2411782107-2092081716-956027298-1000.cfg (SearchQU) C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data (Claro) C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences (Claro) C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\ (Sweetpacks) C:\Users\martyna\AppData\LocalLow\DataMngr\ (SearchQU) C:\Users\martyna\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED} (SearchQU) C:\Users\martyna\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED}64 (SearchQU) C:\Users\martyna\AppData\LocalLow\Delta\ (Delta Search) C:\Users\martyna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FoxTab FLV Player\ (FLV Player) C:\Users\wangzhisong\AppData\Local\Mobogenie\ (Rocketfuel) HKLM\SOFTWARE\Classes\delta.deltadskBnd.1\ (Delta Search) HKLM\SOFTWARE\Classes\delta.deltadskBnd\ (Delta Search) HKLM\SOFTWARE\Classes\delta.deltaHlpr.1\ (Delta Search) HKLM\SOFTWARE\Classes\delta.deltaHlpr\ (Delta Search) HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}\ (Sweetpacks) HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}\ (Sweetpacks) HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}\ (Sweetpacks) HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}\ (Sweetpacks) HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622\ (Linkey) HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622\ (Linkey) HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622\ (Linkey) HKU\.DEFAULT\Software\SuperPlusRadio v2.1-nv\ (SuperPlusRadio) HKU\S-1-5-18\Software\SuperPlusRadio v2.1-nv\ (SuperPlusRadio) HKU\S-1-5-21-2411782107-2092081716-956027298-1000\Software\Classes\.torrent\iLivid.torrent_backup (iLivid) HKU\S-1-5-21-2411782107-2092081716-956027298-1000\Software\DM\ (SearchQU) HKU\S-1-5-21-2411782107-2092081716-956027298-1000\Software\IM\ (Sweetpacks) HKU\S-1-5-21-2411782107-2092081716-956027298-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B} (Claro) HKU\S-1-5-21-2411782107-2092081716-956027298-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} (Claro) HKU\S-1-5-21-2411782107-2092081716-956027298-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC} (Claro) HKU\S-1-5-21-2411782107-2092081716-956027298-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115} (iLivid) HKU\S-1-5-21-2411782107-2092081716-956027298-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\Mobogenie\ (Rocketfuel) HKU\S-1-5-21-2411782107-2092081716-956027298-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QSqlDriverFactoryInterface:\C:\Program Files (x86)\Mobogenie\ (Rocketfuel) HKU\S-1-5-21-2411782107-2092081716-956027298-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files (x86)\Mobogenie\ (Rocketfuel) HKU\S-1-5-21-2411782107-2092081716-956027298-1000_Classes\.torrent\iLivid.torrent_backup (iLivid) Cookies _____________________________________________________________________ C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:1982700803.log.optimizely.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:262855726.log.optimizely.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:acxiom-online.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:addthis.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:adnxs.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:adsymptotic.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:bidswitch.net C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:bluekai.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:crwdcntrl.net C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:demdex.net C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:dotomi.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:dpclk.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:dpm.demdex.net C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:googleadservices.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:igodigital.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:imrworldwide.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:krxd.net C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:lijit.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:mathtag.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:ml314.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:optimizely.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:outbrain.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:owneriq.net C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:rfihub.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:rlcdn.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:scorecardresearch.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:skimresources.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:stat.4u.pl C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:taboola.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.egokick.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:tradedoubler.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:trc.taboola.com C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:w55c.net C:\Users\martyna\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com [/code]