ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=b962e3a3903a9f4abb3d57a83bc750a7 # engine=22467 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2015-02-14 09:59:40 # local_time=2015-02-14 10:59:40 (+0100, Romance (standaardtijd)) # country="Belgium" # lang=1033 # osver=6.2.9200 NT # compatibility_mode_1='AVG AntiVirus 2015' # compatibility_mode=1054 16777213 100 100 9608 111041964 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 104765 14212299 0 0 # scanned=467727 # found=116 # cleaned=92 # scan_time=9253 sh=B554C22F5C32BD884277F2E2E91716CB4FCFE7DE ft=1 fh=2ba75dedb1b48fd7 vn="MSIL/HackTool.IdleKMS.C potentially unsafe application" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\$PowerISO$\sources\$OEM$\$$\Setup\Scripts\KMSpico_setup.exe" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\52e536ef\lpghagnommdfnjpipcfphngegbiikkem\lsdb.js" sh=388DEB981CC4A0D8380ABD002826147868AE1672 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATL trojan" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\52e536ef\qjc@1FH0TAwg.net\content\bg.js" sh=1A1BDE40B1208AD53B8A147DA7EA1139F258CD06 ft=1 fh=de116e01b0463ee8 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\Install_11400\ins_geforce.exe" sh=FC593ACB08296597672A6972F85E9674E780391E ft=1 fh=fd737d266290fb0f vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\Install_11400\ins_sense.exe" sh=8E86F7A9FE35360199F97EA552BAE4BF77351F15 ft=1 fh=7070fc71bf0baeee vn="a variant of Win32/SpeedBit.D potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\Install_11400\ins_shopperpro.exe" sh=8444BB5429A9A7A14BDEF560D93D8E520EEA11D1 ft=1 fh=ab97d4f4985a8764 vn="a variant of Win32/SpeedBit.D potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\Install_11400\ins_ytd.exe" sh=E01EC50CF2EB21B095524A1ED4E168617265CD56 ft=1 fh=0f7a25d8de8c43e3 vn="Win32/VOPackage.AX potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\is45637729\170942_stp\Generic_vo.exe" sh=F866CAC8113D07AD16DF7B9DD8D2ED693D4C21AF ft=1 fh=d72caa47d9d6bfd5 vn="a variant of Win32/AdWare.SpeedingUpMyPC.N application" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\n1074\OptimizerProInstaller.exe" sh=F2934B7CC722826382A59D112412648F167D1880 ft=1 fh=37e32b8143a45256 vn="multiple threats" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\n1074\remarkit_0411-5abe4999.exe" sh=94BAC395699BCE4467B4E610DCA4032CFB6159F1 ft=1 fh=201a419fc3ba059d vn="a variant of MSIL/Solimba.B potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\n1074\s1074.exe" sh=0A7F32971CC0CF9B7AB67968F11BB73E49E81139 ft=1 fh=f748e00a5534bd16 vn="Win32/OutBrowse.BH potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\n1074\ShoppinHelper2_0511-681659e8.exe" sh=1FD165FA92A474FFEB2B4F3FC55D9A2E379C5F88 ft=1 fh=c55ee1fcf121ede7 vn="Win32/SmootherWeb.A potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\n1074\SmootherWeb_0909-20525fcb.exe" sh=E3B3AFD3CC20E22CF3E379B94A8966C16EC5D0BB ft=1 fh=24ce0c8a1105e0ed vn="Win32/VOPackage.AY potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\n1074\VOPackage.exe" sh=762E4A87A63BEC48288E2622CE28778C6AC82961 ft=1 fh=c3c9f24f78261136 vn="multiple threats" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Temp\n1629\wordproser_2110-9e9761dd.exe" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan" ac=I fn="C:\Windows.old\Users\niels\AppData\Local\Torch\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=9C5DD1AB90B3C7790BE3020B175F72F076858362 ft=0 fh=0000000000000000 vn="Win32/SmootherWeb.B potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Roaming\Mozilla\Firefox\Profiles\2z522wwm.default\extensions\jid1-U7omKQ6kQfxMaQ@jetpack.xpi" sh=917130B2D83370ABEFA5F9DD542C348CEEBFE802 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Roaming\Mozilla\Firefox\Profiles\2z522wwm.default\extensions\e2b0dff561784e3db84ed9e@2815a71a2f5d474691ed6bbee47c02.com\extensionData\plugins\91.js" sh=9C5DD1AB90B3C7790BE3020B175F72F076858362 ft=0 fh=0000000000000000 vn="Win32/SmootherWeb.B potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Roaming\SmootherWeb\jid1-U7omKQ6kQfxMaQ@jetpack.xpi" sh=0C53AD8C5815EC193F269B7F4225526331F55560 ft=1 fh=428351b47f1227d5 vn="Win32/SmootherWeb.A potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Roaming\SmootherWeb\SmootherWeb-Installer.exe" sh=E3B3AFD3CC20E22CF3E379B94A8966C16EC5D0BB ft=1 fh=24ce0c8a1105e0ed vn="Win32/VOPackage.AY potentially unwanted application" ac=I fn="C:\Windows.old\Users\niels\AppData\Roaming\VOPackage\VOPackage.exe" sh=E353872854EAD760ACA6E94DAE9A542559C1502E ft=0 fh=0000000000000000 vn="JS/Chromex.Agent.L trojan" ac=I fn="C:\zoek_backup\C_Users_niels_AppData_Local_Google_Chrome_User Data_Default_Extensions_eimhdmlhdgmboegnmecdnfbmdmhdoool\212\content.js" sh=E353872854EAD760ACA6E94DAE9A542559C1502E ft=0 fh=0000000000000000 vn="JS/Chromex.Agent.L trojan" ac=I fn="C:\zoek_backup\C_Users_niels_AppData_Local_Google_Chrome_User Data_Default_Extensions_ihkkeoeinpbomhnpkmmkpggkaefincbn\190\content.js" sh=FDFDF7EBCC99C24E59B1144B6C35544CD8CF7DDC ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application" ac=I fn="C:\zoek_backup\C_Users_niels_AppData_Roaming_Mozilla_Firefox_Profiles_wefebfo6.default_extensions_OIBMBKA115048682@HYKFIU97176590.com\extensionData\plugins\91.js" sh=3058C05E5DB4786A1F5725992C2174A2E5161728 ft=1 fh=e2410540b7b0eaa8 vn="Win64/HackKMS.A potentially unsafe application (deleted (after the next restart) - quarantined)" ac=C fn="C:\SppComApi.dll" sh=608C8B86A6C55901685D8A0048B6D2D40873358C ft=1 fh=99efc7fd26a6da65 vn="a variant of Win32/Toolbar.CrossRider.CB potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Internet Speed Checker\b87021ef-638f-43fb-ace2-bb8a536ab11d-4.exe.vir" sh=E94C3FC95CB298B26933191A5616CDAEE5B17298 ft=1 fh=ec6ba2e34c7adad4 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Internet Speed Checker\b87021ef-638f-43fb-ace2-bb8a536ab11d-5.exe.vir" sh=E4AA8B464C1E45C636F1988D5A90B818A475B579 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Internet Speed Checker\b87021ef-638f-43fb-ace2-bb8a536ab11d.xpi.vir" sh=22BD396655606373CFA57303AD7240E9A62A0090 ft=1 fh=0290c6fc16d4fe61 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Internet Speed Checker\Uninstall.exe.vir" sh=6DE18835E82E7CBABF4392EBF1B13E4436874BB0 ft=1 fh=4bc80f38be8acba1 vn="Win32/Packed.VMDetector.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Internet Speed Checker\utils.exe.vir" sh=0641D63D85DA4259B27FA455972E762B6FC04092 ft=1 fh=b7e7d2287abcc02c vn="a variant of Win32/ELEX.BH potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir" sh=1F39B64D658905D54F4D37DBCAEEA28F0602421B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\niels\AppData\Roaming\Mozilla\Firefox\Profiles\wefebfo6.default\Extensions\sepherdwilbur@aol.com\extensionData\plugins\91.js.vir" sh=5AD647C7C893E4B54107392BC371D5C793AB46C3 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\CinemaP-1.8cV08.02\c798df96-cd2a-49c9-9961-1149b076892c.xpi" sh=A551984913BB1EE8BBCFCBA59E47CEEBCFDDEE81 ft=1 fh=e28db627a643eaa2 vn="Win32/Packed.VMDetector.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\CinemaP-1.8cV08.02\utils.exe" sh=9DCA26C2CC95D1DFFD696676CD558EB8FDCA93F7 ft=1 fh=7673a422f7cbda88 vn="Win32/Patched.NFV trojan (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.94\chrome.dll" sh=74507D2AD5D69252167B682B5FA7E693E1AE0652 ft=1 fh=c644006b49a165d6 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\niels\Downloads\ccsetup502.exe" sh=ED09833A7905D6426427B40C8579B8D4979DAF31 ft=0 fh=0000000000000000 vn="a variant of Win32/Keygen.HY potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\niels\Downloads\Chris-PC.Game.Booster.2.60.rar" sh=A2CFD9F741B6DD3B59B8B024A1BB74061AB83FBF ft=1 fh=72c92fcb4c1374d3 vn="a variant of Win32/Toolbar.MyWebSearch.V potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\niels\Downloads\EliteUnzipSetup2.5.15.9.^BDG^man000^YYA^.exe" sh=F06208B2B323E41033E7ED0CC8C0C0D94F2A0160 ft=0 fh=0000000000000000 vn="a variant of Android/DroidRooter.AC potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\niels\Downloads\KingRootTrunk_105001.apk" sh=4BD3C4C36BF12121406CAF47D1F487E0DC5D3E8C ft=1 fh=0585296d087c6f3b vn="a variant of Win32/ClientConnect.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\niels\Downloads\PowerISO6-x64.exe" sh=3752853D16CE7FB5F0960840C223AC25A5239592 ft=1 fh=cb0b72f56444c592 vn="Win32/OpenCandy potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\niels\Downloads\Setup_GMABooster_21b_10092014(1).exe" sh=3752853D16CE7FB5F0960840C223AC25A5239592 ft=1 fh=cb0b72f56444c592 vn="Win32/OpenCandy potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\niels\Downloads\Setup_GMABooster_21b_10092014.exe" sh=64DC8BA5565C08EB7D20E87F59300167C8490F33 ft=0 fh=0000000000000000 vn="Win32/OutBrowse.BK potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\niels\Downloads\taiG_v1.2.zip" sh=78B63E23AA636DD5724ED20FED0F4D1EFBDB3282 ft=0 fh=0000000000000000 vn="a variant of MSIL/Riskware.HackTool.WinActivator.A application (deleted - quarantined)" ac=C fn="C:\Users\niels\Downloads\Windows_KMS_Activator_Ultimate_2015_v2.4.rar" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=1C350508A5401CB812FDB1842266214045FE8B52 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lpghagnommdfnjpipcfphngegbiikkem\5.2\lsdb.js" sh=D06FD528A0585068782945861D67672814140710 ft=0 fh=0000000000000000 vn="a variant of Win32/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\LPTInstaller.msi" sh=40278DCBBA6961CE2F571740A3CF16C8F4E7CFA9 ft=1 fh=74107cda7b6c8ebd vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\lrrot.dll" sh=9FDA6A85F87F806810F5E31B1CDED7C975E2EAE7 ft=1 fh=e3f325fe782690f8 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=6F5E24BACC073826EBE0274904A52307940A6AD7 ft=1 fh=e3117a35bf03c3d8 vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\smia.exe" sh=1831A138ED60AEE1E61D6581931194E774F0232D ft=1 fh=a8b0a279b496d3bc vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\smia64.exe" sh=6F6EF41A3FF7E4A9714B9B2BCE2F32A7AAC3E2E2 ft=1 fh=fdf83eda99ec04e8 vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\sppsm.dll" sh=CA4E1538A02EADD440BD0ABF925EC25F58E364D9 ft=1 fh=b6f71c311dbe7acb vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\spusm.dll" sh=32DB5F81C91CE0A3BC1943B868A370A4350B5A04 ft=1 fh=737e2a56703d79fc vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\srbs.dll" sh=385D13C3E63B0F4346B3C4F1F9649A04B30B392B ft=1 fh=bcce9affb6585c5c vn="a variant of MSIL/Toolbar.Linkury.F potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\srbu.dll" sh=73C1CAB488614B027DA143A02FB08A19873D300C ft=1 fh=232ac248da6ca285 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\srpt.dll" sh=5CC827427381A0D51CF00DD7F0B49764B08F94BD ft=1 fh=45c09d5b8bcb6169 vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\srptc.dll" sh=F1F65EC8F8657BBC82D4AF75253D1D525199D55C ft=1 fh=5d412254fa1b6d1a vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\srut.dll" sh=D09838E520AFAB1AC27A960E15A1E9E9A6011E2C ft=1 fh=0916a6d9a632f140 vn="a variant of Win32/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\Resources\ntdis_32.dll" sh=568DDC0708C8BD6983081D420074F2FB507A66A4 ft=1 fh=fcb5aef1ede86740 vn="a variant of Win64/Toolbar.Linkury.A.gen potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\LPT\Resources\ntdis_64.dll" sh=978F35019C60F3C10B11E5123AC50C18F89A5970 ft=1 fh=dfb5414546daa732 vn="a variant of Win32/SpeedBit.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BOBZ1Z3Q\ytdieobrdc_obrdc_setup[1].exe" sh=887F8A83AA9ED773788A7306E5A245508916B729 ft=1 fh=41a2dd068f35e5e3 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OQECEI26\setup[1].exe" sh=C80800625897FEEE82227BD17059F3454935AF49 ft=1 fh=7c4e6e7bec1fd2f8 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\Lrcnta.exe" sh=40278DCBBA6961CE2F571740A3CF16C8F4E7CFA9 ft=1 fh=74107cda7b6c8ebd vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\lrrot.dll" sh=A5DC4C86DD6CE113319A947980729BFE910601B0 ft=1 fh=ab1b14efd015115b vn="a variant of MSIL/Toolbar.Linkury.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\Smartbar.exe.unused" sh=EE1087F2B5E273783238105D0D65152DAF5F5CF2 ft=1 fh=6b772f4f78a9ecfa vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll" sh=F36F7B683773CAF024855C4F2DC8862488C9AE1F ft=1 fh=b8fc97b00cf46370 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll" sh=9AC835364714CCF6417241871B44CA81B33476AB ft=1 fh=57c47918558947b6 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ChromeLocalPlugin.dll" sh=EA83969B80DD6B8179DE8B01E2397DE7E2037D42 ft=1 fh=17b6be3c3093df84 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll" sh=63A462959EE3068BF9855D02D4FDFE6377DEB9A5 ft=1 fh=e2fc12b6aa680768 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll" sh=9FDA6A85F87F806810F5E31B1CDED7C975E2EAE7 ft=1 fh=e3f325fe782690f8 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=6B39A43EA6FA65F242E94DFD2D86A407575ACD36 ft=1 fh=649ebbda1db33372 vn="a variant of MSIL/Toolbar.Linkury.E potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll" sh=6B39A43EA6FA65F242E94DFD2D86A407575ACD36 ft=1 fh=649ebbda1db33372 vn="a variant of MSIL/Toolbar.Linkury.E potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll" sh=7138DAF263569A6A2A91740E6E443429C97ED0D5 ft=1 fh=538e8c6c0452ec5c vn="a variant of MSIL/Toolbar.Linkury.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll" sh=7138DAF263569A6A2A91740E6E443429C97ED0D5 ft=1 fh=538e8c6c0452ec5c vn="a variant of MSIL/Toolbar.Linkury.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll" sh=1831A138ED60AEE1E61D6581931194E774F0232D ft=1 fh=a8b0a279b496d3bc vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\smia64.exe" sh=370280D95E24D449093272F759C66467B03F665E ft=1 fh=142a562a9d9feaf4 vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\smsp.dll" sh=5A8DAADD707C2CE4BCF0CEE1D597E7FCE0A6C6B8 ft=1 fh=eb9390dbdb9d8218 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\smta.dll" sh=C7BE4B925C5B131AF88709CAEE956F017462B1A0 ft=1 fh=cebcbcd44ebe5e0e vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\smtu.dll" sh=C54F8E1D20982A1B3919CDCD453A9F101C7B76B2 ft=1 fh=ccdf89f67327b6a0 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\spbe.dll" sh=F6D4FF25986445B4643A4E73DADC1B5CD7C0EE0E ft=1 fh=b7bbca82034f292c vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\spbl.dll" sh=6F6EF41A3FF7E4A9714B9B2BCE2F32A7AAC3E2E2 ft=1 fh=fdf83eda99ec04e8 vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\sppsm.dll" sh=CA4E1538A02EADD440BD0ABF925EC25F58E364D9 ft=1 fh=b6f71c311dbe7acb vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\spusm.dll" sh=CC62E9FAD0D24FB79C68D6C6BD5FC22E571861AE ft=1 fh=dd43176da09cb4e3 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\srau.dll" sh=32DB5F81C91CE0A3BC1943B868A370A4350B5A04 ft=1 fh=737e2a56703d79fc vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\srbs.dll" sh=385D13C3E63B0F4346B3C4F1F9649A04B30B392B ft=1 fh=bcce9affb6585c5c vn="a variant of MSIL/Toolbar.Linkury.F potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\srbu.dll" sh=A55D6032B78270C1498F6095C54D11BE7728D79E ft=1 fh=69d504e7e9cec12c vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\srpu.dll" sh=F1F65EC8F8657BBC82D4AF75253D1D525199D55C ft=1 fh=5d412254fa1b6d1a vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\srut.dll" sh=CD8A7D845F06A8114F63F8D8DA5C82ED4848D423 ft=1 fh=e677a40728d32f51 vn="Win32/Toolbar.Linkury.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll" sh=227281F4DCCFC8653A4A047820304D41FD89ABA4 ft=1 fh=983236cd35c50d2d vn="a variant of Win32/Toolbar.Linkury.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_28.dll" sh=8420B6EEF70EF7DFA434B235C8535AA59D43B92D ft=1 fh=7a2c5825f22bcb1e vn="a variant of Win32/Toolbar.Linkury.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_29.dll" sh=2439E2766E261D37C53E00FCFDCDD9838D25F294 ft=1 fh=ca8e353c50d881e4 vn="a variant of Win32/Toolbar.Linkury.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_30.dll" sh=A2518A65796033B5109D1F37D71295375406D1D7 ft=1 fh=c29dbd558b672040 vn="a variant of Win32/Toolbar.Linkury.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_31.dll" sh=C2A55692F88113EAE1159A072560013E2061B043 ft=1 fh=c050c47c4a50ff01 vn="a variant of Win32/Toolbar.Linkury.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_32.dll" sh=136AD1E074847B7482FFA2E1A27C7E23C1A7876D ft=1 fh=1e3ed9e06f6cad16 vn="a variant of Win32/Toolbar.Linkury.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_33.dll" sh=887F8A83AA9ED773788A7306E5A245508916B729 ft=1 fh=41a2dd068f35e5e3 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Temp\1_Offer_11.exe" sh=C9D33707E5FC0982743F39EE855179B84BF7168B ft=1 fh=66229a9f84ccd5e5 vn="a variant of Win32/InstallCore.PK potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Temp\ICReinstall_nsg707A.tmp" sh=484007082EDDD811496B1E14B75BC8F7846E882F ft=1 fh=24af51a0081ef935 vn="a variant of Win32/OutBrowse.BA potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Temp\instructions.exe" sh=C9D33707E5FC0982743F39EE855179B84BF7168B ft=1 fh=66229a9f84ccd5e5 vn="a variant of Win32/InstallCore.PK potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Temp\nsg707A.tmp" sh=68B53E6C7C6DA98C863C424911BA547B9A3AA088 ft=1 fh=871fbe96a53e35ba vn="a variant of Win32/OptimizerEliteMax.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Temp\optprosetup.exe" sh=C4420C6E94B8CAACCB3811384280D8A93CB0A37D ft=1 fh=25f111c507a31a21 vn="Win32/Toolbar.Conduit.R potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Temp\SearchProtectINT.exe" sh=E68FD5E4FBB9DD65F1E70C99ACAF6E268D93811D ft=1 fh=7e16bbe87712933d vn="MSIL/Toolbar.Linkury.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Temp\Shop2.exe" sh=3DC75996D9D1FE8E0F5A7425C9FCC63B194554F2 ft=1 fh=9cf82d964e42c759 vn="a variant of Win32/SBWatchman.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Temp\tu17p84.exe" sh=52F3182E4CD4058D14AFD9E40B14FED9D9B1494B ft=1 fh=aa14e09e22f2a50f vn="a variant of Win32/OpenCandy.C potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Windows.old\Users\niels\AppData\Local\Temp\uttBDB.tmp"