chromesearch.win

Sekce věnovaná virům a jiným škodlivým kódům, rovněž ale nástrojům, kterým se lze proti nim bránit…

Moderátoři: Mods_senior, Security team

FilipS8
nováček
Příspěvky: 12
Registrován: červen 17
Pohlaví: Muž
Stav:
Offline

Re: chromesearch.win

Příspěvekod FilipS8 » 21 pro 2017 00:02

Zoek.exe v5.0.0.1 Updated 24-October-2017
Tool run by Filip on st 20.12.2017 at 21:47:33,03.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\Filip\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2016-04-05-152939.log 6876 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-4008928030-887218692-4198466271-1001\Software\Mozilla\Firefox\Extensions\acewebextension_unlisted@acestream.org deleted successfully

==== FireFox Fix ======================

Deleted from C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\91vafkhh.default\prefs.js:

Added to C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\91vafkhh.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\91vafkhh.default

user.js not found
---- Lines acewebextension_unlisted@acestream.org removed from prefs.js ----
user_pref("extensions.webextensions.uuids", "{\"acewebextension_unlisted@acestream.org\":\"36995df5-02ce-4027-969d-42ee4513d286\",\"screenshots@mozill
---- FireFox user.js and prefs.js backups ----

prefs_20.12.2017_2246_.backup

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\91vafkhh.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

ProfilePath: C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\91vafkhh.default
- Undetermined - %ProfilePath%\extensions\sp@avast.com.xpi
- Undetermined - %ProfilePath%\extensions\wrc@avast.com.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\91vafkhh.default
FC18E6D133877BE07C753552705A5B8C - c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll - Silverlight Plug-In
81D6D6EE6226773449C5CBE9496EDAF6 - c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrlui.dll - Microsoft® Silverlight
CAA6D1B8F2E65BA4FFF0475251DD61E4 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U79
541B88FA55CD21F749F0B6A4F5B1A796 - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.790.15


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{65201E49-5A37-42D0-BEF2-CDB10628E5B7}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - No_Url_Value
HKLM\SearchScopes\{65201E49-5A37-42D0-BEF2-CDB10628E5B7} - http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{65201E49-5A37-42D0-BEF2-CDB10628E5B7}"
HKLM\Wow6432Node\SearchScopes\{65201E49-5A37-42D0-BEF2-CDB10628E5B7} - http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE11

==== Reset Google Chrome ======================

C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Filip\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Filip\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Filip\AppData\Local\Mozilla\Firefox\Profiles\91vafkhh.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=738 folders=1090 2622165739 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Filip\AppData\Local\Temp will be emptied at reboot
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\windows\Temp successfully emptied
C:\Users\Filip\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on st 20.12.2017 at 22:52:14,80 ======================


Zemana AntiMalware 2.74.2.150 (inštalačná verzia)

-------------------------------------------------------
Scan Result : Dokončené
Scan Date : 2017.12.20
Operating System : Windows 8.1 64-bit
Processor : 4X AMD QC-4000
BIOS Mode : UEFI
CUID : 12B7192AAF779E82D074CA
Scan Type : Kontrola systému
Duration : 60m 0s
Scanned Objects : 244663
Detected Objects : 6
Excluded Objects : 0
Read Level : SCSI
Auto Upload : Zapnuté
Detect All Extensions : Vypnuté
Scan Documents : Vypnuté
Domain Info : WORKGROUP,0,2

Detected Objects
-------------------------------------------------------

Chrome Policy
Status : Skontrolované
Object : https://newtab.today/?ei=sTMyGCjMgxlsXc ... 1tDliYEKbq
MD5 : -
Publisher : -
Size : -
Version : -
Detection : Podozrivé nastavenie prehliadača
Cleaning Action : Opraviť
Related Objects :
Nastavenie prehliadača - Chrome Policy

Chrome Policy
Status : Skontrolované
Object : Web
MD5 : -
Publisher : -
Size : -
Version : -
Detection : Podozrivé nastavenie prehliadača
Cleaning Action : Opraviť
Related Objects :
Nastavenie prehliadača - Chrome Policy

Chrome Policy
Status : Skontrolované
Object : {google:baseURL}complete/search?output=chrome&q={searchTerms}
MD5 : -
Publisher : -
Size : -
Version : -
Detection : Podozrivé nastavenie prehliadača
Cleaning Action : Opraviť
Related Objects :
Nastavenie prehliadača - Chrome Policy

Chrome Policy
Status : Skontrolované
Object : https://chromesearch.win/search/?q={searchTerms}&uid=sTMyGCjMgxlsXc%2FaIudv7IKM%2Fye8Af1eHKtFQ%2Fi0JFnWDJNKLqJKtUn5L2xMPjlYWJY93I9eJh125gVjiS1tDliYEKbq&pid=fob
MD5 : -
Publisher : -
Size : -
Version : -
Detection : Podozrivé nastavenie prehliadača
Cleaning Action : Opraviť
Related Objects :
Nastavenie prehliadača - Chrome Policy

wrc@avast.com
Status : Skontrolované
Object : %appdata%\mozilla\firefox\profiles\91vafkhh.default\extensions\wrc@avast.com.xpi
MD5 : 904CC438CF06B7697F59FE962D612781
Publisher : -
Size : 707252
Version : -
Detection : PUA.FirefoxExt!Gr
Cleaning Action : Opraviť
Related Objects :
Rozšírenie prehliadača - wrc@avast.com
Súbor - %appdata%\mozilla\firefox\profiles\91vafkhh.default\extensions\wrc@avast.com.xpi

Microsoft Excel 2007.exe
Status : Skontrolované
Object : %userprofile%\downloads\microsoft office 2007 portable\microsoft excel 2007.exe
MD5 : 70361EEFF66DA73D88FB6A424B3A42C8
Publisher : -
Size : 39247
Version : 12.0.4518.1014
Detection : Malware:Win32/Fitzia.A!Eelt
Cleaning Action : Karanténa
Related Objects :
Súbor - %userprofile%\downloads\microsoft office 2007 portable\microsoft excel 2007.exe


Cleaning Result
-------------------------------------------------------
Cleaned : 6
Reported as safe : 0
Failed : 0



Zeman to odstránil díky :)

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: chromesearch.win

Příspěvekod jaro3 » 21 pro 2017 09:07

Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “Viry, antiviry, firewally…”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 1 host