prosím o kontrolu, děkuji

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

fulldragons
Level 1.5
Level 1.5
Příspěvky: 100
Registrován: listopad 14
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu, děkuji

Příspěvekod fulldragons » 16 lis 2014 12:34

zoek



Zoek.exe v5.0.0.0 Updated 16-November-2014
Tool run by Filip on ne 16.11.2014 at 12:02:04,93.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\mamka\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32004B8A-44A9-43E7-84E9-808838809519} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1024F1BE-76DC-40d5-AB98-664A4185E5FA} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1024F1BE-76DC-40d5-AB98-664A4185E5FA} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Internet Explorer\Approved Extensions\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\{5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\2amijf40.default\prefs.js:

Added to C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\2amijf40.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\e9u02blj.default\prefs.js:
user_pref("browser.newtab.url", "");
user_pref("browser.search.defaultenginename", "Yahoo! Search");
user_pref("browser.search.selectedEngine", "Yahoo! Search");
user_pref("keyword.URL", "");

Added to C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\e9u02blj.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\2amijf40.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_16.11.2014_1218_.backup

ProfilePath: C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\e9u02blj.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_16.11.2014_1218_.backup

==== Deleting Files \ Folders ======================

C:\PROGRA~3\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} deleted
C:\PROGRA~3\{55A29068-F2CE-456C-9148-C869879E2357} deleted
C:\PROGRA~3\{BD8912D9-3040-46C4-B96A-4C3AC7E43486} deleted
C:\PROGRA~3\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} deleted
C:\PROGRA~3\28150 deleted
C:\PROGRA~3\3262 deleted
C:\PROGRA~3\OneKey Recovery deleted
C:\PROGRA~3\DivX deleted
C:\Users\Filip\.android deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\PROGRA~2\Solibo Ltd deleted
C:\PROGRA~2\Denzi deleted
C:\PROGRA~2\Wondershare deleted
C:\PROGRA~2\COMMON~1\Wondershare deleted
C:\found.000 deleted
C:\PROGRA~3\boost_interprocess deleted
C:\Users\Filip\AppData\Local\speeddial.crx deleted
C:\Users\Filip\AppData\Local\Wondershare deleted
C:\Users\Filip\AppData\Local\cache deleted
C:\Users\mamka\AppData\Local\Wondershare deleted
C:\Users\mamka\AppData\Local\cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solibo Ltd deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare deleted
C:\Users\Public\AlexaNSISPlugin.10192.dll deleted
C:\Users\Filip\Downloads\SweetIMSetup (1).exe deleted
C:\Users\Filip\Downloads\SweetIMSetup.exe deleted
C:\Users\Filip\Downloads\iMeshV11.exe deleted
C:\windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted
C:\windows\SysNative\tasks\ProtectedSearch deleted
C:\windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\windows\Syswow64\GroupPolicy\Machine deleted
C:\windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\e9u02blj.default\searchplugins\keepmysearch.xml deleted
C:\Users\Filip\Desktop\CENZURA HD.lnk deleted
C:\Users\Filip\AppData\Roaming\cerver.exe deleted
C:\Users\Filip\AppData\Roaming\MacroRecorderSetup.exe deleted
"C:\Users\Filip\AppData\Roaming\systempref" deleted
"C:\Users\Filip\AppData\Roaming\Sony" deleted
"C:\Users\Filip\AppData\Roaming\Toggle" deleted
"C:\Users\Filip\AppData\Roaming\WinDbg" deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [13.11.2014 22:41]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\2amijf40.default
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- Surftastic - %ProfilePath%\extensions\{01531192-f7ef-415f-a549-cfdb11836731}.xpi

ProfilePath: C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\e9u02blj.default
- McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- YouTube Video Downloader Lite - %ProfilePath%\extensions\cccc5f0d-b9d0-4314-88b5-7e27551f9e84@jetpack.xpi
- YouTube Video and Audio Downloader - %ProfilePath%\extensions\feca4b87-3be4-43da-a1b1-137c24220968@jetpack.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi

==== Firefox Plugins ======================


==== Deleted Firefox Extensions ======================

C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\2amijf40.default\extensions\{01531192-f7ef-415f-a549-cfdb11836731}.xpi deleted

==== Fake Chromium Profiles Check ======================

Fake profile C:\windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome deleted

==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
apgjagobplilmcdfelodhgefiidomnfl - C:\Program Files (x86)\Inbox Toolbar\Chrome\ibxtoolbar_chr.crx[]
bpgmjapfkjpfkeffiijiebgjhikjogem - C:\Program Files (x86)\Toggle\toggle\1.8.16.4\toggle.crx[01.03.2013 09:39]
ccoepcadgihicpglkgajnpfdconkafam - C:\Program Files (x86)\OApps\chrome-sl.crx[]
ddkpepdilbfaccbiljmaflabkcbgjfin - C:\Program Files (x86)\Search Results Toolbar\Datamngr\chromeExtension.crx[]
fheoggkfdfchfphceeifdbepaooicaho - No path found[]

Toggle Chrome Toolbar - Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpgmjapfkjpfkeffiijiebgjhikjogem
SiteAdvisor - Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho
Surftastic - Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkbhmdcccmdakmgaaejjjgllahmljpge
Seznam Lištička - Email - mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Toggle Chrome Toolbar - mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpgmjapfkjpfkeffiijiebgjhikjogem
Select Links App - mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccoepcadgihicpglkgajnpfdconkafam
SiteAdvisor - mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho
Seznam Lištička - Rychlá volba - mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak
Ghostery - mamka\AppData\Roaming\Opera Software\Opera Stable\Extensions\bbkekonodcdmedgffkkbgmnnekbainbg
Stylish - mamka\AppData\Roaming\Opera Software\Opera Stable\Extensions\bofnhkejmonldphklejelehlhhoecceg
Documents - mamka\AppData\Roaming\Opera Software\Opera Stable\Extensions\dppmcfgmeabflhohikbaegalkbjnbomd
Youtube to mp3 converter - mamka\AppData\Roaming\Opera Software\Opera Stable\Extensions\geioidjhliialbjcekeejcodiahfplgb
Notepad - mamka\AppData\Roaming\Opera Software\Opera Stable\Extensions\pcnbmpliiimnocdfegpdnjfeflibmgbi

==== Chromium Startpages ======================

C:\Users\mamka\AppData\Roaming\Opera Software\Opera Stable\Preferences
"startup_urls": [ "http://google.com/" ],


==== Chromium Fix ======================

C:\Program Files (x86)\Toggle\toggle\1.8.16.4\toggle.crx deleted successfully
C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_isearch.avg.com_0.localstorage deleted successfully
C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_isearch.avg.com_0.localstorage-journal deleted successfully
C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccoepcadgihicpglkgajnpfdconkafam deleted successfully
C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho deleted successfully
C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho deleted successfully
C:\Users\mamka\AppData\Roaming\Opera Software\Opera Stable\Extensions\dppmcfgmeabflhohikbaegalkbjnbomd deleted successfully
C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpgmjapfkjpfkeffiijiebgjhikjogem deleted successfully
C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpgmjapfkjpfkeffiijiebgjhikjogem deleted successfully
C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkbhmdcccmdakmgaaejjjgllahmljpge deleted successfully
C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mkbhmdcccmdakmgaaejjjgllahmljpge_0.localstorage deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN"
"Search Page"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Search Page"="http://www.google.com"
"Start Default_Page_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Search Page"="http://www.google.com"
"Start Default_Page_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.certified-toolbar.com?si=41460&st=bs&tid=2938&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.certified-toolbar.com?si=41460&st=bs&tid=2938&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.certified-toolbar.com?si=41460&st=bs&tid=2938&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.certified-toolbar.com?si=41460&st=bs&tid=2938&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.certified-toolbar.com?si=41460&st=bs&tid=2938&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.certified-toolbar.com?si=41460&st=bs&tid=2938&q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"=""
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search]
"Start Page"="http://search.certified-toolbar.com?si=41460&st=home&tid=2938"
"Start Default_Page_URL"="http://search.certified-toolbar.com?si=41460&st=home&tid=2938"
"Default_Search_URL"="http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q="
"Search Bar"="http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q="
"Search Page"="http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search]
"Start Page"="http://search.certified-toolbar.com?si=41460&st=home&tid=2938"
"Start Default_Page_URL"="http://search.certified-toolbar.com?si=41460&st=home&tid=2938"
"Default_Search_URL"="http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q="
"Search Bar"="http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q="
"Search Page"="http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q="
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Start Page"="http://www.google.com"
"Start Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"Start Page"="http://www.google.com"
"Start Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Start Page"="http://www.google.com"
"Start Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{9BB47C17-9C68-4BB3-B188-DD9AF0FD2002}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2002}] not found

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7LENN_csCZ463"

==== Reset Google Chrome ======================

C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\mamka\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\mamka\AppData\Roaming\Opera Software\Opera Stable\Web Data was reset successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87E90E67-8655-4548-B037-03BA1158A487} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87E90E67-8655-4548-B037-03BA1158A487} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{87E90E67-8655-4548-B037-03BA1158A487} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{87E90E67-8655-4548-B037-03BA1158A487} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{49502A6F-10AD-4EC1-8028-062D8CC5CC7F} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{49502A6F-10AD-4EC1-8028-062D8CC5CC7F} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{49502A6F-10AD-4EC1-8028-062D8CC5CC7F} deleted successfully
HKEY_USERS\S-1-5-21-2562844430-573454042-539011846-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{49502A6F-10AD-4EC1-8028-062D8CC5CC7F} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{87E90E67-8655-4548-B037-03BA1158A487} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{49502A6F-10AD-4EC1-8028-062D8CC5CC7F} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49502A6F-10AD-4EC1-8028-062D8CC5CC7F} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{87E90E67-8655-4548-B037-03BA1158A487} deleted successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
HKEY_CURRENT_USER\Software\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\apgjagobplilmcdfelodhgefiidomnfl deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ccoepcadgihicpglkgajnpfdconkafam deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ddkpepdilbfaccbiljmaflabkcbgjfin deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bpgmjapfkjpfkeffiijiebgjhikjogem deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3F-6E62-4961-A14B-95323C512F9B}_is1 deleted successfully

==== Empty IE Cache ======================

C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Filip\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\mamka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\mamka\AppData\Local\Mozilla\Firefox\Profiles\e9u02blj.default\Cache emptied successfully
C:\Users\mamka\AppData\Local\Mozilla\Firefox\Profiles\e9u02blj.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\mamka\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=1576 folders=169 229792164 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Filip\AppData\Local\Temp will be emptied at reboot
C:\Users\mamka\AppData\Local\Temp will be emptied at reboot
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot

Reklama
fulldragons
Level 1.5
Level 1.5
Příspěvky: 100
Registrován: listopad 14
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu, děkuji

Příspěvekod fulldragons » 16 lis 2014 22:20

refresh

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu, děkuji

Příspěvekod Orcus » 17 lis 2014 11:08

Co problémy?
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

fulldragons
Level 1.5
Level 1.5
Příspěvky: 100
Registrován: listopad 14
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu, děkuji

Příspěvekod fulldragons » 17 lis 2014 12:16

No, nevím, smazali se mi rozšíření k prohlížeči, ale to nevadí, nicméně ntb nabíha stále stejně pomali. Já bych si chtěl notebook přeinstalovat ale před tím odstranit všechno škodlivé, aby se mi z exterka nezálohovala ta špína. tak se chci zeptat jestli podle těch posledních logů co jsem dodal je vše OK nebo mám ještě něco udělat před reinstalací notebooku.

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu, děkuji

Příspěvekod Orcus » 18 lis 2014 07:58

Pokud chceš provést reinstalaci OS, tak proveď čistou pomocí recovery oddílu nebo instalačního CD. Recovery bude s továrním balastem. Nicméně bordel by se tam natahat neměl.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 101 hostů