Prosím o kontrolu logu (reklamy na netu, pomalejší ntb)

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Milhouse
Level 1
Level 1
Příspěvky: 98
Registrován: květen 14
Pohlaví: Muž
Stav:
Offline

Prosím o kontrolu logu (reklamy na netu, pomalejší ntb)

Příspěvekod Milhouse » 16 říj 2015 17:33

HJT

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:42:33, on 15. 10. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Lukáš\AppData\Local\Akamai\netsession_win.exe
C:\Users\Lukáš\AppData\Local\Akamai\netsession_win.exe
C:\Users\Lukáš\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Users\Lukáš\Desktop\Luke\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll
O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [AppEx Accelerator UI] C:\Program Files\AMD Quick Stream\AMDQuickStream.exe -h
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Lukáš\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Lukáš\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Lukáš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - Startup: crossbrowse.lnk = C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: ACP User Service (amdacpusrsvc) - Unknown owner - C:\AMD\amdacpusrsvc.exe
O23 - Service: BTDevManager - Unknown owner - C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
O23 - Service: @C:\windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo EasyPlus Hotspot - Lenovo - C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe
O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe
O23 - Service: Lenovo WiFiHotspot Service (LenovoWiFiHotspotSvr) - Unknown owner - C:\Windows\System32\LenovoWiFiHotspotSvr.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: LUService - Lenovo(beijing) Limited - C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\windows\system32\GameMon.des.exe (file missing)
O23 - Service: Lenovo PhoneCompanionPusher Service (PhoneCompanionPusher) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
O23 - Service: Lenovo PhoneCompanionVap Service (PhoneCompanionVap) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\windows\system32\SAsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: VeriFaceSrv - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11888 bytes


JRT
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.9.1 (06.08.2015:1)
OS: Windows 8.1 x64
Ran by Luk ç on źt 15. 10. 2015 at 11:43:38,58
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks

Successfully deleted: [Task] C:\windows\system32\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-1-6
Successfully deleted: [Task] C:\windows\system32\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-1-7
Successfully deleted: [Task] C:\windows\system32\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-11
Successfully deleted: [Task] C:\windows\system32\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-3
Successfully deleted: [Task] C:\windows\system32\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-5
Successfully deleted: [Task] C:\windows\system32\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-6
Successfully deleted: [Task] C:\windows\system32\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-7
Successfully deleted: [Task] C:\windows\system32\tasks\Crossbrowse
Successfully deleted: [Task] C:\windows\system32\tasks\Uninstaller_SkipUac_Luk ç
Successfully deleted: [Task] C:\windows\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-1-6.job
Successfully deleted: [Task] C:\windows\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-1-7.job
Successfully deleted: [Task] C:\windows\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-10_user.job
Successfully deleted: [Task] C:\windows\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-11.job
Successfully deleted: [Task] C:\windows\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-3.job
Successfully deleted: [Task] C:\windows\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-5.job
Successfully deleted: [Task] C:\windows\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-5_user.job
Successfully deleted: [Task] C:\windows\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-6.job
Successfully deleted: [Task] C:\windows\tasks\80d3da63-f679-45bf-8fe4-3141ea65f874-7.job
Successfully deleted: [Task] C:\windows\tasks\Crossbrowse.job
Successfully deleted: [Task] C:\windows\tasks\Uninstaller_SkipUac_Luk ç.job



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\globalupdate.exe



~~~ Files

Successfully deleted: [File] C:\Users\Luk ç\appdata\local\google\chrome\user data\default\local storage\chrome-extension_bgjpfhpjcgdppjbgnpnjllokbmcdllig_0.localstorage
Successfully deleted: [File] C:\Users\Luk ç\appdata\local\google\chrome\user data\default\local storage\chrome-extension_bgjpfhpjcgdppjbgnpnjllokbmcdllig_0.localstorage-journal
Successfully deleted: [File] C:\Users\Luk ç\appdata\local\google\chrome\user data\default\local storage\chrome-extension_blmojkbhnkkphngknkmgccmlenfaelkd_0.localstorage
Successfully deleted: [File] C:\Users\Luk ç\appdata\local\google\chrome\user data\default\local storage\chrome-extension_blmojkbhnkkphngknkmgccmlenfaelkd_0.localstorage-journal
Successfully deleted: [File] C:\Users\Luk ç\appdata\local\google\chrome\user data\default\local storage\chrome-extension_olfeabkoenfaoljndfecamgilllcpiak_0.localstorage
Successfully deleted: [File] C:\Users\Luk ç\appdata\local\google\chrome\user data\default\local storage\chrome-extension_olfeabkoenfaoljndfecamgilllcpiak_0.localstorage-journal
Successfully deleted: [File] C:\Users\Luk ç\AppData\Roaming\microsoft\internet explorer\quick launch\crossbrowse.lnk



~~~ Folders

Successfully deleted: [Folder] C:\Program Files (x86)\globalupdate
Successfully deleted: [Folder] C:\ProgramData\microsoft\windows\start menu\programs\crossbrowse
Successfully deleted: [Folder] C:\ProgramData\productdata
Successfully deleted: [Folder] C:\Users\Luk ç\appdata\local\crossbrowse
Successfully deleted: [Folder] C:\Users\Luk ç\appdata\local\globalupdate
Successfully deleted: [Folder] C:\Users\Luk ç\AppData\Roaming\productdata



~~~ Chrome

Successfully deleted: [Folder] C:\Users\Luk ç\appdata\local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Successfully deleted: [Folder] C:\Users\Luk ç\appdata\local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd
Successfully deleted: [Folder] C:\Users\Luk ç\appdata\local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak

[C:\Users\Luk ç\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Luk ç\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
bgjpfhpjcgdppjbgnpnjllokbmcdllig
blmojkbhnkkphngknkmgccmlenfaelkd
olfeabkoenfaoljndfecamgilllcpiak

[C:\Users\Luk ç\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Luk ç\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
bgjpfhpjcgdppjbgnpnjllokbmcdllig,
blmojkbhnkkphngknkmgccmlenfaelkd,
olfeabkoenfaoljndfecamgilllcpiak
]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 15. 10. 2015 at 11:51:02,57
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Rogue Killer
RogueKiller V10.8.2.0 (x64) [Jun 9 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 8.1 (6.3.9200 ) 64 bits version
Spuštěno : Normální režim
Uživatel : Lukáš [Práva správce]
Started from : C:\Users\Lukáš\Desktop\Luke\hjt\RogueKillerX64.exe
Mód : Prohledat -- Datum : 10/16/2015 12:23:49

¤¤¤ Procesy : 2 ¤¤¤
[Suspicious.Path] szndesktop.exe(2268) -- C:\Users\Lukáš\AppData\Roaming\Seznam.cz\bin\szndesktop.exe[7] -> Zastaveno [TermProc]
[Suspicious.Path] listicka-x64.exe(4660) -- C:\Users\Lukáš\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe[7] -> Zastaveno [TermThr]

¤¤¤ Registry : 8 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-280777465-42782906-1610825260-1002\Software\Microsoft\Windows\CurrentVersion\Run | cz.seznam.software.autoupdate : "C:\Users\Lukáš\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7][x] -> Nalezeno
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-280777465-42782906-1610825260-1002\Software\Microsoft\Windows\CurrentVersion\Run | cz.seznam.software.szndesktop : "C:\Users\Lukáš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7][x] -> Nalezeno
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-280777465-42782906-1610825260-1002\Software\Microsoft\Windows\CurrentVersion\Run | cz.seznam.software.autoupdate : "C:\Users\Lukáš\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7][x] -> Nalezeno
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-280777465-42782906-1610825260-1002\Software\Microsoft\Windows\CurrentVersion\Run | cz.seznam.software.szndesktop : "C:\Users\Lukáš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7][x] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{687D3CBD-2534-4E1B-98F7-61C1C960C26A} | DhcpNameServer : 10.0.0.138 [X] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6BB14843-A068-4B78-BA5A-29DF28B5B231} | DhcpNameServer : 188.175.121.1 188.175.121.2 [X][X] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{687D3CBD-2534-4E1B-98F7-61C1C960C26A} | DhcpNameServer : 10.0.0.138 [X] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6BB14843-A068-4B78-BA5A-29DF28B5B231} | DhcpNameServer : 188.175.121.1 188.175.121.2 [X][X] -> Nalezeno

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 1 ¤¤¤
[Suspicious.Path|Suspicious.Startup][Soubor] crossbrowse.lnk -- C:\Users\Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk -> Nalezeno

¤¤¤ Soubor HOSTS : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABF050 +++++
--- User ---
[MBR] 00f372e3daf1a5d0783b2a0fed4f2ac4
[BSP] cc78849e0194b98c094fdaddded4a884 : Empty MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 1000 MB
1 - [SYSTEM][MAN-MOUNT] EFI system partition | Offset (sectors): 2050048 | Size: 260 MB
2 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2582528 | Size: 1000 MB
3 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 4630528 | Size: 128 MB
4 - Basic data partition | Offset (sectors): 4892672 | Size: 434526 MB
5 - Basic data partition | Offset (sectors): 894801920 | Size: 25600 MB
6 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 947230720 | Size: 14425 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_SCN_06112015_175620.log - RKreport_SCN_06132015_105235.log - RKreport_DEL_06132015_110612.log


ADW
# AdwCleaner v5.013 - Logfile created 16/10/2015 at 17:24:18
# Updated 09/10/2015 by Xplode
# Database : 2015-10-16.1 [Server]
# Operating system : Windows 8.1 (x64)
# Username : Lukáš - SRNEC
# Running from : C:\Users\Lukáš\Desktop\adwcleaner_5.013.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

Folder Found : C:\Program Files (x86)\CinemaP-1.9cV25.09
Folder Found : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi
Folder Found : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi

***** [ Files ] *****

File Found : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lkadffjmnaiokkdncgdlecdegajoiemi_0.localstorage
File Found : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lkadffjmnaiokkdncgdlecdegajoiemi_0.localstorage-journal
File Found : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lkadffjmnaiokkdncgdlecdegajoiemi
File Found : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lkadffjmnaiokkdncgdlecdegajoiemi_0.localstorage
File Found : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lkadffjmnaiokkdncgdlecdegajoiemi_0.localstorage-journal
File Found : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lkadffjmnaiokkdncgdlecdegajoiemi
File Found : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nps.pastaleads.com_0.localstorage
File Found : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nps.pastaleads.com_0.localstorage-journal
File Found : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_hdapp1008-a.akamaihd.net_0.localstorage
File Found : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_hdapp1008-a.akamaihd.net_0.localstorage-journal
File Found : C:\Users\Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

Task Found : amiupdaterExd
Task Found : amiupdaterExi

***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Found : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Found : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Found : HKLM\SOFTWARE\Microsoft\Mediaplayer\Shiminclusionlist\crossbrowse.exe
Key Found : HKLM\SOFTWARE\Classes\CRSBRWSHTML
Key Found : HKLM\SOFTWARE\Clients\StartMenuInternet\Crossbrowse
Value Found : HKLM\SOFTWARE\Classes\.htm\OpenWithProgids [CRSBRWSHTML]
Value Found : HKLM\SOFTWARE\Classes\.html\OpenWithProgids [CRSBRWSHTML]
Value Found : HKLM\SOFTWARE\RegisteredApplications [Crossbrowse]
Key Found : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe
Value Found : HKLM\SOFTWARE\Classes\.xht\OpenWithProgIDs [CRSBRWSHTML]
Value Found : HKLM\SOFTWARE\Classes\.webp\OpenWithProgIDs [CRSBRWSHTML]
Value Found : HKLM\SOFTWARE\Classes\.shtml\OpenWithProgIDs [CRSBRWSHTML]
Key Found : HKLM\SOFTWARE\CLASSES\APPID\VISUALDISCOVERY.EXE
Key Found : HKLM\SOFTWARE\Classes\Crossbrowse
Key Found : HKLM\SOFTWARE\3886a92c-5cf9-4159-8310-36cfff30d53f
Key Found : HKLM\SOFTWARE\8f9afc7a-79f7-4836-9888-88ef43d1deb6
Key Found : HKLM\SOFTWARE\e9a6067d-13cb-4bbf-99ec-facec714ab0f
Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{2A563926-CF4B-4363-A760-F71E46205B7E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
Key Found : HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
Key Found : HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
Key Found : HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
Key Found : HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
Key Found : HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
Key Found : HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Key Found : HKU\.DEFAULT\Software\CinemaP-1.9cV25.09-nv
Key Found : HKU\.DEFAULT\Software\CinemaP-1.9cV25.09-nv-ie
Key Found : HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\CrossBrowser
Key Found : HKCU\Software\YorkNewCin
Key Found : HKCU\Software\HighDefAction
Key Found : HKCU\Software\ArenaHD
Key Found : HKCU\Software\WEBAPP
Key Found : HKCU\Software\CinemaP-1.9cV25.09-nv
Key Found : HKCU\Software\CinemaP-1.9cV25.09-nv-ie
Key Found : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKLM\SOFTWARE\AppDataLow\SOFTWARE\Crossrider
Key Found : HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : HKLM\SOFTWARE\Crossbrowse
Key Found : HKLM\SOFTWARE\YorkNewCin
Key Found : HKLM\SOFTWARE\HighDefAction
Key Found : HKLM\SOFTWARE\ArenaHD
Key Found : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Found : HKLM\SOFTWARE\CinemaP-1.9cV25.09
Key Found : HKLM\SOFTWARE\CinemaP-1.9cV25.09-nv
Key Found : HKLM\SOFTWARE\CinemaP-1.9cV25.09-nv-ie
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaP-1.9cV25.09
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\InstalledBrowserExtensions
Key Found : [x64] HKCU\Software\CrossBrowser
Key Found : [x64] HKCU\Software\YorkNewCin
Key Found : [x64] HKCU\Software\HighDefAction
Key Found : [x64] HKCU\Software\ArenaHD
Key Found : [x64] HKCU\Software\WEBAPP
Key Found : [x64] HKCU\Software\CinemaP-1.9cV25.09-nv
Key Found : [x64] HKCU\Software\CinemaP-1.9cV25.09-nv-ie
Key Found : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : [x64] HKLM\SOFTWARE\YorkNewCin
Key Found : [x64] HKLM\SOFTWARE\HighDefAction
Key Found : [x64] HKLM\SOFTWARE\ArenaHD
Key Found : [x64] HKLM\SOFTWARE\CinemaP-1.9cV25.09-nv
Key Found : HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
Key Found : HKU\S-1-5-21-280777465-42782906-1610825260-1002\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Found : HKU\S-1-5-21-280777465-42782906-1610825260-1002\Software\AppDataLow\Software\Crossrider
Key Found : HKU\S-1-5-18\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Found : HKU\S-1-5-18\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_

***** [ Web browsers ] *****

[C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : aaaaaiabcopkplhgaedhbloeejhhankf
[C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : lkadffjmnaiokkdncgdlecdegajoiemi
[C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : lkadffjmnaiokkdncgdlecdegajoiemi

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [13495 bytes] ##########
Ntb Lenovo ideapad z50-75
CPU - AMD FX-7500 (512MB ATI AMD Radeon R7 Graphics)
RAM - 4GB
MB - LENOVO Lancer 5B3
GK - 2048MB ATI AMD Radeon R7 M260DX
HDD - 465GB TOSHIBA MQ01ABF050

Reklama
Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu (reklamy na netu, pomalejší ntb)

Příspěvekod jerabina » 16 říj 2015 17:44

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na Kopírovat do schránky a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Uživatelský avatar
Milhouse
Level 1
Level 1
Příspěvky: 98
Registrován: květen 14
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu (reklamy na netu, pomalejší ntb)

Příspěvekod Milhouse » 18 říj 2015 13:00

ADW

# AdwCleaner v5.013 - Logfile created 16/10/2015 at 21:20:34
# Updated 09/10/2015 by Xplode
# Database : 2015-10-16.1 [Server]
# Operating system : Windows 8.1 (x64)
# Username : Lukáš - SRNEC
# Running from : C:\Users\Lukáš\Desktop\Luke\hjt\adwcleaner_5.013.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\CinemaP-1.9cV25.09
[-] Folder Deleted : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi
[!] Folder Not Deleted : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi

***** [ Files ] *****

[-] File Deleted : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lkadffjmnaiokkdncgdlecdegajoiemi_0.localstorage
[-] File Deleted : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lkadffjmnaiokkdncgdlecdegajoiemi_0.localstorage-journal
[-] File Deleted : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lkadffjmnaiokkdncgdlecdegajoiemi
[-] File Deleted : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lkadffjmnaiokkdncgdlecdegajoiemi_0.localstorage
[-] File Deleted : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lkadffjmnaiokkdncgdlecdegajoiemi_0.localstorage-journal
[-] File Deleted : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lkadffjmnaiokkdncgdlecdegajoiemi
[-] File Deleted : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nps.pastaleads.com_0.localstorage
[-] File Deleted : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nps.pastaleads.com_0.localstorage-journal
[-] File Deleted : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_hdapp1008-a.akamaihd.net_0.localstorage
[-] File Deleted : C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_hdapp1008-a.akamaihd.net_0.localstorage-journal
[-] File Deleted : C:\Users\Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : amiupdaterExd
[-] Task Deleted : amiupdaterExi

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
[-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
[-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Mediaplayer\Shiminclusionlist\crossbrowse.exe
[-] Key Deleted : HKLM\SOFTWARE\Classes\CRSBRWSHTML
[-] Key Deleted : HKLM\SOFTWARE\Clients\StartMenuInternet\Crossbrowse
[-] Value Deleted : HKLM\SOFTWARE\Classes\.htm\OpenWithProgids [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\Classes\.html\OpenWithProgids [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\RegisteredApplications [Crossbrowse]
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe
[-] Value Deleted : HKLM\SOFTWARE\Classes\.xht\OpenWithProgIDs [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\Classes\.webp\OpenWithProgIDs [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\Classes\.shtml\OpenWithProgIDs [CRSBRWSHTML]
[-] Key Deleted : HKLM\SOFTWARE\CLASSES\APPID\VISUALDISCOVERY.EXE
[-] Key Deleted : HKLM\SOFTWARE\Classes\Crossbrowse
[-] Key Deleted : HKLM\SOFTWARE\3886a92c-5cf9-4159-8310-36cfff30d53f
[-] Key Deleted : HKLM\SOFTWARE\8f9afc7a-79f7-4836-9888-88ef43d1deb6
[-] Key Deleted : HKLM\SOFTWARE\e9a6067d-13cb-4bbf-99ec-facec714ab0f
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2A563926-CF4B-4363-A760-F71E46205B7E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : HKU\.DEFAULT\Software\CinemaP-1.9cV25.09-nv
[-] Key Deleted : HKU\.DEFAULT\Software\CinemaP-1.9cV25.09-nv-ie
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
[-] Key Deleted : HKCU\Software\GlobalUpdate
[-] Key Deleted : HKCU\Software\InstalledBrowserExtensions
[-] Key Deleted : HKCU\Software\CrossBrowser
[-] Key Deleted : HKCU\Software\YorkNewCin
[-] Key Deleted : HKCU\Software\HighDefAction
[-] Key Deleted : HKCU\Software\ArenaHD
[-] Key Deleted : HKCU\Software\WEBAPP
[-] Key Deleted : HKCU\Software\CinemaP-1.9cV25.09-nv
[-] Key Deleted : HKCU\Software\CinemaP-1.9cV25.09-nv-ie
[-] Key Deleted : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
[-] Key Deleted : HKLM\SOFTWARE\AppDataLow\SOFTWARE\Crossrider
[-] Key Deleted : HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
[-] Key Deleted : HKLM\SOFTWARE\GlobalUpdate
[-] Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Key Deleted : HKLM\SOFTWARE\Crossbrowse
[-] Key Deleted : HKLM\SOFTWARE\YorkNewCin
[-] Key Deleted : HKLM\SOFTWARE\HighDefAction
[-] Key Deleted : HKLM\SOFTWARE\ArenaHD
[-] Key Deleted : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Key Deleted : HKLM\SOFTWARE\CinemaP-1.9cV25.09
[-] Key Deleted : HKLM\SOFTWARE\CinemaP-1.9cV25.09-nv
[-] Key Deleted : HKLM\SOFTWARE\CinemaP-1.9cV25.09-nv-ie
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaP-1.9cV25.09
[!] Key Not Deleted : [x64] HKCU\Software\GlobalUpdate
[!] Key Not Deleted : [x64] HKCU\Software\InstalledBrowserExtensions
[!] Key Not Deleted : [x64] HKCU\Software\CrossBrowser
[!] Key Not Deleted : [x64] HKCU\Software\YorkNewCin
[!] Key Not Deleted : [x64] HKCU\Software\HighDefAction
[!] Key Not Deleted : [x64] HKCU\Software\ArenaHD
[!] Key Not Deleted : [x64] HKCU\Software\WEBAPP
[!] Key Not Deleted : [x64] HKCU\Software\CinemaP-1.9cV25.09-nv
[!] Key Not Deleted : [x64] HKCU\Software\CinemaP-1.9cV25.09-nv-ie
[-] Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Key Deleted : [x64] HKLM\SOFTWARE\YorkNewCin
[-] Key Deleted : [x64] HKLM\SOFTWARE\HighDefAction
[-] Key Deleted : [x64] HKLM\SOFTWARE\ArenaHD
[-] Key Deleted : [x64] HKLM\SOFTWARE\CinemaP-1.9cV25.09-nv
[!] Key Not Deleted : HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[!] Key Not Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
[!] Key Not Deleted : HKU\S-1-5-21-280777465-42782906-1610825260-1002\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[!] Key Not Deleted : HKU\S-1-5-21-280777465-42782906-1610825260-1002\Software\AppDataLow\Software\Crossrider
[!] Key Not Deleted : HKU\S-1-5-18\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[!] Key Not Deleted : HKU\S-1-5-18\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_

***** [ Web browsers ] *****

[-] [C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : aaaaaiabcopkplhgaedhbloeejhhankf
[-] [C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : lkadffjmnaiokkdncgdlecdegajoiemi
[-] [C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : lkadffjmnaiokkdncgdlecdegajoiemi

*************************

:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [14622 bytes] ##########



Anti malware

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 16. 10. 2015
Čas skenování: 18:29
Protokol: malware.txt
Správce: Ano

Verze: 2.1.8.1057
Databáze malwaru: v2015.10.16.07
Databáze rootkitů: v2015.10.16.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows 8.1
CPU: x64
Souborový systém: NTFS
Uživatel: Lukáš

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 335730
Uplynulý čas: 31 min, 42 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 2
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\80D3DA63-F679-45BF-8FE4-3141EA65F874-6.EXE, 3780, , [b2f52a2dcebd0a2cca4867fc45bf837d]
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\80D3DA63-F679-45BF-8FE4-3141EA65F874-1-6.EXE, 3860, , [683fd38478138aacfc166af96e961ce4]

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 100
PUP.Optional.MyBrowser, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{2A563926-CF4B-4363-A760-F71E46205B7E}, , [961181d678133501086463d154aef60a],
PUP.Optional.MyBrowser, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{2A563926-CF4B-4363-A760-F71E46205B7E}, , [961181d678133501086463d154aef60a],
PUP.Optional.Downloader, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CinemaP-1.9cV25.09, , [dbcc2136b4d7e84ec2430c4c7889e21e],
PUP.Optional.Cinema, HKLM\SOFTWARE\CinemaP-1.9cV25.09-nv, , [a30441168ffc31052e11d293fc07e917],
PUP.Optional.HighDefAction, HKLM\SOFTWARE\HighDefAction, , [1d8ac295b5d649eddecdeb8ca45fd12f],
PUP.Optional.YorkNewCin, HKLM\SOFTWARE\YorkNewCin, , [00a791c68209c76f4ce2fba660a3da26],
PUP.Optional.CinemaPlus, HKLM\SOFTWARE\ARENAHD, , [dacd3e19cfbc62d40cbdee7738cb0cf4],
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\CLASSES\Crossbrowse, , [cdda2e29fe8d3df9f4dcbcf216edba46],
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\CLASSES\CRSBRWSHTML, , [fdaa59fedab12511672ec3a6be457e82],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, , [b2f57bdcd9b226101d969bda53b0ad53],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickProcessLauncherMachine, , [7d2ab7a072190b2b367dfd787b887d83],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickProcessLauncherMachine.1.0, , [a70088cf870473c3f0c37bfa5ca7e917],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoCreateAsync, , [4d5a6cebe4a72b0bd6de1c590300bf41],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoCreateAsync.1.0, , [624596c164279e984f65a0d5719236ca],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreClass, , [bcebc88fd8b3e5517f35264f14ef2bd5],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreClass.1, , [8b1c69eea5e695a1feb65b1a699a40c0],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreMachineClass, , [436495c2781375c1961e591cda29837d],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreMachineClass.1, , [51561542e9a2ee4801b3bdb8a261d52b],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CredentialDialogMachine, , [e0c7c7909cef6acc8d272154bf448f71],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CredentialDialogMachine.1.0, , [5b4c411653386dc9793b8ee70af9e51b],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine, , [e1c61146018a96a0f2c2fb7a30d33bc5],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine.1.0, , [4265c88fc6c5b77f605472030ef58d73],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback, , [5f48aea9b1daf5414f6578fd26ddff01],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, , [aafd97c04b4080b68f25482d3cc7db25],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc, , [d9ce94c3adde66d01e96a3d2cb3821df],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc.1.0, , [8e19c39457341a1cc5ef5b1a8182f20e],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.ProcessLauncher, , [1295f85fc7c4a88eaf050a6b5ba8d42c],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.ProcessLauncher.1.0, , [5c4b0f4856355cda0fa587eeea191ae6],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3COMClassService, , [b5f2ca8d6f1cc274348003729370a15f],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3COMClassService.1.0, , [1394e86f83087bbbbff5482d946f05fb],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachine, , [8d1a183f9cefc07607ada5d061a26e92],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachine.1.0, , [dacdff582566f83ee5cfcca90cf7ab55],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback, , [099e0a4d4e3dfd393c78b9bc12f1b947],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback.1.0, , [911642155d2e46f0d6dee59019eaeb15],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebSvc, , [6e3958ff5932af87278d3f36f90acb35],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebSvc.1.0, , [60472b2cc4c7bf77367e76fff70c6b95],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\APPID\GLOBALUPDATE.EXE, , [9b0cd97e672445f1f6bccea7b64dfc04],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\GLOBALUPDATE.EXE, , [e3c4e671cbc050e6f7bbf87d7d86857b],
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\Crossbrowse, , [2b7c0354d9b256e01a81d3967a898080],
PUP.Optional.CrossRider, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, , [426500576a2149ed930e88e48c77f60a],
PUP.Optional.AmiUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\amiupdaterExd, , [5057afa84843c76f5715a8b6bf4416ea],
PUP.Optional.AmiUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\amiupdaterExi, , [7730cd8afd8ef83e7af275e9cb38a65a],
PUP.Optional.Cinema, HKLM\SOFTWARE\WOW6432NODE\CinemaP-1.9cV25.09, , [30775cfb0a81fb3b172891d45fa4c838],
PUP.Optional.Cinema, HKLM\SOFTWARE\WOW6432NODE\CinemaP-1.9cV25.09-nv, , [7334e671107b043289b6e382f310926e],
PUP.Optional.Cinema, HKLM\SOFTWARE\WOW6432NODE\CinemaP-1.9cV25.09-nv-ie, , [575083d496f58aac8ab53c2915ee629e],
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\WOW6432NODE\Crossbrowse, , [a403e5726e1d6acce4b9f772996aee12],
PUP.Optional.HighDefAction, HKLM\SOFTWARE\WOW6432NODE\HighDefAction, , [cadd1e39ccbfe5519e0d6c0b847fcb35],
PUP.Optional.YorkNewCin, HKLM\SOFTWARE\WOW6432NODE\YorkNewCin, , [b4f359fedead9c9ae34b90112ed59b65],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\APPDATALOW\SOFTWARE\Crossrider, , [9017e86f6f1c7eb822766309ab589e62],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, , [6d3aef68b9d25fd76cac6349cd36d32d],
PUP.Optional.CinemaPlus, HKLM\SOFTWARE\WOW6432NODE\ARENAHD, , [ced95cfbc0cb003650791a4b9370de22],
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Crossbrowse, , [00a78bccafdc0a2c5f71446a58ab0df3],
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CRSBRWSHTML, , [f7b06fe87714d1651184bcadf70c6a96],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, , [8225f364a4e72f07b9fa3540b0535ea2],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickProcessLauncherMachine, , [f8afd186414ad75fe7cc52234ab949b7],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickProcessLauncherMachine.1.0, , [a9fe5403f59681b5bcf7e98cce35b947],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoCreateAsync, , [e6c1fa5de1aa72c4faba93e233d0be42],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoCreateAsync.1.0, , [a8ff92c53358d3632094066f2cd709f7],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreClass, , [5d4a45123d4e3105bafa3a3be71c59a7],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreClass.1, , [fbace572b0dbc472c2f20174b44ff907],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreMachineClass, , [5156d186f794d2645a5a8ee7ad5618e8],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreMachineClass.1, , [7433dc7b13785cda7c38a9cc21e2f010],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CredentialDialogMachine, , [5c4bc2957d0e1224c9ebbabb51b27789],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CredentialDialogMachine.1.0, , [c8df46113d4e75c1eec6a2d30cf7d12f],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine, , [ecbb4a0dd7b4ef475e56e78e0102c23e],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine.1.0, , [b9ee5cfb018a3600a0147df853b044bc],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback, , [8126c88fddae59dde1d3d3a2649fb34d],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, , [8b1cd87f4348f34374400075996a23dd],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc, , [8225dc7b692268cec1f386efc34003fd],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc.1.0, , [3275381f0487c86e2c88f382d82bac54],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.ProcessLauncher, , [6c3b8ccb692260d6fdb787ee5ca70df3],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.ProcessLauncher.1.0, , [a00791c63f4c072f7d37730211f2a55b],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3COMClassService, , [07a099be771401354a6a7ff69d6614ec],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3COMClassService.1.0, , [7b2c65f2cebd72c4af055b1a31d27090],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachine, , [367195c259321620c8ece392ff0407f9],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachine.1.0, , [44631a3d3457c5718b291f5609fa3fc1],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback, , [9a0d2631eaa19b9b5361bcb9679c3ec2],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback.1.0, , [bfe8401776152f07407453225da654ac],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebSvc, , [37700057711ac076dada25501ae9d030],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebSvc.1.0, , [7b2c0255e3a88da95163fb7a818222de],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\GLOBALUPDATE.EXE, , [7433da7d92f972c4bdf589ec11f2f50b],
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\Crossbrowse, , [5057292e6427ab8b14876702d1328f71],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE\Clients, , [bbec9fb88cffbe78b5014b2a29da4db3],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\30935, , [3a6d71e6206bf73f8120c4a81de6a15f],
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\MEDIAPLAYER\SHIMINCLUSIONLIST\crossbrowse.exe, , [4166cc8b6a2125110f92f475ae556799],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, , [63443b1c2b60c472edcdd5a0e122e61a],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, , [2b7c24337e0d65d114a5bcb953b0b64a],
PUP.Optional.Cinema, HKU\S-1-5-18\SOFTWARE\CinemaP-1.9cV25.09-nv, , [3e69fd5a5437ae880f2797ce43c023dd],
PUP.Optional.Cinema, HKU\S-1-5-18\SOFTWARE\CinemaP-1.9cV25.09-nv-ie, , [f4b3ba9dccbfea4c6ec898cdac570af6],
PUP.Optional.CrossRider, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, , [4d5a4b0caddef83e6de64724ef14b54b],
PUP.Optional.Cinema, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\CinemaP-1.9cV25.09-nv, , [2d7ad97e1b7022141422bbaa7d8632ce],
PUP.Optional.Cinema, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\CinemaP-1.9cV25.09-nv-ie, , [1e8954034b40ea4cef47e184f3104fb1],
PUP.Optional.CrossBrowse, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\CrossBrowser, , [e5c2e770f9925adc8711f0797d86d729],
PUP.Optional.HighDefAction, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\HighDefAction, , [f9aef364fd8ef343fab0b5c23ec558a8],
PUP.Optional.YorkNewCin, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\YorkNewCin, , [485f53043a51e5518ca18e131fe4817f],
PUP.Optional.CrossRider, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [1295acaba2e9b97db69ddc8fc340d828],
PUP.Optional.CinemaPlus, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\ARENAHD, , [5f4887d0a1ead660b8f2b3b2b84bac54],
PUP.Optional.GlobalUpdate, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, , [9215fc5bcbc079bdb6ff5c194ab97090],
PUP.Optional.CrossRider, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, , [ced96ee993f802340e5a5318d330d030],
PUP.Optional.CrossRider, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Cinema PlusV25.09, , [70376fe8c4c7c670aebce289e51ee020],

Hodnoty registru: 21
PUP.Optional.CinemaPlus, HKLM\SOFTWARE\ARENAHD|value, 1, , [dacd3e19cfbc62d40cbdee7738cb0cf4]
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\CLASSES\.HTML\OPENWITHPROGIDS|CRSBRWSHTML, , [921559fe5f2c8da9dfb5f475d62d26da],
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\CLASSES\.HTM\OPENWITHPROGIDS|CRSBRWSHTML, , [8423bd9ab1da2f075d368adf36cd17e9],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\APPID\GLOBALUPDATE.EXE|AppID, {3278F5CF-48F3-4253-A6BB-004CE84AF492}, , [9b0cd97e672445f1f6bccea7b64dfc04]
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\CLASSES\WOW6432NODE\.HTML\OPENWITHPROGIDS|CRSBRWSHTML, , [1f883126058613235d37b3b690734bb5],
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\CLASSES\WOW6432NODE\.HTM\OPENWITHPROGIDS|CRSBRWSHTML, , [3b6cbf98c1cafe386e25581118ebb64a],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\GLOBALUPDATE.EXE|AppID, {3278F5CF-48F3-4253-A6BB-004CE84AF492}, , [e3c4e671cbc050e6f7bbf87d7d86857b]
PUP.Optional.PCTuner, HKLM\SOFTWARE\HIGHDEFACTION|value, 1, , [73345dfa65263bfb42a1dbad7d869a66]
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\REGISTEREDAPPLICATIONS|Crossbrowse, Software\Clients\StartMenuInternet\Crossbrowse\Capabilities, , [f6b110475437e84e2583c9a0ed16a759]
PUP.Optional.CinemaPlus, HKLM\SOFTWARE\WOW6432NODE\ARENAHD|value, 1, , [ced95cfbc0cb003650791a4b9370de22]
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\.HTML\OPENWITHPROGIDS|CRSBRWSHTML, , [b4f3e374305bda5c157fe6832fd4dc24],
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\.HTM\OPENWITHPROGIDS|CRSBRWSHTML, , [5651cd8a4a41f442b2e171f8d92ad32d],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\GLOBALUPDATE.EXE|AppID, {3278F5CF-48F3-4253-A6BB-004CE84AF492}, , [7433da7d92f972c4bdf589ec11f2f50b]
PUP.Optional.PCTuner, HKLM\SOFTWARE\WOW6432NODE\HIGHDEFACTION|value, 1, , [505767f0642760d628bb1b6dfb0835cb]
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS, Crossbrowse, , [32758fc8cdbe3bfb8f0f21486d9604fc]
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS|StubPath, "C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\39.6.2171.95\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level, , [485fb99ef09b4ee87925aabfc1427e82]
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS|Localized Name, Crossbrowse, , [a9fe3126b1daea4c75298bdef80b3fc1]
PUP.Optional.CrossBrowse, HKLM\SOFTWARE\WOW6432NODE\REGISTEREDAPPLICATIONS|Crossbrowse, Software\Clients\StartMenuInternet\Crossbrowse\Capabilities, , [dbcc35221a7180b6abfdb4b5679c0ef2]
PUP.Optional.CinemaPlus, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\ARENAHD|value, 1, , [5f4887d0a1ead660b8f2b3b2b84bac54]
PUP.Optional.GlobalUpdate, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|source, IE, , [9215fc5bcbc079bdb6ff5c194ab97090]
PUP.Optional.PCTuner, HKU\S-1-5-21-280777465-42782906-1610825260-1002\SOFTWARE\HIGHDEFACTION|value, 1, , [7037a4b3a7e4f3432bb42d5ba95a38c8]

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 22
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09, , [aafde86f9eed6acc949e85e63ec5a759],
PUP.Optional.GlobalUpdate, C:\Users\Lukáš\AppData\Local\Temp\comh.327971, , [b2f5a9aedbb041f54a404f0f92702ad6],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\userCode, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\actions, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\api, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\popupResource, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\api, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\popupResource, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\actions, , [dfc8b3a453388fa75c1f7bf0ad5758a8],

Soubory: 96
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\80D3DA63-F679-45BF-8FE4-3141EA65F874-6.EXE, , [b2f52a2dcebd0a2cca4867fc45bf837d],
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\80D3DA63-F679-45BF-8FE4-3141EA65F874-1-6.EXE, , [683fd38478138aacfc166af96e961ce4],
PUP.Optional.CrossRider, C:\Program Files (x86)\862659b5-cc9a-4b2d-a034-f7a06a281b52\362a69f2-9f97-4cbe-ab53-366a024b91e0.dll, , [792ec493eaa13ff7d61013407d8439c7],
PUP.Optional.CrossRider, C:\Program Files (x86)\862659b5-cc9a-4b2d-a034-f7a06a281b52\862659b5-cc9a-4b2d-a034-f7a06a281b52.dll, , [8f186ee9147747ef4e98332016eb5ba5],
PUP.Optional.Nova, C:\Program Files (x86)\862659b5-cc9a-4b2d-a034-f7a06a281b52\8f9afc7a-79f7-4836-9888-88ef43d1deb6.dll, , [dccbdf787e0df6408974530703fee917],
PUP.Optional.Nova, C:\Program Files (x86)\862659b5-cc9a-4b2d-a034-f7a06a281b52\ace9cd84-4202-437b-a435-969b6094ffe2.dll, , [aef9f1668cff67cf6796aab0966b55ab],
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\80d3da63-f679-45bf-8fe4-3141ea65f874-1-7.exe, , [dbccacab63280d29b1611152ee163bc5],
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\80d3da63-f679-45bf-8fe4-3141ea65f874-10.exe, , [3e6977e0cac1f343848e1251ab591ce4],
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\80d3da63-f679-45bf-8fe4-3141ea65f874-11.exe, , [3c6b56010982b680d53d6df67292f709],
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\80d3da63-f679-45bf-8fe4-3141ea65f874-3.exe, , [881f65f2b0db40f651c1283bc73d926e],
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\80d3da63-f679-45bf-8fe4-3141ea65f874-5.exe, , [0a9d16414645c1759f73c3a0c53f3fc1],
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\80d3da63-f679-45bf-8fe4-3141ea65f874-64.exe, , [b2f574e302891b1bb45e4e1553b160a0],
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\80d3da63-f679-45bf-8fe4-3141ea65f874-7.exe, , [703784d3cdbe92a4c151234012f24db3],
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\e9a6067d-13cb-4bbf-99ec-facec714ab0f.dll, , [485fe86f03882412f7ef084b04fd7d83],
PUP.Optional.Downloader, C:\Program Files (x86)\CinemaP-1.9cV25.09\Uninstall.exe, , [dbcc2136b4d7e84ec2430c4c7889e21e],
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\UninstallBrw.exe, , [d9cec295d0bbb77f0b07dd86669ec838],
PUP.Optional.CrossBrowse, C:\Users\Lukáš\AppData\Local\Temp\8486.exe, , [46613522078452e4ffd365badc2545bb],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\CHROME-EXTENSION_LKADFFJMNAIOKKDNCGDLECDEGAJOIEMI_0.LOCALSTORAGE, , [1196d97e6a2145f114e50a6d0ff3be42],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\CHROME-EXTENSION_LKADFFJMNAIOKKDNCGDLECDEGAJOIEMI_0.LOCALSTORAGE-JOURNAL, , [089f8ccbdbb08ea88c6d572092701be5],
PUP.Optional.CrossBrowse, C:\Users\Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CROSSBROWSE.LNK, , [6245cc8bdead2016157b3534748f41bf],
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaP-1.9cV25.09\BGNOVA.HTML, , [aafde86f9eed6acc949e85e63ec5a759],
PUP.Optional.PastaLeads, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\HTTPS_NPS.PASTALEADS.COM_0.LOCALSTORAGE, , [f3b4e4737219b680be0d6746d62d3cc4],
PUP.Optional.PastaLeads, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\HTTPS_NPS.PASTALEADS.COM_0.LOCALSTORAGE-JOURNAL, , [d0d75bfc9bf012240dbe5f4ed2312bd5],
PUP.Optional.PastaLeads, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\HTTP_NPS.PASTALEADS.COM_0.LOCALSTORAGE, , [3e6966f1533856e03e8d0ba2da297888],
PUP.Optional.PastaLeads, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\HTTP_NPS.PASTALEADS.COM_0.LOCALSTORAGE-JOURNAL, , [8b1cb0a7652674c213b8b9f4af5413ed],
PUP.Optional.GlobalUpdate, C:\Users\Lukáš\AppData\Local\Temp\comh.327971\globalupdateHelper.msi, , [b2f5a9aedbb041f54a404f0f92702ad6],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\background.html, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\chromeCoreFilesIndex.txt, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\manifest.json, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\popup.html, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\Settings.json, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\manifest.xml, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins.json, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\246.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\13.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\17.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\345.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\354.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\4.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\7.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\78.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\80.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\9.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\userCode\background.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\userCode\extension.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\icon128.png, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\icon16.png, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\icon48.png, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\actions\1.png, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\fbf3b67f866c31f9e9533b350ceead48.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\main.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\api\8e2726ec2b610564cf22dbfbaef506a2.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\api\cd5f22435b84fa30702bdfb44097c13e.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\api\pageAction.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\1a3bc10fb38e9ed8b7552f47ec45685f.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\4220deae5aede79dac70d6eb8584a1b4.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\7dbfb6ae96992fb6edbeca82cf5a4613.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\9185416d397044c25b5ea05f602a807b.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\app_api.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\b8f5386fe9f444efcfe13abd4e1a8a3d.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\e5057dd7bf0f95a382b4eec923080dba.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\e56192258a48c2a8c96f24a193b4bf38.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\installer.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\popupResource\newPopup.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\popupResource\popup.js, , [812678df4d3e270f6d769dda887a5ea2],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\main.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\fbf3b67f866c31f9e9533b350ceead48.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\api\8e2726ec2b610564cf22dbfbaef506a2.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\api\cd5f22435b84fa30702bdfb44097c13e.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\api\pageAction.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\1a3bc10fb38e9ed8b7552f47ec45685f.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\4220deae5aede79dac70d6eb8584a1b4.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\7dbfb6ae96992fb6edbeca82cf5a4613.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\9185416d397044c25b5ea05f602a807b.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\app_api.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\b8f5386fe9f444efcfe13abd4e1a8a3d.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\e5057dd7bf0f95a382b4eec923080dba.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\e56192258a48c2a8c96f24a193b4bf38.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\installer.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\popupResource\newPopup.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\js\lib\popupResource\popup.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\background.html, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\chromeCoreFilesIndex.txt, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\manifest.json, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\popup.html, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\manifest.xml, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins.json, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\345.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\354.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\4.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\7.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins\9.js, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\icon128.png, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\icon16.png, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\icon48.png, , [dfc8b3a453388fa75c1f7bf0ad5758a8],
PUP.Optional.CrossRider, C:\Users\Lukáš\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\actions\1.png, , [dfc8b3a453388fa75c1f7bf0ad5758a8],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)


Rogue

RogueKiller V10.8.2.0 (x64) [Jun 9 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 8.1 (6.3.9200 ) 64 bits version
Spuštěno : Normální režim
Uživatel : Lukáš [Práva správce]
Started from : C:\Users\Lukáš\Desktop\Luke\hjt\RogueKillerX64.exe
Mód : Smazat -- Datum : 10/17/2015 17:05:38

¤¤¤ Procesy : 1 ¤¤¤
[VT.Unknown] explorer.exe(4060) -- C:\windows\SYSTEM32\amdocl64.dll[7] -> Uvolněno

¤¤¤ Registry : 4 ¤¤¤
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{687D3CBD-2534-4E1B-98F7-61C1C960C26A} | DhcpNameServer : 10.0.0.138 [(Private Address) (XX)] -> Nevybráno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6BB14843-A068-4B78-BA5A-29DF28B5B231} | DhcpNameServer : 10.0.0.138 [(Private Address) (XX)] -> Nevybráno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{687D3CBD-2534-4E1B-98F7-61C1C960C26A} | DhcpNameServer : 10.0.0.138 [(Private Address) (XX)] -> Nevybráno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6BB14843-A068-4B78-BA5A-29DF28B5B231} | DhcpNameServer : 10.0.0.138 [(Private Address) (XX)] -> Nevybráno

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABF050 +++++
--- User ---
[MBR] 00f372e3daf1a5d0783b2a0fed4f2ac4
[BSP] cc78849e0194b98c094fdaddded4a884 : Empty|VT.Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 1000 MB
1 - [SYSTEM][MAN-MOUNT] EFI system partition | Offset (sectors): 2050048 | Size: 260 MB
2 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2582528 | Size: 1000 MB
3 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 4630528 | Size: 128 MB
4 - Basic data partition | Offset (sectors): 4892672 | Size: 434526 MB
5 - Basic data partition | Offset (sectors): 894801920 | Size: 25600 MB
6 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 947230720 | Size: 14425 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_SCN_06112015_175620.log - RKreport_SCN_06132015_105235.log - RKreport_DEL_06132015_110612.log - RKreport_SCN_10162015_122349.log
RKreport_SCN_10172015_170533.log
Ntb Lenovo ideapad z50-75
CPU - AMD FX-7500 (512MB ATI AMD Radeon R7 Graphics)
RAM - 4GB
MB - LENOVO Lancer 5B3
GK - 2048MB ATI AMD Radeon R7 M260DX
HDD - 465GB TOSHIBA MQ01ABF050

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu (reklamy na netu, pomalejší ntb)

Příspěvekod jerabina » 18 říj 2015 13:08

Spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni antivir
Stáhni
Zoek.exe

a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit Farbar Recovery Scan Tool (FRST)
32bit.:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
64bit.:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
a ulož jej na plochu. ,pak spusť FRST jako správce
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 49 hostů