prosim o kontrolu logu.

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

pisar.Adam
nováček
Příspěvky: 5
Registrován: leden 16
Pohlaví: Nespecifikováno
Stav:
Offline

prosim o kontrolu logu.

Příspěvekod pisar.Adam » 16 led 2016 14:43

Dobrý den/ahoj,
prosim o kontrolu logu, zdá se mi,že mám v notasu podezřelé soubory,počítač běží pomaleji a do nějakých složek se nemůžu dostat,jelikož nemám oprávnění k přístupu,přitom notebook použivám z 99% jen já ná svém hlavním profilu (nastaven na přístup ke všemu),pak mám ještě jeden profil volný,ale ten nepouživám. :huh:

Asi před půl rokem jsem měl ''modrou smrt'' ,poté sem notebook reinstaloval. Dnes to vypadá takhle:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:32:06, on 16.1.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Adam\Downloads\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Advanced SystemCare Surfing Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O4 - HKLM\..\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [cmsc] "c:\program files (x86)\cmcm\Clean Master\cmtray.exe" -autorun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SpyEmergency] C:\Program Files\NETGATE\Spy Emergency\SpyEmergency.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Advanced SystemCare 9] "C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe" /Auto
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-961867671-1593851035-7881977-1000\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-961867671-1593851035-7881977-1000\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'Default user')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 9 (AdvancedSystemCareService9) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - Unknown owner - (no file)
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - Unknown owner - (no file)
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - Unknown owner - (no file)
O23 - Service: Clean Master Core Service (cmcore) - Kingsoft Corporation - c:\program files (x86)\cmcm\Clean Master\cmcore.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: NTI IScheduleSvc - NTI Corporation - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spy Emergency Health Check (SpyEmrgHealth) - NETGATE Technologies s.r.o. - C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyHealth.exe
O23 - Service: Spy Emergency Engine Service (SpyEmrgSrv) - NETGATE Technologies s.r.o. - C:\Program Files\NETGATE\Spy Emergency\SpyEmergencySrv.exe
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\Windows\SysWOW64\ssins.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless ZeroConfig Service (ZcfgSvc7) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe

--
End of file - 12883 bytes

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosim o kontrolu logu.

Příspěvekod jaro3 » 17 led 2016 10:08

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
http://www.geekstogo.com/forum/files/fi ... -oldtimer/
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu klikni na „Logfile“ ,objeví log ( jinak je uložen systémovem disku jako AdwCleaner[C?].txt), jeho obsah sem celý vlož.


Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na Kopírovat do schránky a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

pisar.Adam
nováček
Příspěvky: 5
Registrován: leden 16
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosim o kontrolu logu.

Příspěvekod pisar.Adam » 17 led 2016 15:13

Tady je log z AdwCleaner.


# AdwCleaner v5.029 - Logfile created 17/01/2016 at 15:11:00
# Updated 11/01/2016 by Xplode
# Database : 2016-01-15.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Adam - ADAM-PC
# Running from : C:\Users\Adam\Desktop\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

Folder Found : C:\ProgramData\IHProtectUpDate
Folder Found : C:\Users\Adam\AppData\Local\webplayer
Folder Found : C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl
Folder Found : C:\Users\Adam\AppData\Roaming\istartsurf
Folder Found : C:\Users\Adam\AppData\Roaming\elroar

***** [ Files ] *****

File Found : C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\1k77qwz4.default\user.js
File Found : C:\Windows\Reimage.ini

***** [ DLL ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

Task Found : amiupdaterExd
Task Found : amiupdaterExi

***** [ Registry ] *****

Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Found : HKLM\SOFTWARE\CLASSES\dream.capture
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{1F91A9A1-01BA-4C81-863D-3BA0751E1419}]
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Key Found : HKLM\SOFTWARE\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}
Key Found : HKLM\SOFTWARE\istartsurfSoftware
Key Found : HKLM\SOFTWARE\SupDp
Key Found : HKLM\SOFTWARE\SupTab
Key Found : HKLM\SOFTWARE\supWindowsMangerProtect
Key Found : HKLM\SOFTWARE\IHProtect
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{576c2c91-0d04-4c34-5587-1ae85d92099a}
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1B91313A-3010-4632-8825-A69C4F6FA6AF}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{461E6384-AF21-4D55-9B26-87B7C1140561}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{4D6A2496-2B7F-4F43-A58B-ABEE44EE6135}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{5D757790-842F-41E7-920A-8C321E6A5796}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6BF210EB-402A-4CB6-98B9-56AAA420701C}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6F4100B2-628A-4B28-8E38-97AD9D2F8C17}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8FA2F8C4-946F-4207-B281-CC1A07F367CD}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A185D828-3F97-459A-B38D-25E111F592D6}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C5E1878C-B93A-4EB8-A973-48FA8B9B71E5}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Found : HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [] - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1 ... X51RQB15LB

***** [ Web browsers ] *****

[C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\1k77qwz4.default\prefs.js] [Preference] Found : user_pref("network.hxxp.request.max-start-delay", 0);
[C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : prg.aero
[C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Found : hxxp://www.istartsurf.com/webfavicon.ico
[C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : mppnoffgpafgpgbaigljliadgbnhljfl

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [7536 bytes] ##########

pisar.Adam
nováček
Příspěvky: 5
Registrován: leden 16
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosim o kontrolu logu.

Příspěvekod pisar.Adam » 17 led 2016 15:43

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 17.1.2016
Čas skenování: 15:20
Protokol:
Správce: Ano

Verze: 2.2.0.1024
Databáze malwaru: v2016.01.17.02
Databáze rootkitů: v2016.01.09.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Adam

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 416619
Uplynulý čas: 20 min, 13 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 26
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [7c3a7cbeb0e951e55e2df7a6ee158080],
PUP.Optional.AmiUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\amiupdaterExd, , [179f41f9445554e21ada159316edb848],
PUP.Optional.AmiUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\amiupdaterExi, , [e4d2dc5e4752a78f04f06a3e897a7c84],
PUP.Optional.IHProtect, HKLM\SOFTWARE\WOW6432NODE\IHProtect, , [4c6a60da4d4cd0660cd9f8ca1ee5a25e],
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\istartsurfSoftware, , [8c2a6fcb1188c6707565d5402ed6ca36],
PUP.Optional.SupTab, HKLM\SOFTWARE\WOW6432NODE\supTab, , [a4129f9bf4a5c37346f265c47e86d32d],
PUP.Optional.WPM, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, , [9a1c7dbd178255e13702a840ad561ae6],
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [d8debb7f3e5b082eaedd5c418e7531cf],
PUP.Optional.IStartSurf, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\istartsurf uninstall, , [a90d4dede9b0999dfb708e362dd6966a],
PUP.Optional.Hicosmea, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{576c2c91-0d04-4c34-5587-1ae85d92099a}, , [922442f83069b87e5bd0f1faa36048b8],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}, , [2393ef4badec25117b4334e4976d43bd],
PUP.Optional.MiuiTab, HKLM\SOFTWARE\WOW6432NODE\SUPDP, , [63539e9c1485b87e50ef3e8eac57639d],
PUP.Optional.WindowsMangerProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, , [15a10e2cd4c5ff37841522c59f649d63],
PUP.Optional.Hicosmea, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\toralsup, , [ac0a72c8c3d69c9aa68429c2a55e9769],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{1B91313A-3010-4632-8825-A69C4F6FA6AF}, , [a61047f3851441f57a1016877a899967],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}, , [f5c1ce6ce9b0ae884644f5a825de07f9],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [a3137bbf7029c076ccbe2c71f60d51af],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{461E6384-AF21-4D55-9B26-87B7C1140561}, , [8b2b3208c0d9171f4842990425de847c],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4D6A2496-2B7F-4F43-A58B-ABEE44EE6135}, , [5b5b7dbdcccd1f176822811c768d56aa],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{5D757790-842F-41E7-920A-8C321E6A5796}, , [16a0f2480d8cf046612997061fe48080],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6BF210EB-402A-4CB6-98B9-56AAA420701C}, , [b7ff3efc16830036cac07e1fff0450b0],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6F4100B2-628A-4B28-8E38-97AD9D2F8C17}, , [585e122878217cba0f7ba2fb21e2926e],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{8FA2F8C4-946F-4207-B281-CC1A07F367CD}, , [ebcb5cde3861da5c07839eff43c05da3],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{A185D828-3F97-459A-B38D-25E111F592D6}, , [635390aa2f6a54e22b5fa1fcff0432ce],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C5E1878C-B93A-4EB8-A973-48FA8B9B71E5}, , [9026a199f7a2c3735733613c1ae943bd],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}, , [e1d5b28876234aec3357dac3e32048b8],

Hodnoty registru: 21
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, istartsurf, , [7c3a7cbeb0e951e55e2df7a6ee158080]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, , [2195ea50128785b17e0dfca1986b20e0]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, istartsurf, , [d8debb7f3e5b082eaedd5c418e7531cf]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, , [7d392713e4b5a6908506d7c67f842ad6]
PUP.Optional.MiuiTab, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\MiuiTab, , [63539e9c1485b87e50ef3e8eac57639d]
PUP.Optional.SupTab, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, smt, , [ab0b14264b4e56e0290148979b68837d]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{1B91313A-3010-4632-8825-A69C4F6FA6AF}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [a61047f3851441f57a1016877a899967]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [f5c1ce6ce9b0ae884644f5a825de07f9]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|FaviconURL, http://www.istartsurf.com//favicon.ico, , [11a571c91d7c68ce7713d4c9a16248b8]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, istartsurf, , [a3137bbf7029c076ccbe2c71f60d51af]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [1f972e0cdfbaf04662285f3ec73c7d83]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|TopResultURL, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, , [ddd90832a9f0de58bcce0c9123e00000]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{461E6384-AF21-4D55-9B26-87B7C1140561}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [8b2b3208c0d9171f4842990425de847c]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4D6A2496-2B7F-4F43-A58B-ABEE44EE6135}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [5b5b7dbdcccd1f176822811c768d56aa]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{5D757790-842F-41E7-920A-8C321E6A5796}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [16a0f2480d8cf046612997061fe48080]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6BF210EB-402A-4CB6-98B9-56AAA420701C}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [b7ff3efc16830036cac07e1fff0450b0]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6F4100B2-628A-4B28-8E38-97AD9D2F8C17}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [585e122878217cba0f7ba2fb21e2926e]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{8FA2F8C4-946F-4207-B281-CC1A07F367CD}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [ebcb5cde3861da5c07839eff43c05da3]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{A185D828-3F97-459A-B38D-25E111F592D6}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [635390aa2f6a54e22b5fa1fcff0432ce]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C5E1878C-B93A-4EB8-A973-48FA8B9B71E5}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [9026a199f7a2c3735733613c1ae943bd]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [e1d5b28876234aec3357dac3e32048b8]

Data registru: 13
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... X51RQB15LB, Dobré: (iexplore.exe), Špatné: (C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... X51RQB15LB),,[ccea1921cbce36004ca1901b1fe5669a]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}),,[07af2614f6a320165541822942c20ff1]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB),,[744235058415b284d8be317a8f759769]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB),,[42741624c0d987af66306e3df70d0cf4]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}),,[7c3a0b2fb1e82a0c4254307b9f656898]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Dobré: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Špatné: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[b2048fab9efb66d0a5a0377b956f966a]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... X51RQB15LB, Dobré: (iexplore.exe), Špatné: (C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... X51RQB15LB),,[d9dd300aff9af145d11cc3e84fb504fc]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}),,[b50193a7742586b01f774764e4206898]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB),,[674ffb3ffc9df541d2c4466511f329d7]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB),,[11a548f2ebaeef47187e03a81aea1ce4]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}),,[8b2b201adcbd74c2ddb9dad1ff0514ec]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Dobré: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Špatné: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[a313d466b0e9dc5a47fefcb673911be5]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB),,[55612a10e1b8b97d7420337840c4fc04]

Složky: 15
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IHProtectUpDate, C:\ProgramData\IHProtectUpDate, , [c1f5f9416f2a57df90da88296a9857a9],
PUP.Optional.IHProtectUpDate, C:\ProgramData\IHProtectUpDate\update, , [c1f5f9416f2a57df90da88296a9857a9],
PUP.Optional.ProtectWindowsManager, C:\ProgramData\3WinManPro3, , [65511f1b9207b6802d5d289d7d8517e9],
PUP.Optional.ProtectWindowsManager, C:\ProgramData\3WinManPro3\update, , [65511f1b9207b6802d5d289d7d8517e9],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\common, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\config, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\settings, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\settings\common, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\settings\partner, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\_metadata, , [6056a6943d5cdd5923837353f2105ca4],

Soubory: 36
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\586.json, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\MessageBox.xml, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\bg.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\bg1.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\bk_shadow.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\button.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\button1.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\checkbox.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\checkbox_select.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\checked.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\close.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\loading_bg.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\loading_light.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\min.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\scrollbar.bmp, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\Thumbs.db, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\unchecked.png, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\code1.jpg, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\code2.jpg, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\code3.jpg, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\code4.jpg, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\code5.jpg, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\code6.jpg, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\Thumbs.db, , [b7ff52e8d6c3d462173ebddbe41e08f8],
PUP.Optional.ProtectWindowsManager, C:\ProgramData\3WinManPro3\updateconf, , [65511f1b9207b6802d5d289d7d8517e9],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\manifest.json, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\common\aes.js, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\common\config.js, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\common\config.js.bak, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\common\mode-ecb.js, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\common\utils.js, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\config\build.json, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\settings\common\redirect.js, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\settings\partner\background.js, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\settings\partner\Reporting.js, , [6056a6943d5cdd5923837353f2105ca4],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\_metadata\verified_contents.json, , [6056a6943d5cdd5923837353f2105ca4],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: prosim o kontrolu logu.

Příspěvekod Orcus » 17 led 2016 18:59

Odinstaluj Advanced SystemCare.

- Spusť znovu MbAM a dej Skenovat nyní
- Po proběhnutí programu, se ti objeví hláška, tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

====================================================

- Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
- Klikni na „ Smazat“
- Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

====================================================

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

====================================================

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- Počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

pisar.Adam
nováček
Příspěvky: 5
Registrován: leden 16
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosim o kontrolu logu.

Příspěvekod pisar.Adam » 17 led 2016 20:01

Tady je log z MBaM.



Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 17.1.2016
Čas skenování: 19:29
Protokol: MBam.txt
Správce: Ano

Verze: 2.2.0.1024
Databáze malwaru: v2016.01.17.04
Databáze rootkitů: v2016.01.09.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Adam

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 416981
Uplynulý čas: 23 min, 5 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 26
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [10a8a991d6c353e39573722cf80b718f],
PUP.Optional.AmiUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\amiupdaterExd, , [6157fe3c3d5c0e287ef25b4ed72c738d],
PUP.Optional.AmiUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\amiupdaterExi, , [e5d3fc3e2178f73fdc941891d92afd03],
PUP.Optional.IHProtect, HKLM\SOFTWARE\WOW6432NODE\IHProtect, , [d6e24feb7425b4829dc4af142ad9cc34],
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\istartsurfSoftware, , [80381e1c5e3b9b9b88cbc4520ff5fe02],
PUP.Optional.SupTab, HKLM\SOFTWARE\WOW6432NODE\supTab, , [e3d5b08a40594aec08a934f55da75da3],
PUP.Optional.WPM, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, , [befa58e2376291a5c8eaf6f2ab58a957],
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [6850e753aaef4fe7d533ddc137cc738d],
PUP.Optional.IStartSurf, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\istartsurf uninstall, , [09afd76363366bcbda0d6e56ec1731cf],
PUP.Optional.Hicosmea, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{576c2c91-0d04-4c34-5587-1ae85d92099a}, , [18a041f94f4a1620bbe97b703cc73dc3],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}, , [7048d367425778be3ff882973cc8e719],
PUP.Optional.MiuiTab, HKLM\SOFTWARE\WOW6432NODE\SUPDP, , [388064d6e8b1ad8994277f4dcd3641bf],
PUP.Optional.WindowsMangerProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, , [7c3c40fa0f8a45f1f31fcc1c0201e818],
PUP.Optional.Hicosmea, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\toralsup, , [9721172304953cfaf3b0de0d93707090],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{1B91313A-3010-4632-8825-A69C4F6FA6AF}, , [09af7fbb7722162014f39806a06333cd],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}, , [8038bd7dafeadc5ae5224a545ba8e11f],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [ecccd3670f8a59dd18effaa40bf8d927],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{461E6384-AF21-4D55-9B26-87B7C1140561}, , [dade4eec8514d95dc443a3fb56ade11f],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4D6A2496-2B7F-4F43-A58B-ABEE44EE6135}, , [12a664d6a9f01620ed1a277728db3ec2],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{5D757790-842F-41E7-920A-8C321E6A5796}, , [edcb3703cdccb87e7295bae419eaa15f],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6BF210EB-402A-4CB6-98B9-56AAA420701C}, , [9622ac8ebcdd9e98f611afef2cd7e31d],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6F4100B2-628A-4B28-8E38-97AD9D2F8C17}, , [7444db5f0f8a023408ff0a94db28649c],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{8FA2F8C4-946F-4207-B281-CC1A07F367CD}, , [7e3acf6bfe9b4ee88c7b742a966dd22e],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{A185D828-3F97-459A-B38D-25E111F592D6}, , [08b078c265348caa11f6d7c7c241b848],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C5E1878C-B93A-4EB8-A973-48FA8B9B71E5}, , [b20657e31c7dad895daa930b897a9c64],
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}, , [a51354e611882016e126029c14ef54ac],

Hodnoty registru: 21
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, istartsurf, , [10a8a991d6c353e39573722cf80b718f]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, , [4c6c50ea0f8a1c1a10f8b9e52ad9639d]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, istartsurf, , [6850e753aaef4fe7d533ddc137cc738d]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, , [e0d8b5854158290d75934b535ca7cc34]
PUP.Optional.MiuiTab, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\MiuiTab, , [388064d6e8b1ad8994277f4dcd3641bf]
PUP.Optional.SupTab, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, smt, , [754356e4dbbeb97d7c27617e3fc46b95]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{1B91313A-3010-4632-8825-A69C4F6FA6AF}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [09af7fbb7722162014f39806a06333cd]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [8038bd7dafeadc5ae5224a545ba8e11f]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|FaviconURL, http://www.istartsurf.com//favicon.ico, , [e1d77dbdc5d459dd1fe89905a65d3bc5]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, istartsurf, , [ecccd3670f8a59dd18effaa40bf8d927]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [e5d35edcf0a953e3bf485b43778c639d]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|TopResultURL, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, , [dade61d94b4e3204c4437d2144bf19e7]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{461E6384-AF21-4D55-9B26-87B7C1140561}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [dade4eec8514d95dc443a3fb56ade11f]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4D6A2496-2B7F-4F43-A58B-ABEE44EE6135}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [12a664d6a9f01620ed1a277728db3ec2]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{5D757790-842F-41E7-920A-8C321E6A5796}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [edcb3703cdccb87e7295bae419eaa15f]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6BF210EB-402A-4CB6-98B9-56AAA420701C}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [9622ac8ebcdd9e98f611afef2cd7e31d]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6F4100B2-628A-4B28-8E38-97AD9D2F8C17}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [7444db5f0f8a023408ff0a94db28649c]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{8FA2F8C4-946F-4207-B281-CC1A07F367CD}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [7e3acf6bfe9b4ee88c7b742a966dd22e]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{A185D828-3F97-459A-B38D-25E111F592D6}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [08b078c265348caa11f6d7c7c241b848]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C5E1878C-B93A-4EB8-A973-48FA8B9B71E5}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [b20657e31c7dad895daa930b897a9c64]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}|URL, http://www.istartsurf.com/web/?utm_sour ... default&q={searchTerms}, , [a51354e611882016e126029c14ef54ac]

Data registru: 13
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... X51RQB15LB, Dobré: (iexplore.exe), Špatné: (C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... X51RQB15LB),,[07b10238b8e1ff37433d8329ce365fa1]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}),,[4a6ef04ad9c080b658d1f0bc6d976a96]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB),,[3d7b95a5c5d4e84eb673bbf1ec18f60a]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB),,[665236044257171f0227911bb84ce020]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}),,[5b5d9aa06a2fd066d8511399b54f6f91]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Dobré: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Špatné: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[d6e211292970d75fd9ff4d6530d48977]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... X51RQB15LB, Dobré: (iexplore.exe), Špatné: (C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... X51RQB15LB),,[a90f5bdfa7f286b06c140f9dc440fb05]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}),,[23950f2b6b2e83b3a683ddcf38cc25db]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB),,[8038f941910860d6d158e0ccf2129967]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB),,[b701ff3b6831ff375ccddbd155af6898]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/web/?type=ds& ... RQB15LB&q={searchTerms}),,[e5d378c21f7a53e3d059347818ecc838]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Dobré: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Špatné: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[5167bc7eff9a181e1fb9436f768e14ec]
PUP.Optional.IStartSurf.ShrtCln, HKU\S-1-5-21-961867671-1593851035-7881977-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB, Dobré: (www.google.com), Špatné: (http://www.istartsurf.com/?type=hp&ts=1 ... X51RQB15LB),,[dade5bdf9cfd2c0a4bdc426af50fcd33]

Složky: 15
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IHProtectUpDate, C:\ProgramData\IHProtectUpDate, , [2f89f3476b2e4de94189cbe612f0e719],
PUP.Optional.IHProtectUpDate, C:\ProgramData\IHProtectUpDate\update, , [2f89f3476b2e4de94189cbe612f0e719],
PUP.Optional.ProtectWindowsManager, C:\ProgramData\3WinManPro3, , [13a59b9f85144ee85f8b10b5aa584fb1],
PUP.Optional.ProtectWindowsManager, C:\ProgramData\3WinManPro3\update, , [13a59b9f85144ee85f8b10b5aa584fb1],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\common, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\config, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\settings, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\settings\common, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\settings\partner, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\_metadata, , [5167bf7b673238fe3ccac007f909b44c],

Soubory: 36
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\586.json, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\MessageBox.xml, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\bg.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\bg1.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\bk_shadow.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\button.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\button1.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\checkbox.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\checkbox_select.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\checked.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\close.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\loading_bg.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\loading_light.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\min.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\scrollbar.bmp, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\Thumbs.db, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\unchecked.png, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\code1.jpg, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\code2.jpg, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\code3.jpg, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\code4.jpg, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\code5.jpg, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\code6.jpg, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.IStartSurf.ShrtCln, C:\Users\Adam\AppData\Roaming\istartsurf\images\code\Thumbs.db, , [86323cfe9dfc47effeb79afe4cb6fe02],
PUP.Optional.ProtectWindowsManager, C:\ProgramData\3WinManPro3\updateconf, , [13a59b9f85144ee85f8b10b5aa584fb1],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\manifest.json, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\common\aes.js, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\common\config.js, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\common\config.js.bak, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\common\mode-ecb.js, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\common\utils.js, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\config\build.json, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\settings\common\redirect.js, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\settings\partner\background.js, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\settings\partner\Reporting.js, , [5167bf7b673238fe3ccac007f909b44c],
PUP.Optional.Ilivid, C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl\1.1_1\_metadata\verified_contents.json, , [5167bf7b673238fe3ccac007f909b44c],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

pisar.Adam
nováček
Příspěvky: 5
Registrován: leden 16
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosim o kontrolu logu.

Příspěvekod pisar.Adam » 17 led 2016 20:16

Log po scanu a restartu ADWcleaneru.


# AdwCleaner v5.029 - Logfile created 17/01/2016 at 20:10:32
# Updated 11/01/2016 by Xplode
# Database : 2016-01-15.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Adam - ADAM-PC
# Running from : C:\Users\Adam\Desktop\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Users\Adam\AppData\Local\webplayer
[-] Folder Deleted : C:\Users\Adam\AppData\Roaming\elroar

***** [ Files ] *****

[-] File Deleted : C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\1k77qwz4.default\user.js
[-] File Deleted : C:\Windows\Reimage.ini

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\CLASSES\dream.capture
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{1F91A9A1-01BA-4C81-863D-3BA0751E1419}]
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : HKLM\SOFTWARE\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}

***** [ Web browsers ] *****

[-] [C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\1k77qwz4.default\prefs.js] [Preference] Deleted : user_pref("network.hxxp.request.max-start-delay", 0);
[-] [C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Deleted : hxxp://www.istartsurf.com/webfavicon.ico
[-] [C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : mppnoffgpafgpgbaigljliadgbnhljfl

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [2570 bytes] ##########

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosim o kontrolu logu.

Příspěvekod jaro3 » 18 led 2016 10:03

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Cleaning (Vymazat)

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

. spusť znovu Malwarebytes' Anti-Malware a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“ , v okně na pak na „Open TXT“ a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 43 hostů