Otevírání nechtěných reklamních stránek Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Otevírání nechtěných reklamních stránek

Příspěvekod jaro3 » 04 zář 2013 11:47

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\_elementtree.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\_socket.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\pysqlite2._sqlite.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32com.shell.shell.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32api.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._html2.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\_multiprocessing.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32ts.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._gdi_.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\windows._cacheinvalidation.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\_ctypes.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32profile.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32crypt.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\pythoncom27.dll ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._core_.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\_ssl.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._misc_.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\PyWinTypes27.dll ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32security.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32process.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32pdh.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._windows_.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\_hashlib.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._wizard.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32file.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32inet.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._controls_.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\pyexpat.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32event.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\unicodedata.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\select.pyd ()
DRV:64bit: - (01420742) -- C:\Windows\SysNative\drivers\01420742.sys (Kaspersky Lab ZAO)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope = {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
FF - prefs.js..extensions.enabledAddons: %7B35106bca-6c78-48c7-ac28-56df30b51d2a%7D:1.3.8
FF - prefs.js..extensions.enabledAddons: foxmarks%40kei.com:4.2.1
FF - prefs.js..extensions.enabledAddons: mozilla_cc%40internetdownloadmanager.com:7.3.55
FF - prefs.js..extensions.enabledAddons: toolbarbutton%40browseradditions.com:1.0
FF - prefs.js..extensions.enabledAddons: %7B740B3FD5-4483-469D-BE7F-8555B153BD04%7D:1.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll File not found
[2012.11.28 01:10:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\hellhound71\AppData\Roaming\Mozilla\Extensions
[2013.09.01 13:05:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions
[2013.07.22 23:17:14 | 000,000,000 | ---D | M] (saFe syave) -- C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\coafy3@pieu.edu
[2013.04.20 18:52:47 | 000,301,821 | ---- | M] () (No name found) -- C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\compatibility@addons.mozilla.org.xpi
[2012.12.28 17:39:19 | 000,067,812 | ---- | M] () (No name found) -- C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}.xpi
[2013.08.12 20:06:32 | 000,824,302 | ---- | M] () (No name found) -- C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.08.31 03:38:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013.08.31 03:38:19 | 000,000,000 | ---D | M] (BasicServe) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{740B3FD5-4483-469D-BE7F-8555B153BD04}
O4 - HKLM..\RunOnce: [GrpConv] C:\Windows\SysWow64\grpconv.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2013.09.01 15:48:03 | 000,634,530 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2013.09.01 15:48:03 | 000,618,936 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.09.01 15:48:03 | 000,123,120 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2013.09.01 15:48:03 | 000,107,256 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:1CE11B51
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:B797EE03

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\ProgramData\Kaspersky Lab
C:\Windows\SysNative\drivers\01420742.sys
C:\Users\hellhound71\Desktop\Kaspersky-Virus-Removal-Tool_11.0.0.1245_[07.07.2013].exe
C:\Windows\MusiccityDownload.exe
C:\Windows\SysWow64\cis-2.4.dll
C:\Windows\SysWow64\issacapi_bs-2.3.dll
C:\Windows\SysWow64\issacapi_pe-2.3.dll
C:\Windows\SysWow64\issacapi_se-2.3.dll
C:\Windows\ativpsrm.bin
C:\Users\hellhound71\AppData\Local\Temp\_MEI50282

:Reg
:Commands
[purity]
[emptytemp]
[CLEARALLRESTOREPOINTS]
[CREATERESTOREPOINT]
[start explorer]
[Reboot]

Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

Drive C: | 97,66 Gb Total Space | 7,73 Gb Free Space | 7,92% Space Free | Partition Type: NTFS

Málo místa na syst. disku!! Něco musíš odinstalovat , smazat. Je třeba mít alespoň 15% volného místa pro správný chod windows.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
yanek71
Level 1
Level 1
Příspěvky: 50
Registrován: březen 06
Pohlaví: Muž
Stav:
Offline

Re: Otevírání nechtěných reklamních stránek

Příspěvekod yanek71 » 04 zář 2013 18:19

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
Error: No service named 01420742 was found to stop!
Service\Driver key 01420742 not found.
File C:\Windows\SysNative\drivers\01420742.sys not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Prefs.js: %7B35106bca-6c78-48c7-ac28-56df30b51d2a%7D:1.3.8 removed from extensions.enabledAddons
Prefs.js: foxmarks%40kei.com:4.2.1 removed from extensions.enabledAddons
Prefs.js: mozilla_cc%40internetdownloadmanager.com:7.3.55 removed from extensions.enabledAddons
Prefs.js: toolbarbutton%40browseradditions.com:1.0 removed from extensions.enabledAddons
Prefs.js: %7B740B3FD5-4483-469D-BE7F-8555B153BD04%7D:1.0 removed from extensions.enabledAddons
Prefs.js: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0 removed from extensions.enabledAddons
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Extensions folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\toolbarbutton@browseradditions.com\defaults\preferences folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\toolbarbutton@browseradditions.com\defaults folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\toolbarbutton@browseradditions.com\chrome\skin folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\toolbarbutton@browseradditions.com\chrome\locale\en-US folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\toolbarbutton@browseradditions.com\chrome\locale folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\toolbarbutton@browseradditions.com\chrome\content folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\toolbarbutton@browseradditions.com\chrome folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\toolbarbutton@browseradditions.com folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\modules folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\META-INF folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\defaults\preferences folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\defaults folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\components folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\skin\modern\images folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\skin\modern folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\skin folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\zh-TW folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\zh-CN folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\vi folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\uk-UA folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\tr-TR folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\sv-SE folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\sk-SK folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\ru-RU folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\ro folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\pt-PT folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\pt-BR folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\pl-PL folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\nn-NO folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\nl folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\ko-KR folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\ja-JP folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\it-IT folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\hu-HU folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\fy-NL folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\fr folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\fi-FI folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\eu-ES folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\et-EE folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\es-ES folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\en-US folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\el-GR folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\de folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\da-DK folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\cs-CZ folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\bn-IN folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\bg-BG folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale\ar folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\locale folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\content\shared folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome\content folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com\chrome folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\foxmarks@kei.com folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\coafy3@pieu.edu\content folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\coafy3@pieu.edu folder moved successfully.
C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions folder moved successfully.
Folder C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\coafy3@pieu.edu\ not found.
File C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\compatibility@addons.mozilla.org.xpi not found.
File C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}.xpi not found.
File C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi not found.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{740B3FD5-4483-469D-BE7F-8555B153BD04}\defaults\preferences folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{740B3FD5-4483-469D-BE7F-8555B153BD04}\defaults folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{740B3FD5-4483-469D-BE7F-8555B153BD04}\chrome folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{740B3FD5-4483-469D-BE7F-8555B153BD04} folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions folder moved successfully.
Folder C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{740B3FD5-4483-469D-BE7F-8555B153BD04}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\GrpConv not found.
File move failed. C:\Windows\SysWOW64\grpconv.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\grooveLocalGWS\ deleted successfully.
File Protocol\Handler\grooveLocalGWS - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
C:\Windows\SysNative\perfh005.dat moved successfully.
C:\Windows\SysNative\perfh009.dat moved successfully.
C:\Windows\SysNative\perfc005.dat moved successfully.
C:\Windows\SysNative\perfc009.dat moved successfully.
ADS C:\ProgramData\TEMP:1CE11B51 deleted successfully.
ADS C:\ProgramData\TEMP:B797EE03 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\system32\DUMP*.tmp not found.
c:\windows\Tasks\Adobe Flash Player Updater.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
File\Folder C:\Windows\SysNative\drivers\*.tmp not found.
File\Folder C:\Windows\SysWow64\drivers\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
File\Folder C:\Windows\SysWow64\*.tmp not found.
File\Folder C:\Windows\SysNative\*.tmp not found.
C:\ProgramData\Kaspersky Lab folder moved successfully.
File\Folder C:\Windows\SysNative\drivers\01420742.sys not found.
C:\Users\hellhound71\Desktop\Kaspersky-Virus-Removal-Tool_11.0.0.1245_[07.07.2013].exe moved successfully.
C:\Windows\MusiccityDownload.exe moved successfully.
C:\Windows\SysWow64\cis-2.4.dll moved successfully.
C:\Windows\SysWow64\issacapi_bs-2.3.dll moved successfully.
C:\Windows\SysWow64\issacapi_pe-2.3.dll moved successfully.
C:\Windows\SysWow64\issacapi_se-2.3.dll moved successfully.
C:\Windows\ativpsrm.bin moved successfully.
File\Folder C:\Users\hellhound71\AppData\Local\Temp\_MEI50282 not found.
========== REGISTRY ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: hellhound71
->Temp folder emptied: 2085475987 bytes
->Temporary Internet Files folder emptied: 88927 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 286721929 bytes
->Google Chrome cache emptied: 77235744 bytes
->Flash cache emptied: 5278 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 621232 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50635 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 2 337,00 mb

Restore point Set: OTL Restore Point
Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 09042013_180409

Files\Folders moved on Reboot...
File move failed. C:\Windows\SysWOW64\grpconv.exe scheduled to be moved on reboot.
File\Folder C:\Users\hellhound71\AppData\Local\Temp\hsperfdata_hellhound71\2840 not found!
C:\Users\hellhound71\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\hellhound71\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File\Folder C:\Windows\temp\hsperfdata_HELLHOUND$\2124 not found!
C:\Windows\temp\sqlite-3.7.2-sqlitejdbc.dll moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Myslim že už před touhle opravou se problem vyřešil, ale ještě budu testovat a dám vědět.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Otevírání nechtěných reklamních stránek

Příspěvekod jaro3 » 04 zář 2013 19:26

Pokud bude vše v pořádku:

Spusť OTL a klikni na Vyčisti.

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

yanek71
Level 1
Level 1
Příspěvky: 50
Registrován: březen 06
Pohlaví: Muž
Stav:
Offline

Re: Otevírání nechtěných reklamních stránek  Vyřešeno

Příspěvekod yanek71 » 04 zář 2013 23:06

Problém zdá se vyřešen.Mockrát děkuji všem zůčastněným.Ste PROFÍCI.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 78 hostů