kontrola ,nefunguje internet stahování, ping ok Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Irelas
Level 1
Level 1
Příspěvky: 57
Registrován: květen 08
Pohlaví: Žena
Stav:
Offline

kontrola ,nefunguje internet stahování, ping ok

Příspěvekod Irelas » 18 led 2015 12:59

Dobrý den
Již dva dny zkouším řešit problém pročetla jsem hodně sekcí ale nevím si dál rady.Nefunguje mi internet jen na stahování mohu načítat stránky některé poněk hůře ale at se snažím o jakékoliv stažení ,nefunguje ani aktualizace hitjack jsem stáhla pro jeho malou velikost ostaní se zaseknou asi kolem 4 mb spíš měně.Zkouším přes ie mozilu a free rapid všude stejné.Při trasování je vše v pořádku dokonce v tak dokonalém které jsem nikdy neměla jsem na wifi .Poskytovatel se semnou odmítá bavit prý je vše ok .Tento problém ale nastal u všech pc které ma připojené na switch nikdo nestáhne ani jeden soubor .Dělala jsem udržbu přes eset ale začalo to házet modrou smrt eset jsem odinstalovala modrá smrt přestala ale problém který jsem řešila na začátku je ještě horší a nemohu si stáhnout ani jiný antivir ani aktualizace win nic nefunguje přikládám log apředem díky za jakoukoliv pomoc


Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 12:26:25, on 18.1.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)

FIREFOX: 34.0.5 (x86 cs)
Boot mode: Normal

Running processes:
K:\programy ++\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
K:\instalace programy\NetWorx\networx.exe
C:\Program Files\NetSoftware\NetSoftware.exe
C:\Users\nikdo\AppData\Local\Temp\widows.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_257.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_257.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
K:\stahování\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - K:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - (no file)
O2 - BHO: InternetPanelBHO - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\NetSoftware\IEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NetWorx] "K:\instalace programy\NetWorx\networx.exe" /auto
O4 - HKLM\..\Run: [NetSoftware] "C:\Program Files\NetSoftware\Starter.exe" /path="C:\Program Files\NetSoftware"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] K:\programy ++\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - Startup: 284db1d79e871dc8e3adb71dcdf8747f.exe
O4 - Startup: svhost.exe
O4 - Global Startup: GIGABYTE OC_GURU.lnk = C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU\OC_GURU.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - K:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - K:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - K:\programy ++\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10144 bytes

Reklama
Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: kontrola ,nefunguje internet stahování, ping ok

Příspěvekod memphisto » 18 led 2015 17:44

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranìní historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit doèasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner
Ulož si ho na svojí plochu
Ukonči všechny programy, okna a prohlížeče
Spusť program poklepáním a klikni na „Search“
Po skenu se objeví log (jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.


Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na Kopírovat do schránky a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Irelas
Level 1
Level 1
Příspěvky: 57
Registrován: květen 08
Pohlaví: Žena
Stav:
Offline

Re: kontrola ,nefunguje internet stahování, ping ok

Příspěvekod Irelas » 18 led 2015 18:20

# AdwCleaner v4.108 - Report created 18/01/2015 at 18:18:34
# Updated 17/01/2015 by Xplode
# Database : 2015-01-13.2 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : nikdo - NIKDY
# Running from : C:\Users\nikdo\Desktop\adwcleaner_4.108(2).exe
# Option : Scan

***** [ Services ] *****

Service Found : vToolbarUpdater18.2.0

***** [ Files / Folders ] *****

File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\delta-homes.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
File Found : C:\Users\nikdo\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\avg-secure-search.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\funmoods.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\Conduit.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\funmoods.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\user.js
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\Askcom.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\funmoods.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\qip-search.xml
File Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\user.js
File Found : C:\Users\Public\Desktop\iLivid.lnk
File Found : C:\Users\Public\Desktop\iLivid.lnk
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Program Files (x86)\SupTab
Folder Found : C:\Program Files (x86)\WinZipper
Folder Found : C:\ProgramData\AlawarWrapper
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\AVG Security Toolbar
Folder Found : C:\ProgramData\IePluginServices
Folder Found : C:\ProgramData\Trymedia
Folder Found : C:\ProgramData\WindowsMangerProtect
Folder Found : C:\Users\nikdo\AppData\Local\AlawarWrapper
Folder Found : C:\Users\nikdo\AppData\Local\apn
Folder Found : C:\Users\nikdo\AppData\Local\cool_mirage
Folder Found : C:\Users\nikdo\AppData\Local\PackageAware
Folder Found : C:\Users\nikdo\AppData\Local\SwvUpdater
Folder Found : C:\Users\nikdo\AppData\LocalLow\Funmoods
Folder Found : C:\Users\nikdo\AppData\LocalLow\PriceGong
Folder Found : C:\Users\nikdo\AppData\Roaming\eCyber
Folder Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\Extensions\Avg@toolbar
Folder Found : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\Extensions\{32A1FD71-835E-4B11-8E54-886FDA0B4C89}
Folder Found : C:\Users\nikdo\AppData\Roaming\WinZipper
Folder Found : C:\Users\Public\Documents\AlawarWrapper
Folder Found : C:\Users\Public\Documents\iWin

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191
Key Found : HKCU\Software\1ClickDownload
Key Found : HKCU\Software\27ccc8c626aecdf2927cdc5ef0c9bde2
Key Found : HKCU\Software\284db1d79e871dc8e3adb71dcdf8747f
Key Found : HKCU\Software\84de8db26feb13
Key Found : HKCU\Software\AppDataLow\Software\adawarebp
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKCU\Software\Mozilla\Extends
Key Found : HKCU\Software\SupHpUISoft
Key Found : [x64] HKCU\Software\1ClickDownload
Key Found : [x64] HKCU\Software\DataMngr
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : [x64] HKCU\Software\SupHpUISoft
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{A2773ED4-83BD-488A-A186-73590706C916}
Key Found : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Found : HKLM\SOFTWARE\Classes\S
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\DataMngr
Key Found : HKLM\SOFTWARE\delta-homesSoftware
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh
Key Found : HKLM\SOFTWARE\hdcode
Key Found : HKLM\SOFTWARE\istartsurfSoftware
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : HKLM\SOFTWARE\SupDp
Key Found : HKLM\SOFTWARE\SupTab
Key Found : HKLM\SOFTWARE\supWindowsMangerProtect
Key Found : HKLM\SOFTWARE\supWPM
Key Found : HKLM\SOFTWARE\systweak
Key Found : HKLM\SOFTWARE\Trymedia Systems
Key Found : HKLM\SOFTWARE\V9
Key Found : HKLM\SOFTWARE\winzipersvc
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant] - hxxp://search.qip.ru/ie
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [bProtectTabs] - hxxp://mixidj.delta-search.com/?affID=1 ... 6F65CE77B8
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds& ... BA04191&q={searchTerms}
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.delta-homes.com/?type=hp&ts= ... JX0BA04191
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.delta-homes.com/?type=hp&ts= ... JX0BA04191
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds& ... BA04191&q={searchTerms}

-\\ Mozilla Firefox v35.0 (x86 cs)

[g0syoo15.default-1349863581988] - Line Found : user_pref("browser.newtab.url", "hxxp://www.delta-homes.com/newtab/?type=nt&ts=1419407016&from=wpm12233&uid=SAMSUNGXHD103SJ_S246JX0BA04191");
[g0syoo15.default-1349863581988] - Line Found : user_pref("browser.search.selectedEngine", "AVG Secure Search");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.aflt", "ddrnw");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.dfltLng", "");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.dfltSrch", true);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.dnsErr", true);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.excTlbr", false);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.hmpg", true);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=ddrnw");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.id", "c20d6c7b0000000000001c6f65ce77b8");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.instlDay", "15710");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.instlRef", "");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.newTab", true);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=ddrnw");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.prdct", "funmoods");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.prtnrId", "funmoods");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.smplGrp", "none");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.srchPrvdr", "Search");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.tlbrId", "base");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=ddrnw&q=");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.vrsn", "1.5.11.16");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.vrsnTs", "1.5.11.1622:26:22");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.funmoods_i.vrsni", "1.5.11.16");
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.quick_start.enable_search1", false);
[g0syoo15.default-1349863581988] - Line Found : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595..clientLogIsEnabled", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.CT2832595", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.CurrentServerDate", "20-7-2012");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.DSInstall", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.DialogsAlignMode", "LTR");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.DialogsGetterLastCheckTime", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.DownloadReferralCookieData", "");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FirstServerDate", "20-7-2012");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FirstTime", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FirstTimeFF3", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FirstTimeHiddenVer", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.FixPageNotFoundErrors", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.GroupingServerCheckInterval", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.HPInstall", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.HasUserGlobalKeys", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.HomePageProtectorEnabled", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.HomepageBeforeUnload", "www.seznam.cz");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.Initialize", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.InitializeCommonPrefs", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.InstallationAndCookieDataSentCount", 2);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.InstallationType", "Unknown");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.InstalledDate", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsAlertDBUpdated", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsGrouping", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsInitSetupIni", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsMulticommunity", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsOpenThankYouPage", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsOpenUninstallPage", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.IsProtectorsInit", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LanguagePackLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LanguagePackReloadIntervalMM", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LastLogin_3.14.1.0", "Tue Jun 19 2012 06:03:26 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.LatestVersion", "3.13.0.6");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.Locale", "en");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.MCDetectTooltipHeight", "83");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.MCDetectTooltipWidth", "295");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.MyStuffEnabledAtInstallation", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.OriginalFirstVersion", "3.14.1.0");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SHRINK_TOOLBAR", 1);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SavedHomepage", "chrome://branding/locale/browserconfig.properties");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchCaption", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchEngineBeforeUnload", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchFromAddressBarIsInit", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=2&q=");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchInNewTabEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchInNewTabIntervalMM", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchInNewTabLastCheckTime", "Tue Jun 19 2012 00:38:59 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchProtectorEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SearchProtectorToolbarDisabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SendProtectorDataViaLogin", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ServiceMapLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SettingsLastCheckTime", "Tue Jun 19 2012 06:03:25 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.SettingsLastUpdate", "1342353688");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2832595&SearchSource=13");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ThirdPartyComponentsInterval", 504);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ThirdPartyComponentsLastCheck", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ThirdPartyComponentsLastUpdate", "1331805997");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ToolbarDisabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ToolbarShrinkedFromSetup", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.UserID", "UN66842355699789321");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.ValidationData_Toolbar", 2);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.alertChannelId", "1224658");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.activetoolbar", "77657374");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.toolbar_market", "637A");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.toolbarurl", "687474703A2F2F746F6F6C6261722E696E6E6F67616D65732E64652F746F6F6C626172732F776573742F746F6F6C6261722E706870");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.west_password_cz", "5A57787063327468");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.west_session_id_cz", "30366139633234643932643930343531");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.west_username_cz", "61584A6C6247467A");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.backendstorage.west_world_url_cz", "687474703A2F2F637A31312E7468652D776573742E637A");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.globalFirstTimeInfoLastCheckTime", "Tue Jun 19 2012 00:39:02 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.homepageProtectorEnableByLogin", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.initDone", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.isAppTrackingManagerOn", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffPublihserMinWidth", 400);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffServiceIntervalMM", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.navigateToUrlOnSearch", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.revertSettingsEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.searchProtectorDialogDelayInSec", 10);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.searchProtectorEnableByLogin", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.testingCtid", "");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.toolbarAppMetaDataLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.toolbarContextMenuLastCheckTime", "Tue Jun 19 2012 00:38:55 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CT2832595.usagesFlag", 2);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2832595&SearchSource=13");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ConduitSearchList", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "G9mW7heT/8xIX1frcduu0A==");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "mfQ70fvlD2zuBxSBj8rQqA==");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "UgzXjW7BIkfdx+x39Ruv3w==");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "4BgM4MhF/sOgPsDNmIs3Yw==");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\nikdo\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\h3z7n07y.default-1340054342780\\conduitCommon\\modules\\3.14.1.0");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.14.1.0");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ToolbarsList", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.globalUserId", "391fe62a-3022-4398-9628-b9e8e063f367");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2832595");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.alertEnabled", true);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Jun 19 2012 01:38:58 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.locale", "en");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.notifications.userId", "c828a219-d890-4df5-b53d-ead686137cd0");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("browser.search.defaultthis.engineName", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=3&q={searchTerms}");
[h3z7n07y.default-1340054342780] - Line Found : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");

-\\ Google Chrome v39.0.2171.99

[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}

-\\ Chromium v

[C:\Users\nikdo\AppData\Local\Chromium\User Data\Default\preferences] - Found [Homepage] : hxxp://qip.ru

*************************

AdwCleaner[R0].txt - [31704 octets] - [18/01/2015 18:18:34]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [31765 octets] ##########

Irelas
Level 1
Level 1
Příspěvky: 57
Registrován: květen 08
Pohlaví: Žena
Stav:
Offline

Re: kontrola ,nefunguje internet stahování, ping ok

Příspěvekod Irelas » 19 led 2015 04:46

nezapoměla jsem jen se mi nepovedlo stáhnout poslední soubor malwarebytes po práci budu pokračovat ,děkuji

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola ,nefunguje internet stahování, ping ok

Příspěvekod jaro3 » 19 led 2015 09:55

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Ještě MbAM.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Irelas
Level 1
Level 1
Příspěvky: 57
Registrován: květen 08
Pohlaví: Žena
Stav:
Offline

Re: kontrola ,nefunguje internet stahování, ping ok

Příspěvekod Irelas » 19 led 2015 16:51

dodán scen z malware

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 19.1.2015
Scan Time: 16:44:36
Logfile: log malwar.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.01.19.08
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: nikdo

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 378300
Time Elapsed: 3 min, 56 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 30
PUP.Optional.MixiDJToolbar.A, HKLM\SOFTWARE\CLASSES\APPID\{A2773ED4-83BD-488A-A186-73590706C916}, , [b68e6a8f1d6c5fd7ffdc2ef8ec17aa56],
PUP.Optional.MixiDJToolbar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{A2773ED4-83BD-488A-A186-73590706C916}, , [b68e6a8f1d6c5fd7ffdc2ef8ec17aa56],
PUP.Optional.Babylon.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [60e451a828618fa7ba7bd815df23956b],
PUP.Optional.SupTab.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [4202a554a6e3e452387fb53c60a2a15f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [4202a554a6e3e452387fb53c60a2a15f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [4202a554a6e3e452387fb53c60a2a15f],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\CLASSES\Updater.AmiUpd.1, , [59ebe41523666ec864f48c6d17eb4fb1],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Updater.AmiUpd.1, , [3d0726d3028790a6db7de31625ddcc34],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\Updater.AmiUpd, , [62e2da1f4b3e62d4a44d0484da298c74],
PUP.Optional.SecurityProtection.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\noajmlkipclmeolfcnflkjhijkigpfjh, , [da6a31c8f990d75fb54ca0d700036a96],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [a99bc0392a5f7fb717cec712ad578779],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, , [2f15ce2b1376e84e786d3b6047bc4fb1],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\delta-homesSoftware, , [95af76838cfda294d875573722e149b7],
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\istartsurfSoftware, , [d66e5d9c6a1f2e08d702a9e1966d51af],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, , [90b4b445583186b03ffb6d8123e1e61a],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, , [d66e3abf375253e39193d2b7db2834cc],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Updater.AmiUpd, , [a2a2e514a7e2d36343ae86029d66a65a],
PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\fdloijijlkoblmigdofommgnheckmaki, , [a2a205f479104ee80791c7c4768e6a96],
PUP.Optional.SecurityProtection.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\noajmlkipclmeolfcnflkjhijkigpfjh, , [bf85b6436b1e1026d72ad0a734cf6a96],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [88bc12e793f647ef44a1d009c341e41c],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, , [fc484bae2465d75f3fb366222ed5e11f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, , [7dc703f68900e155a47f296010f3649c],
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, , [ef553ebb2a5f69cdca863c42cb38c43c],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, , [8db7e118e3a6d56157fa85f9e320bc44],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, , [261e85740089a78feeb78847f90ba65a],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, , [7ec6669390f974c2c66e6866976dfe02],
PUP.Optional.WebSearches.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SupHpUISoft, , [ad97a75297f250e622b1ff8b38cb6e92],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [ba8aba3fa6e353e3b5cd3942986bb749],
PUP.Optional.Qone8, HKU\S-1-5-21-2107716189-2857289073-577814198-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [360e10e9dfaae5515e862eab010316ea],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-2107716189-2857289073-577814198-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [9ea636c35534d85ecfb38eeda65d0df3],

Registry Values: 4
PUP.Optional.BrowserProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\ABOUTURLS|bProtectTabs, http://mixidj.delta-search.com/?affID=1 ... 6F65CE77B8, , [a89c639659307eb8debc636e9371fa06]
PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\extensions\faststartff@gmail.com, , [b58f34c59eebe25498bcf4f95ca8d729]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, , [fc484bae2465d75f3fb366222ed5e11f]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, ild, , [7dc703f68900e155a47f296010f3649c]

Registry Data: 6
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191),,[3a0ac33698f1f83e4d240d837f86926e]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.istartsurf.com/web/?type=ds& ... BA04191&q={searchTerms}, Good: (www.google.com), Bad: (http://www.istartsurf.com/web/?type=ds& ... BA04191&q={searchTerms}),,[45ffdf1a4a3f0b2bafb8345cc342ac54]
PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.delta-homes.com/?type=hp&ts= ... JX0BA04191, Good: (www.google.com), Bad: (http://www.delta-homes.com/?type=hp&ts= ... JX0BA04191),,[44006a8fb5d47eb898d1b6e62dd8dc24]
PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.delta-homes.com/?type=hp&ts= ... JX0BA04191, Good: (www.google.com), Bad: (http://www.delta-homes.com/?type=hp&ts= ... JX0BA04191),,[b78d34c537528ea8a5c8069651b429d7]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[66de54a5f891a78ff07af2a9fe075aa6]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... JX0BA04191),,[11336d8cc4c576c0abc65b35d72e6c94]

Folders: 37
PUP.Optional.SoftwareUpdater.A, C:\Users\nikdo\AppData\Local\SwvUpdater, , [d47040b9315867cf0bfae8a9e122c838],
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct, , [49fbcf2af891ae88865af344a26115eb],
PUP.Optional.PriceGong.A, C:\Users\nikdo\AppData\LocalLow\PriceGong, , [261e9a5fd7b2a690e12a94aa8a796b95],
PUP.Optional.PriceGong.A, C:\Users\nikdo\AppData\LocalLow\PriceGong\Data, , [261e9a5fd7b2a690e12a94aa8a796b95],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, , [f54fb148810831055bafdd7304ffa35d],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, , [f54fb148810831055bafdd7304ffa35d],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\LocalLow\Funmoods, , [04407e7b0386a591c393133e55ae1ce4],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\LocalLow\Funmoods\Funmoods, , [04407e7b0386a591c393133e55ae1ce4],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],

Files: 71
Trojan.BitCoinMiner, C:\Users\nikdo\Downloads\ESET NOD32 2014 antivirus 8.0.304.1 (x86,x64)(CZ,SK).rar.part, , [053f05f4e3a663d33f15a9bb42bf44bc],
PUP.Optional.SecurityProtection.A, C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx, , [fe468a6fe0a99e98827eed8a2fd453ad],
PUP.Optional.IStartSurf.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml, , [ca7ad128d8b1979fc7403b51d42fe719],
PUP.Optional.SoftwareUpdater.A, C:\Users\nikdo\AppData\Local\SwvUpdater\Updater.xml, , [d47040b9315867cf0bfae8a9e122c838],
PUP.Optional.SoftwareUpdater.A, C:\Users\nikdo\AppData\Local\SwvUpdater\status.cfg, , [d47040b9315867cf0bfae8a9e122c838],
PUP.Optional.Delta.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\delta-homes.xml, , [d0746c8d860358de4d8dfb9c11f249b7],
PUP.Optional.Conduit.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\conduit.xml, , [b98be4158009270f05b42984877cb947],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\funmoods.xml, , [e36122d71970b97d825ca607d82b6997],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\funmoods.xml, , [94b005f4ef9af6407c627c3109fa6e92],
PUP.Optional.FunMoods.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\funmoods.xml, , [0b39c6331c6d5ed84a94c4e9857ec13f],
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\ESET Fix SB 2.1.0.exe, , [49fbcf2af891ae88865af344a26115eb],
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\m.exe, , [49fbcf2af891ae88865af344a26115eb],
PUP.Optional.PriceGong.A, C:\Users\nikdo\AppData\LocalLow\PriceGong\Data\mru.xml, , [261e9a5fd7b2a690e12a94aa8a796b95],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, , [f54fb148810831055bafdd7304ffa35d],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-09-28[12-38-47-571].log, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\update.exe, , [7dc70decd8b15dd924428dc55ba83fc1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\bk_shadow.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\btn.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\close.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml.bak, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_box.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_check.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_bk.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_check.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit-ie8.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit2.0.js, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, , [64e0af4a0d7c3bfb76fc7cdc4fb4916f],
PUP.Optional.Delta.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "http://www.delta-homes.com/newtab/?type=nt&ts=1419407016&from=wpm12233&uid=SAMSUNGXHD103SJ_S246JX0BA04191");), ,[c183fcfd90f925116b320fc663a24fb1]
PUP.Optional.Conduit.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\prefs.js, Good: (), Bad: (user_pref("browser.search.defaulturl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=3&q={searchTerms}");), ,[61e322d71475ce68196a5f7733d2e917]
PUP.Optional.Conduit.A, C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\prefs.js, Good: (), Bad: (user_pref("CT2832595.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=2&q=");), ,[e85cc4354445d95dcdb75086e71e6898]

Physical Sectors: 0
(No malicious items detected)


(end)

Irelas
Level 1
Level 1
Příspěvky: 57
Registrován: květen 08
Pohlaví: Žena
Stav:
Offline

Re: kontrola ,nefunguje internet stahování, ping ok

Příspěvekod Irelas » 19 led 2015 17:00

provedeno adw cleaneru

# AdwCleaner v4.108 - Report created 19/01/2015 at 16:56:46
# Updated 17/01/2015 by Xplode
# Database : 2015-01-18.1 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : nikdo - NIKDY
# Running from : C:\Users\nikdo\Desktop\adwcleaner_4.108(2).exe
# Option : Clean

***** [ Services ] *****

Service Deleted : vToolbarUpdater18.2.0

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\ProgramData\AlawarWrapper
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Program Files (x86)\WinZipper
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Users\nikdo\AppData\Local\apn
Folder Deleted : C:\Users\nikdo\AppData\Local\cool_mirage
Folder Deleted : C:\Users\nikdo\AppData\Local\PackageAware
Folder Deleted : C:\Users\nikdo\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\nikdo\AppData\Local\AlawarWrapper
Folder Deleted : C:\Users\nikdo\AppData\LocalLow\Funmoods
Folder Deleted : C:\Users\nikdo\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\nikdo\AppData\Roaming\eCyber
Folder Deleted : C:\Users\nikdo\AppData\Roaming\WinZipper
Folder Deleted : C:\Users\Public\Documents\iWin
Folder Deleted : C:\Users\Public\Documents\AlawarWrapper
Folder Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\Extensions\{32A1FD71-835E-4B11-8E54-886FDA0B4C89}
Folder Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\Extensions\Avg@toolbar
File Deleted : C:\Users\Public\Desktop\iLivid.lnk
File Deleted : C:\Users\nikdo\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\Askcom.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\avg-secure-search.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\Conduit.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\delta-homes.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\g0syoo15.default-1349863581988\searchplugins\funmoods.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\searchplugins\funmoods.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\funmoods.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\searchplugins\qip-search.xml
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\h3z7n07y.default-1340054342780\user.js
File Deleted : C:\Users\nikdo\AppData\Roaming\Mozilla\Firefox\Profiles\qiz32wjj.default\user.js
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Shortcut Disinfected : C:\Users\nikdo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\nikdo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\nikdo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\nikdo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk

***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKCU\Software\Mozilla\Extends
Key Deleted : HKCU\Software\27ccc8c626aecdf2927cdc5ef0c9bde2
Key Deleted : HKCU\Software\284db1d79e871dc8e3adb71dcdf8747f
Key Deleted : HKCU\Software\84de8db26feb13
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A2773ED4-83BD-488A-A186-73590706C916}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKCU\Software\AppDataLow\Software\adawarebp
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\delta-homesSoftware
Key Deleted : HKLM\SOFTWARE\hdcode
Key Deleted : HKLM\SOFTWARE\istartsurfSoftware
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\supWPM
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\Trymedia Systems
Key Deleted : HKLM\SOFTWARE\V9
Key Deleted : HKLM\SOFTWARE\winzipersvc
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [bProtectTabs]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Mozilla Firefox v35.0 (x86 cs)

[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("browser.newtab.url", "hxxp://www.delta-homes.com/newtab/?type=nt&ts=1419407016&from=wpm12233&uid=SAMSUNGXHD103SJ_S246JX0BA04191");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.aflt", "ddrnw");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.dfltLng", "");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.dfltSrch", true);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.dnsErr", true);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.excTlbr", false);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.hmpg", true);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=ddrnw");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.id", "c20d6c7b0000000000001c6f65ce77b8");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.instlDay", "15710");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.instlRef", "");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.newTab", true);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=ddrnw");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.prdct", "funmoods");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.prtnrId", "funmoods");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.smplGrp", "none");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.srchPrvdr", "Search");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.tlbrId", "base");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=ddrnw&q=");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.vrsn", "1.5.11.16");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.11.1622:26:22");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.funmoods_i.vrsni", "1.5.11.16");
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.quick_start.enable_search1", false);
[g0syoo15.default-1349863581988\prefs.js] - Line Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595..clientLogIsEnabled", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.CT2832595", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.CurrentServerDate", "20-7-2012");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.DSInstall", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.DialogsAlignMode", "LTR");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.DialogsGetterLastCheckTime", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.DownloadReferralCookieData", "");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FirstServerDate", "20-7-2012");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FirstTime", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FirstTimeFF3", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FirstTimeHiddenVer", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.FixPageNotFoundErrors", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.GroupingServerCheckInterval", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.HPInstall", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.HasUserGlobalKeys", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.HomePageProtectorEnabled", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.HomepageBeforeUnload", "www.seznam.cz");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.Initialize", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.InitializeCommonPrefs", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.InstallationAndCookieDataSentCount", 2);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.InstallationType", "Unknown");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.InstalledDate", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsAlertDBUpdated", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsGrouping", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsInitSetupIni", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsMulticommunity", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsOpenThankYouPage", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsOpenUninstallPage", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.IsProtectorsInit", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LanguagePackLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LanguagePackReloadIntervalMM", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LastLogin_3.14.1.0", "Tue Jun 19 2012 06:03:26 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.LatestVersion", "3.13.0.6");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.Locale", "en");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.MCDetectTooltipHeight", "83");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.MCDetectTooltipWidth", "295");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.MyStuffEnabledAtInstallation", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.OriginalFirstVersion", "3.14.1.0");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SHRINK_TOOLBAR", 1);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SavedHomepage", "chrome://branding/locale/browserconfig.properties");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchCaption", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchEngineBeforeUnload", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchFromAddressBarIsInit", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=2&q=");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchInNewTabEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchInNewTabIntervalMM", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchInNewTabLastCheckTime", "Tue Jun 19 2012 00:38:59 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchProtectorEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SearchProtectorToolbarDisabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SendProtectorDataViaLogin", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ServiceMapLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SettingsLastCheckTime", "Tue Jun 19 2012 06:03:25 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.SettingsLastUpdate", "1342353688");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2832595&SearchSource=13");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ThirdPartyComponentsInterval", 504);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ThirdPartyComponentsLastCheck", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ThirdPartyComponentsLastUpdate", "1331805997");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ToolbarDisabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ToolbarShrinkedFromSetup", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.UserID", "UN66842355699789321");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.ValidationData_Toolbar", 2);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.alertChannelId", "1224658");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.activetoolbar", "77657374");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.toolbar_market", "637A");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.toolbarurl", "687474703A2F2F746F6F6C6261722E696E6E6F67616D65732E64652F746F6F6C626172732F776573742F746F6F6C6261722E706870");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.west_password_cz", "5A57787063327468");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.west_session_id_cz", "30366139633234643932643930343531");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.west_username_cz", "61584A6C6247467A");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.backendstorage.west_world_url_cz", "687474703A2F2F637A31312E7468652D776573742E637A");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.globalFirstTimeInfoLastCheckTime", "Tue Jun 19 2012 00:39:02 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.homepageProtectorEnableByLogin", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.initDone", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.isAppTrackingManagerOn", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffPublihserMinWidth", 400);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffServiceIntervalMM", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.navigateToUrlOnSearch", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.revertSettingsEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.searchProtectorDialogDelayInSec", 10);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.searchProtectorEnableByLogin", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.testingCtid", "");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.toolbarAppMetaDataLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.toolbarContextMenuLastCheckTime", "Tue Jun 19 2012 00:38:55 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CT2832595.usagesFlag", 2);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2832595&SearchSource=13");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ConduitSearchList", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "G9mW7heT/8xIX1frcduu0A==");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "mfQ70fvlD2zuBxSBj8rQqA==");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "UgzXjW7BIkfdx+x39Ruv3w==");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-serv ... &locale=en", "4BgM4MhF/sOgPsDNmIs3Yw==");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\nikdo\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\h3z7n07y.default-1340054342780\\conduitCommon\\modules\\3.14.1.0");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.14.1.0");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.globalUserId", "391fe62a-3022-4398-9628-b9e8e063f367");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2832595");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Jun 19 2012 00:38:53 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", true);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Jun 19 2012 01:38:58 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue Jun 19 2012 00:38:52 GMT+0200");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.userId", "c828a219-d890-4df5-b53d-ead686137cd0");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("browser.search.defaultthis.engineName", "InnoGames International Customized Web Search");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=3&q={searchTerms}");
[h3z7n07y.default-1340054342780\prefs.js] - Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");

-\\ Google Chrome v39.0.2171.99

[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}

-\\ Chromium v

[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
[C:\Users\nikdo\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?type ... BA04191&q={searchTerms}
[C:\Users\nikdo\AppData\Local\Chromium\User Data\Default\preferences] - Deleted [Homepage] : hxxp://qip.ru

*************************

AdwCleaner[R0].txt - [31930 octets] - [18/01/2015 18:18:34]
AdwCleaner[R1].txt - [31991 octets] - [19/01/2015 16:54:44]
AdwCleaner[S0].txt - [33776 octets] - [19/01/2015 16:56:46]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [33837 octets] ##########

Irelas
Level 1
Level 1
Příspěvky: 57
Registrován: květen 08
Pohlaví: Žena
Stav:
Offline

Re: kontrola ,nefunguje internet stahování, ping ok

Příspěvekod Irelas » 19 led 2015 17:15

Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Professional x64
Ran by nikdo on po 19.01.2015 at 17:02:42,03
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440}
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully deleted [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\bProtectTabs
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}



~~~ Files

Successfully deleted: [File] "C:\Windows\wininit.ini"



~~~ Folders



~~~ FireFox

Successfully deleted: [File] C:\user.js
Successfully deleted: [Folder] C:\Users\nikdo\AppData\Roaming\mozilla\firefox\profiles\h3z7n07y.default-1340054342780\conduitcommon
Emptied folder: C:\Users\nikdo\AppData\Roaming\mozilla\firefox\profiles\h3z7n07y.default-1340054342780\minidumps [38 files]
Emptied folder: C:\Users\nikdo\AppData\Roaming\mozilla\firefox\profiles\g0syoo15.default-1349863581988\minidumps [383 files]



~~~ Event Viewer Logs were cleared




zde je text z jrt
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 19.01.2015 at 17:05:56,47
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola ,nefunguje internet stahování, ping ok

Příspěvekod jaro3 » 19 led 2015 19:43

Odinstaluj:
Spybot - Search & Destroy

. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Irelas
Level 1
Level 1
Příspěvky: 57
Registrován: květen 08
Pohlaví: Žena
Stav:
Offline

Re: kontrola ,nefunguje internet stahování, ping ok

Příspěvekod Irelas » 20 led 2015 16:52

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 20.1.2015
Scan Time: 16:46:12
Logfile: log k.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.01.20.07
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: nikdo

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 378821
Time Elapsed: 3 min, 27 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

Irelas
Level 1
Level 1
Příspěvky: 57
Registrován: květen 08
Pohlaví: Žena
Stav:
Offline

Re: kontrola ,nefunguje internet stahování, ping ok

Příspěvekod Irelas » 20 led 2015 17:02

poslední provedená část kontroly

RogueKiller V10.2.0.0 (x64) [Jan 19 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : nikdo [Práva správce]
Mód : Prohledat -- Datum : 01/20/2015 16:59:29

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 26 ¤¤¤
[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.centrum.cz/ -> Nalezeno
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.centrum.cz/ -> Nalezeno
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms} -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E185C1E4-E1AF-4554-94D5-B23829320333} | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{E185C1E4-E1AF-4554-94D5-B23829320333} | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{E185C1E4-E1AF-4554-94D5-B23829320333} | DhcpNameServer : 192.168.88.1 192.168.49.222 81.0.237.225 [CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 0 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 0 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowUser : 0 -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowUser : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-2107716189-2857289073-577814198-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno

¤¤¤ Úlohy : 2 ¤¤¤
[Suspicious.Path] \\{59BF6E3D-FE4C-49B8-A1E8-E6F513944F6A} -- C:\Users\nikdo\Desktop\Setup\SETUP.EXE -> Nalezeno
[Suspicious.Path] \\{B9E36A42-505F-45A8-B10E-3892BD832F94} -- C:\Users\nikdo\Desktop\Setup\SETUP.EXE -> Nalezeno

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] g0syoo15.default-1349863581988 : user_pref("browser.startup.homepage", "www.centrum.cz"); -> Nalezeno

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HD103SJ ATA Device +++++
--- User ---
[MBR] d6e3ec34ff2fcd1cd69c9085c1147cbb
[BSP] 0376dbff6967f308ccdff6efd94ab64f : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 953867 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: OCZ-AGILITY3 ATA Device +++++
--- User ---
[MBR] 2f570e319eab6b19b3c5647a44b5dc55
[BSP] 19711608946a274f028ea6f53d22f296 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 57139 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: Generic- Compact Flash USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive3: Generic- SM/xD-Picture USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive4: Generic- SD/MMC USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive5: Generic- MS/MS-Pro USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola ,nefunguje internet stahování, ping ok

Příspěvekod jaro3 » 20 led 2015 18:47

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:


- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)

- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni antivir
Stáhni
Zoek.exe

a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 93 hostů