Kontrola logu HJT
Napsal: 24 pro 2015 08:40
Hezký Štědrý den. Asi před dvěma týdny jsem tu řešil tento problém:http://www.pc-help.cz/viewtopic.php?f=70&t=166659. Situace je úplně stejná i se stále se opakujícími 8 nálezy MBAM, které i po zlikvidování se opět objěví. Poradí mi prosím někdo?
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:12:10, on 24.12.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18124)
FIREFOX: 43.0.1 (x86 cs)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\AVG\Av\avgui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\PixArt\Pac7302\Monitor.exe
C:\Program Files\AVG\Framework\Common\avguix.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\NetSoftware\NetSoftware.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\GWX\GWX.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\pc\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: InternetPanelBHO - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\NetSoftware\IEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\Av\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe" -s
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [AvgUi] "C:\Program Files\AVG\Framework\Common\avguix.exe" /fmw.trayonly
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NetSoftware] "C:\Program Files\NetSoftware\Starter.exe" /path="C:\Program Files\NetSoftware"
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AvgAMPS - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Av\avgamps.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Av\avgidsagent.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Framework\Common\avgsvcx.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Av\avgwdsvcx.exe
O23 - Service: Broadcom Management Agent (BrcmMgmtAgent) - Broadcom Corporation - C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\Windows\System32\ssins.exe
--
End of file - 4243 bytes
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 24.12.2015
Čas skenování: 8:17
Protokol: MBAM.txt
Správce: Ano
Verze: 2.2.0.1024
Databáze malwaru: v2015.12.24.02
Databáze rootkitů: v2015.12.18.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x86
Souborový systém: NTFS
Uživatel: pc
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 317371
Uplynulý čas: 18 min, 29 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Nenalezeny žádné škodlivé položky)
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 7
PUP.Optional.Gemius, HKLM\SOFTWARE\CLASSES\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}, , [a0421d8b8b00ad89762b0f4e53af11ef],
PUP.Optional.Gemius, HKLM\SOFTWARE\CLASSES\TYPELIB\{CE7C3CE2-4B15-11D1-ABED-709549C10000}, , [a0421d8b8b00ad89762b0f4e53af11ef],
PUP.Optional.Gemius, HKLM\SOFTWARE\CLASSES\INTERFACE\{CE7C3CEF-4B15-11D1-ABED-709549C10000}, , [a0421d8b8b00ad89762b0f4e53af11ef],
PUP.Optional.Gemius, HKLM\SOFTWARE\CLASSES\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\INPROCSERVER32, , [a0421d8b8b00ad89762b0f4e53af11ef],
PUP.Optional.Gemius, HKLM\SOFTWARE\CLASSES\Gemius.IEHlprObj.1, , [a0421d8b8b00ad89762b0f4e53af11ef],
PUP.Optional.Gemius, HKLM\SOFTWARE\CLASSES\Gemius.IEHlprObj, , [a0421d8b8b00ad89762b0f4e53af11ef],
PUP.Optional.Gemius, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{CE7C3CF0-4B15-11D1-ABED-709549C10000}, , [a0421d8b8b00ad89762b0f4e53af11ef],
Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 0
(Nenalezeny žádné škodlivé položky)
Soubory: 1
PUP.Optional.Gemius, C:\Program Files\NetSoftware\IEHelper.dll, , [a0421d8b8b00ad89762b0f4e53af11ef],
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:12:10, on 24.12.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18124)
FIREFOX: 43.0.1 (x86 cs)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\AVG\Av\avgui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\PixArt\Pac7302\Monitor.exe
C:\Program Files\AVG\Framework\Common\avguix.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\NetSoftware\NetSoftware.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\GWX\GWX.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\pc\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: InternetPanelBHO - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\NetSoftware\IEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\Av\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe" -s
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [AvgUi] "C:\Program Files\AVG\Framework\Common\avguix.exe" /fmw.trayonly
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NetSoftware] "C:\Program Files\NetSoftware\Starter.exe" /path="C:\Program Files\NetSoftware"
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AvgAMPS - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Av\avgamps.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Av\avgidsagent.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Framework\Common\avgsvcx.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Av\avgwdsvcx.exe
O23 - Service: Broadcom Management Agent (BrcmMgmtAgent) - Broadcom Corporation - C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\Windows\System32\ssins.exe
--
End of file - 4243 bytes
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 24.12.2015
Čas skenování: 8:17
Protokol: MBAM.txt
Správce: Ano
Verze: 2.2.0.1024
Databáze malwaru: v2015.12.24.02
Databáze rootkitů: v2015.12.18.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x86
Souborový systém: NTFS
Uživatel: pc
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 317371
Uplynulý čas: 18 min, 29 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Nenalezeny žádné škodlivé položky)
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 7
PUP.Optional.Gemius, HKLM\SOFTWARE\CLASSES\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}, , [a0421d8b8b00ad89762b0f4e53af11ef],
PUP.Optional.Gemius, HKLM\SOFTWARE\CLASSES\TYPELIB\{CE7C3CE2-4B15-11D1-ABED-709549C10000}, , [a0421d8b8b00ad89762b0f4e53af11ef],
PUP.Optional.Gemius, HKLM\SOFTWARE\CLASSES\INTERFACE\{CE7C3CEF-4B15-11D1-ABED-709549C10000}, , [a0421d8b8b00ad89762b0f4e53af11ef],
PUP.Optional.Gemius, HKLM\SOFTWARE\CLASSES\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\INPROCSERVER32, , [a0421d8b8b00ad89762b0f4e53af11ef],
PUP.Optional.Gemius, HKLM\SOFTWARE\CLASSES\Gemius.IEHlprObj.1, , [a0421d8b8b00ad89762b0f4e53af11ef],
PUP.Optional.Gemius, HKLM\SOFTWARE\CLASSES\Gemius.IEHlprObj, , [a0421d8b8b00ad89762b0f4e53af11ef],
PUP.Optional.Gemius, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{CE7C3CF0-4B15-11D1-ABED-709549C10000}, , [a0421d8b8b00ad89762b0f4e53af11ef],
Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 0
(Nenalezeny žádné škodlivé položky)
Soubory: 1
PUP.Optional.Gemius, C:\Program Files\NetSoftware\IEHelper.dll, , [a0421d8b8b00ad89762b0f4e53af11ef],
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)