Stránka 1 z 4

Prosimt o kontrolu

Napsal: 01 kvě 2016 20:30
od Sylton
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:28:51, on 1. 5. 2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18283)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\nikol\Downloads\HijackThis (1).exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_s ... 2&tsp=5266
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - (no file)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O3 - Toolbar: (no name) - {828DC97A-2277-4E10-92A9-4907FA0922A9} - (no file)
O4 - HKLM\..\Run: [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [BitTorrent] "C:\Users\nikol\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
O4 - Global Startup: FancyStart daemon.lnk = ?
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - (no file)
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - (no file)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{01AD3069-9A3C-4AFF-AC52-83ABDC678595}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{01AD3069-9A3C-4AFF-AC52-83ABDC678595}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{01AD3069-9A3C-4AFF-AC52-83ABDC678595}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Firewall (avast! Firewall) - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11204 bytes

Re: Prosimt o kontrolu

Napsal: 02 kvě 2016 09:09
od jaro3
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
http://www.geekstogo.com/forum/files/fi ... -oldtimer/
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu klikni na „Logfile“ ,objeví log ( jinak je uložen systémovem disku jako AdwCleaner[C?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na Kopírovat do schránky a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.

Re: Prosimt o kontrolu

Napsal: 02 kvě 2016 17:45
od Sylton
# AdwCleaner v5.115 - Logfile created 01/05/2016 at 17:32:09
# Updated 01/05/2016 by Xplode
# Database : 2016-05-01.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (X64)
# Username : nikol - NIKOL-PC
# Running from : C:\Users\nikol\Downloads\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

Folder Found : C:\ProgramData\Partner
Folder Found : C:\ProgramData\Tarma Installer
Folder Found : C:\ProgramData\Application Data\Partner
Folder Found : C:\ProgramData\Application Data\Tarma Installer
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Protected Search
Folder Found : C:\Program Files (x86)\Red Sky
Folder Found : C:\Users\nikol\AppData\Local\DownTango
Folder Found : C:\Users\nikol\AppData\Local\iLivid
Folder Found : C:\Users\nikol\AppData\Local\onlysearch
Folder Found : C:\Users\nikol\AppData\LocalLow\SimplyTech
Folder Found : C:\Users\nikol\AppData\Roaming\OpenCandy
Folder Found : C:\Windows\SysNative\Tasks\ProtectedSearch

***** [ Files ] *****

File Found : C:\END
File Found : C:\Windows\launcher.exe
File Found : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0.localstorage
File Found : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0.localstorage-journal
File Found : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam
File Found : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_fbcdn-sphotos-f-a.akamaihd.net_0.localstorage-journal
File Found : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_lp.sweetim.com_0.localstorage-journal
File Found : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.searchinsocial.com_0.localstorage-journal
File Found : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_videodownloadconverter.dl.mywebsearch.com_0.localstorage-journal
File Found : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_wlogin.icq.com_0.localstorage-journal
File Found : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.buenosearch.com_0.localstorage-journal
File Found : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.veoh.com_0.localstorage-journal

***** [ DLL ] *****


***** [ WMI ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

Task Found : ProtectedSearch\Protected Search

***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\SysMenu.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Key Found : HKLM\SOFTWARE\Classes\Applications\iLividSetup-r514-n-bc.exe
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Key Found : HKCU\Software\Classes\keepmysearch
Key Found : HKCU\Software\Classes\pokki
Key Found : HKLM\SOFTWARE\Classes\AniGIFPpg.AniGIFPpg
Key Found : HKLM\SOFTWARE\Classes\AniGIFPpg2.AniGIFPpg2
Key Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Classes\keepmysearch
Key Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Classes\pokki
Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{828DC97A-2277-4E10-92A9-4907FA0922A9}]
Key Found : HKCU\Software\ProtectedSearch
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\SweetIM
Key Found : HKCU\Software\WEBAPP
Key Found : HKLM\SOFTWARE\dt soft\daemon tools toolbar
Key Found : HKLM\SOFTWARE\Iminent
Key Found : HKLM\SOFTWARE\SweetIM
Key Found : [x64] HKLM\SOFTWARE\Tarma Installer
Key Found : [x64] HKLM\SOFTWARE\YTDownloader
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\iWebar
Key Found : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\iWebar
Key Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\ProtectedSearch
Key Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Softonic
Key Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\SweetIM
Key Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\WEBAPP
Key Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\iWebar
Key Found : HKU\S-1-5-18\Software\AppDataLow\Software\iWebar
Key Found : HKU\S-1-5-18\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\iWebar
Data Found : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI [(Default)] - hxxp://search.certified-toolbar.com?si= ... id=2938&q=%s
Data Found : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)] - hxxp://search.certified-toolbar.com?si= ... id=2938&q=%s
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.buenosearch.com/?babsrc=HP_s ... 2&tsp=5266
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKCU\Software\Microsoft\Internet Explorer\Search [Start Page] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKCU\Software\Microsoft\Internet Explorer\Search [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [(Default)] - hxxp://search.certified-toolbar.com?si= ... id=2938&q=%s
Data Found : HKCU\Software\Microsoft\Internet Explorer\SearchURI [(Default)] - hxxp://search.certified-toolbar.com?si= ... id=2938&q=%s
Data Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.buenosearch.com/?babsrc=HP_s ... 2&tsp=5266
Data Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\Main [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\Search [Start Page] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\Search [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si= ... e&tid=2938
Data Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\SearchUrl [(Default)] - hxxp://search.certified-toolbar.com?si= ... id=2938&q=%s
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Value Found : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DisplayName]
Value Found : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [URL]
Key Found : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key Found : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}

***** [ Web browsers ] *****

[C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : buenosearch.com_
[C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : buenosearch.com
[C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://www.buenosearch.com/?babsrc=HP_s ... 2&tsp=5266
[C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Found : hxxp://www.buenosearch.com/?babsrc=HP_s ... 2&tsp=5266

*************************

C:\AdwCleaner\AdwCleaner[S1].txt - [11161 bytes] - [01/05/2016 17:32:09]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [11235 bytes] ##########

Re: Prosimt o kontrolu

Napsal: 02 kvě 2016 18:17
od Sylton
Malwarebytes Anti-Malware
www.malwarebytes.org

Dátum kontroly: 1. 5. 2016
Čas kontroly: 17:52
Protokol: anti malware.txt
Správca: Áno

Verzia: 2.2.1.1043
Dazabáza malware: v2016.05.02.03
Databáza rootkitov: v2016.04.17.01
Licencia: Bezplatná verzia
Ochrana pred škodlivým softvérom: Vypnuté
Ochrana pred škodlivými webstránkami: Vypnuté
Vlastná ochrana: Vypnuté

OS: Windows 7 Service Pack 1
CPU: x64
Súborový systém: NTFS
Používateľ: nikol

Typ kontroly: Kontrola hrozieb
Výsledok: Dokončená
Skontrolovaných objektov: 344114
Uplynulý čas: 21 min, 10 s

Pamäť: Zapnuté
Pri spustení: Zapnuté
Súborový systém: Zapnuté
Archívy: Zapnuté
Rootkity: Vypnuté
Heuristika: Zapnuté
PUP: Zapnuté
PUM: Zapnuté

Procesy: 0
(Žiadne škodlivé položky neboli zistené)

Moduly: 0
(Žiadne škodlivé položky neboli zistené)

Kľúče databázy Registry: 32
Adware.1ClickDownload, HKLM\SOFTWARE\CLASSES\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}, , [5dbe785960398da98bc6a1608b789070],
Adware.1ClickDownload, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}, , [5dbe785960398da98bc6a1608b789070],
Adware.1ClickDownload, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}, , [5dbe785960398da98bc6a1608b789070],
PUP.Optional.Babylon, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [50cb89489cfdeb4b7865be306a9851af],
PUP.Optional.BetterSurf, HKLM\SOFTWARE\CLASSES\APPID\YontooIEClient.DLL, , [9d7e51808811f5410fc8170d4aba7888],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\TYPELIB\{157B1AA6-3E5C-404A-9118-C1D91F537040}, , [2bf08c451a7fd0660e6f03695ba9f50b],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\INTERFACE\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}, , [2bf08c451a7fd0660e6f03695ba9f50b],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}, , [2bf08c451a7fd0660e6f03695ba9f50b],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}, , [2bf08c451a7fd0660e6f03695ba9f50b],
PUP.Optional.BetterSurf, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\YontooIEClient.DLL, , [f922438e8d0ce05623b4be66e22234cc],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{157B1AA6-3E5C-404A-9118-C1D91F537040}, , [4fcc25acc9d086b0d0ad6507ac58aa56],
PUP.Optional.ProtectedSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ProtectedSearch, , [ee2deae703966ec8e006f755a85cfa06],
PUP.Optional.Iminent, HKLM\SOFTWARE\WOW6432NODE\Iminent, , [8d8e6170c7d264d2a4d767d5b94b1fe1],
PUP.Optional.SweetIM, HKLM\SOFTWARE\WOW6432NODE\SweetIM, , [f229a62b2b6eec4a50d67ade12f20bf5],
PUP.Optional.BetterSurf, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\YontooIEClient.DLL, , [55c6636e15845dd930a7c85ca75d1de3],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{157B1AA6-3E5C-404A-9118-C1D91F537040}, , [2eed08c9e2b778bea3dae88491739d63],
PUP.Optional.Yontoo, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\niapdbllcanepiiimjjndipklodoedlc, , [34e77f520594ce685dbb6af7be46a957],
PUP.Optional.iWebar, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\iWebar, , [4ccfae23aced9f97b42fa19c9371e719],
PUP.Optional.SweetIM, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\SweetIM, , [aa7123aee6b33303ca57d187887ccf31],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4EE12902-11B2-403E-9CCB-8AD47CFEA7D6}, , [bd5ecc05adecd4629d5f7cb307fd9070],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4F1B1BC1-FB2D-403C-BEE3-4A2F111928BE}, , [d843874aa8f12d0958a5de5121e3f808],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{58872591-4DE5-4B86-B053-E25AC296CE23}, , [8c8f656ce8b133039963f33c4eb6e31d],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{684C05D5-2464-420F-B080-A65AEE3A9478}, , [0219953caced88ae4cb1cc63669e28d8],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B4C98D4-2C62-4B0D-8F2A-B2AA89134A8C}, , [af6cfed34c4d9c9ae91330ff70946c94],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{77C48713-8F01-4F0A-AF6C-69E2391D2DE5}, , [5cbf0ac73564f34306f6c76829dbf709],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{907A83E8-FF40-4B7A-A4F7-243EAF1DAA3D}, , [8d8ea42dcccd7db9857832fdbe461de3],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9DCAAD4D-6140-492A-ADAC-6CCDF16B358B}, , [28f3fcd5f8a1bc7a36c649e610f4e917],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA803F96-9D91-48B4-AFE0-8D3399C47437}, , [06159d34a9f08da9897357d8e123d030],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D8FEEFBC-C9B0-4B8D-9D8B-FDDDC63532BC}, , [9b80d2ff6633ae889a6369c64eb615eb],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DF9CAC4F-72F0-460B-A3F0-AE66EDDED6A7}, , [8398fbd62079b77fb449b97639cb52ae],
PUP.Optional.KeepMySearch, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002_Classes\keepmysearch, , [e2397d54d1c81620fd723905b15305fb],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002_Classes\LOCAL SETTINGS\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APPCONTAINER\STORAGE\WINDOWS_IE_AC_001\SOFTWARE\iWebar, , [d249a1307623ef471a1229199f64df21],

Hodnoty databázy Registry: 13
PUP.Optional.BuenoSearch, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{828DC97A-2277-4E10-92A9-4907FA0922A9}, , [d34841905f3a3ff70d6b22cd59a9ae52],
PUP.Optional.BuenoSearch, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{828DC97A-2277-4E10-92A9-4907FA0922A9}, buenosearch Toolbar, , [d34841905f3a3ff70d6b22cd59a9ae52]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4EE12902-11B2-403E-9CCB-8AD47CFEA7D6}|AppName, iWebar-enabler.exe-buttonutil.exe, , [bd5ecc05adecd4629d5f7cb307fd9070]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4F1B1BC1-FB2D-403C-BEE3-4A2F111928BE}|AppName, iWebar-enabler.exe-codedownloader.exe, , [d843874aa8f12d0958a5de5121e3f808]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{58872591-4DE5-4B86-B053-E25AC296CE23}|AppName, iWebar-enabler.exe-buttonutil.exe, , [8c8f656ce8b133039963f33c4eb6e31d]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{684C05D5-2464-420F-B080-A65AEE3A9478}|AppName, iWebar-enabler.exe-codedownloader.exe, , [0219953caced88ae4cb1cc63669e28d8]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B4C98D4-2C62-4B0D-8F2A-B2AA89134A8C}|AppName, iWebar-enabler.exe-buttonutil.exe, , [af6cfed34c4d9c9ae91330ff70946c94]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{77C48713-8F01-4F0A-AF6C-69E2391D2DE5}|AppName, iWebar-enabler.exe-buttonutil.exe, , [5cbf0ac73564f34306f6c76829dbf709]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{907A83E8-FF40-4B7A-A4F7-243EAF1DAA3D}|AppName, iWebar-enabler.exe-codedownloader.exe, , [8d8ea42dcccd7db9857832fdbe461de3]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9DCAAD4D-6140-492A-ADAC-6CCDF16B358B}|AppName, iWebar-enabler.exe-buttonutil.exe, , [28f3fcd5f8a1bc7a36c649e610f4e917]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA803F96-9D91-48B4-AFE0-8D3399C47437}|AppName, iWebar-enabler.exe-buttonutil.exe, , [06159d34a9f08da9897357d8e123d030]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D8FEEFBC-C9B0-4B8D-9D8B-FDDDC63532BC}|AppName, iWebar-enabler.exe-codedownloader.exe, , [9b80d2ff6633ae889a6369c64eb615eb]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DF9CAC4F-72F0-460B-A3F0-AE66EDDED6A7}|AppName, iWebar-enabler.exe-codedownloader.exe, , [8398fbd62079b77fb449b97639cb52ae]

Údaj databázy Registry: 9
Hijack.StartPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Default_Page_URL, http://search.certified-toolbar.com?si= ... e&tid=2938, Dobrá: (http://www.google.com), Zlá: (http://search.certified-toolbar.com?si= ... e&tid=2938),,[bb60834e2e6b8aacf38fc18be124a759]
Hijack.SearchPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|Start Page, http://search.certified-toolbar.com?si= ... e&tid=2938, Dobrá: (http://www.google.com/), Zlá: (http://search.certified-toolbar.com?si= ... e&tid=2938),,[43d8359ccfca6acc572cb29a20e5aa56]
Hijack.SearchPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|Start Default_Page_URL, http://search.certified-toolbar.com?si= ... e&tid=2938, Dobrá: (http://www.google.com/), Zlá: (http://search.certified-toolbar.com?si= ... e&tid=2938),,[8299e0f16732d95dea99ae9e6e976d93]
Hijack.StartPage, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.buenosearch.com/?babsrc=HP_s ... 2&tsp=5266, Dobrá: (www.google.com), Zlá: (http://www.buenosearch.com/?babsrc=HP_s ... 2&tsp=5266),,[1ffc7d542b6e43f331e79cb1d2334ab6]
Hijack.StartPage, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Default_Page_URL, http://search.certified-toolbar.com?si= ... e&tid=2938, Dobrá: (http://www.google.com), Zlá: (http://search.certified-toolbar.com?si= ... e&tid=2938),,[c358438ee0b93402216083c9b74ecf31]
Hijack.SearchPage, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Start Page, http://search.certified-toolbar.com?si= ... e&tid=2938, Dobrá: (http://www.google.com/), Zlá: (http://search.certified-toolbar.com?si= ... e&tid=2938),,[ab70d5fc2c6d2511d5af1f2da560b749]
Hijack.SearchPage, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Start Default_Page_URL, http://search.certified-toolbar.com?si= ... e&tid=2938, Dobrá: (http://www.google.com/), Zlá: (http://search.certified-toolbar.com?si= ... e&tid=2938),,[de3d4d845e3bf93dd3b1a6a6ee1735cb]
PUP.Optional.SearchCertifiedTB, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), http://search.certified-toolbar.com?si= ... id=2938&q=%s, Dobrá: (www.google.com), Zlá: (http://search.certified-toolbar.com?si= ... id=2938&q=%s),,[e03b58793e5b80b6693c4d02bc497a86]
PUP.Optional.SearchCertifiedTB, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|(Default), http://search.certified-toolbar.com?si= ... id=2938&q=%s, Dobrá: (www.google.com/), Zlá: (http://search.certified-toolbar.com?si= ... id=2938&q=%s),,[96858e4304950d29dcca3a158c79d030]

Priečinky: 37
PUP.Optional.OpenCandy, C:\Users\nikol\AppData\Roaming\OpenCandy, , [3fdc1fb2bfda58dec84639d5f70cd927],
PUP.Optional.OpenCandy, C:\Users\nikol\AppData\Roaming\OpenCandy\C6F3AD46836E462DA25E0C930ECF571E, , [3fdc1fb2bfda58dec84639d5f70cd927],
PUP.Optional.OnlySearch, C:\Users\nikol\AppData\Local\onlysearch, , [48d32da48e0bb581e8dc43cfff0418e8],
PUP.Optional.OnlySearch, C:\Users\nikol\AppData\Local\onlysearch\onlysearch, , [48d32da48e0bb581e8dc43cfff0418e8],
PUP.Optional.OnlySearch, C:\Users\nikol\AppData\Local\onlysearch\onlysearch\1.3.12.9, , [48d32da48e0bb581e8dc43cfff0418e8],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\Downloads, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\Logs, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\scripts, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\scripts\after_reconnect, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\scripts\all_dls_finished, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\scripts\all_dls_processed, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\scripts\before_reconnect, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\scripts\download_finished, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\scripts\download_preparing, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\scripts\package_finished, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\scripts\unrar_finished, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\tmp, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\tmp\container_file, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\tmp\container_file\a, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\tmp\container_file\a\af, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\tmp\container_file_lock, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\tmp\jinja_cache, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\accounts, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\captcha, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\container, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\crypter, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\hooks, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\hoster, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\internal, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Program Files (x86)\Red Sky\DownTango, , [45d69e330e8b5adcbb88ba6712f1b14f],
PUP.Optional.ProtectedSearch, C:\Windows\System32\Tasks\ProtectedSearch, , [0b1017ba9cfd9a9ca84439f4a85bf50b],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer, , [50cbfed3fb9e66d04231ac91758e9a66],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}, , [50cbfed3fb9e66d04231ac91758e9a66],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache, , [50cbfed3fb9e66d04231ac91758e9a66],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}, , [50cbfed3fb9e66d04231ac91758e9a66],

Súbory: 35
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll, , [7c9f339edbbed56141654a84c73a54ac],
PUP.Optional.BuenoSearch, C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.buenosearch.com_0.localstorage-journal, , [e536e3eedabfe35381ab30f8c73d6a96],
PUP.Optional.CrossRider, C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0.localstorage, , [0f0c953c4950ea4c7d4215189272b848],
PUP.Optional.CrossRider, C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0.localstorage-journal, , [ec2f5e73960373c3f2cd151859abf10f],
PUP.Optional.OpenCandy, C:\Users\nikol\AppData\Roaming\OpenCandy\C6F3AD46836E462DA25E0C930ECF571E\pokkiInstaller.exe, , [3fdc1fb2bfda58dec84639d5f70cd927],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\accounts.conf, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\application.log, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\config.db, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\files.db, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\files.version, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\plugin.conf, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\pyload.conf, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\unrar_passwords.txt, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\Logs\log.txt, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\tmp\container_file\a\af\af242d834ae078c00e3c0b9a270b425e.cache, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\__init__.py, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\accounts\__init__.py, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\captcha\__init__.py, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\container\__init__.py, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\crypter\__init__.py, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\hooks\__init__.py, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\hoster\__init__.py, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Users\nikol\AppData\Local\DownTango\userplugins\internal\__init__.py, , [b06b3c950792d1657fbfa77a0bf8f60a],
PUP.Optional.DownTango, C:\Program Files (x86)\Red Sky\DownTango\npbrowserPlugin.dll, , [45d69e330e8b5adcbb88ba6712f1b14f],
PUP.Optional.DownTango, C:\Program Files (x86)\Red Sky\DownTango\qgif4.dll, , [45d69e330e8b5adcbb88ba6712f1b14f],
PUP.Optional.DownTango, C:\Program Files (x86)\Red Sky\DownTango\qico4.dll, , [45d69e330e8b5adcbb88ba6712f1b14f],
PUP.Optional.DownTango, C:\Program Files (x86)\Red Sky\DownTango\qjpeg4.dll, , [45d69e330e8b5adcbb88ba6712f1b14f],
PUP.Optional.ProtectedSearch, C:\Windows\System32\Tasks\ProtectedSearch\Protected Search, , [0b1017ba9cfd9a9ca84439f4a85bf50b],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat, , [50cbfed3fb9e66d04231ac91758e9a66],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe, , [50cbfed3fb9e66d04231ac91758e9a66],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico, , [50cbfed3fb9e66d04231ac91758e9a66],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll, , [50cbfed3fb9e66d04231ac91758e9a66],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe, , [50cbfed3fb9e66d04231ac91758e9a66],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico, , [50cbfed3fb9e66d04231ac91758e9a66],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll, , [50cbfed3fb9e66d04231ac91758e9a66],

Fyzické sektory: 0
(Žiadne škodlivé položky neboli zistené)


(end)

Re: Prosimt o kontrolu

Napsal: 02 kvě 2016 19:22
od jaro3
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Cleaning (Vymazat)

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

. spusť znovu Malwarebytes' Anti-Malware a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7,8,10 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“ , v okně pak na „Open TXT“ a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.

Re: Prosimt o kontrolu

Napsal: 02 kvě 2016 20:23
od Sylton
po restarte mi ukazalo log...tak ho prikladam :)
# AdwCleaner v5.115 - Logfile created 02/05/2016 at 20:14:53
# Updated 01/05/2016 by Xplode
# Database : 2016-05-01.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (X64)
# Username : nikol - NIKOL-PC
# Running from : C:\Users\nikol\Downloads\AdwCleaner.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\ProgramData\Partner
[-] Folder Deleted : C:\ProgramData\Tarma Installer
[#] Folder Deleted : C:\ProgramData\Application Data\Partner
[#] Folder Deleted : C:\ProgramData\Application Data\Tarma Installer
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Protected Search
[-] Folder Deleted : C:\Program Files (x86)\Red Sky
[-] Folder Deleted : C:\Users\nikol\AppData\Local\DownTango
[-] Folder Deleted : C:\Users\nikol\AppData\Local\iLivid
[-] Folder Deleted : C:\Users\nikol\AppData\Local\onlysearch
[-] Folder Deleted : C:\Users\nikol\AppData\LocalLow\SimplyTech
[-] Folder Deleted : C:\Users\nikol\AppData\Roaming\OpenCandy
[-] Folder Deleted : C:\Windows\SysNative\Tasks\ProtectedSearch

***** [ Files ] *****

[-] File Deleted : C:\END
[-] File Deleted : C:\Windows\launcher.exe
[-] File Deleted : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0.localstorage
[-] File Deleted : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0.localstorage-journal
[-] File Deleted : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cigiagpbkapepgklncnajbakkpkopmam
[-] File Deleted : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_fbcdn-sphotos-f-a.akamaihd.net_0.localstorage-journal
[-] File Deleted : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_lp.sweetim.com_0.localstorage-journal
[-] File Deleted : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.searchinsocial.com_0.localstorage-journal
[-] File Deleted : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_videodownloadconverter.dl.mywebsearch.com_0.localstorage-journal
[-] File Deleted : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_wlogin.icq.com_0.localstorage-journal
[-] File Deleted : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.buenosearch.com_0.localstorage-journal
[-] File Deleted : C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.veoh.com_0.localstorage-journal

***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : ProtectedSearch\Protected Search

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\SysMenu.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\Applications\iLividSetup-r514-n-bc.exe
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
[-] Key Deleted : HKCU\Software\Classes\keepmysearch
[-] Key Deleted : HKCU\Software\Classes\pokki
[-] Key Deleted : HKLM\SOFTWARE\Classes\AniGIFPpg.AniGIFPpg
[-] Key Deleted : HKLM\SOFTWARE\Classes\AniGIFPpg2.AniGIFPpg2
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{828DC97A-2277-4E10-92A9-4907FA0922A9}]
[-] Key Deleted : HKCU\Software\ProtectedSearch
[-] Key Deleted : HKCU\Software\Softonic
[-] Key Deleted : HKCU\Software\SweetIM
[-] Key Deleted : HKCU\Software\WEBAPP
[-] Key Deleted : HKLM\SOFTWARE\dt soft\daemon tools toolbar
[-] Key Deleted : HKLM\SOFTWARE\Iminent
[-] Key Deleted : HKLM\SOFTWARE\SweetIM
[-] Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
[-] Key Deleted : [x64] HKLM\SOFTWARE\YTDownloader
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\iWebar
[-] Key Deleted : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\iWebar
[-] Key Deleted : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\iWebar
[-] Data Restored : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
[-] Data Restored : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page]
[-] Data Restored : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
[-] Data Restored : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI [(Default)]
[-] Data Restored : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)]
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Start Page]
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [(Default)]
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchURI [(Default)]
[-] Data Restored : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
[-] Data Restored : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\Search [Start Page]
[-] Data Restored : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
[-] Data Restored : HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\SearchUrl [(Default)]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
[-] Value Deleted : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DisplayName]
[-] Value Deleted : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [URL]
[-] Key Deleted : HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}

***** [ Web browsers ] *****

[-] [C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : buenosearch.com_
[-] [C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : buenosearch.com
[-] [C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://www.buenosearch.com/?babsrc=HP_s ... 2&tsp=5266
[-] [C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Deleted : hxxp://www.buenosearch.com/?babsrc=HP_s ... 2&tsp=5266

*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [9576 bytes] - [02/05/2016 20:14:53]
C:\AdwCleaner\AdwCleaner[S1].txt - [11323 bytes] - [01/05/2016 17:32:09]
C:\AdwCleaner\AdwCleaner[S2].txt - [11397 bytes] - [02/05/2016 20:08:25]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [9797 bytes] ##########

Re: Prosimt o kontrolu

Napsal: 02 kvě 2016 20:35
od Sylton
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.6 (04.25.2016)
Operating System: Windows 7 Home Premium x64
Ran by nikol (Administrator) on po 02. 05. 2016 at 20:28:43,96
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 33

Failed to delete: C:\ai_recyclebin (Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{01AE746C-498A-4F98-AAE8-915884C61576} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{07707B9C-3D3A-4046-9363-C3B7445FC065} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{079ECD5E-800D-42D6-9E12-A8BCD4A0CB22} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{09ACEA23-0536-46CA-84F0-E6BE20DE33FF} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{09D6E3C0-9662-461E-BFE1-BBD10CAEFE25} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{109FCF00-795E-4825-BDE3-A0760A5DF61D} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{181FE5B6-6200-4436-90E8-87F51B6F63D5} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{234B13F0-1B04-4FF1-9482-0D9B08C676C7} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{3A3AC4CA-3165-4D7A-95B9-1ED367533D43} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{51A7E3D4-487F-40BD-8DAB-13AC01E5FDB9} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{5B5F5879-8A53-45F9-90B1-9627804DE079} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{611231F8-877B-4C84-A2CD-7BECA37B783F} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{618E19ED-C870-42A4-ABFB-2E4F5C7C8BD5} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{701CEE1C-5733-437B-816F-2A69DE81BACA} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{77298C33-81E4-4738-AE80-5EDF1BB78357} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{77CF85FB-74D2-46D0-8E18-92DD9157D7B3} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{7D0AEACB-DB98-4A04-AB7D-2170A55D528B} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{878F71ED-C6A5-4B06-A8F8-536FBA05FAB2} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{9473F7B2-556B-452B-B023-C523C1DE7C3B} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{AB781C5D-80B1-4216-B596-A01E39865051} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{BABA0886-8303-4E2A-9B5C-E58B5DE622B7} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{C007F4BB-C783-4C75-922A-F9AF49960089} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{D0981C8F-B9F6-4CC3-8073-E09BF1161333} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\{FDDA90BF-FEB4-4A39-A900-AEDCD2005ECF} (Empty Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\crashrpt (Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal (File)
Successfully deleted: C:\Users\nikol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal (File)
Successfully deleted: C:\Users\nikol\Appdata\LocalLow\DownTango4SToolbar (Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0U05X9O9 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\nikol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KLUUDU4J (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0U05X9O9 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KLUUDU4J (Temporary Internet Files Folder)



Registry: 3

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 02. 05. 2016 at 20:33:36,44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Re: Prosimt o kontrolu

Napsal: 02 kvě 2016 21:12
od Sylton
Malwarebytes Anti-Malware
www.malwarebytes.org

Dátum kontroly: 2. 5. 2016
Čas kontroly: 20:37
Protokol: anti malware.txt
Správca: Áno

Verzia: 2.2.1.1043
Dazabáza malware: v2016.05.02.04
Databáza rootkitov: v2016.04.17.01
Licencia: Bezplatná verzia
Ochrana pred škodlivým softvérom: Vypnuté
Ochrana pred škodlivými webstránkami: Vypnuté
Vlastná ochrana: Vypnuté

OS: Windows 7 Service Pack 1
CPU: x64
Súborový systém: NTFS
Používateľ: nikol

Typ kontroly: Kontrola hrozieb
Výsledok: Dokončená
Skontrolovaných objektov: 343113
Uplynulý čas: 20 min, 28 s

Pamäť: Zapnuté
Pri spustení: Zapnuté
Súborový systém: Zapnuté
Archívy: Zapnuté
Rootkity: Vypnuté
Heuristika: Zapnuté
PUP: Zapnuté
PUM: Zapnuté

Procesy: 0
(Žiadne škodlivé položky neboli zistené)

Moduly: 0
(Žiadne škodlivé položky neboli zistené)

Kľúče databázy Registry: 12
PUP.Optional.ProtectedSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ProtectedSearch, Odstrániť-pri-Reštarte, [a676ede41e7b56e0818873da6e96f709],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4EE12902-11B2-403E-9CCB-8AD47CFEA7D6}, V karanténe, [e23a448d8019e0564ad5230d5da71ce4],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4F1B1BC1-FB2D-403C-BEE3-4A2F111928BE}, V karanténe, [ec3028a9c3d6132321ffbc74ab593dc3],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{58872591-4DE5-4B86-B053-E25AC296CE23}, V karanténe, [af6d577aa9f05adcf42b1a16ee16738d],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{684C05D5-2464-420F-B080-A65AEE3A9478}, V karanténe, [3ce04e83c8d1a195e93773bd9c68b54b],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B4C98D4-2C62-4B0D-8F2A-B2AA89134A8C}, V karanténe, [ff1d28a93861e94df926d65aec187b85],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{77C48713-8F01-4F0A-AF6C-69E2391D2DE5}, V karanténe, [0715c1104851ea4cc659fc348e7638c8],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{907A83E8-FF40-4B7A-A4F7-243EAF1DAA3D}, V karanténe, [08146a670d8ca690b96749e7da2afb05],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9DCAAD4D-6140-492A-ADAC-6CCDF16B358B}, V karanténe, [0418efe24b4e7bbbe23d5cd4e420cf31],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA803F96-9D91-48B4-AFE0-8D3399C47437}, V karanténe, [05174f8281184de9d54a959ba460fc04],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D8FEEFBC-C9B0-4B8D-9D8B-FDDDC63532BC}, V karanténe, [8e8edbf6b8e1f5414dd3210fa55ffe02],
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DF9CAC4F-72F0-460B-A3F0-AE66EDDED6A7}, V karanténe, [c656d9f832672115d44c1917e81cf20e],

Hodnoty databázy Registry: 11
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4EE12902-11B2-403E-9CCB-8AD47CFEA7D6}|AppName, iWebar-enabler.exe-buttonutil.exe, V karanténe, [e23a448d8019e0564ad5230d5da71ce4]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4F1B1BC1-FB2D-403C-BEE3-4A2F111928BE}|AppName, iWebar-enabler.exe-codedownloader.exe, V karanténe, [ec3028a9c3d6132321ffbc74ab593dc3]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{58872591-4DE5-4B86-B053-E25AC296CE23}|AppName, iWebar-enabler.exe-buttonutil.exe, V karanténe, [af6d577aa9f05adcf42b1a16ee16738d]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{684C05D5-2464-420F-B080-A65AEE3A9478}|AppName, iWebar-enabler.exe-codedownloader.exe, V karanténe, [3ce04e83c8d1a195e93773bd9c68b54b]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B4C98D4-2C62-4B0D-8F2A-B2AA89134A8C}|AppName, iWebar-enabler.exe-buttonutil.exe, V karanténe, [ff1d28a93861e94df926d65aec187b85]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{77C48713-8F01-4F0A-AF6C-69E2391D2DE5}|AppName, iWebar-enabler.exe-buttonutil.exe, V karanténe, [0715c1104851ea4cc659fc348e7638c8]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{907A83E8-FF40-4B7A-A4F7-243EAF1DAA3D}|AppName, iWebar-enabler.exe-codedownloader.exe, V karanténe, [08146a670d8ca690b96749e7da2afb05]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9DCAAD4D-6140-492A-ADAC-6CCDF16B358B}|AppName, iWebar-enabler.exe-buttonutil.exe, V karanténe, [0418efe24b4e7bbbe23d5cd4e420cf31]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA803F96-9D91-48B4-AFE0-8D3399C47437}|AppName, iWebar-enabler.exe-buttonutil.exe, V karanténe, [05174f8281184de9d54a959ba460fc04]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D8FEEFBC-C9B0-4B8D-9D8B-FDDDC63532BC}|AppName, iWebar-enabler.exe-codedownloader.exe, V karanténe, [8e8edbf6b8e1f5414dd3210fa55ffe02]
PUP.Optional.CrossRider, HKU\S-1-5-21-2659214294-1756257098-4147057040-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DF9CAC4F-72F0-460B-A3F0-AE66EDDED6A7}|AppName, iWebar-enabler.exe-codedownloader.exe, V karanténe, [c656d9f832672115d44c1917e81cf20e]

Údaj databázy Registry: 0
(Žiadne škodlivé položky neboli zistené)

Priečinky: 0
(Žiadne škodlivé položky neboli zistené)

Súbory: 0
(Žiadne škodlivé položky neboli zistené)

Fyzické sektory: 0
(Žiadne škodlivé položky neboli zistené)


(end)

Re: Prosimt o kontrolu

Napsal: 03 kvě 2016 10:14
od jaro3
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7,8,10 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“ , v okně pak na „Open TXT“ a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.

Re: Prosimt o kontrolu

Napsal: 03 kvě 2016 18:00
od Sylton
Dobrý deň, dodal by som to ešte v ten deň , avšak niekedy mi nejde vôbec net, ako keby som mal zdielanie wi-fi cez telefon a minuté dáta :D
RogueKiller V12.1.5.0 (x64) [May 2 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : nikol [Administrator]
Started from : C:\Users\nikol\Desktop\RogueKillerX64.exe
Mode : Scan -- Date : 05/03/2016 17:44:36

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 4 ¤¤¤
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://asus.msn.com -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://asus.msn.com -> Found
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Found
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 7 (Driver: Loaded) ¤¤¤
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_CREATE[0] : Unknown @ 0xfffffa8001b862c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_CLOSE[2] : Unknown @ 0xfffffa8001b862c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_DEVICE_CONTROL[14] : Unknown @ 0xfffffa8001b862c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_INTERNAL_DEVICE_CONTROL[15] : Unknown @ 0xfffffa8001b862c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_POWER[22] : Unknown @ 0xfffffa8001b862c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_SYSTEM_CONTROL[23] : Unknown @ 0xfffffa8001b862c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_PNP[27] : Unknown @ 0xfffffa8001b862c0

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD50 00BPVT-80HXZT3 SATA Disk Device +++++
--- User ---
[MBR] 123b72a2e2db8c0e507e9a25d6ad310b
[BSP] a8e3b45d88f8e4350bf008fb4a1a1ecc : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 2048 | Size: 25600 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 52430848 | Size: 205084 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 472442880 | Size: 246255 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD50 00BPVT-80HXZT3 SATA Disk Device +++++
--- User ---
[MBR] e65fdbf8533de163d4653b1dd893a4a8
[BSP] bd3184861b1c3e61e9dde75bb5fbaa22 : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 238470 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 488388608 | Size: 238469 MB
User = LL1 ... OK
User = LL2 ... OK

Re: Prosimt o kontrolu

Napsal: 03 kvě 2016 20:32
od jaro3
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)


- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni antivir i firewall.
Stáhni
Zoek.exe

a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Re: Prosimt o kontrolu

Napsal: 04 kvě 2016 10:07
od Sylton
RogueKiller V12.1.5.0 (x64) [May 2 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : nikol [Administrator]
Started from : C:\Users\nikol\Desktop\RogueKillerX64.exe
Mode : Delete -- Date : 05/04/2016 10:05:51

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 4 ¤¤¤
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://asus.msn.com -> Replaced (http://www.microsoft.com/isapi/redir.dl ... ar=msnhome)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2659214294-1756257098-4147057040-1002\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://asus.msn.com -> Replaced (http://www.microsoft.com/isapi/redir.dl ... ar=msnhome)
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Replaced (2)
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Replaced (2)

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 7 (Driver: Loaded) ¤¤¤
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_CREATE[0] : Unknown @ 0xfffffa8001b852c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_CLOSE[2] : Unknown @ 0xfffffa8001b852c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_DEVICE_CONTROL[14] : Unknown @ 0xfffffa8001b852c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_INTERNAL_DEVICE_CONTROL[15] : Unknown @ 0xfffffa8001b852c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_POWER[22] : Unknown @ 0xfffffa8001b852c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_SYSTEM_CONTROL[23] : Unknown @ 0xfffffa8001b852c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_PNP[27] : Unknown @ 0xfffffa8001b852c0

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD50 00BPVT-80HXZT3 SATA Disk Device +++++
--- User ---
[MBR] 123b72a2e2db8c0e507e9a25d6ad310b
[BSP] a8e3b45d88f8e4350bf008fb4a1a1ecc : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 2048 | Size: 25600 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 52430848 | Size: 205084 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 472442880 | Size: 246255 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD50 00BPVT-80HXZT3 SATA Disk Device +++++
--- User ---
[MBR] e65fdbf8533de163d4653b1dd893a4a8
[BSP] bd3184861b1c3e61e9dde75bb5fbaa22 : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 238470 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 488388608 | Size: 238469 MB
User = LL1 ... OK
User = LL2 ... OK