Hodně moc virů a reklam na ruský stránky

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
PavlinQa1234
Level 2
Level 2
Příspěvky: 163
Registrován: květen 15
Pohlaví: Žena
Stav:
Offline

Hodně moc virů a reklam na ruský stránky

Příspěvekod PavlinQa1234 » 09 srp 2016 15:31

Dam google, vyhledam.. A vyhledá se to přes ruský stránky.. Nebo kliknu.. A zobrazí se mi v nové liště ruská stránka, takže jí zavřu kliknu, znovu zase se mi zobrazí v nové liště ruská stránka, takhle opakuji dokud se mi nezobrazí to co chci.. Asi mi jebne.. Jsem bezradná.. Prosím o pomoc.. Počítač je i o dost pomalejší..

Děkuji za pomoc s logem a nebo radu :)
S láskou PavlinQa :3

Reklama
Uživatelský avatar
mmmartin
Moderátor
Elite Level 10
Elite Level 10
Příspěvky: 9639
Registrován: srpen 04
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: Hodně moc virů a reklam na ruský stránky

Příspěvekod mmmartin » 09 srp 2016 15:39

Rada č. 1: Vygeneruj log a vlož ho do příspěvku. Jak na to? Tady je návod.
ASUS Prime Z390-P / Hexa Core Intel core i5 Coffee Lake-S / Gigabyte GeForce GTX 650 Ti / FORTRON BlueStorm Bronze 80PLUS / W 11

Uživatelský avatar
PavlinQa1234
Level 2
Level 2
Příspěvky: 163
Registrován: květen 15
Pohlaví: Žena
Stav:
Offline

Re: Hodně moc virů a reklam na ruský stránky

Příspěvekod PavlinQa1234 » 09 srp 2016 15:45

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 15:44:37, on 9. 8. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Hotspot Shield\bin\hsscp.exe
C:\Windows\System32\TiltWheelMouse.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe
C:\Program Files (x86)\Clownfish\Clownfish.exe
C:\Windows\SysWOW64\Codecs\TrayMenu.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\Rockstar Games\GTA San Andreas\samp.exe
E:\Filmy\Filmy\Moje Filmy\PAWNO\SAMP server\pawno\pawno.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\Jiří\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll
O2 - BHO: MRSearchPlugin - {8E8F97CD-60B5-456F-A201-73065652D099} - C:\Users\Jiří\AppData\Local\Mail.Ru\Sputnik\IESearchPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Codec Settings UAC Manager] "C:\Windows\system32\Codecs\CodecUACManager.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [PC Remote Server] C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe /silent
O4 - HKCU\..\Run: [Clownfish] "C:\Program Files (x86)\Clownfish\Clownfish.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Codec Pack Update Checker] "C:\Windows\system32\Codecs\UpdateChecker.exe"
O4 - HKCU\..\Run: [dugdivdaxa] explorer "http://exensup.ru/?utm_source=uoua03&utm_content=007c9d4ee02e99e60ccdb633929370f7&utm_term=DF10FEDC4F60E1F8112B85A3BD8FFEBF&utm_d=20160808"
O4 - Startup: IMVU.lnk = ?
O4 - Global Startup: CodecPackTrayMenu.lnk = C:\Windows\SysWOW64\Codecs\TrayMenu.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{26E2A1A3-207B-4500-BCA7-45E4AE3672F4}: NameServer = 82.163.142.7,95.211.158.134
O17 - HKLM\System\CCS\Services\Tcpip\..\{7CF1544F-78F9-460F-81F8-6326ABE19ABD}: NameServer = 82.163.142.7,95.211.158.134
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 82.163.143.171 82.163.142.173
O17 - HKLM\System\CS1\Services\Tcpip\..\{26E2A1A3-207B-4500-BCA7-45E4AE3672F4}: NameServer = 82.163.142.7,95.211.158.134
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 82.163.143.171 82.163.142.173
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
O23 - Service: Hotspot Shield Service (hshld) - AnchorFree Inc. - C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MPC Core Protect Service (MPCProtectService) - DotC United Inc - C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PACE License Services (PaceLicenseDServices) - PACE Anti-Piracy, Inc. - C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11067 bytes
S láskou PavlinQa :3

Uživatelský avatar
PavlinQa1234
Level 2
Level 2
Příspěvky: 163
Registrován: květen 15
Pohlaví: Žena
Stav:
Offline

Re: Hodně moc virů a reklam na ruský stránky

Příspěvekod PavlinQa1234 » 09 srp 2016 15:45

Tohle?
S láskou PavlinQa :3

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Hodně moc virů a reklam na ruský stránky

Příspěvekod jerabina » 09 srp 2016 15:52

Ano, super :-)

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.

===================================================

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

===================================================

Stáhni AdwCleaner (by Xplode)

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

===================================================

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na Kopírovat do schránky a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Uživatelský avatar
PavlinQa1234
Level 2
Level 2
Příspěvky: 163
Registrován: květen 15
Pohlaví: Žena
Stav:
Offline

Re: Hodně moc virů a reklam na ruský stránky

Příspěvekod PavlinQa1234 » 09 srp 2016 16:16

# AdwCleaner v5.026 - Logfile created 29/12/2015 at 14:40:35
# Updated 21/12/2015 by Xplode
# Database : 2015-12-23.1 [Server]
# Operating system : Windows 8.1 Pro (x64)
# Username : Jiří - CHAPPIE
# Running from : C:\Users\Jiří\Downloads\AdwCleaner.exe
# Option : Scan
# Support : hxxp://toolslib.net/forum

***** [ Services ] *****

Service Found : webTinstMKTN84
Service Found : ApplicationHosting
Service Found : caMyciloP
Service Found : webTinstMKTN84

***** [ Folders ] *****

Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\Program Files (x86)\simplitec
Folder Found : C:\Program Files (x86)\Crossbrowse
Folder Found : C:\Program Files (x86)\OLBPre
Folder Found : C:\Program Files (x86)\version09CheckMeUp
Folder Found : C:\Program Files (x86)\Crossbrowse
Folder Found : C:\Program Files (x86)\gmsd_re_004010007
Folder Found : C:\Program Files (x86)\gmsd_re_004010007
Folder Found : C:\ProgramData\Mail.Ru
Folder Found : C:\ProgramData\simplitec
Folder Found : C:\ProgramData\camycilop
Folder Found : C:\ProgramData\ApplicationHosting
Folder Found : C:\ProgramData\Medlights
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\simplitec
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZaxarGameBrowser
Folder Found : C:\Users\Jiří\AppData\Local\globalUpdate
Folder Found : C:\Users\Jiří\AppData\Local\Mail.Ru
Folder Found : C:\Users\Jiří\AppData\Local\MailRu
Folder Found : C:\Users\Jiří\AppData\Local\PriceMeter
Folder Found : C:\Users\Jiří\AppData\Local\PriceFountain
Folder Found : C:\Users\Jiří\AppData\Local\Kometa
Folder Found : C:\Users\Jiří\AppData\Local\Crossbrowse
Folder Found : C:\Users\Jiří\AppData\Local\Crossbrowse
Folder Found : C:\Users\Jiří\AppData\Local\gmsd_re_004010007
Folder Found : C:\Users\Jiří\AppData\Local\gmsd_re_004010007
Folder Found : C:\Users\Jiří\AppData\Local\19040
Folder Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmpieponfdjfekdfdfgmhamccfddpfb
Folder Found : C:\Users\Jiří\AppData\LocalLow\mystarttb
Folder Found : C:\Users\Jiří\AppData\Roaming\SetMyHomePage
Folder Found : C:\Users\Jiří\AppData\Roaming\newSI_1007
Folder Found : C:\Users\Jiří\AppData\Roaming\newSI_1017
Folder Found : C:\Users\Jiří\AppData\Roaming\newSI_1022
Folder Found : C:\Users\Jiří\AppData\Roaming\Microsoft\Windows\Start Menu\Боковая панель - Комета
Folder Found : C:\Users\Jiří\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kometa

***** [ Files ] *****

File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_oppjbdkgpfhhllancffaoaemplhkngoc_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_oppjbdkgpfhhllancffaoaemplhkngoc_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.bestpriceninja.com_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.bestpriceninja.com_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_hdapp1008-a.akamaihd.net_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_hdapp1008-a.akamaihd.net_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.kingtopdeals.com_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.kingtopdeals.com_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.re-markit00.re-markit.co_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.re-markit00.re-markit.co_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_clpremdo.com_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_clpremdo.com_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_cs.reimageplus.com_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_cs.reimageplus.com_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_mmotraffic.com_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_mmotraffic.com_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.safefinder.com_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.safefinder.com_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.snapdo.com_0.localstorage
File Found : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.snapdo.com_0.localstorage-journal
File Found : C:\Users\Jiří\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Kometa.lnk
File Found : C:\Users\Jiří\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
File Found : C:\Users\Jiří\Desktop\MyPC Backup.lnk
File Found : C:\WINDOWS\patsearch.bin
File Found : C:\WINDOWS\SysNative\drivers\webTinstMKTN84.sys
File Found : C:\WINDOWS\SysWOW64\findit.xml

***** [ DLL ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

Task Found : pricemeterdownloader
Task Found : pricemetertask
Task Found : pricemeterwatcher
Task Found : LaunchPreSignup
Task Found : simplitec Power Suite (Tray)
Task Found : simplitec Power Suite
Task Found : CheckMeUp Update
Task Found : CheckMeUp Update

***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\IELNKSRCH
Key Found : HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Stpro.exe
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ZaxarLoader]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ZaxarGameBrowser]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Timestasks]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_re_004010007]
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A31488E-DAF4-EDDA-DA38-6E056E4A093B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5A31488E-DAF4-EDDA-DA38-6E056E4A093B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5A31488E-DAF4-EDDA-DA38-6E056E4A093B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5A31488E-DAF4-EDDA-DA38-6E056E4A093B}
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}]
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A31488E-DAF4-EDDA-DA38-6E056E4A093B}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5A31488E-DAF4-EDDA-DA38-6E056E4A093B}
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\PriceMeter
Key Found : HKCU\Software\Tutorials
Key Found : HKCU\Software\TutoTag
Key Found : HKCU\Software\GAMESDESKTOP
Key Found : HKCU\Software\SetMyHomePage
Key Found : HKCU\Software\Microsoft\Tinstalls
Key Found : HKCU\Software\AppDataLow\Software\CheckMeUp
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\DealPlyLive
Key Found : HKLM\SOFTWARE\mystarttb
Key Found : HKLM\SOFTWARE\PriceMeterLiveUpdate
Key Found : HKLM\SOFTWARE\simplitec
Key Found : HKLM\SOFTWARE\Tutorials
Key Found : HKLM\SOFTWARE\GAMESDESKTOP
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D01A33E2-0A34-4659-82AA-8A90C51C0D21}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\simplitec POWER SUITE_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D01A33E2-0A34-4659-82AA-8A90C51C0D21}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\6ECB650E-8177-CC04-71B4-6BE3CD063758
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_re_004010007_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_re_004010007_is1
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OLBPre
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ielnksrch
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\internetspeedtracker.dl.tb.ask.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.snapdo.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\snapdo.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.com

***** [ Web browsers ] *****

[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : omniboxes
[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : morphvox-voice-changer.en.softonic.com
[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : feed.snapdo.com
[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Found : hxxp://www.omniboxes.com/webfavicon.ico
[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : fcgnigmofekcllgbiejhmigggmgehkip
[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : inmpieponfdjfekdfdfgmhamccfddpfb

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [11518 bytes] ##########
# AdwCleaner v5.201 - Log vytvořen 09/08/2016 v 16:12:15
# Aktualizováno 30/06/2016 by ToolsLib
# Databáze : 2016-08-08.3 [Server]
# OperaÄŤnĂ­ system : Windows 8.1 (X64)
# Uživatelské jméno : Jiří - LEATHERFACE
# Spuštěno z : C:\Users\Jiří\Downloads\AdwCleaner.exe
# NastavenĂ­ : Sken
# Podpora : https://toolslib.net/forum

***** [ SluĹľby ] *****

SluĹľba Nalezeno : MPCProtectService
SluĹľba Nalezeno : MPCKpt

***** [ SloĹľky ] *****

SloĹľka Nalezeno : C:\ProgramData\Mail.Ru
SloĹľka Nalezeno : C:\ProgramData\be08f282-01e5-1
SloĹľka Nalezeno : C:\ProgramData\be08f282-0f61-1
SloĹľka Nalezeno : C:\ProgramData\be08f282-1001-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-13e5-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-17b7-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-1f75-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-2247-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-28e7-1
SloĹľka Nalezeno : C:\ProgramData\be08f282-2a07-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-34b1-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-5445-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-5691-1
SloĹľka Nalezeno : C:\ProgramData\be08f282-5975-1
SloĹľka Nalezeno : C:\ProgramData\be08f282-5b43-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-5ed5-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-5f03-1
SloĹľka Nalezeno : C:\ProgramData\be08f282-6a43-1
SloĹľka Nalezeno : C:\ProgramData\be08f282-7807-1
SloĹľka Nalezeno : C:\ProgramData\be08f282-7997-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-79c1-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-7ab1-1
SloĹľka Nalezeno : C:\ProgramData\be08f282-7bf1-0
SloĹľka Nalezeno : C:\ProgramData\be08f282-7ea5-1
SloĹľka Nalezeno : C:\ProgramData\d892ddc1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-0651-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-0775-0
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-0d47-0
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-1191-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-2ad5-0
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-2d47-0
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-2ed5-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-32a5-0
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-3687-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-4161-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-41a3-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-4723-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-48b1-0
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-4913-0
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-4997-0
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-49c7-0
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-4ea5-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-5005-0
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-51b3-0
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-6001-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-68e1-0
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-6b57-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-70a1-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-71c5-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-78b7-1
SloĹľka Nalezeno : C:\ProgramData\dc6979a7-7a81-0
SloĹľka Nalezeno : C:\ProgramData\{027e0083-112c-1}
SloĹľka Nalezeno : C:\ProgramData\{08972b53-512c-0}
SloĹľka Nalezeno : C:\ProgramData\{091ed25a-612c-0}
SloĹľka Nalezeno : C:\ProgramData\{125f4579-512c-1}
SloĹľka Nalezeno : C:\ProgramData\{130424a1-512c-1}
SloĹľka Nalezeno : C:\ProgramData\{15bf6ede-712c-0}
SloĹľka Nalezeno : C:\ProgramData\{19c85b93-012c-1}
SloĹľka Nalezeno : C:\ProgramData\{1d361565-612c-0}
SloĹľka Nalezeno : C:\ProgramData\{23bd8805-512c-0}
SloĹľka Nalezeno : C:\ProgramData\{39ab9b9f-712c-0}
SloĹľka Nalezeno : C:\ProgramData\Application Data\Mail.Ru
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-01e5-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-0f61-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-1001-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-13e5-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-17b7-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-1f75-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-2247-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-28e7-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-2a07-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-34b1-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-5445-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-5691-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-5975-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-5b43-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-5ed5-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-5f03-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-6a43-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-7807-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-7997-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-79c1-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-7ab1-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-7bf1-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\be08f282-7ea5-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\d892ddc1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-0651-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-0775-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-0d47-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-1191-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-2ad5-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-2d47-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-2ed5-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-32a5-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-3687-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-4161-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-41a3-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-4723-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-48b1-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-4913-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-4997-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-49c7-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-4ea5-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-5005-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-51b3-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-6001-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-68e1-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-6b57-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-70a1-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-71c5-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-78b7-1
SloĹľka Nalezeno : C:\ProgramData\Application Data\dc6979a7-7a81-0
SloĹľka Nalezeno : C:\ProgramData\Application Data\{027e0083-112c-1}
SloĹľka Nalezeno : C:\ProgramData\Application Data\{08972b53-512c-0}
SloĹľka Nalezeno : C:\ProgramData\Application Data\{091ed25a-612c-0}
SloĹľka Nalezeno : C:\ProgramData\Application Data\{125f4579-512c-1}
SloĹľka Nalezeno : C:\ProgramData\Application Data\{130424a1-512c-1}
SloĹľka Nalezeno : C:\ProgramData\Application Data\{15bf6ede-712c-0}
SloĹľka Nalezeno : C:\ProgramData\Application Data\{19c85b93-012c-1}
SloĹľka Nalezeno : C:\ProgramData\Application Data\{1d361565-612c-0}
SloĹľka Nalezeno : C:\ProgramData\Application Data\{23bd8805-512c-0}
SloĹľka Nalezeno : C:\ProgramData\Application Data\{39ab9b9f-712c-0}
SloĹľka Nalezeno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC
SloĹľka Nalezeno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC AdCleaner
SloĹľka Nalezeno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC Desktop
SloĹľka Nalezeno : C:\Program Files (x86)\Mail.Ru
SloĹľka Nalezeno : C:\Program Files (x86)\MPC Cleaner
Složka Nalezeno : C:\Users\Jiří\AppData\Local\Amigo
Složka Nalezeno : C:\Users\Jiří\AppData\Local\Mail.Ru
Složka Nalezeno : C:\Users\Jiří\AppData\Local\sysnet
Složka Nalezeno : C:\Users\Jiří\AppData\Local\ScriptWriter
Složka Nalezeno : C:\Users\Jiří\AppData\Local\fupdate
Složka Nalezeno : C:\Users\Jiří\AppData\Roaming\MailProducts
Složka Nalezeno : C:\Users\Jiří\AppData\Roaming\MCorp
SloĹľka Nalezeno : C:\extensions
Složka Nalezeno : C:\Users\Jiří\AppData\Roaming\MCorp

***** [ Soubory ] *****

Soubor Nalezeno : C:\Users\Public\Desktop\MPC AdCleaner.lnk
Soubor Nalezeno : C:\Users\Public\Desktop\MPC Cleaner.lnk
Soubor Nalezeno : C:\Users\Public\Desktop\MPC Desktop.lnk
Soubor Nalezeno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk
Soubor Nalezeno : C:\Users\Jiří\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk
Soubor Nalezeno : C:\Users\Jiří\Favorites\Mail.Ru.url
Soubor Nalezeno : C:\Users\Jiří\Favorites\Mail.Ru Агент - используй для общения!.url
Soubor Nalezeno : C:\Users\Jiří\Desktop\Вoйти в Интeрнет.lnk
Soubor Nalezeno : C:\Users\Jiří\Desktop\Поиcк в Интeрнете.lnk
Soubor Nalezeno : C:\Users\Jiří\Desktop\Искать в Интернете.url
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.bestpriceninja.com_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.bestpriceninja.com_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.eshopcomp.com_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.eshopcomp.com_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.re-markit00.re-markit.co_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.re-markit00.re-markit.co_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_audio-amplifier-pro.en.softonic.com_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_audio-amplifier-pro.en.softonic.com_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nova.rambler.ru_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nova.rambler.ru_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.eshopcomp.com_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.eshopcomp.com_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.mpc.am_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.mpc.am_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_song-director.en.softonic.com_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_song-director.en.softonic.com_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_sound-volume-7.en.softonic.com_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_sound-volume-7.en.softonic.com_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.coupontime00.coupontime.co_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.coupontime00.coupontime.co_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_workno.ru_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_workno.ru_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.metrolyrics.com_0.localstorage
Soubor Nalezeno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.metrolyrics.com_0.localstorage-journal
Soubor Nalezeno : C:\Windows\SysNative\drivers\MPCKpt.sys

***** [ DLL ] *****


***** [ WMI ] *****


***** [ Zástupci ] *****

Zástupce Infikováno : C:\Users\Jiří\Desktop\Поиcк в Интeрнете.lnk ( "hxxp://go-search.ru/?utm_source=desktop" )
Zástupce Infikováno : C:\Users\Jiří\Desktop\District\District (1).lnk ( --app=hxxp://mmotraffic.com/catalog/goplay/1000932/MTE3NjYvLy8xMDAwOTMy/?subid=3&click_id=06cf547f8083117ee0049637601401477ced05ba --start-fullscreen )
Zástupce Infikováno : C:\Users\Jiří\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk ( url,FileProtocolHandler "hxxp://www.mail.ru/cnt/20775012?gp=811008" )

***** [ Naplánované úlohy ] *****

Ăšloha Nalezeno : LaunchPreSignup
Ăšloha Nalezeno : sysnet
Ăšloha Nalezeno : ScriptWriter
Ăšloha Nalezeno : fupdate
Ăšloha Nalezeno : DNSPLUM

***** [ Registry ] *****

KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E
Hodnota Nalezeno : HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION [SystemCash.exe]
Hodnota Nalezeno : HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION [SystemCash.exe]
KlĂ­ÄŤ Nalezeno : HKCU\Software\3b94e07441cb07d760e92ec9e1c32f2d
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d892ddc1}
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\filmfanatic.com
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\filmfanatic2.dl.myway.com
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\myway.com
KlĂ­ÄŤ Nalezeno : HKCU\Software\Google\Chrome\Extensions\hegneaniplmfjcmohoclabblbahcbjoe
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\Google\Chrome\Extensions\hegneaniplmfjcmohoclabblbahcbjoe
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\Google\Chrome\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\Google\Chrome\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\Google\Chrome\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099}
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E8F97CD-60B5-456F-A201-73065652D099}
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E8F97CD-60B5-456F-A201-73065652D099}
KlĂ­ÄŤ Nalezeno : HKCU\Software\One System Care
KlĂ­ÄŤ Nalezeno : HKCU\Software\PRODUCTSETUP
KlĂ­ÄŤ Nalezeno : HKCU\Software\Mail.Ru
KlĂ­ÄŤ Nalezeno : HKCU\Software\csastats
KlĂ­ÄŤ Nalezeno : HKCU\Software\AppDataLow\Software\Mail.Ru
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\Cheat Engine\OpenCandy
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\MPC
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\MPC AdCleaner
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\Mail.Ru
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E1527582-8509-4011-B922-29E3FB548882}_is1
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPC
KlĂ­ÄŤ Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
KlĂ­ÄŤ Nalezeno : [x64] HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
KlĂ­ÄŤ Nalezeno : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E1527582-8509-4011-B922-29E3FB548882}_is1
KlĂ­ÄŤ Nalezeno : HKU\S-1-5-21-2083599567-3356488530-3129411815-1001\Software\One System Care
KlĂ­ÄŤ Nalezeno : HKU\S-1-5-21-2083599567-3356488530-3129411815-1001\Software\PRODUCTSETUP
KlĂ­ÄŤ Nalezeno : HKU\S-1-5-21-2083599567-3356488530-3129411815-1001\Software\Mail.Ru
KlĂ­ÄŤ Nalezeno : HKU\S-1-5-21-2083599567-3356488530-3129411815-1001\Software\csastats
KlĂ­ÄŤ Nalezeno : HKU\S-1-5-21-2083599567-3356488530-3129411815-1001\Software\AppDataLow\Software\Mail.Ru
Hodnota Nalezeno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{D11EA041-1904-463C-8140-35FFDEE31BC3}]
Hodnota Nalezeno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{E1860243-C205-40EA-B6C7-058A83F99E9F}]
Hodnota Nalezeno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{FC2B8141-4520-44A5-8D43-FD6EC30CC21B}]
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
KlĂ­ÄŤ Nalezeno : HKU\S-1-5-21-2083599567-3356488530-3129411815-1001\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
Data Nalezeno : HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{26E2A1A3-207B-4500-BCA7-45E4AE3672F4} [NameServer] - 82.163.142.7,95.211.158.134
Data Nalezeno : HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{7CF1544F-78F9-460F-81F8-6326ABE19ABD} [NameServer] - 82.163.142.7,95.211.158.134
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\bestpriceninja.com
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\eshopcomp.com
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\filmfanatic2.dl.myway.com
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\myway.com
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\pstatic.bestpriceninja.com
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\pstatic.eshopcomp.com
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\staticimgfarm.com
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\utop.it
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mpc.am
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.mpc.am
KlĂ­ÄŤ Nalezeno : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\utop.it
Hodnota Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Codec Settings UAC Manager]

***** [ ProhlĂ­ĹľeÄŤe ] *****

[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Nalezeno : webcammax-full.en.softonic.com
[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Nalezeno : song-director.en.softonic.com
[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Nalezeno : searchtds.ru
[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Nalezeno : ccfifbojenkenpkmnbnndeadpfdiffof
[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Nalezeno : hegneaniplmfjcmohoclabblbahcbjoe
[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Nalezeno : oelpkepjlgmehajehfeicfbjdiobdkfj
[C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Nalezeno : ojlcebdkbpjdpiligkdbbkdkfjmchbfd

*************************

C:\AdwCleaner\AdwCleaner[S1].txt - [32919 bytĹŻ] - [29/12/2015 15:40:35]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [32993 bytĹŻ] ##########
S láskou PavlinQa :3

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Hodně moc virů a reklam na ruský stránky

Příspěvekod jaro3 » 09 srp 2016 16:41

Ještě Malwarebytes' Anti-Malware.

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Cleaning (Vymazat)

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
PavlinQa1234
Level 2
Level 2
Příspěvky: 163
Registrován: květen 15
Pohlaví: Žena
Stav:
Offline

Re: Hodně moc virů a reklam na ruský stránky

Příspěvekod PavlinQa1234 » 09 srp 2016 16:45

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 9. 8. 2016
Čas skenování: 16:28
Protokol:
Správce: Ano

Verze: 2.2.1.1043
Databáze malwaru: v2016.08.09.07
Databáze rootkitů: v2016.08.09.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto

OS: Windows 8.1
CPU: x64
Souborový systém: NTFS
Uživatel: Jiří

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 306451
Uplynulý čas: 14 min, 53 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 4
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe, 1772, , [0efd0742752538fef66c2a8c58ac639d]
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCTray.exe, 272, , [22e9d5746d2d2313342e724420e4c739]
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCDesktop.exe, 4328, , [16f5ca7f5d3df640382aa11561a360a0]
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCTray64.exe, 4924, , [b853ac9dd0ca1a1ce970068c936e54ac]

Moduly: 46
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\LpcManager.dll, , [94770148069479bd134f10a6c53fbe42],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\LpcManager.dll, , [94770148069479bd134f10a6c53fbe42],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\LpcManager.dll, , [94770148069479bd134f10a6c53fbe42],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\WinService.dll, , [f4173613702a59ddc69c9e18ad57f010],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\XProcessBus.dll, , [f714ec5d2b6ffd39cc9601b5b15313ed],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\XProcessBus.dll, , [f714ec5d2b6ffd39cc9601b5b15313ed],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\XProcessBus.dll, , [f714ec5d2b6ffd39cc9601b5b15313ed],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Support.dll, , [8b80ba8fe4b6b18539292d89fb09ca36],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Support.dll, , [8b80ba8fe4b6b18539292d89fb09ca36],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Support.dll, , [8b80ba8fe4b6b18539292d89fb09ca36],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Utility.dll, , [f219da6f3e5cd95dfb670bab1fe533cd],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Utility.dll, , [f219da6f3e5cd95dfb670bab1fe533cd],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Utility.dll, , [f219da6f3e5cd95dfb670bab1fe533cd],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Report.dll, , [27e425248d0dc274352d5e5840c424dc],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Report.dll, , [27e425248d0dc274352d5e5840c424dc],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Report.dll, , [27e425248d0dc274352d5e5840c424dc],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\XSkin.dll, , [bd4ed1782b6f8da919491f97669e2cd4],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\XSkin.dll, , [bd4ed1782b6f8da919491f97669e2cd4],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\XBus.dll, , [838893b6fb9ffb3b84de4d6946be41bf],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\XBus.dll, , [838893b6fb9ffb3b84de4d6946be41bf],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TrayFrame.dll, , [19f286c3485274c2b0b2b006b94b0ff1],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Monitor.dll, , [25e63811b0ead660105285310103b14f],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Database.dll, , [e2294cfda3f7be789fc3ab0b3bc947b9],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\LogReport.dll, , [818a7bceb1e91e1802603086749043bd],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\LogReport.dll, , [818a7bceb1e91e1802603086749043bd],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Cleaner.dll, , [af5c1c2d87137eb867fbc7ef2cd8fa06],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\SafeProtect.dll, , [35d671d82a7050e60c5616a073917789],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\BrowserPlugIn.dll, , [50bb3c0df2a86bcb293954628f755da3],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Update.dll, , [36d59faa96040f27b6ac3383eb19c33d],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Web.dll, , [15f6ea5f32687abc5909744233d120e0],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\SafeNavi.dll, , [32d90f3a0e8c5ed8eb7744727b8949b7],

Klíče registru: 5
PUP.Optional.MorePowerfulCleaner, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\MPCProtectService, , [0efd0742752538fef66c2a8c58ac639d],
PUP.Optional.MorePowerfulCleaner, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\MPCKpt, , [48c3ea5fb8e2aa8c43c20098e120d927],
PUP.Optional.MorePowerfulCleaner, HKLM\SOFTWARE\WOW6432NODE\MPC, , [95763811712988ae217e00f109fada26],
PUP.Optional.MorePowerfulCleaner, HKLM\SOFTWARE\WOW6432NODE\MPC DESKTOP, , [ef1c4dfc574340f67eb7f70861a2f50b],
PUP.Optional.StartPage, HKU\S-1-5-21-2083599567-3356488530-3129411815-1001\SOFTWARE\START PAGE, , [a269d27731692e08cb7c43b132d159a7],

Hodnoty registru: 6
PUP.Optional.MorePowerfulCleaner, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT|MPCInstalled, , , [808bf2579109171f0ed7de21709325db]
PUP.Optional.MorePowerfulCleaner, HKLM\SOFTWARE\WOW6432NODE\MPC|Location, C:\Program Files (x86)\MPC Cleaner, , [95763811712988ae217e00f109fada26]
PUP.Optional.MorePowerfulCleaner, HKLM\SOFTWARE\WOW6432NODE\MPC DESKTOP|Location, C:\Program Files (x86)\MPC Cleaner, , [ef1c4dfc574340f67eb7f70861a2f50b]
PUP.Optional.MorePowerfulCleaner, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\MPCPROTECTSERVICE|ImagePath, "C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe", , [9873e168a0fac175067026cc8380867a]
PUP.Optional.StartPage.Generic, HKU\S-1-5-21-2083599567-3356488530-3129411815-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|dugdivdaxa, explorer "http://exensup.ru/?utm_source=uoua03&utm_content=007c9d4ee02e99e60ccdb633929370f7&utm_term=DF10FEDC4F60E1F8112B85A3BD8FFEBF&utm_d=20160808", , [d03b91b8cfcb0d299b11b118e41e728e]
PUP.Optional.StartPage, HKU\S-1-5-21-2083599567-3356488530-3129411815-1001\SOFTWARE\START PAGE|Start Page, http://exensup.ru/?utm_source=startpage ... d=20160808, , [a269d27731692e08cb7c43b132d159a7]

Data registru: 1
Trojan.DNSChanger.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|NameServer, 82.163.143.171 82.163.142.173, Dobré: (8.8.8.8), Špatné: (82.163.143.171 82.163.142.173),,[e02bc9806337979fe5dfa9d0a1639070]

Složky: 34
PUP.Optional.MorePowerfulCleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC, , [b457ef5a4654b383dd18b6331ae96e92],
PUP.Optional.MCorp, C:\Users\Jiří\AppData\Roaming\MCorp\1147, , [719a8abf7327de58c4bfa15cc241fe02],
PUP.Optional.MCorp, C:\Users\Jiří\AppData\Roaming\MCorp, , [719a8abf7327de58c4bfa15cc241fe02],
PUP.Optional.MorePowerfulCleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC AdCleaner, , [f11a6edb5d3d87af1d03349233cfe41c],
PUP.Optional.MorePowerfulCleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC Desktop, , [dc2f9faa37633bfb2223cefb4cb65ba5],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Config, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Config\DB, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Drivers, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Exe, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Log, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Microsoft.VC90.CRT, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\AdCleaner, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\Cleaner, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\CrashReport, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\Desktop, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\DesktopSetup, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\DesktopUninstall, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\News, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\Tray, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\Uninstall, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule\Module, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\SpecialRule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\SpecialRule\Module, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SearchIcon, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SgIcon, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.DNSUnlocker.Gen, C:\Program Files (x86)\DNSPLUM, , [09026adfbedc9b9ba833930aeb19ba46],

Soubory: 318
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll.dll, , [4ebd4aff3a60e1552042ab0b7391827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe, , [0efd0742752538fef66c2a8c58ac639d],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\LpcManager.dll, , [94770148069479bd134f10a6c53fbe42],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\WinService.dll, , [f4173613702a59ddc69c9e18ad57f010],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\XProcessBus.dll, , [f714ec5d2b6ffd39cc9601b5b15313ed],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Support.dll, , [8b80ba8fe4b6b18539292d89fb09ca36],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Utility.dll, , [f219da6f3e5cd95dfb670bab1fe533cd],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Report.dll, , [27e425248d0dc274352d5e5840c424dc],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCTray.exe, , [22e9d5746d2d2313342e724420e4c739],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\XSkin.dll, , [bd4ed1782b6f8da919491f97669e2cd4],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\XBus.dll, , [838893b6fb9ffb3b84de4d6946be41bf],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TrayFrame.dll, , [19f286c3485274c2b0b2b006b94b0ff1],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Monitor.dll, , [25e63811b0ead660105285310103b14f],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Database.dll, , [e2294cfda3f7be789fc3ab0b3bc947b9],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\LogReport.dll, , [818a7bceb1e91e1802603086749043bd],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Cleaner.dll, , [af5c1c2d87137eb867fbc7ef2cd8fa06],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\SafeProtect.dll, , [35d671d82a7050e60c5616a073917789],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\BrowserPlugIn.dll, , [50bb3c0df2a86bcb293954628f755da3],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Update.dll, , [36d59faa96040f27b6ac3383eb19c33d],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Web.dll, , [15f6ea5f32687abc5909744233d120e0],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\SafeNavi.dll, , [32d90f3a0e8c5ed8eb7744727b8949b7],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCDesktop.exe, , [16f5ca7f5d3df640382aa11561a360a0],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCTray64.exe, , [b853ac9dd0ca1a1ce970068c936e54ac],
PUP.Optional.MorePowerfulCleaner, C:\Windows\System32\drivers\MPCKpt.sys, , [48c3ea5fb8e2aa8c43c20098e120d927],
PUP.Optional.LoadMoney, C:\Users\Jiří\AppData\Roaming\Skype\My Skype Received Files\0 3z attacker interface.exe, , [1bf070d9a0fa64d2b3afc2062cd8fe02],
Trojan.PasswordStealer.FD, C:\Users\Jiří\AppData\Roaming\Skype\My Skype Received Files\Remote Console.rar, , [e52675d42e6ced493d823321cf3222de],
PUP.Optional.LoadMoney, C:\Users\Jiří\Desktop\0 3z attacker interface.exe, , [20eb55f4fb9f1026a1c1a1272bd928d8],
CheatTool.CETTrainer, C:\Users\Jiří\Desktop\Grand Theft Auto 5 V1.0.372.2 Trainer +12 MrAntiFun.EXE, , [16f51732f1a94aec5ce0c305669b1de3],
CheatTool.CETTrainer, C:\Users\Jiří\Desktop\Dying Light V1.10.0 Trainer +19 MrAntiFun.EXE, , [ad5ebb8ea4f65fd778c4a42425dcd42c],
PUP.Optional.TopFlix, C:\Program Files (x86)\DNSPLUM\dnsplum.exe, , [f01b1336c1d967cfe08324bbb05118e8],
HackTool.Agent, C:\Program Files (x86)\Sniper Elite 3\steam_api.dll, , [987328212d6d46f0d69bdb74cd34c43c],
RiskWare.GameHack, C:\Program Files (x86)\Sniper Elite 3\steam_api64.dll, , [95763e0baaf0f4421d1d2286848011ef],
RiskWare.GameHack, C:\Program Files (x86)\South Park - The Stick of Truth\steam_api.dll, , [0506e3666e2cf145c77396125ba949b7],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\CeBase.dll, , [bf4c4bfe891191a581e16c4aaa5a56aa],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\CrashReport.exe, , [57b44405267471c569f91b9bae5615eb],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\DesktopPatch.dll, , [d13a4207a0fa4beb0c56a3130400c13f],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\DesktopPatch64.dll, , [28e37acf4f4b5bdb6bf79f17709402fe],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\DesktopPatch64_1.dll, , [4dbea3a645558caaf270d5e1f80c837d],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MainFrame.dll, , [2ae10049405af73f0e54d4e293713dc3],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPC.exe, , [c2496cdd465442f4b4aee4d2f4108c74],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCAutoClean.exe, , [dc2f2227d4c6eb4b1f43892da262817f],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCDesktop64.exe, , [65a63910e2b8ea4ca5bdc0f6976d38c8],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, , [9b7081c82377c76f461c882ee81c2bd5],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCSecurity.exe, , [b65510392278e74fc1a1f7bf51b313ed],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCSetting.exe, , [63a88dbcd7c3c96d075be8ce8c78e11f],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\SetupFrame.dll, , [c843c9808416e65068f1d0c2ea17827e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Uninstall.exe, , [28e3f554198137ffb2a7b1e1738efa06],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\UninstallFrame.dll, , [f21970d981195dd9d683177b07fa9b65],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\UninstDelete.exe, , [58b37dcca8f2999d0b4ea5ed4fb28a76],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\AdCleaner.exe, , [31da90b975255cda82e0e4d246be10f0],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\AdcManager.dll, , [aa611831544674c23131882e768ed729],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\AdControl.dll, , [4ebdc28714863204e87aa412e81ce11f],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\AdkFwd.dll, , [ce3dcd7caaf0f83e32302195e51fc43c],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\AdkWsf.dll, , [1cef73d65149e3533d25872f15ef748c],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\AdPopWnd.exe, , [36d53712e7b3270fe2806f4717ed49b7],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\AdxEngine.exe, , [f8139baeedadf1451949843248bc669a],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MPCNews.exe, , [db308cbddcbebd79f969d1e5ac58b24e],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\SafeNavi64.dll, , [9e6d52f75e3cfe38bea4783e2ada58a8],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\UpdateHost.exe, , [10fbc8815f3bcb6bc49edfd7e61e4db3],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Upgrade.dll, , [e427e465efab86b0b6acb7ffd133ec14],
Backdoor.Bladabindi.Generic, C:\Users\Jiří\Downloads\SA-MP-DDoS (1).rar, , [5bb0c089cecc93a3edeffb8ba55c966a],
PUP.Optional.InstallCore, C:\Users\Jiří\Downloads\Codec-Pack_installer.exe, , [39d28abfa8f21c1a77fe39026e938c74],
PUP.Optional.LoadMoney, C:\Users\Jiří\Downloads\0 3z attacker interface.exe, , [ed1e70d99901063089d9ba0e07fd8977],
CheatTool.CETTrainer, C:\Users\Jiří\Downloads\Fallout 4 V1.1.30.0.0 Trainer +17 MrAntiFun.zip, , [6aa1064329713ff71e1e2e9a5ba6639d],
CheatTool.CETTrainer, C:\Users\Jiří\Downloads\Fallout 4 V1.5.157.0.1 Trainer +17 MrAntiFun.zip, , [98733c0da1f980b691abc008b948659b],
Backdoor.Bladabindi.Generic, C:\Users\Jiří\Downloads\Nepotvrzeno 112274.crdownload, , [11fae9605941b3836676087e0df4a65a],
PUP.Optional.MorePowerfulCleaner, C:\Users\Public\Desktop\MPC Desktop.lnk, , [78930c3de9b1a78f940c1bae27db8a76],
Trojan.Agent, C:\Extracted\Server.exe, , [4bc0c08956441224c94f76d4ef140000],
PUP.Optional.CrossRider, C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage, , [927923263b5fd660ce1bc128d92ac739],
PUP.Optional.CrossRider, C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal, , [c645fa4f0d8d45f13cadd11819ea9e62],
PUP.Optional.MorePowerfulCleaner, C:\Users\Public\Desktop\MPC AdCleaner.lnk, , [ea2180c99efc53e30ae9c5243ec556aa],
PUP.Optional.MorePowerfulCleaner, C:\Users\Public\Desktop\MPC Cleaner.lnk, , [f61582c7930712243aba6683cf341be5],
PUP.Optional.MorePowerfulCleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC\MPC Cleaner.lnk, , [b457ef5a4654b383dd18b6331ae96e92],
PUP.Optional.MCorp, C:\Users\Jiří\AppData\Roaming\MCorp\1147\udpx, , [719a8abf7327de58c4bfa15cc241fe02],
PUP.Optional.MorePowerfulCleaner, C:\Users\Jiří\AppData\Roaming\Microsoft\Windows\SendTo\MPC Desktop.lnk, , [59b21e2b613937ffc470c63914ef6b95],
PUP.Optional.MorePowerfulCleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC AdCleaner\MPC AdCleaner.lnk, , [f11a6edb5d3d87af1d03349233cfe41c],
PUP.Optional.MorePowerfulCleaner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC Desktop\MPC Desktop.lnk, , [dc2f9faa37633bfb2223cefb4cb65ba5],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\config.ini, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\dbgkpt.dll, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Microsoft.VC90.CRT.manifest, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\msvcm90.dll, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\msvcp90.dll, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\msvcr90.dll, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\nmlct, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\ps.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\ruleInfo.ini, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\snh.dll, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\specRuleInfo.ini, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\symsrv.dll, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\symsrv.yes, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\AdcSafeDll.dll, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\AdcUpdate.exe, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\AdUpdate.dll, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\AdUpdateHost.exe, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\wfhxte.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\ws.db, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\zlib1.dll, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Config\Clean.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Config\PlugIn.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Config\DB\as.db, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Config\DB\cf.db, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Config\DB\run.db, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Config\DB\st.db, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Drivers\MPCBase_32.sys, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Drivers\MPCKpt.inf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Drivers\MPCKpt.sys, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Drivers\MPCKpt_vista_32.sys, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Drivers\MPCKpt_vista_64.sys, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Drivers\MPCKpt_xp_32.sys, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Log\20160809.log, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Microsoft.VC90.CRT\msvcm90.dll, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Microsoft.VC90.CRT\msvcp90.dll, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Microsoft.VC90.CRT\msvcr90.dll, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1055.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\adc.system.daton, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\css.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1025.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1025.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1029.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1029.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1031.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1031.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1033.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1033.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1036.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1036.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1040.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1040.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1041.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1041.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1046.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1046.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1048.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1048.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1049.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1049.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1055.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1057.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\1057.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\11274.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\11274.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\16393.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\16393.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\2057.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\2057.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\2058.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\2058.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\2080.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\2080.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\3081.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\3081.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\3082.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\3082.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\4105.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\4105.rc, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\adc.system.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\adc.system.datoff, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\adc.system.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\adc.system.ruleoff, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\adc.system.ruleon, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\antifraud.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\antifraud.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\auto.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\base.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\base.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\blocked, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\CleanCache.bat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\css.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\default.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\default.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\fast.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\fast.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\mod-support-and-service, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\mpc-reading.js, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\no-such-domain, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\putian.js, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\qiyi.swf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\qiyi3.swf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\ReadMode.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\ReadMode.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\RuleVersion.ini, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\sohu_live.swf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\sweetalert.css, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\sweetalert.min.js, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\trust.txt, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\user.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\user.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\user.rule_, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\video.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Module\video.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\AdCleaner\Lang.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\AdCleaner\Skin.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\Cleaner\Lang.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\Cleaner\Skin.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\CrashReport\Lang.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\CrashReport\Skin.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\Desktop\Lang.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\Desktop\Skin.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\News\Lang.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\News\Skin.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\Tray\Lang.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\Tray\Skin.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\Uninstall\Lang.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Skin\Uninstall\Skin.xf, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule\CommonRuleDownLoad.ini, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule\ruleInfo.ini, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule\Module\blocked, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule\Module\fast.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule\Module\fast.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule\Module\mod-support-and-service, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule\Module\ReadMode.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule\Module\ReadMode.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule\Module\trust.txt, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule\Module\user.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\CommonRule\Module\user.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\SpecialRule\SpecialRuleDownLoad.ini, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\SpecialRule\specRuleInfo.ini, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\SpecialRule\Module\1029.dat, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\TEMP\Rule\SpecialRule\Module\1029.rule, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\q2.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\ad_gray.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\ad_green.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\ad_org.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\ad_red.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\g1.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\g10.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\g11.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\g12.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\g2.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\g3.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\g4.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\g5.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\g6.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\g7.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\g8.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\g9.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\q1.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\q10.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\q11.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\q12.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\q3.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\q4.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\q5.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\q6.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\q7.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\q8.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\q9.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\r1.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\r10.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\r11.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\r12.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\r2.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\r3.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\r4.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\r5.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\r6.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\r7.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\r8.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\r9.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\sys_gray.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\sys_green.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\sys_org.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\sys_red.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\y1.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\y10.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\y11.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\y12.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\y2.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\y3.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\y4.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\y5.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\y6.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\y7.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\y8.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\y9.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SearchIcon\search_{08DA4B46-E0EB-4B4D-8C8B-558C967AF6C5}.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SearchIcon\search_{22A8D5A3-F368-4C6B-BF4D-3C901EBCF242}.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SearchIcon\search_{3F9A707D-2C36-4344-8621-B8E4ADC95C18}.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SearchIcon\search_{ADC520A9-B4B3-791E-B149-845C11673CB0}.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SearchIcon\search_{CDA529A9-B1B3-793E-B449-845C11673CB5}.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SearchIcon\search_{D8EC46AF-529F-4636-963B-C086429C73DA}.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SearchIcon\search_{DE37CD8C-DE7B-481F-A676-303ABAFBEE04}.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SearchIcon\search_{EDA029A1-B5BA-793E-B649-875C18673CC5}.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SearchIcon\search_{F154C596-75A9-4028-90E8-9752BD7CA05B}.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SearchIcon\search_{FDA029A2-A5BA-797E-B689-875E18673FC2}.ico, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SearchIcon\toasts_waring.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SgIcon\adcapp.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SgIcon\adcweb.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SgIcon\block.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SgIcon\home.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SgIcon\ie.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SgIcon\search.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\AR_green.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\AR_org.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\AR_red.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\Bp_green.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\Bp_org.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\Bp_red.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\SpeedUp_green.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\SpeedUp_org.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\SpeedUp_red.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\SVC_green.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\SVC_org.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\SVC_red.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\TSK_green.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\TSK_org.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\Image\SoIcon\TSK_red.png, , [38d387c261396fc7b6a962673ec40000],
PUP.Optional.DNSUnlocker.Gen, C:\Program Files (x86)\DNSPLUM\Info.rtf, , [09026adfbedc9b9ba833930aeb19ba46],
PUP.Optional.DNSUnlocker.Gen, C:\Program Files (x86)\DNSPLUM\config.ini, , [09026adfbedc9b9ba833930aeb19ba46],
PUP.Optional.DNSUnlocker.Gen, C:\Program Files (x86)\DNSPLUM\DNSPLUM.cer, , [09026adfbedc9b9ba833930aeb19ba46],
PUP.Optional.DNSUnlocker.Gen, C:\Program Files (x86)\DNSPLUM\License.rtf, , [09026adfbedc9b9ba833930aeb19ba46],
PUP.Optional.DNSUnlocker.Gen, C:\Program Files (x86)\DNSPLUM\LogoBlack.ico, , [09026adfbedc9b9ba833930aeb19ba46],
PUP.Optional.DNSUnlocker.Gen, C:\Program Files (x86)\DNSPLUM\LogoGreen.ico, , [09026adfbedc9b9ba833930aeb19ba46],
PUP.Optional.DNSUnlocker.Gen, C:\Program Files (x86)\DNSPLUM\LogoYellow.ico, , [09026adfbedc9b9ba833930aeb19ba46],
PUP.Optional.DNSUnlocker.Gen, C:\Program Files (x86)\DNSPLUM\settings.ini, , [09026adfbedc9b9ba833930aeb19ba46],
PUP.Optional.DNSUnlocker.Gen, C:\Program Files (x86)\DNSPLUM\unins000.dat, , [09026adfbedc9b9ba833930aeb19ba46],
PUP.Optional.DNSUnlocker.Gen, C:\Program Files (x86)\DNSPLUM\unins000.exe, , [09026adfbedc9b9ba833930aeb19ba46],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)
S láskou PavlinQa :3

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Hodně moc virů a reklam na ruský stránky

Příspěvekod jaro3 » 09 srp 2016 16:47

. spusť znovu Malwarebytes' Anti-Malware a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Cleaning (Vymazat)

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7,8,10 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Open Report “ , v okně pak na „Open TXT“ a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
PavlinQa1234
Level 2
Level 2
Příspěvky: 163
Registrován: květen 15
Pohlaví: Žena
Stav:
Offline

Re: Hodně moc virů a reklam na ruský stránky

Příspěvekod PavlinQa1234 » 09 srp 2016 16:51

Už jsem udělala ten Adw.. Takže znova spustit Malwarebytes?
# AdwCleaner v5.201 - Log vytvořen 09/08/2016 v 16:20:19
# Aktualizováno 30/06/2016 by ToolsLib
# Databáze : 2016-08-08.3 [Server]
# OperaÄŤnĂ­ system : Windows 8.1 (X64)
# Uživatelské jméno : Jiří - LEATHERFACE
# Spuštěno z : C:\Users\Jiří\Downloads\AdwCleaner.exe
# Nastavení : Čištění
# Podpora : https://toolslib.net/forum

***** [ SluĹľby ] *****

[-] Služba Smazáno : MPCProtectService
[-] Služba Smazáno : MPCKpt

***** [ SloĹľky ] *****

[-] Složka Smazáno : C:\ProgramData\Mail.Ru
[-] Složka Smazáno : C:\ProgramData\be08f282-01e5-1
[-] Složka Smazáno : C:\ProgramData\be08f282-0f61-1
[-] Složka Smazáno : C:\ProgramData\be08f282-1001-0
[-] Složka Smazáno : C:\ProgramData\be08f282-13e5-0
[-] Složka Smazáno : C:\ProgramData\be08f282-17b7-0
[-] Složka Smazáno : C:\ProgramData\be08f282-1f75-0
[-] Složka Smazáno : C:\ProgramData\be08f282-2247-0
[-] Složka Smazáno : C:\ProgramData\be08f282-28e7-1
[-] Složka Smazáno : C:\ProgramData\be08f282-2a07-0
[-] Složka Smazáno : C:\ProgramData\be08f282-34b1-0
[-] Složka Smazáno : C:\ProgramData\be08f282-5445-0
[-] Složka Smazáno : C:\ProgramData\be08f282-5691-1
[-] Složka Smazáno : C:\ProgramData\be08f282-5975-1
[-] Složka Smazáno : C:\ProgramData\be08f282-5b43-0
[-] Složka Smazáno : C:\ProgramData\be08f282-5ed5-0
[-] Složka Smazáno : C:\ProgramData\be08f282-5f03-1
[-] Složka Smazáno : C:\ProgramData\be08f282-6a43-1
[-] Složka Smazáno : C:\ProgramData\be08f282-7807-1
[-] Složka Smazáno : C:\ProgramData\be08f282-7997-0
[-] Složka Smazáno : C:\ProgramData\be08f282-79c1-0
[-] Složka Smazáno : C:\ProgramData\be08f282-7ab1-1
[-] Složka Smazáno : C:\ProgramData\be08f282-7bf1-0
[-] Složka Smazáno : C:\ProgramData\be08f282-7ea5-1
[-] Složka Smazáno : C:\ProgramData\d892ddc1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-0651-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-0775-0
[-] Složka Smazáno : C:\ProgramData\dc6979a7-0d47-0
[-] Složka Smazáno : C:\ProgramData\dc6979a7-1191-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-2ad5-0
[-] Složka Smazáno : C:\ProgramData\dc6979a7-2d47-0
[-] Složka Smazáno : C:\ProgramData\dc6979a7-2ed5-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-32a5-0
[-] Složka Smazáno : C:\ProgramData\dc6979a7-3687-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-4161-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-41a3-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-4723-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-48b1-0
[-] Složka Smazáno : C:\ProgramData\dc6979a7-4913-0
[-] Složka Smazáno : C:\ProgramData\dc6979a7-4997-0
[-] Složka Smazáno : C:\ProgramData\dc6979a7-49c7-0
[-] Složka Smazáno : C:\ProgramData\dc6979a7-4ea5-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-5005-0
[-] Složka Smazáno : C:\ProgramData\dc6979a7-51b3-0
[-] Složka Smazáno : C:\ProgramData\dc6979a7-6001-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-68e1-0
[-] Složka Smazáno : C:\ProgramData\dc6979a7-6b57-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-70a1-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-71c5-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-78b7-1
[-] Složka Smazáno : C:\ProgramData\dc6979a7-7a81-0
[-] Složka Smazáno : C:\ProgramData\{027e0083-112c-1}
[-] Složka Smazáno : C:\ProgramData\{08972b53-512c-0}
[-] Složka Smazáno : C:\ProgramData\{091ed25a-612c-0}
[-] Složka Smazáno : C:\ProgramData\{125f4579-512c-1}
[-] Složka Smazáno : C:\ProgramData\{130424a1-512c-1}
[-] Složka Smazáno : C:\ProgramData\{15bf6ede-712c-0}
[-] Složka Smazáno : C:\ProgramData\{19c85b93-012c-1}
[-] Složka Smazáno : C:\ProgramData\{1d361565-612c-0}
[-] Složka Smazáno : C:\ProgramData\{23bd8805-512c-0}
[-] Složka Smazáno : C:\ProgramData\{39ab9b9f-712c-0}
[#] Složka Smazáno : C:\ProgramData\Application Data\Mail.Ru
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-01e5-1
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-0f61-1
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-1001-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-13e5-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-17b7-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-1f75-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-2247-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-28e7-1
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-2a07-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-34b1-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-5445-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-5691-1
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-5975-1
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-5b43-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-5ed5-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-5f03-1
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-6a43-1
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-7807-1
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-7997-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-79c1-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-7ab1-1
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-7bf1-0
[#] Složka Smazáno : C:\ProgramData\Application Data\be08f282-7ea5-1
[#] Složka Smazáno : C:\ProgramData\Application Data\d892ddc1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-0651-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-0775-0
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-0d47-0
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-1191-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-2ad5-0
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-2d47-0
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-2ed5-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-32a5-0
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-3687-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-4161-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-41a3-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-4723-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-48b1-0
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-4913-0
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-4997-0
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-49c7-0
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-4ea5-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-5005-0
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-51b3-0
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-6001-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-68e1-0
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-6b57-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-70a1-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-71c5-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-78b7-1
[#] Složka Smazáno : C:\ProgramData\Application Data\dc6979a7-7a81-0
[#] Složka Smazáno : C:\ProgramData\Application Data\{027e0083-112c-1}
[#] Složka Smazáno : C:\ProgramData\Application Data\{08972b53-512c-0}
[#] Složka Smazáno : C:\ProgramData\Application Data\{091ed25a-612c-0}
[#] Složka Smazáno : C:\ProgramData\Application Data\{125f4579-512c-1}
[#] Složka Smazáno : C:\ProgramData\Application Data\{130424a1-512c-1}
[#] Složka Smazáno : C:\ProgramData\Application Data\{15bf6ede-712c-0}
[#] Složka Smazáno : C:\ProgramData\Application Data\{19c85b93-012c-1}
[#] Složka Smazáno : C:\ProgramData\Application Data\{1d361565-612c-0}
[#] Složka Smazáno : C:\ProgramData\Application Data\{23bd8805-512c-0}
[#] Složka Smazáno : C:\ProgramData\Application Data\{39ab9b9f-712c-0}
[-] Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC
[-] Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC AdCleaner
[-] Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC Desktop
[-] Složka Smazáno : C:\Program Files (x86)\Mail.Ru
[#] Složka Smazáno : C:\Program Files (x86)\MPC Cleaner
[-] Složka Smazáno : C:\Users\Jiří\AppData\Local\Amigo
[-] Složka Smazáno : C:\Users\Jiří\AppData\Local\Mail.Ru
[-] Složka Smazáno : C:\Users\Jiří\AppData\Local\sysnet
[-] Složka Smazáno : C:\Users\Jiří\AppData\Local\ScriptWriter
[-] Složka Smazáno : C:\Users\Jiří\AppData\Local\fupdate
[-] Složka Smazáno : C:\Users\Jiří\AppData\Roaming\MailProducts
[-] Složka Smazáno : C:\Users\Jiří\AppData\Roaming\MCorp
[-] Složka Smazáno : C:\extensions
[#] Složka Smazáno : C:\Users\Jiří\AppData\Roaming\MCorp

***** [ Soubory ] *****

[-] Soubor Smazáno : C:\Users\Public\Desktop\MPC AdCleaner.lnk
[-] Soubor Smazáno : C:\Users\Public\Desktop\MPC Cleaner.lnk
[-] Soubor Smazáno : C:\Users\Public\Desktop\MPC Desktop.lnk
[-] Soubor Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk
[-] Soubor Smazáno : C:\Users\Jiří\Favorites\Mail.Ru.url
[-] Soubor Smazáno : C:\Users\Jiří\Favorites\Mail.Ru Агент - используй для общения!.url
[-] Soubor Smazáno : C:\Users\Jiří\Desktop\Вoйти в Интeрнет.lnk
[-] Soubor Smazáno : C:\Users\Jiří\Desktop\Поиcк в Интeрнете.lnk
[-] Soubor Smazáno : C:\Users\Jiří\Desktop\Искать в Интернете.url
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.bestpriceninja.com_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.bestpriceninja.com_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.eshopcomp.com_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.eshopcomp.com_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.re-markit00.re-markit.co_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.re-markit00.re-markit.co_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_audio-amplifier-pro.en.softonic.com_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_audio-amplifier-pro.en.softonic.com_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nova.rambler.ru_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nova.rambler.ru_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.eshopcomp.com_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.eshopcomp.com_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.mpc.am_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.mpc.am_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_song-director.en.softonic.com_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_song-director.en.softonic.com_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_sound-volume-7.en.softonic.com_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_sound-volume-7.en.softonic.com_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.coupontime00.coupontime.co_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.coupontime00.coupontime.co_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_workno.ru_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_workno.ru_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.metrolyrics.com_0.localstorage
[-] Soubor Smazáno : C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.metrolyrics.com_0.localstorage-journal
[#] Soubor Smazáno : C:\Windows\SysNative\drivers\MPCKpt.sys

***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Zástupci ] *****

[!] Zástupce Ne Vyléčeno : C:\Users\Jiří\Desktop\Поиcк в Интeрнете.lnk
[-] Zástupce Vyléčeno : C:\Users\Jiří\Desktop\District\District (1).lnk
[!] Zástupce Ne Vyléčeno : C:\Users\Jiří\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk

***** [ Naplánované úlohy ] *****

[-] Úloha Smazáno : LaunchPreSignup
[-] Úloha Smazáno : sysnet
[-] Úloha Smazáno : ScriptWriter
[-] Úloha Smazáno : fupdate
[-] Úloha Smazáno : DNSPLUM

***** [ Registry ] *****

[-] Klíč Smazáno : HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E
[-] Hodnota Smazáno : HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION [SystemCash.exe]
[-] Hodnota Smazáno : HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION [SystemCash.exe]
[-] Klíč Smazáno : HKCU\Software\3b94e07441cb07d760e92ec9e1c32f2d
[-] Klíč Smazáno : HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d892ddc1}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\filmfanatic.com
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\filmfanatic2.dl.myway.com
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\myway.com
[-] Klíč Smazáno : HKCU\Software\Google\Chrome\Extensions\hegneaniplmfjcmohoclabblbahcbjoe
[-] Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\hegneaniplmfjcmohoclabblbahcbjoe
[-] Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj
[-] Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd
[-] Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E8F97CD-60B5-456F-A201-73065652D099}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E8F97CD-60B5-456F-A201-73065652D099}
[-] Klíč Smazáno : HKCU\Software\One System Care
[-] Klíč Smazáno : HKCU\Software\PRODUCTSETUP
[-] Klíč Smazáno : HKCU\Software\Mail.Ru
[-] Klíč Smazáno : HKCU\Software\csastats
[-] Klíč Smazáno : HKCU\Software\AppDataLow\Software\Mail.Ru
[-] Klíč Smazáno : HKLM\SOFTWARE\Cheat Engine\OpenCandy
[-] Klíč Smazáno : HKLM\SOFTWARE\MPC
[-] Klíč Smazáno : HKLM\SOFTWARE\MPC AdCleaner
[-] Klíč Smazáno : HKLM\SOFTWARE\Mail.Ru
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E1527582-8509-4011-B922-29E3FB548882}_is1
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPC
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
[-] Klíč Smazáno : [x64] HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
[-] Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E1527582-8509-4011-B922-29E3FB548882}_is1
[-] Hodnota Smazáno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{D11EA041-1904-463C-8140-35FFDEE31BC3}]
[-] Hodnota Smazáno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{E1860243-C205-40EA-B6C7-058A83F99E9F}]
[-] Hodnota Smazáno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{FC2B8141-4520-44A5-8D43-FD6EC30CC21B}]
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
[-] Data Obnoveno : HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{26E2A1A3-207B-4500-BCA7-45E4AE3672F4} [NameServer]
[-] Data Obnoveno : HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{7CF1544F-78F9-460F-81F8-6326ABE19ABD} [NameServer]
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\bestpriceninja.com
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\eshopcomp.com
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\pstatic.bestpriceninja.com
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\pstatic.eshopcomp.com
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\staticimgfarm.com
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\utop.it
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mpc.am
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.mpc.am
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\utop.it
[-] Hodnota Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Codec Settings UAC Manager]

***** [ ProhlĂ­ĹľeÄŤe ] *****

[-] [C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Smazáno : webcammax-full.en.softonic.com
[-] [C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Smazáno : song-director.en.softonic.com
[-] [C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Smazáno : searchtds.ru
[-] [C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Smazáno : ccfifbojenkenpkmnbnndeadpfdiffof
[-] [C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Smazáno : hegneaniplmfjcmohoclabblbahcbjoe
[-] [C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Smazáno : oelpkepjlgmehajehfeicfbjdiobdkfj
[-] [C:\Users\Jiří\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Smazáno : ojlcebdkbpjdpiligkdbbkdkfjmchbfd

*************************

:: "Tracing" klíče smazány
:: Nastavení Winsock vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [21188 bytĹŻ] - [09/08/2016 16:20:19]
C:\AdwCleaner\AdwCleaner[S1].txt - [33081 bytĹŻ] - [29/12/2015 15:40:35]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [21336 bytĹŻ] ##########
S láskou PavlinQa :3

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Hodně moc virů a reklam na ruský stránky

Příspěvekod jaro3 » 09 srp 2016 22:07

. spusť znovu Malwarebytes' Anti-Malware a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7,8,10 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Open Report “ , v okně pak na „Open TXT“ a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
PavlinQa1234
Level 2
Level 2
Příspěvky: 163
Registrován: květen 15
Pohlaví: Žena
Stav:
Offline

Re: Hodně moc virů a reklam na ruský stránky

Příspěvekod PavlinQa1234 » 09 srp 2016 23:52

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.7 (07.03.2016)
Operating System: Windows 8.1 x64
Ran by Jiýˇ (Administrator) on Łt 09. 08. 2016 at 23:49:03,88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 3

Successfully deleted: C:\Users\Jiýˇ\AppData\Local\crashrpt (Folder)
Successfully deleted: C:\Users\Jiýˇ\AppData\Roaming\imvuclient (Folder)
Successfully deleted: C:\Users\Public\Desktop\hotspot shield.lnk (Shortcut)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 09. 08. 2016 at 23:50:36,69
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
S láskou PavlinQa :3


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 80 hostů