Prosím o kontrolu logu - asi vir.. Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

flowem
Level 5.5
Level 5.5
Příspěvky: 2858
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Prosím o kontrolu logu - asi vir..

Příspěvekod flowem » 24 čer 2014 13:52

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:50:07, on 24.6.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16521)

FIREFOX: 29.0.1 (cs)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Analog Devices\SoundMAX\SoundMAX.exe
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Program Files (x86)\SEC\MT4.0\GammaTray.exe
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Jirka-PC\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *origin.com;*ea.com;*akamaihd.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 216.239.32.20 google.com
O1 - Hosts: 216.239.32.20 google.com www.google.ad
O1 - Hosts: 216.239.32.20 google.com www.google.ae
O1 - Hosts: 216.239.32.20 google.com www.google.com.af
O1 - Hosts: 216.239.32.20 google.com www.google.com.ag
O1 - Hosts: 216.239.32.20 google.com www.google.com.ai
O1 - Hosts: 216.239.32.20 google.com www.google.al
O1 - Hosts: 216.239.32.20 google.com www.google.am
O1 - Hosts: 216.239.32.20 google.com www.google.co.ao
O1 - Hosts: 216.239.32.20 google.com www.google.com.ar
O1 - Hosts: 216.239.32.20 google.com www.google.as
O1 - Hosts: 216.239.32.20 google.com www.google.at
O1 - Hosts: 216.239.32.20 google.com www.google.com.au
O1 - Hosts: 216.239.32.20 google.com www.google.az
O1 - Hosts: 216.239.32.20 google.com www.google.ba
O1 - Hosts: 216.239.32.20 google.com www.google.com.bd
O1 - Hosts: 216.239.32.20 google.com www.google.be
O1 - Hosts: 216.239.32.20 google.com www.google.bf
O1 - Hosts: 216.239.32.20 google.com www.google.bg
O1 - Hosts: 216.239.32.20 google.com www.google.com.bh
O1 - Hosts: 216.239.32.20 google.com www.google.bi
O1 - Hosts: 216.239.32.20 google.com www.google.bj
O1 - Hosts: 216.239.32.20 google.com www.google.com.bn
O1 - Hosts: 216.239.32.20 google.com www.google.com.bo
O1 - Hosts: 216.239.32.20 google.com www.google.com.br
O1 - Hosts: 216.239.32.20 google.com www.google.bs
O1 - Hosts: 216.239.32.20 google.com www.google.bt
O1 - Hosts: 216.239.32.20 google.com www.google.co.bw
O1 - Hosts: 216.239.32.20 google.com www.google.by
O1 - Hosts: 216.239.32.20 google.com www.google.com.bz
O1 - Hosts: 216.239.32.20 google.com www.google.ca
O1 - Hosts: 216.239.32.20 google.com www.google.cd
O1 - Hosts: 216.239.32.20 google.com www.google.cf
O1 - Hosts: 216.239.32.20 google.com www.google.cg
O1 - Hosts: 216.239.32.20 google.com www.google.ch
O1 - Hosts: 216.239.32.20 google.com www.google.ci
O1 - Hosts: 216.239.32.20 google.com www.google.co.ck
O1 - Hosts: 216.239.32.20 google.com www.google.cl
O1 - Hosts: 216.239.32.20 google.com www.google.cm
O1 - Hosts: 216.239.32.20 google.com www.google.cn
O1 - Hosts: 216.239.32.20 google.com www.google.com.co
O1 - Hosts: 216.239.32.20 google.com www.google.co.cr
O1 - Hosts: 216.239.32.20 google.com www.google.com.cu
O1 - Hosts: 216.239.32.20 google.com www.google.cv
O1 - Hosts: 216.239.32.20 google.com www.google.com.cy
O1 - Hosts: 216.239.32.20 google.com www.google.cz
O1 - Hosts: 216.239.32.20 google.com www.google.de
O1 - Hosts: 216.239.32.20 google.com www.google.dj
O1 - Hosts: 216.239.32.20 google.com www.google.dk
O1 - Hosts: 216.239.32.20 google.com www.google.dm
O1 - Hosts: 216.239.32.20 google.com www.google.com.do
O1 - Hosts: 216.239.32.20 google.com www.google.dz
O1 - Hosts: 216.239.32.20 google.com www.google.com.ec
O1 - Hosts: 216.239.32.20 google.com www.google.ee
O1 - Hosts: 216.239.32.20 google.com www.google.com.eg
O1 - Hosts: 216.239.32.20 google.com www.google.es
O1 - Hosts: 216.239.32.20 google.com www.google.com.et
O1 - Hosts: 216.239.32.20 google.com www.google.fi
O1 - Hosts: 216.239.32.20 google.com www.google.com.fj
O1 - Hosts: 216.239.32.20 google.com www.google.fm
O1 - Hosts: 216.239.32.20 google.com www.google.fr
O1 - Hosts: 216.239.32.20 google.com www.google.ga
O1 - Hosts: 216.239.32.20 google.com www.google.ge
O1 - Hosts: 216.239.32.20 google.com www.google.gg
O1 - Hosts: 216.239.32.20 google.com www.google.com.gh
O1 - Hosts: 216.239.32.20 google.com www.google.com.gi
O1 - Hosts: 216.239.32.20 google.com www.google.gl
O1 - Hosts: 216.239.32.20 google.com www.google.gm
O1 - Hosts: 216.239.32.20 google.com www.google.gp
O1 - Hosts: 216.239.32.20 google.com www.google.gr
O1 - Hosts: 216.239.32.20 google.com www.google.com.gt
O1 - Hosts: 216.239.32.20 google.com www.google.gy
O1 - Hosts: 216.239.32.20 google.com www.google.com.hk
O1 - Hosts: 216.239.32.20 google.com www.google.hn
O1 - Hosts: 216.239.32.20 google.com www.google.hr
O1 - Hosts: 216.239.32.20 google.com www.google.ht
O1 - Hosts: 216.239.32.20 google.com www.google.hu
O1 - Hosts: 216.239.32.20 google.com www.google.co.id
O1 - Hosts: 216.239.32.20 google.com www.google.ie
O1 - Hosts: 216.239.32.20 google.com www.google.co.il
O1 - Hosts: 216.239.32.20 google.com www.google.im
O1 - Hosts: 216.239.32.20 google.com www.google.co.in
O1 - Hosts: 216.239.32.20 google.com www.google.iq
O1 - Hosts: 216.239.32.20 google.com www.google.is
O1 - Hosts: 216.239.32.20 google.com www.google.it
O1 - Hosts: 216.239.32.20 google.com www.google.je
O1 - Hosts: 216.239.32.20 google.com www.google.com.jm
O1 - Hosts: 216.239.32.20 google.com www.google.jo
O1 - Hosts: 216.239.32.20 google.com www.google.co.jp
O1 - Hosts: 216.239.32.20 google.com www.google.co.ke
O1 - Hosts: 216.239.32.20 google.com www.google.com.kh
O1 - Hosts: 216.239.32.20 google.com www.google.ki
O1 - Hosts: 216.239.32.20 google.com www.google.kg
O1 - Hosts: 216.239.32.20 google.com www.google.co.kr
O1 - Hosts: 216.239.32.20 google.com www.google.com.kw
O1 - Hosts: 216.239.32.20 google.com www.google.kz
O1 - Hosts: 216.239.32.20 google.com www.google.la
O1 - Hosts: 216.239.32.20 google.com www.google.com.lb
O1 - Hosts: 216.239.32.20 google.com www.google.li
O1 - Hosts: 216.239.32.20 google.com www.google.lk
O1 - Hosts: 216.239.32.20 google.com www.google.co.ls
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: IEExtension.Extension - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - mscoree.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files (x86)\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Color Calibration.lnk = ?
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Unknown owner - C:\Windows\system32\AEADISRV.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PirritDesktop - Unknown owner - C:\Users\Jirka-PC\AppData\Local\PirritSuggestor\PirritService.exe (file missing)
O23 - Service: PirritUpdater - Unknown owner - C:\Program Files (x86)\Pirrit\AutoUpdater.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: RzKLService - Razer Inc. - C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WinRST - Unknown owner - C:\Program Files (x86)\WinRST\WinRST.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 17715 bytes


Děkuji moc! :-)
AMD Ryzen 5 5600X | MSI MAG B550 TOMAHAWK | G.Skill Aegis 32GB 3200MHz | Kingston A2000 1TB | PowerColor Red Devil RX 6700 XT 12GB | XPG Core Reactor 750W | Be quiet! PURE BASE 500 | Asus VG27AQ1A

Reklama
flowem
Level 5.5
Level 5.5
Příspěvky: 2858
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - asi vir..

Příspěvekod flowem » 24 čer 2014 19:41

Prosím :D
AMD Ryzen 5 5600X | MSI MAG B550 TOMAHAWK | G.Skill Aegis 32GB 3200MHz | Kingston A2000 1TB | PowerColor Red Devil RX 6700 XT 12GB | XPG Core Reactor 750W | Be quiet! PURE BASE 500 | Asus VG27AQ1A

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - asi vir..

Příspěvekod jaro3 » 24 čer 2014 20:56

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

@echo off
del /q /a /f %systemroot%\system32\drivers\etc\hosts 2>nul
echo 127.0.0.1 localhost>>%systemroot%\system32\drivers\etc\hosts
exit

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:název souboru, zde napiš: FixHosts.bat
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Poklepáním na soubor ho spusť.

***********************************
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

************************************
Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

flowem
Level 5.5
Level 5.5
Příspěvky: 2858
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - asi vir..

Příspěvekod flowem » 25 čer 2014 15:55

# AdwCleaner v3.213 - Report created 25/06/2014 at 15:53:43
# Updated 23/06/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Jirka-PC - JIRKA
# Running from : C:\Users\Jirka-PC\Desktop\adwcleaner_3.213.exe
# Option : Scan

***** [ Services ] *****

Service Found : {0782648b-1717-4fef-ac58-8cb3ce03adb3}Gw64
Service Found : PirritDesktop
Service Found : PirritUpdater

***** [ Files / Folders ] *****

File Found : C:\END
File Found : C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\invalidprefs.js
File Found : C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\searchplugins\buenosearch.xml
File Found : C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js
File Found : C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
File Found : C:\Windows\System32\drivers\{0782648b-1717-4fef-ac58-8cb3ce03adb3}Gw64.sys
File Found : C:\Windows\System32\Tasks\EPUpdater
Folder Found : C:\Program Files (x86)\Gophoto.it
Folder Found : C:\Program Files (x86)\Mobogenie
Folder Found : C:\Program Files (x86)\SmartTweak
Folder Found : C:\Program Files (x86)\WinRST
Folder Found : C:\Users\Jirka-PC\AppData\Local\WinRST
Folder Found : C:\Users\Jirka-PC\AppData\Roaming\BabSolution
Folder Found : C:\Users\Jirka-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
Folder Found : C:\Users\Jirka-PC\AppData\Roaming\Pirrit

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\1ClickDownload
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\BabSolution
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Key Found : HKCU\Software\smarttweak
Key Found : HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\1ClickDownload
Key Found : [x64] HKCU\Software\BabSolution
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\InstallCore
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : [x64] HKCU\Software\smarttweak
Key Found : [x64] HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Mobogenie.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Key Found : HKLM\Software\Pirrit
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16521


-\\ Mozilla Firefox v29.0.1 (cs)

[ File : C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js ]

Line Found : user_pref("CT3289075.UserID", "UN28552918532185013");
Line Found : user_pref("CT3289075.fullUserID", "UN28552918532185013.IN.20140302122147");
Line Found : user_pref("CT3289075.installDate", "02/03/2014 12:21:50");
Line Found : user_pref("CT3289075.installSessionId", "{90DF8345-520F-4691-AA43-D77D893797B4}");
Line Found : user_pref("CT3289075.installSp", "false");
Line Found : user_pref("CT3289075.installerVersion", "1.8.1.4");
Line Found : user_pref("CT3289075.searchRevert", "false");
Line Found : user_pref("CT3289075.searchUninstallUserMode", "1");
Line Found : user_pref("CT3289075.searchUserMode", "1");
Line Found : user_pref("CT3289075.toolbarInstallDate", "02-03-2014 12:21:47");
Line Found : user_pref("CT3289075.versionFromInstaller", "10.23.0.1000");
Line Found : user_pref("CT3289075.xpeMode", "1");
Line Found : user_pref("extensions.buenosearch.admin", false);
Line Found : user_pref("extensions.buenosearch.aflt", "babsst");
Line Found : user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");
Line Found : user_pref("extensions.buenosearch.autoRvrt", "false");
Line Found : user_pref("extensions.buenosearch.dfltLng", "en");
Line Found : user_pref("extensions.buenosearch.excTlbr", false);
Line Found : user_pref("extensions.buenosearch.ffxUnstlRst", true);
Line Found : user_pref("extensions.buenosearch.id", "ec52895c0000000000000015f2a2752a");
Line Found : user_pref("extensions.buenosearch.instlDay", "16131");
Line Found : user_pref("extensions.buenosearch.instlRef", "sst");
Line Found : user_pref("extensions.buenosearch.newTab", false);
Line Found : user_pref("extensions.buenosearch.prdct", "buenosearch");
Line Found : user_pref("extensions.buenosearch.prtnrId", "buenosearch");
Line Found : user_pref("extensions.buenosearch.rvrt", "false");
Line Found : user_pref("extensions.buenosearch.smplGrp", "none");
Line Found : user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=EC520015F2A2752A&affID=128403&tsp=5174");
Line Found : user_pref("extensions.buenosearch.tlbrId", "base");
Line Found : user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=EC520015F2A2752A&affID=128403&tsp=5174");
Line Found : user_pref("extensions.buenosearch.vrsn", "1.8.28.7");
Line Found : user_pref("extensions.buenosearch.vrsnTs", "1.8.28.712:14:02");
Line Found : user_pref("extensions.buenosearch.vrsni", "1.8.28.7");
Line Found : user_pref("smartbar.machineId", "63QH+NWLKEV3NJPCB0K4Y+OGA93DKFWI18OIQ2CF6NEPWK2ZFLN5BDTPJTQAQ4L2KBIMO7EAXPTGKPSKGK3UGA");

[ File : C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js ]


-\\ Google Chrome v35.0.1916.153

[ File : C:\Users\Jirka-PC\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found [Extension] : pfmopbbadnfoelckkcmjjeaaegjpjjbk

*************************

AdwCleaner[R0].txt - [7130 octets] - [25/06/2014 15:53:43]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [7190 octets] ##########
AMD Ryzen 5 5600X | MSI MAG B550 TOMAHAWK | G.Skill Aegis 32GB 3200MHz | Kingston A2000 1TB | PowerColor Red Devil RX 6700 XT 12GB | XPG Core Reactor 750W | Be quiet! PURE BASE 500 | Asus VG27AQ1A

flowem
Level 5.5
Level 5.5
Příspěvky: 2858
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - asi vir..

Příspěvekod flowem » 25 čer 2014 16:16

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 25.6.2014
Scan Time: 15:58:53
Logfile:
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.06.25.11
Rootkit Database: v2014.06.23.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Jirka-PC

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 275732
Time Elapsed: 14 min, 3 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 1
PUP.Optional.WinRST.A, C:\Program Files (x86)\WinRST\WinRST.exe, 2264, , [139c89f3b2c99e983890c5f8cc36b44c]

Modules: 4
PUP.Optional.WinRST.A, C:\Program Files (x86)\WinRST\msvcp100.dll, , [139c89f3b2c99e983890c5f8cc36b44c],
PUP.Optional.WinRST.A, C:\Program Files (x86)\WinRST\msvcr100.dll, , [139c89f3b2c99e983890c5f8cc36b44c],
PUP.Optional.WinRST.A, C:\Program Files (x86)\WinRST\QtCore4.dll, , [139c89f3b2c99e983890c5f8cc36b44c],
PUP.Optional.WinRST.A, C:\Program Files (x86)\WinRST\QtNetwork4.dll, , [139c89f3b2c99e983890c5f8cc36b44c],

Registry Keys: 13
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, , [ab045d1f95e686b0cc507dcdd9293cc4],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, , [ab045d1f95e686b0cc507dcdd9293cc4],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, , [ab045d1f95e686b0cc507dcdd9293cc4],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, , [ab045d1f95e686b0cc507dcdd9293cc4],
PUP.Optional.WinRST.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WinRST, , [139c89f3b2c99e983890c5f8cc36b44c],
PUP.Optional.Gophoto.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pfmopbbadnfoelckkcmjjeaaegjpjjbk, , [efc056265a21c96d39e56c7d689b3fc1],
PUP.Optional.Pirrit.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PirritDesktop, , [a6097606b6c576c067107d3cc042f907],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-1705033116-2515132334-3789885432-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, , [604fa0dc91eabb7b2e8e4a9b8a7911ef],
PUP.Optional.Babylon.A, HKU\S-1-5-21-1705033116-2515132334-3789885432-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, , [edc2d4a8bcbfa3936adc0fd639ca738d],
PUP.Optional.Conduit.A, HKU\S-1-5-21-1705033116-2515132334-3789885432-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\FF, , [4768a0dc1e5d5cda9d4a648525de11ef],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1705033116-2515132334-3789885432-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, , [a10eb6c6c8b3b3838ac1a22c12f08a76],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1705033116-2515132334-3789885432-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, , [d6d9522afc7fa2949bc9eef6f0130000],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1705033116-2515132334-3789885432-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [832ca3d9295213239e63ceefd92932ce],

Registry Values: 2
PUP.Optional.WinRST.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINRST|ImagePath, C:\Program Files (x86)\WinRST\WinRST.exe, , [0ba4c6b6453665d1fdca5f5ec53d6f91]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1705033116-2515132334-3789885432-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0J1L2U1C1H1Q0R2X1L1R1P0B1P, , [d6d9522afc7fa2949bc9eef6f0130000]

Registry Data: 0
(No malicious items detected)

Folders: 4
PUP.Optional.WinRST.A, C:\Program Files (x86)\WinRST, , [139c89f3b2c99e983890c5f8cc36b44c],
PUP.Optional.Gophoto.A, C:\Program Files (x86)\Gophoto.it, , [68477606017a6ec863bae009689be719],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\bitstreams, , [f3bcfc80f289c86e58ab870d54ae6a96],

Files: 66
PUP.Optional.Babylon.A, C:\Windows\System32\Tasks\EPUpdater, , [832c3b4116658babdef5951425dd6997],
PUP.Optional.WinRST.A, C:\Program Files (x86)\WinRST\msvcp100.dll, , [139c89f3b2c99e983890c5f8cc36b44c],
PUP.Optional.WinRST.A, C:\Program Files (x86)\WinRST\msvcr100.dll, , [139c89f3b2c99e983890c5f8cc36b44c],
PUP.Optional.WinRST.A, C:\Program Files (x86)\WinRST\QtCore4.dll, , [139c89f3b2c99e983890c5f8cc36b44c],
PUP.Optional.WinRST.A, C:\Program Files (x86)\WinRST\QtNetwork4.dll, , [139c89f3b2c99e983890c5f8cc36b44c],
PUP.Optional.WinRST.A, C:\Program Files (x86)\WinRST\WinRST.exe, , [139c89f3b2c99e983890c5f8cc36b44c],
PUP.Optional.BuenoSearch.A, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\searchplugins\buenosearch.xml, , [bdf28cf0abd0eb4b85e20db67290db25],
PUP.Optional.BuenoSearch.A, C:\Users\Jirka-PC\AppData\Roaming\BabSolution\Shared\BuenoSearch.ico, , [a50af18b4e2dfc3ac2eb9236e81a30d0],
Malware.Trace, C:\Windows\inf\ntvdm.inf, , [159ae696c3b80a2c2775df0646bdbc44],
PUP.Optional.Gophoto.A, C:\Program Files (x86)\Gophoto.it\gophotoit16.crx, , [68477606017a6ec863bae009689be719],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\diablo130302.cl, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\diakgcn121016.cl, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\libcurl-4.dll, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\libeay32.dll, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\libidn-11.dll, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\librtmp.dll, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\libssh2.dll, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\mncucnft.exe, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\phatk121016.cl, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\poclbm130302.cl, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\scrypt130511.cl, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\ssleay32.dll, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\zlib1.dll, , [f3bcfc80f289c86e58ab870d54ae6a96],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\bitstreams\fpgaminer_top_fixed7_197MHz.ncd, , [f3bcfc80f289c86e58ab870d54ae6a96],
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.admin", false);), ,[67483547087382b4aac72d89ec1804fc]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.aflt", "babsst");), ,[fcb37408710aba7c1a57bff74aba54ac]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");), ,[e1ce0a72d2a9e74f0b66199dcd37f808]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.autoRvrt", "false");), ,[585708742655b086462b1a9ccb3938c8]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.dfltLng", "en");), ,[1c93116b87f445f1e48d872ffc087a86]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.excTlbr", false);), ,[7a35f88444377eb8e78ac1f5976de51b]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.ffxUnstlRst", true);), ,[8e21ee8eeb90aa8c4b264373c53fcc34]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.id", "ec52895c0000000000000015f2a2752a");), ,[b9f62557d6a50432422f50669c68db25]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.instlDay", "16131");), ,[c8e734489fdc87afb0c1f9bd32d2e31d]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.instlRef", "sst");), ,[723d5527106b05313b368036768e8e72]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.newTab", false);), ,[2c833a429be0b97d86eb7541e0241ee2]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.prdct", "buenosearch");), ,[0ba46a12de9df73fef82e4d253b10af6]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.prtnrId", "buenosearch");), ,[d6d98def1764ff379ad7f8bef410ee12]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.rvrt", "false");), ,[624d23599cdf05316809cbeb1ce87d83]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.smplGrp", "none");), ,[c2ed611b8af19c9af27f2591b64e619f]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.tb_url", "http://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=EC520015F2A2752A&affID=128403&tsp=5174");), ,[753afe7e86f5999d2b4602b41aeaf907]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrId", "base");), ,[ecc3dca081fa2e08125f764012f2e11f]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrSrchUrl", "http://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=EC520015F2A2752A&affID=128403&tsp=5174");), ,[307f14682c4f3600d69b03b39d672ed2]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsn", "1.8.28.7");), ,[03ac1f5d86f56bcbcba68036bd4760a0]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsnTs", "1.8.28.712:14:02");), ,[7f303646a0dbf046264beacc44c09d63]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsni", "1.8.28.7");), ,[8c239be1daa16ccafb768135c044b14f]
PUP.Optional.BuenoSearch.A, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrSrchUrl", "http://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=EC520015F2A2752A&affID=128403&tsp=5174");), ,[307f1666bebd56e0e290fbba788c3dc3]
PUP.Optional.BuenoSearch.A, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.tb_url", "http://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=EC520015F2A2752A&affID=128403&tsp=5174");), ,[d7d884f81c5f4fe7e88a664fd1338e72]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.id", "ec52895c0000000000000015f2a2752a");), ,[f6b9641806751a1cb5bbe7cfb3516b95]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");), ,[00af6f0d6f0c33035b157541d2324db3]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.instlDay", "16131");), ,[5857780490ebbb7b115f506645bf21df]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsn", "1.8.28.7");), ,[5c539ede9ae12f077bf53f774fb5b848]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsni", "1.8.28.7");), ,[c3ecef8df88379bd4927892db84c6997]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsnTs", "1.8.28.712:14:02");), ,[1a956b11fa817fb7e789e2d4d72d40c0]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.prtnrId", "buenosearch");), ,[a30cd8a4106b4de9b6badadc57adf40c]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.prdct", "buenosearch");), ,[406f6c10c0bb1d19313f22947292d927]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.aflt", "babsst");), ,[9c13e19be695f046b1bf9026c044b749]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.smplGrp", "none");), ,[a00fdba196e5f145e18f3d79a55f42be]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrId", "base");), ,[57587309e69592a4d19fe1d552b2d12f]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.instlRef", "sst");), ,[d7d85923fe7d0d297af6526459ab738d]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.dfltLng", "en");), ,[d2dd0973de9da69017596e487490639d]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.excTlbr", false);), ,[8c2346361c5f62d476faa610788c629e]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.ffxUnstlRst", true);), ,[9f10fc80abd0e74f115fa90d996be61a]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.admin", false);), ,[f1befb81f7843bfb0e6276407b891fe1]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.autoRvrt", "false");), ,[cbe4dca0f6853afc5a162f878381d42c]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.rvrt", "false");), ,[228d7b01a3d84aeccda3cde954b031cf]
PUP.Optional.BuenoSearch, C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.newTab", false);), ,[258a2557b2c91521502014a2739118e8]

Physical Sectors: 0
(No malicious items detected)


(end)
AMD Ryzen 5 5600X | MSI MAG B550 TOMAHAWK | G.Skill Aegis 32GB 3200MHz | Kingston A2000 1TB | PowerColor Red Devil RX 6700 XT 12GB | XPG Core Reactor 750W | Be quiet! PURE BASE 500 | Asus VG27AQ1A

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - asi vir..

Příspěvekod jaro3 » 25 čer 2014 21:16

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.


. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

flowem
Level 5.5
Level 5.5
Příspěvky: 2858
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - asi vir..

Příspěvekod flowem » 26 čer 2014 19:53

# AdwCleaner v3.213 - Report created 26/06/2014 at 19:45:13
# Updated 23/06/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Jirka-PC - JIRKA
# Running from : C:\Users\Jirka-PC\Desktop\adwcleaner_3.213.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : {0782648b-1717-4fef-ac58-8cb3ce03adb3}Gw64
[#] Service Deleted : PirritDesktop
[#] Service Deleted : PirritUpdater

***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\Gophoto.it
Folder Deleted : C:\Program Files (x86)\Mobogenie
Folder Deleted : C:\Program Files (x86)\SmartTweak
Folder Deleted : C:\Program Files (x86)\WinRST
Folder Deleted : C:\Users\Jirka-PC\AppData\Local\WinRST
Folder Deleted : C:\Users\Jirka-PC\AppData\Roaming\BabSolution
Folder Deleted : C:\Users\Jirka-PC\AppData\Roaming\Pirrit
Folder Deleted : C:\Users\Jirka-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
File Deleted : C:\END
File Deleted : C:\Windows\System32\drivers\{0782648b-1717-4fef-ac58-8cb3ce03adb3}Gw64.sys
File Deleted : C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\invalidprefs.js
File Deleted : C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\searchplugins\buenosearch.xml
File Deleted : C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\user.js
File Deleted : C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
File Deleted : C:\Windows\System32\Tasks\EPUpdater

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Mobogenie.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\smarttweak
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\Pirrit

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16521


-\\ Mozilla Firefox v29.0.1 (cs)

[ File : C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\8wqkjwui.default\prefs.js ]

Line Deleted : user_pref("CT3289075.UserID", "UN28552918532185013");
Line Deleted : user_pref("CT3289075.fullUserID", "UN28552918532185013.IN.20140302122147");
Line Deleted : user_pref("CT3289075.installDate", "02/03/2014 12:21:50");
Line Deleted : user_pref("CT3289075.installSessionId", "{90DF8345-520F-4691-AA43-D77D893797B4}");
Line Deleted : user_pref("CT3289075.installSp", "false");
Line Deleted : user_pref("CT3289075.installerVersion", "1.8.1.4");
Line Deleted : user_pref("CT3289075.searchRevert", "false");
Line Deleted : user_pref("CT3289075.searchUninstallUserMode", "1");
Line Deleted : user_pref("CT3289075.searchUserMode", "1");
Line Deleted : user_pref("CT3289075.toolbarInstallDate", "02-03-2014 12:21:47");
Line Deleted : user_pref("CT3289075.versionFromInstaller", "10.23.0.1000");
Line Deleted : user_pref("CT3289075.xpeMode", "1");
Line Deleted : user_pref("extensions.buenosearch.admin", false);
Line Deleted : user_pref("extensions.buenosearch.aflt", "babsst");
Line Deleted : user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");
Line Deleted : user_pref("extensions.buenosearch.autoRvrt", "false");
Line Deleted : user_pref("extensions.buenosearch.dfltLng", "en");
Line Deleted : user_pref("extensions.buenosearch.excTlbr", false);
Line Deleted : user_pref("extensions.buenosearch.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.buenosearch.id", "ec52895c0000000000000015f2a2752a");
Line Deleted : user_pref("extensions.buenosearch.instlDay", "16131");
Line Deleted : user_pref("extensions.buenosearch.instlRef", "sst");
Line Deleted : user_pref("extensions.buenosearch.newTab", false);
Line Deleted : user_pref("extensions.buenosearch.prdct", "buenosearch");
Line Deleted : user_pref("extensions.buenosearch.prtnrId", "buenosearch");
Line Deleted : user_pref("extensions.buenosearch.rvrt", "false");
Line Deleted : user_pref("extensions.buenosearch.smplGrp", "none");
Line Deleted : user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=EC520015F2A2752A&affID=128403&tsp=5174");
Line Deleted : user_pref("extensions.buenosearch.tlbrId", "base");
Line Deleted : user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=EC520015F2A2752A&affID=128403&tsp=5174");
Line Deleted : user_pref("extensions.buenosearch.vrsn", "1.8.28.7");
Line Deleted : user_pref("extensions.buenosearch.vrsnTs", "1.8.28.712:14:02");
Line Deleted : user_pref("extensions.buenosearch.vrsni", "1.8.28.7");
Line Deleted : user_pref("smartbar.machineId", "63QH+NWLKEV3NJPCB0K4Y+OGA93DKFWI18OIQ2CF6NEPWK2ZFLN5BDTPJTQAQ4L2KBIMO7EAXPTGKPSKGK3UGA");

[ File : C:\Users\Jirka-PC\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js ]


-\\ Google Chrome v35.0.1916.153

[ File : C:\Users\Jirka-PC\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Extension] : pfmopbbadnfoelckkcmjjeaaegjpjjbk

*************************

AdwCleaner[R0].txt - [7310 octets] - [26/06/2014 19:43:33]
AdwCleaner[S0].txt - [7009 octets] - [26/06/2014 19:45:13]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7069 octets] ##########
AMD Ryzen 5 5600X | MSI MAG B550 TOMAHAWK | G.Skill Aegis 32GB 3200MHz | Kingston A2000 1TB | PowerColor Red Devil RX 6700 XT 12GB | XPG Core Reactor 750W | Be quiet! PURE BASE 500 | Asus VG27AQ1A

flowem
Level 5.5
Level 5.5
Příspěvky: 2858
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - asi vir..

Příspěvekod flowem » 26 čer 2014 20:08

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Jirka-PC on źt 26.06.2014 at 19:55:07,60
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Emptied folder: C:\Users\Jirka-PC\AppData\Roaming\mozilla\firefox\profiles\8wqkjwui.default\minidumps [133 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 26.06.2014 at 20:02:22,94
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
AMD Ryzen 5 5600X | MSI MAG B550 TOMAHAWK | G.Skill Aegis 32GB 3200MHz | Kingston A2000 1TB | PowerColor Red Devil RX 6700 XT 12GB | XPG Core Reactor 750W | Be quiet! PURE BASE 500 | Asus VG27AQ1A

flowem
Level 5.5
Level 5.5
Příspěvky: 2858
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - asi vir..

Příspěvekod flowem » 26 čer 2014 20:27

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 26.6.2014
Čas skenování: 20:10:21
Protokol: malware.txt
Správce: Ano

Verze: 2.00.2.1012
Databáze malwaru: v2014.06.25.11
Databáze rootkitů: v2014.06.23.02
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Self-protection: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Jirka-PC

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 275827
Uplynulý čas: 14 min, 46 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristics: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(No malicious items detected)

Moduly: 0
(No malicious items detected)

Klíče registru: 1
PUP.Optional.WinRST.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINRST, Do karantény, [1996e894fa8143f363648538bf438977],

Hodnoty registru: 1
PUP.Optional.WinRST.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINRST|ImagePath, C:\Program Files (x86)\WinRST\WinRST.exe, Do karantény, [1996e894fa8143f363648538bf438977]

Data registru: 0
(No malicious items detected)

Složky: 2
Trojan.Agent.BCM, C:\Windows\inf\mncucnft, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\bitstreams, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],

Soubory: 15
Malware.Trace, C:\Windows\inf\ntvdm.inf, Do karantény, [258a53297209270fc7d5489d18eb31cf],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\diablo130302.cl, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\diakgcn121016.cl, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\libcurl-4.dll, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\libeay32.dll, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\libidn-11.dll, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\librtmp.dll, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\libssh2.dll, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\mncucnft.exe, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\phatk121016.cl, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\poclbm130302.cl, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\scrypt130511.cl, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\ssleay32.dll, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\zlib1.dll, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],
Trojan.Agent.BCM, C:\Windows\inf\mncucnft\bitstreams\fpgaminer_top_fixed7_197MHz.ncd, Do karantény, [4e61b8c4225983b3b84b781c46bce41c],

Fyzické sektory: 0
(No malicious items detected)


(end)
AMD Ryzen 5 5600X | MSI MAG B550 TOMAHAWK | G.Skill Aegis 32GB 3200MHz | Kingston A2000 1TB | PowerColor Red Devil RX 6700 XT 12GB | XPG Core Reactor 750W | Be quiet! PURE BASE 500 | Asus VG27AQ1A

flowem
Level 5.5
Level 5.5
Příspěvky: 2858
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - asi vir..

Příspěvekod flowem » 26 čer 2014 20:39

RogueKiller V9.1.0.0 (x64) [Jun 23 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Jirka-PC [Práva správce]
Mód : Kontrola -- Datum : 06/26/2014 20:37:32

¤¤¤ Škodlivé procesy: : 1 ¤¤¤
[Hidden] -- [x] -> SMAZÁNO [TermThr]

¤¤¤ ¤¤¤ Záznamy Registrů: : 24 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RegFltrX64 -> NALEZENO
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RegFltrX64 -> NALEZENO
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RegFltrX64 -> NALEZENO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2E128D16-231A-46AF-939C-0FDA4E9FD208} | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6DCC73E6-2D2F-4C64-9CE0-CC0442ADBC9D} | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{2E128D16-231A-46AF-939C-0FDA4E9FD208} | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6DCC73E6-2D2F-4C64-9CE0-CC0442ADBC9D} | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{2E128D16-231A-46AF-939C-0FDA4E9FD208} | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{6DCC73E6-2D2F-4C64-9CE0-CC0442ADBC9D} | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-1705033116-2515132334-3789885432-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-1705033116-2515132334-3789885432-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-1705033116-2515132334-3789885432-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-1705033116-2515132334-3789885432-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-1705033116-2515132334-3789885432-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-1705033116-2515132334-3789885432-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-1705033116-2515132334-3789885432-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-1705033116-2515132334-3789885432-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 [Too big!] ¤¤¤

¤¤¤ Antirootkit : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD6400AACS-00G8B1 ATA Device +++++
--- User ---
[MBR] 9f0d4c2f66438e7fdde1b4b583fabf6f
[BSP] 9ec583a0472dcdaed209ad66e464491c : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 610470 MB
User = LL1 ... OK
User = LL2 ... OK
AMD Ryzen 5 5600X | MSI MAG B550 TOMAHAWK | G.Skill Aegis 32GB 3200MHz | Kingston A2000 1TB | PowerColor Red Devil RX 6700 XT 12GB | XPG Core Reactor 750W | Be quiet! PURE BASE 500 | Asus VG27AQ1A

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - asi vir..

Příspěvekod jaro3 » 27 čer 2014 10:05

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "

- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)

- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

flowem
Level 5.5
Level 5.5
Příspěvky: 2858
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - asi vir..

Příspěvekod flowem » 27 čer 2014 15:17

Jenom mám problém s tím RogueKiller... když ho otevřu, počkám na dokončení Prescan, tak nevím, co dělat dále...
Nějak nechápu tu větu "- Počkej, dokud status okno zobrazuje "Prohledat ""
AMD Ryzen 5 5600X | MSI MAG B550 TOMAHAWK | G.Skill Aegis 32GB 3200MHz | Kingston A2000 1TB | PowerColor Red Devil RX 6700 XT 12GB | XPG Core Reactor 750W | Be quiet! PURE BASE 500 | Asus VG27AQ1A


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 98 hostů