Procesy bez popisu ve správci úloh

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

elanor.k.a
nováček
Příspěvky: 4
Registrován: květen 15
Pohlaví: Žena
Stav:
Offline

Procesy bez popisu ve správci úloh

Příspěvekod elanor.k.a » 22 kvě 2015 02:32

Ahoj,

pár dní zpátky se mi po stažení a instalaci jednoho programu změnila domovská stránka v prohlížeči, na ploše se objevilo několik neznámých zástupců (neotevírala jsem) a ve správci úloh nová položka s chybějícím popisem (to se mi dosud nikdy nestalo). Následně stažený Malwarebytes našel a odstranil asi 10 různých malware (všechny pocházející z toho jednoho dne). U prohlížeče jsem obnovila nastavení a položky z plochy smazala, ale počítač je najednou výrazně pomalejší, taky prohlížeč, stránky se mi načítají mnohem pomaleji než dosud a ve správci úloh je najednou úloh bez popisu 5. Nejdou zobrazit jejich vlastnosti ani vytvořit soubor výpisu, přístup byl odepřen. Správce souborů u nich navíc nezobrazuje ani uživatele, ani cestu k nim. Jde o úlohy csrss.exe, winlogon.exe, tpnumlk.exe, rundll32.exe a tpnumlkd.exe. Ukončit jsem je ale nezkoušela. Prosím o radu, zda se jedná o podezřelé procesy, případně jestli je problém někde jinde. Log přikládám a předem mockrát děkuji za ochotu :-)

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 1:16:18, on 22.5.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)

FIREFOX: 25.0.1 (cs)
Boot mode: Normal

Running processes:
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\Program Files\Lenovo Fingerprint Reader\x86\BioMonitor.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Lenovo\message center plus\mcplaunch.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\el\Downloads\HijackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = cache.natur.cuni.cz:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - (no file)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: IEPlugin - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
O4 - HKLM\..\Run: [Dolby Advanced Audio v2] "C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
O4 - HKLM\..\Run: [Fastboot] C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe
O4 - HKLM\..\Run: [Lenovo Registration] C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe /boot
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Device Monitor - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth Media Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
O23 - Service: Bluetooth OBEX Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FastbootService - Lenovo - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: TrueSuiteService (FPLService) - AuthenTec, Inc - C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HyperW7 Service (HyperW7Svc) - Lenovo Group Limited - C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe
O23 - Service: Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VIPAppService - Symantec Corporation - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 15080 bytes

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Procesy bez popisu ve správci úloh

Příspěvekod jaro3 » 22 kvě 2015 10:46

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

elanor.k.a
nováček
Příspěvky: 4
Registrován: květen 15
Pohlaví: Žena
Stav:
Offline

Re: Procesy bez popisu ve správci úloh

Příspěvekod elanor.k.a » 23 kvě 2015 02:29

Používám jen Google Chrome, takže jsem ATF nepoužila.

Log z AdwCleaner:

# AdwCleaner v4.205 - Log vytvořen 23/05/2015 v 01:43:57
# Aktualizováno 21/05/2015 by Xplode
# Databáze : 2015-05-21.2 [Server]
# Operační system : Windows 7 Professional Service Pack 1 (x64)
# Uživatelské jméno : el - NOTEBOOK
# Spuštěno z : C:\Users\el\Desktop\adwcleaner_4.205.exe
# Nastavení : Sken

***** [ Služby ] *****


***** [ Soubory / Složky ] *****

Složka Nalezeno : C:\Program Files (x86)\Amazon\ABB
Složka Nalezeno : C:\Program Files (x86)\Ask.com
Složka Nalezeno : C:\Program Files (x86)\GreenTree Applications
Složka Nalezeno : C:\Program Files (x86)\Smart Driver Updater
Složka Nalezeno : C:\ProgramData\Ask
Složka Nalezeno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Video Converter
Složka Nalezeno : C:\ProgramData\Partner
Složka Nalezeno : C:\Users\el\AppData\Local\pokki
Složka Nalezeno : C:\Users\el\AppData\Roaming\PerformerSoft
Složka Nalezeno : C:\Users\el\AppData\Roaming\Systweak
Složka Nalezeno : C:\Users\el\Documents\PC Speed Maximizer
Složka Nalezeno : C:\Windows\Util
Soubor Nalezeno : C:\Users\el\AppData\Roaming\Mozilla\Firefox\Profiles\wk6j8gor.default\searchplugins\yahoo_ff.xml
Soubor Nalezeno : C:\Windows\System32\roboot64.exe

***** [ Naplánované úlohy ] *****

Úloha Nalezeno : LaunchPreSignup

***** [ Zástupci ] *****

Zástupce Infikováno : C:\Users\Public\Desktop\Google Chrome.lnk
Zástupce Infikováno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Zástupce Infikováno : C:\Users\el\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Zástupce Infikováno : C:\Users\el\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Zástupce Infikováno : C:\Users\el\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Zástupce Infikováno : C:\Users\el\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk

***** [ Registry ] *****

Data Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - cache.natur.cuni.cz:3128
Hodnota Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [DefaultConnectionSettings]
Hodnota Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [SavedLegacySettings]
Klíč Nalezeno : HKCU\Software\Alexa Internet
Klíč Nalezeno : HKCU\Software\Free Video Converter
Klíč Nalezeno : HKCU\Software\Softonic
Klíč Nalezeno : [x64] HKCU\Software\Alexa Internet
Klíč Nalezeno : [x64] HKCU\Software\Free Video Converter
Klíč Nalezeno : [x64] HKCU\Software\Softonic
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Klíč Nalezeno : HKLM\SOFTWARE\Google\Chrome\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90120000-00B2-0405-0000-0000000FF1CE}
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
Klíč Nalezeno : HKLM\SOFTWARE\SupDp
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{0923E315-2D8B-48CE-A37C-AE9A42F9711C}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{1A1BBE49-C6F1-40EA-9D2F-262F0AF6DDE3}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{2022154E-7E3E-4809-871E-1B45A6FC7058}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{292ECB89-350E-45D2-816F-52C15305B144}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{36CC2180-B6BF-4951-9578-6B0C40044AAA}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{44A36944-22C6-4A08-BC7C-161F3E540DBF}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{6247DD2C-8CF9-4041-A235-93691D71B8B4}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{835BED79-DF7E-4096-B355-ED43FA2EA87B}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{8E863BD6-50DE-47D0-A6F1-3C1F6DB72451}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{9DD36F1E-5111-41C5-ADED-A2A11A2FF3E4}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{A2FB8217-E320-434E-BA79-513E357AD54F}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{A9CEBBF4-9129-479A-9231-E833ED3D3A8F}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{AFD4D1F9-167C-4884-95AE-B5A9797B0D16}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{B3EAD50C-ECB0-459A-9EDA-F505AB99675B}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{C47788B1-9604-4D7A-A684-F4D450F2D7D2}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{CA3B41D0-D4C1-4808-B248-75DA27238828}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{D4A2FF6C-087F-4D40-8DFE-92AAD484BFB8}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{D88B9D5C-A9CF-4C69-906D-1CCA5D85A2EF}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{F83AF01C-AA2F-469F-8BE7-D178FB15FD07}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}

***** [ Prohlížeče ] *****

-\\ Internet Explorer v11.0.9600.17801


-\\ Mozilla Firefox v25.0.1 (cs)


-\\ Google Chrome v43.0.2357.65


*************************

AdwCleaner[R0].txt - [5712 bytů] - [20/05/2015 14:49:34]
AdwCleaner[R1].txt - [5158 bytů] - [23/05/2015 01:43:57]
AdwCleaner[S0].txt - [383 bytů] - [20/05/2015 15:03:31]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [5273 bytů] ##########

Původní Malwarebytes jsem odinstalovala a stáhla nový, log:

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 23.5.2015
Čas skenování: 2:01:11
Protokol:
Správce: Ano

Verze: 2.01.6.1022
Databáze malwaru: v2015.05.22.06
Databáze rootkitů: v2015.05.16.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: el

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 354759
Uplynulý čas: 16 min, 4 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Varovat
PUM: Varovat

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 1
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [1d914155711967cfb038254be71ea15f],

Hodnoty registru: 2
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, mystartsearch, , [1d914155711967cfb038254be71ea15f]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, http://www.mystartsearch.com/web/?type= ... 26N2126&q={searchTerms}, , [119d9600b7d3a492a6423d33ec19d62a]

Data registru: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Dobré: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Špatné: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[6846ade95e2ce056e216fe28cd393bc5]

Složky: 0
(Nenalezeny žádné škodlivé položky)

Soubory: 3
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, , [1e90b7dfc0ca9c9ad3569f8405fbe11f],
PUP.Optional.Freemium.A, C:\Users\el\Downloads\TestDisk & PhotoRec 6.11.3 Downloader.exe, , [822c8f073258e74f1736610260a6ef11],
PUP.Optional.Spigot.A, C:\Users\el\AppData\Roaming\Mozilla\Firefox\Profiles\wk6j8gor.default\searchplugins\yahoo_ff.xml, , [36787d196624ee481e52a7468083f50b],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Procesy bez popisu ve správci úloh

Příspěvekod jerabina » 23 kvě 2015 07:05

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

elanor.k.a
nováček
Příspěvky: 4
Registrován: květen 15
Pohlaví: Žena
Stav:
Offline

Re: Procesy bez popisu ve správci úloh

Příspěvekod elanor.k.a » 23 kvě 2015 18:22

Přikládám logy, ve Správci úloh jsou teď už jen dva procesy bez popisu.

Log z AdwCleaner:

# AdwCleaner v4.205 - Log vytvořen 23/05/2015 v 16:32:38
# Aktualizováno 21/05/2015 by Xplode
# Databáze : 2015-05-21.2 [Server]
# Operační system : Windows 7 Professional Service Pack 1 (x64)
# Uživatelské jméno : el - NOTEBOOK
# Spuštěno z : C:\Users\el\Desktop\adwcleaner_4.205.exe
# Nastavení : Čištění

***** [ Služby ] *****


***** [ Soubory / Složky ] *****

Složka Smazáno : C:\ProgramData\Ask
Složka Smazáno : C:\ProgramData\Partner
Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Video Converter
Složka Smazáno : C:\Program Files (x86)\Amazon\ABB
Složka Smazáno : C:\Program Files (x86)\Ask.com
Složka Smazáno : C:\Program Files (x86)\GreenTree Applications
Složka Smazáno : C:\Program Files (x86)\Smart Driver Updater
Složka Smazáno : C:\Windows\Util
Složka Smazáno : C:\Users\el\AppData\Local\pokki
Složka Smazáno : C:\Users\el\AppData\Roaming\PerformerSoft
Složka Smazáno : C:\Users\el\AppData\Roaming\Systweak
Složka Smazáno : C:\Users\el\Documents\PC Speed Maximizer
Soubor Smazáno : C:\Windows\System32\roboot64.exe
Soubor Smazáno : C:\Users\el\AppData\Roaming\Mozilla\Firefox\Profiles\wk6j8gor.default\searchplugins\yahoo_ff.xml

***** [ Naplánované úlohy ] *****

Úloha Smazáno : LaunchPreSignup

***** [ Zástupci ] *****

Zástupce Vyléčeno : C:\Users\Public\Desktop\Google Chrome.lnk
Zástupce Vyléčeno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Zástupce Vyléčeno : C:\Users\el\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Zástupce Vyléčeno : C:\Users\el\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Zástupce Vyléčeno : C:\Users\el\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Zástupce Vyléčeno : C:\Users\el\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk

***** [ Registry ] *****

Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{0923E315-2D8B-48CE-A37C-AE9A42F9711C}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{1A1BBE49-C6F1-40EA-9D2F-262F0AF6DDE3}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{2022154E-7E3E-4809-871E-1B45A6FC7058}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{292ECB89-350E-45D2-816F-52C15305B144}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{36CC2180-B6BF-4951-9578-6B0C40044AAA}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{44A36944-22C6-4A08-BC7C-161F3E540DBF}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{6247DD2C-8CF9-4041-A235-93691D71B8B4}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{835BED79-DF7E-4096-B355-ED43FA2EA87B}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{8E863BD6-50DE-47D0-A6F1-3C1F6DB72451}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{9DD36F1E-5111-41C5-ADED-A2A11A2FF3E4}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{A2FB8217-E320-434E-BA79-513E357AD54F}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{A9CEBBF4-9129-479A-9231-E833ED3D3A8F}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{AFD4D1F9-167C-4884-95AE-B5A9797B0D16}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{B3EAD50C-ECB0-459A-9EDA-F505AB99675B}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{C47788B1-9604-4D7A-A684-F4D450F2D7D2}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{CA3B41D0-D4C1-4808-B248-75DA27238828}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{D4A2FF6C-087F-4D40-8DFE-92AAD484BFB8}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{D88B9D5C-A9CF-4C69-906D-1CCA5D85A2EF}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{F83AF01C-AA2F-469F-8BE7-D178FB15FD07}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Klíč Smazáno : HKCU\Software\Alexa Internet
Klíč Smazáno : HKCU\Software\Free Video Converter
Klíč Smazáno : HKCU\Software\Softonic
Klíč Smazáno : HKLM\SOFTWARE\SupDp
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90120000-00B2-0405-0000-0000000FF1CE}
Data Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - cache.natur.cuni.cz:3128

***** [ Prohlížeče ] *****

-\\ Internet Explorer v11.0.9600.17801


-\\ Mozilla Firefox v25.0.1 (cs)


-\\ Google Chrome v43.0.2357.65


*************************

AdwCleaner[R0].txt - [5712 bytů] - [20/05/2015 14:49:34]
AdwCleaner[R1].txt - [5443 bytů] - [23/05/2015 01:43:57]
AdwCleaner[R2].txt - [5501 bytů] - [23/05/2015 16:29:35]
AdwCleaner[S0].txt - [383 bytů] - [20/05/2015 15:03:31]
AdwCleaner[S1].txt - [4914 bytů] - [23/05/2015 16:32:38]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4972 bytů] ##########


Log z MbAM:

Malwarebytes Anti-Malware
http://www.malwarebytes.org

Datum skenování: 23.5.2015
Čas skenování: 16:43:03
Protokol: Malwarebytes_log.txt
Správce: Ano

Verze: 2.01.6.1022
Databáze malwaru: v2015.05.23.01
Databáze rootkitů: v2015.05.16.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: el

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 354909
Uplynulý čas: 17 min, 46 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Varovat
PUM: Varovat

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 0
(Nenalezeny žádné škodlivé položky)

Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 0
(Nenalezeny žádné škodlivé položky)

Soubory: 0
(Nenalezeny žádné škodlivé položky)

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Log z Jungware:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.7.8 (05.23.2015:2)
OS: Windows 7 Professional x64
Ran by el on so 23.05.2015 at 17:03:57,97
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}



~~~ Files



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\el\appdata\local\{27D71760-D580-4599-BD09-1344279373E3}
Successfully deleted: [Empty Folder] C:\Users\el\appdata\local\{518F6AA2-E93B-4CD7-83F9-FC92C48CC1CF}



~~~ FireFox

Successfully deleted the following from C:\Users\el\AppData\Roaming\mozilla\firefox\profiles\wk6j8gor.default\prefs.js

user_pref(browser.search.defaulturl, hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&);
user_pref(keyword.URL, hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&);
Emptied folder: C:\Users\el\AppData\Roaming\mozilla\firefox\profiles\wk6j8gor.default\minidumps [3 files]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 23.05.2015 at 17:09:30,41
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Zpráva z RogueKiller:

RogueKiller V10.6.5.0 (x64) [May 20 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : el [Práva správce]
Started from : C:\Users\el\Desktop\RogueKiller.exe
Mód : Prohledat -- Datum : 05/23/2015 18:03:45

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 25 ¤¤¤
[PUM.Orphan] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -> Nalezeno
[PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -> Nalezeno
[PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> Nalezeno
[PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853} -> Nalezeno
[PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> Nalezeno
[PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} -> Nalezeno
[PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar | {BFC32E1D-EE75-4A48-BC60-104E11EE2431} : WebTranslator -> Nalezeno
[PUM.Orphan] (X64) HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {2318C2B1-4965-11D4-9B18-009027A5CD4F} : -> Nalezeno
[PUM.Orphan] (X86) HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {2318C2B1-4965-11D4-9B18-009027A5CD4F} : -> Nalezeno
[PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263} | CLSID : {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16} -> Nalezeno
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms} -> Nalezeno
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Bar : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : https://www.seznam.cz/?clid=22668 -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DBD0C758-DF56-43F4-AC3B-942609D13414} | DhcpNameServer : 94.74.192.252 94.74.192.244 [CZECH REPUBLIC (CZ)][CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{DBD0C758-DF56-43F4-AC3B-942609D13414} | DhcpNameServer : 94.74.192.252 94.74.192.244 [CZECH REPUBLIC (CZ)][CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{DBD0C758-DF56-43F4-AC3B-942609D13414} | DhcpNameServer : 94.74.192.252 94.74.192.244 [CZECH REPUBLIC (CZ)][CZECH REPUBLIC (CZ)] -> Nalezeno
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nalezeno
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] wk6j8gor.default : user_pref("browser.startup.homepage", "https://www.seznam.cz/?clid=22668"); -> Nalezeno

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD5000BPKT-08PK4T0 +++++
--- User ---
[MBR] e82d284f773d2e01515146a5cfc6679a
[BSP] 2b463bc5bbad775529967cc9a65af740 : Lenovo MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1500 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 3074048 | Size: 457438 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 939907072 | Size: 18000 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Procesy bez popisu ve správci úloh

Příspěvekod jerabina » 23 kvě 2015 18:29

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni antivir
Stáhni
Zoek.exe

a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

Vlož nový log z HJT + informuj o problémech.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

elanor.k.a
nováček
Příspěvky: 4
Registrován: květen 15
Pohlaví: Žena
Stav:
Offline

Re: Procesy bez popisu ve správci úloh

Příspěvekod elanor.k.a » 26 kvě 2015 18:44

Zpráva z RogueKiller:

RogueKiller V10.7.0.0 (x64) [May 25 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : el [Práva správce]
Started from : C:\Users\el\Desktop\RogueKillerX64.exe
Mód : Smazat -- Datum : 05/26/2015 17:57:29

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 6 ¤¤¤
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Bar : http://search.msn.com/spbasic.htm -> Nahrazeno (http://search.msn.com/spbasic.htm)
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : http://search.msn.com/spbasic.htm -> Nahrazeno (http://search.msn.com/spbasic.htm)
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : http://search.msn.com/spbasic.htm -> Nahrazeno (http://search.msn.com/spbasic.htm)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DBD0C758-DF56-43F4-AC3B-942609D13414} | DhcpNameServer : 94.74.192.252 94.74.192.244 [CZECH REPUBLIC (CZ)][CZECH REPUBLIC (CZ)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{DBD0C758-DF56-43F4-AC3B-942609D13414} | DhcpNameServer : 94.74.192.252 94.74.192.244 [CZECH REPUBLIC (CZ)][CZECH REPUBLIC (CZ)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{DBD0C758-DF56-43F4-AC3B-942609D13414} | DhcpNameServer : 94.74.192.252 94.74.192.244 [CZECH REPUBLIC (CZ)][CZECH REPUBLIC (CZ)] -> Nahrazeno ()

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD5000BPKT-08PK4T0 +++++
--- User ---
[MBR] e82d284f773d2e01515146a5cfc6679a
[BSP] 2b463bc5bbad775529967cc9a65af740 : Lenovo MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1500 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 3074048 | Size: 457438 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 939907072 | Size: 18000 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_SCN_05232015_180345.log - RKreport_SCN_05242015_020535.log - RKreport_DEL_05242015_025411.log - RKreport_DEL_05242015_025420.log
RKreport_DEL_05242015_025455.log - RKreport_DEL_05242015_025538.log - RKreport_DEL_05242015_025546.log - RKreport_DEL_05242015_025550.log
RKreport_DEL_05242015_025555.log - RKreport_DEL_05242015_025559.log - RKreport_DEL_05242015_025604.log - RKreport_DEL_05242015_025611.log
RKreport_DEL_05242015_030141.log - RKreport_DEL_05242015_030146.log - RKreport_DEL_05242015_030157.log - RKreport_DEL_05242015_030200.log
RKreport_DEL_05242015_030304.log - RKreport_SCN_05242015_034939.log - RKreport_DEL_05242015_040306.log - RKreport_DEL_05242015_040319.log
RKreport_DEL_05242015_040330.log - RKreport_DEL_05242015_040334.log - RKreport_SCN_05242015_042924.log - RKreport_SCN_05262015_175453.log


Log ze Zoek:


Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by el on Łt 26.05.2015 at 17:58:59,45.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\el\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

26.5.2015 18:00:32 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Amazon deleted successfully
C:\PROGRA~2\GUM1DBD.tmp deleted successfully
C:\PROGRA~2\McAfee Security Scan deleted successfully
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\Origin Games deleted successfully
C:\PROGRA~2\Seznam.cz deleted successfully
C:\PROGRA~2\Tremulous deleted successfully
C:\PROGRA~2\COMMON~1\Apple deleted successfully
C:\PROGRA~2\COMMON~1\PDF Architect deleted successfully
C:\Program Files\Google deleted successfully
C:\PROGRA~3\Oracle deleted successfully
C:\Users\el\AppData\Roaming\dlg deleted successfully
C:\Users\el\AppData\Roaming\ImperiaOnline deleted successfully
C:\Users\el\AppData\Local\CrashDumps deleted successfully
C:\Users\el\AppData\Local\VeriSign deleted successfully
C:\Users\el\AppData\Local\VirtualStore deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8590886E-EC8C-43C1-A32C-E4C2B0B6395B} deleted successfully
HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8590886E-EC8C-43C1-A32C-E4C2B0B6395B} deleted successfully
HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} deleted successfully
HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{8590886E-EC8C-43C1-A32C-E4C2B0B6395B} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8590886E-EC8C-43C1-A32C-E4C2B0B6395B} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8590886E-EC8C-43C1-A32C-E4C2B0B6395B} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\el\AppData\Roaming\Mozilla\Firefox\Profiles\wk6j8gor.default\prefs.js:
user_pref("browser.startup.homepage", "about:home"about:home);
user_pref("browser.search.defaultengine", "Seznam");
user_pref("browser.search.defaultenginename", "Seznam");
user_pref("browser.search.selectedEngine", "Seznam");
user_pref("browser.search.order.1", "Seznam");

Added to C:\Users\el\AppData\Roaming\Mozilla\Firefox\Profiles\wk6j8gor.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Amazon not found
C:\PROGRA~2\GUM1DBD.tmp not found
C:\PROGRA~2\McAfee Security Scan not found
C:\PROGRA~2\Origin Games not found
C:\PROGRA~2\Seznam.cz not found
C:\PROGRA~2\Tremulous not found
C:\PROGRA~3\Špidla Data Processing, s.r.o not found
C:\PROGRA~2\PDF Password Remover v3.1 deleted
C:\PROGRA~2\Splashtop deleted
C:\LOGFILE.TXT deleted
C:\Users\el\AppData\Roaming\Error.log deleted
C:\Users\el\AppData\Roaming\pcouffin.log deleted
C:\Users\el\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Video Converter.lnk deleted
C:\windows\SysNative\Tasks\avastBCLRestartS-1-5-21-1036634796-3205486453-2887417223-1000 deleted
C:\Users\Public\AlexaNSISPlugin.5060.dll deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\el\AppData\Roaming\Mozilla\Firefox\Profiles\wk6j8gor.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"VIP2X@verisign.com"="C:\Program Files (x86)\Symantec\VIP Access Client" [16.11.2014 14:22]

==== Firefox Extensions ======================

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- TrueSuite Website Logon - %AppDir%\distribution\bundles\websitelogon@truesuite.com

==== Firefox Plugins ======================

Profilepath: C:\Users\el\AppData\Roaming\Mozilla\Firefox\Profiles\wk6j8gor.default
9AE02005247DA91AB1743F5208DBEF76 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll - Shockwave Flash


==== Chromium Look ======================

Google Chrome Version: 43.0.2357.65

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
cdkedefaddcdlpmiafhicjnkbogjiogj - C:\Program Files\Lenovo Fingerprint Reader\x86\tschrome.crx[14.03.2012 07:31]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[25.05.2015 20:57]

AdBlock - el\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Bookmark Manager - el\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gmlllbghnfkpflemihljekbapjopfjik

==== Chromium Startpages ======================

C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences
tocol_str":"quic"}],"network_stats":{"srtt":31759},"supports_spdy":true},"www.google-analytics.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.google.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":52868},"supports_spdy":true},"www.google.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.google.cz:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":80645},"supports_spdy":true},"www.google.cz:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.google.sk:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.googleadservices.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":49636},"supports_spdy":true},"www.googleadservices.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":39236}},"www.googleapis.com:443":{"supports_spdy":true},"www.googletagmanager.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":4740},"supports_spdy":true},"www.googletagmanager.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.googletagservices.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":47376},"supports_spdy":true},"www.googletagservices.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":11643}},"www.gstatic.com:443":{"network_stats":{"srtt":33809},"supports_spdy":true},"www.i-moda.cz:443":{"supports_spdy":true},"www.mall.cz:443":{"supports_spdy":true},"www.researchgate.net:443":{"supports_spdy":true},"www.snapengage.com:443":{"supports_spdy":true},"www.snapengage.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.youtube-nocookie.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":24177},"supports_spdy":true},"www.youtube.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":603940},"supports_spdy":true},"www.youtube.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"yt3.ggpht.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":657733},"supports_spdy":true}},"supports_quic":{"address":"192.168.0.100","used_quic":true},"version":3}},"ntp":{"app_page_names":["Aplikace"]},"partition":{"per_host_zoom_levels":{"2166136261":{"data:text/html,chromewebdata":0.5227586988632231,"www.google.cz":0.5227586988632231,"www.topvip.cz":0.5227586988632231}}},"password_bubble":{"nopes":1},"plugins":{"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"printing":{"print_preview_sticky_settings":{"appState":"{\"version\":2,\"isGcpPromoDismissed\":false,\"selectedDestinationId\":\"Samsung SCX-4300 Series\",\"selectedDestinationOrigin\":\"local\",\"selectedDestinationAccount\":\"\",\"selectedDestinationCapabilities\":{\"printer\":{\"collate\":{},\"color\":{\"option\":[{\"is_default\":true,\"type\":\"STANDARD_COLOR\",\"vendor_id\":\"2\"}]},\"copies\":{},\"dpi\":{\"option\":[{\"horizontal_dpi\":600,\"is_default\":true,\"vertical_dpi\":600},{\"horizontal_dpi\":300,\"vertical_dpi\":300}]},\"media_size\":{\"option\":[{\"custom_display_name\":\"Letter\",\"height_microns\":279400,\"name\":\"NA_LETTER\",\"vendor_id\":\"1\",\"width_microns\":215900},{\"custom_display_name\":\"Legal\",\"height_microns\":355600,\"name\":\"NA_LEGAL\",\"vendor_id\":\"5\",\"width_microns\":215900},{\"custom_display_name\":\"Executive\",\"height_microns\":266700,\"name\":\"NA_EXECUTIVE\",\"vendor_id\":\"7\",\"width_microns\":184100},{\"custom_display_name\":\"A4\",\"height_microns\":296900,\"is_default\":true,\"name\":\"ISO_A4\",\"vendor_id\":\"9\",\"width_microns\":209900},{\"custom_display_name\":\"A5\",\"height_microns\":209900,\"name\":\"ISO_A5\",\"vendor_id\":\"11\",\"width_microns\":147900},{\"custom_display_name\":\"JIS B5\",\"height_microns\":256900,\"name\":\"JIS_B5\",\"vendor_id\":\"13\",\"width_microns\":181900},{\"custom_display_name\":\"US Folio\",\"height_microns\":330200,\"name\":\"JIS_EXEC\",\"vendor_id\":\"14\",\"width_microns\":215900},{\"custom_display_name\":\"Obál.č.10\",\"height_microns\":241300,\"name\":\"NA_NUMBER_10\",\"vendor_id\":\"20\",\"width_microns\":104700},{\"custom_display_name\":\"Obálka DL\",\"height_microns\":219900,\"name\":\"ISO_DL\",\"vendor_id\":\"27\",\"width_microns\":109900},{\"custom_display_name\":\"Obálka C5\",\"height_microns\":228900,\"name\":\"ISO_C5\",\"vendor_id\":\"28\",\"width_microns\":161900},{\"custom_display_name\":\"Obálka C6\",\"height_microns\":162000,\"name\":\"ISO_C6\",\"vendor_id\":\"31\",\"width_microns\":113900},{\"custom_display_name\":\"ISO B5\",\"height_microns\":249900,\"name\":\"ISO_B5\",\"vendor_id\":\"34\",\"width_microns\":175900},{\"custom_display_name\":\"Ob.Monarch\",\"height_microns\":190500,\"name\":\"NA_MONARCH\",\"vendor_id\":\"37\",\"width_microns\":98300},{\"custom_display_name\":\"A6\",\"height_microns\":147900,\"name\":\"ISO_A6\",\"vendor_id\":\"70\",\"width_microns\":104900},{\"custom_display_name\":\"Oficio\",\"height_microns\":342900,\"vendor_id\":\"190\",\"width_microns\":215900},{\"custom_display_name\":\"Vlastní formát\",\"height_microns\":297000,\"name\":\"ISO_A4\",\"vendor_id\":\"256\",\"width_microns\":210000}]},\"page_orientation\":{\"option\":[{\"is_default\":true,\"type\":\"PORTRAIT\"},{\"type\":\"LANDSCAPE\"},{\"type\":\"AUTO\"}]},\"supported_content_type\":[{\"content_type\":\"application/pdf\"}]},\"version\":\"1.0\"},\"selectedDestinationName\":\"Samsung SCX-4300 Series\",\"selectedDestinationExtensionId\":\"\",\"dpi\":{\"horizontal_dpi\":600,\"is_default\":true,\"vertical_dpi\":600},\"mediaSize\":{\"custom_display_name\":\"A4\",\"height_microns\":296900,\"is_default\":true,\"name\":\"ISO_A4\",\"vendor_id\":\"9\",\"width_microns\":209900}}"}},"profile":{"avatar_bubble_tutorial_shown":1,"avatar_index":0,"content_settings":{"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{"https://www.youtube.com:443,https://www.facebook.com:443":{"setting":1},"https://www.youtube.com:443,https://www.youtube.com:443":{"setting":1}},"geolocation":{"http://www.drmax.cz:80,http://www.drmax.cz:80":{"last_used":1432509125.470669,"setting":1}},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{},"plugins":{},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{"https://www.youtube.com:443,https://www.facebook.com:443":{"fullscreen":1},"https://www.youtube.com:443,https://www.youtube.com:443":{"fullscreen":1}},"pref_version":1},"default_content_settings":{},"exit_type":"Normal","exited_cleanly":true,"icon_version":3,"managed_user_id":"","migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"Osoba 1","per_host_zoom_levels":{}},"protection":{"macs":{}},"savefile":{"default_directory":"C:\\Downloads\\Dropbox\\Aktuálně"},"selectfile":{"last_directory":"C:\\Users\\el\\Desktop"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13068547079736870"},"translate_accepted_count":{"en":0,"sk":0},"translate_blocked_languages":[],"translate_denied_count":{"en":1,"sk":1},"translate_last_denied_time":1424183095004.425,"translate_site_blacklist":[],"translate_too_often_denied":true,"translate_whitelists":{},"zerosuggest":{"cachedresults":""}}
onStartup","runtime.onSuspend","storage.onChanged"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13048535946225006","location":5,"manifest":{"background":{"persistent":false,"scripts":["utility.js","cards.js","background.js"]},"description":"Integrates Google Now into Chrome.","icons":{"128":"images/icon128.png","16":"images/icon16.png","48":"images/icon48.png"},"key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkhqJr32OFD/bMXW4Md7jMfd7LbwHXVc6x5bBQG5U+dloofoxrICDR20yur/40mQ8O//0sS1b8srvbab1CRlSrxoNCr9T80NAkfzx0gHyVS+p1Zow+1FzLMu9PiGwwFyN80HIB7GI/dIa0wC9K/2OrrzcHEhVH96DacTtWQqjfDVtZPjT7Xwv23dgoWcpbkRC86jMJot3dmX9xnn0KzoVc9gDOHSIkBLbkkr6Sp3LGXCCM4L0DJgxdFwaLr5WBzgC3y5x0/wwPIwN4PtIaK3BhH6njlksfnKwwIJ9iRT41V4BqbWu4mszO/7VJ3HJyw2DBpIc2grU9ZRRxrV3fRQG4wIDAQAB","manifest_version":2,"name":"Google Now","oauth2":{"auto_approve":true,"scopes":["https://www.googleapis.com/auth/googlenow"]},"optional_permissions":["background"],"permissions":["alarms","identity","metricsPrivate","notifications","pushMessaging","storage","tabs","webstorePrivate","\u003Call_urls>"],"version":"1.2.0.1"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\google_now","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"pbjikboenpfhbbejgkoklgkhjpfogcam":{"ack_external":true,"active_permissions":{"api":["bookmarks","clipboardRead","geolocation","management","notifications","storage","tabs","webRequest","webRequestBlocking"],"explicit_host":["http://*/*","https://*/*"],"manifest_permissions":[],"scriptable_host":["*://*.amazon.ca/*","*://*.amazon.cn/*","*://*.amazon.co.jp/*","*://*.amazon.co.uk/*","*://*.amazon.com/*","*://*.amazon.de/*","*://*.amazon.es/*","*://*.amazon.fr/*","*://*.amazon.it/*"]},"commands":{},"content_settings":[],"creation_flags":9,"disable_reasons":1,"events":[],"external_first_run":true,"from_bookmark":false,"from_webstore":true,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13065792478818937","lastpingday":"13065782402983998","location":3,"manifest":{"background":{"page":"main.html","persistent":true},"browser_action":{"default_icon":"images/asmile_16.png","default_popup":"popup.html","default_title":"Amazon"},"content_scripts":[{"js":["page_messaging.js"],"matches":["*://*.amazon.co.uk/*","*://*.amazon.de/*","*://*.amazon.cn/*","*://*.amazon.it/*","*://*.amazon.com/*","*://*.amazon.es/*","*://*.amazon.co.jp/*","*://*.amazon.ca/*","*://*.amazon.fr/*","*://*.amazon.com/*"],"run_at":"document_start"}],"current_locale":"cs","default_locale":"en","description":"This is an official Amazon extension for Chrome","icons":{"128":"images/asmile_128.png","16":"images/asmile_16.png","48":"images/asmile_48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDKG0WaGRpHAruDLb/KOzlSPd2R4/6Ll6DRZ/EPR93yIRiExTUZJaUg4jmBNs7jXP2FPjgXm4STlz3WYInHttYuCdEGDB1ky+w5B5S+a8kVFkSJBZ3AJR0WQWqbUFKt0WlLdITEjUlbB5iI9PGbuyjqvlyYB+sn8F15wfevfPD4tQIDAQAB","manifest_version":2,"name":"Amazon 1Button App for Chrome","permissions":["tabs","storage","http://*/*","https://*/*","notifications","tabs","bookmarks","management","clipboardRead","geolocation","webRequest","webRequestBlocking"],"update_url":"https://clients2.google.com/service/update2/crx","version":"4.2015.106.0","web_accessible_resources":["page_messaging.js"]},"path":"pbjikboenpfhbbejgkoklgkhjpfogcam\\4.2015.106.0_0","preferences":{},"regular_only_preferences":{},"state":2,"was_installed_by_default":false,"was_installed_by_oem":false}}},"pinned_tabs":[],"protection":{"macs":{"browser":{"show_home_button":"C60F95ED5797FEBBEB95F27D93EC2DA9A17CECFA55EBBA14BC8698D673D773D8"},"default_search_provider":{"keyword":"5EB862F3DA0612BC01B2A48040161205677B9A6E51B595B4EBB9D5A8168A5088","name":"090B35FE425742C38A0180994BB92944CAADBE63C9677B01229AC06FA0D2E02C","search_url":"4DCC9F463C2FE5E40EF2A02C05F6E9AD3B5E0CF266EAF56E1B4B154F5B5D3A1C"},"default_search_provider_data":{"template_url_data":"37AD170E5A233A2DEA640D7524CC3507389F825654A7833D0B7759FC5EFAC80D"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":"021036B7340E40173D1FCC42FEB4325E39E9FE7D4727C33E694FC9168B5E8F95","bepbmhgboaologfdajaanbcjmnhjmhfn":"4DED38F778CC5FA2D1DCDDDFC143C2B734FAE6BBA6940BE47443C1205D0707BC","cdkedefaddcdlpmiafhicjnkbogjiogj":"15778B31A94A1193A0BD883A02087C5EB8CD89BBD12914945494B14F58845288","eemcgdkfndhakfknompkggombfjjjeno":"3D56E7FD37E856315888E394F66B5259B7DB19CAEF84E39152E879B3CF6997D9","ennkphjdgehloodpbhlhldgbnhmacadg":"DF4805034F65C0450AAE6B4C6B0019367F59C584783490F16FB800B9C084F7B1","gfdkimpbcpahaombhbimeihdjnejgicl":"62301DFC385708352D220131D235B8994C8CAD9B3F5280DFF6C0B21E88CAC291","gighmmpiobklfepjocnamgkkbiglidom":"3C7D01BA85B18A4BD16363FA95A1CEACD0BD87EEEAD37E9070B8E9887E554D68","gmlllbghnfkpflemihljekbapjopfjik":"1AF8E9545D49BAF92710D4F7FC9CACAD2FC20B1D2CFC1D93D4DF76E8E00BB576","gomekmidlodglbbmalcneegieacbdmki":"E37219C9AFC25E2F6D2AE9890F6588D4179A294A78D58932C4D07107360503CE","kmendfapggjehodndflmmgagdbamhnfd":"88199001C6F36AEFE32CE75987F27819D3B96740D9D17E3C88D6E47160302422","lifbcibllhkdhoafpjfnlhfpfgnpldfl":"D9669A48F11633B460EC3E6A449A134EAD7CA3FCF25ED250A8FB818ECB700AF3","mfehgcgbbipciphmccgaenjidiccnmng":"1482F6BA89E97936CA6FAD41DC8A2E06DFB2EF81139B0216ACB9806964DA31ED","mgndgikekgjfcpckkfioiadnlibdjbkf":"CE5828CC9B61E59A61CF5696BA5941477E4958F7665ACF6E1E9C11A5D7E8B6AF","mhjfbmdgcfjbbpaeojofohoefgiehjai":"2276B723FC47DB71F865265E0E33FB7C931A2B1616F592E7AD0AAB06C0E5D4F1","neajdppkdcdipfabeoofebfddakdcjhd":"5D5F89F9F64133C365D69A33F0AC6B3959F91B7CBED07FE1E4572AF451F807E4","nkeimhogjdpnpccoofpliimaahmaaome":"088B2F85BF323349E1CBFDB99FA1EFC92DFDCC3D43282ECD0B14F33425E27F2C","nmmhkkegccagdldgiimedpiccmgmieda":"8C7ED3387389BAB9439B3C45DD2D3024AE9D550A0DB33A0DE5FEFCEC995106AC","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"B2F8D11691A9B2FF7309357D6557CB30AB000C44FE16762AEC7054EBD76F15C5","pbjikboenpfhbbejgkoklgkhjpfogcam":"946540F368EE346F6EAE5E93F6957AF8F8D943911ADDDECB59D49D76CE14FAA3"}},"google":{"services":{"last_username":"24BB508312284BD74DC0BD921CF2FC93B48BD11E661671CD30A20B5DF810F505","username":"0F42E4F9E9318B49C5B380226BCA491F18B55468828FBAA84037D9880F3AEABD"}},"homepage":"104721C8EDFC6E6324C4BEB0305F5E40B24221F5C0F8ABDACF4310318A277400","homepage_is_newtabpage":"2798F1E027864AC3C8BFFB11E9CA6F4ECCE26A2CEF06D177D46175B46273397F","pinned_tabs":"C330851EF8C4B5863978BD14250EE9FB376F364C16B5DFFBA65B01591CD4B450","prefs":{"preference_reset_time":"00916744E3C9101418E068D82DE19D57507B0DD3451297F3E9355016EC2176D8"},"profile":{"reset_prompt_memento":"683B67C143BEB05CF75465A8BBDF818455EB651175B12C437A94A635D3E7E5B1"},"safebrowsing":{"incidents_sent":"76B8B147C30FD69B06219072F6D1A64469484D2DD992D083FA800E523C338DCE"},"search_provider_overrides":"8996B8E63921B38EF88C3A2093058628BF54409096F2B557927F7E7BB7C4071B","session":{"restore_on_startup":"80431D98171931FA2379FD6F3FA207DAF9DD8E2E67DE3454361E5A2EB715141B","startup_urls":"3A5874EA9D6913DC3A11DAAA8F6A38DD8C3BA96D49F04EB44BA1ECF1BEA0A14C"},"software_reporter":{"prompt_reason":"5A75817B5C490B4FA005679F28880681764D23B1BC6613BF9D54A71D1B59C261","prompt_seed":"E03855839672CB153AF42F37D1F2DC60C8F9F924DD544A5A4BF2E42AC0663475","prompt_version":"2D38455D527B9FE2D0730ADB1BB0B582012C4DADD604E6B7E88BFD6FE57A27AA"},"sync":{"remaining_rollback_tries":"4B3D0ABC0645F05ADC7C59F31602D40AD43F8C04E4F511A786895B49176D77DC"}},"super_mac":"B1C83C113B628C21142523B1E264F4E2D05E424779DE1D9378ECC29E86E293A6"},"session":{"restore_on_startup":4,"startup_urls":["https://www.google.com/"]},"sync":{"remaining_rollback_tries":0}}


==== Chromium Fix ======================

C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gmlllbghnfkpflemihljekbapjopfjik deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-devtools_devtools_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_eemcgdkfndhakfknompkggombfjjjeno_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_gighmmpiobklfepjocnamgkkbiglidom_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_gighmmpiobklfepjocnamgkkbiglidom_0.localstorage-journal deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_pafkbggdmjlpgkdkcbjmhmfcdpncadgh_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_email.seznam.cz_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_email.seznam.cz_0.localstorage-journal deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_login.szn.cz_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_login.szn.cz_0.localstorage-journal deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_ls.hit.gemius.pl_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_ls.hit.gemius.pl_0.localstorage-journal deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_plus.google.com_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_plus.google.com_0.localstorage-journal deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_www.facebook.com_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_www.facebook.com_0.localstorage-journal deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_www.google.com_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_www.google.cz_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_www.google.cz_0.localstorage-journal deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_www.seznam.cz_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_www.seznam.cz_0.localstorage-journal deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_ls.hit.gemius.pl_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_ls.hit.gemius.pl_0.localstorage-journal deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_www.novinky.cz_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_www.novinky.cz_0.localstorage-journal deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_www.super.cz_0.localstorage deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_www.super.cz_0.localstorage-journal deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\databases\https_www.google.com_0 deleted successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Local Extension Settings\pafkbggdmjlpgkdkcbjmhmfcdpncadgh deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Old Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Old Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{33BB0A4E-99AF-4226-BDF6-49120163DE86} Unknown Url="Not_Found"
{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} Google Url="https://www.google.com/search?trackid=sp-006&q={searchTerms}"

==== Reset Google Chrome ======================

C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences.bad was reset successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Secure Preferences was reset successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data-journal was reset successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1036634796-3205486453-2887417223-1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Badoo Desktop deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadwin PrintScreen Pro (64-bit) deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intel AppUp(R) center deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSpeedUp deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StudentDOG deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\el\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\el\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=420 folders=218 21878577 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\el\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\el\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on Łt 26.05.2015 at 18:25:39,23 ======================



Při mazání v RogueKilleru jsem měla problém se smazáním výsledků v záložce AntiRootkit - k položkám nešla dát zatržítka. U všech těchto položek je info "The item is clean. Only shown for information.", ale zobrazují se znovu při každém spuštění programu.
Dále jak jsem psala minule, že po použití AdwCleaneru zmizely ze Správce úloh některé procesy bez popisu a zůstaly už jen dvě, po restartu se objevily znovu všechny a jedna dokonce přibyla - rundll.32.exe se někdy objevuje dvakrát a stejně jako ostatní nelze vypnout. V současné chvíli jsou tam stále a všechny problémy přetrvávají.

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Procesy bez popisu ve správci úloh

Příspěvekod jerabina » 26 kvě 2015 18:49

Udělej prosím znovu AdwCleaner, všechny nalezené položky můžeš hned smazat. Log sem vlož.

Udělej prosím znovu sken MBAM, nálezy smaž. Log sem vlož.

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 121 hostů