Zalagovany notebook, sekajúce hry. Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Krantz
Level 3
Level 3
Příspěvky: 626
Registrován: duben 15
Pohlaví: Muž
Stav:
Offline

Re: Zalagovany notebook, sekajúce hry.

Příspěvekod Krantz » 27 čer 2015 21:27

ADW:
# AdwCleaner v4.207 - Log vytvorený 27/06/2015 at 21:26:00
# Aktualizované 21/06/2015 by Xplode
# Databáza : 2015-06-23.1 [Server]
# Operačný systém : Windows 8.1 (x64)
# Uživateľské meno : nayAS - NAY
# Spustené z : C:\Users\nayAS\Downloads\AdwCleaner.exe
# Nastavenia : Skenovať

***** [ Služby ] *****


***** [ Súbory / Priečinky ] *****

Priečinok Nájdené : C:\Program Files (x86)\globalUpdate
Priečinok Nájdené : C:\Program Files (x86)\GreenTree Applications
Priečinok Nájdené : C:\Program Files (x86)\SealePPlus
Priečinok Nájdené : C:\ProgramData\{8626da00-acd8-abd2-8626-6da00acd6802}
Priečinok Nájdené : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader
Priečinok Nájdené : C:\ProgramData\mjdbadfngamkhcekeckbjofkchoakmlm
Priečinok Nájdené : C:\ProgramData\mjdbadfngamkhcekeckbjofkchoakmlm
Priečinok Nájdené : C:\ProgramData\ytd video downloader
Priečinok Nájdené : C:\Users\nayAS\AppData\Local\globalUpdate
Priečinok Nájdené : C:\Users\nayAS\AppData\LocalLow\Conduit
Priečinok Nájdené : C:\Users\nayAS\AppData\Roaming\Mozilla\Firefox\Profiles\2f09ydko.default\Extensions\ZDJ@Vw9xYt.net
Súbor Nájdené : C:\Users\Public\Desktop\YTD Video Downloader.lnk

***** [ Naplánované úlohy ] *****


***** [ Zástupcovia ] *****

Zástupca Nájdená infekcia : C:\Users\nayAS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Zástupca Nájdená infekcia : C:\Users\nayAS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

***** [ Registre ] *****

Kľúč registra Nájdené : HKCU\Software\Classes\pokki
Kľúč registra Nájdené : HKCU\Software\GlobalUpdate
Kľúč registra Nájdené : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Kľúč registra Nájdené : HKCU\Software\powerpack
Kľúč registra Nájdené : HKCU\Software\SafetyNut
Kľúč registra Nájdené : [x64] HKCU\Software\GlobalUpdate
Kľúč registra Nájdené : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Kľúč registra Nájdené : [x64] HKCU\Software\powerpack
Kľúč registra Nájdené : [x64] HKCU\Software\SafetyNut
Kľúč registra Nájdené : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Kľúč registra Nájdené : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Kľúč registra Nájdené : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Kľúč registra Nájdené : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Kľúč registra Nájdené : HKLM\SOFTWARE\GlobalUpdate
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Kľúč registra Nájdené : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}
Kľúč registra Nájdené : [x64] HKLM\SOFTWARE\Classes\CLSID\{A75BE48D-BF58-4A8B-B96C-F9A09DFB9844}
Kľúč registra Nájdené : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Kľúč registra Nájdené : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}

***** [ Webové prehliadače ] *****

-\\ Internet Explorer v11.0.9600.17840


-\\ Mozilla Firefox v34.0.5 (x86 sk)


-\\ Google Chrome v43.0.2357.130

[C:\Users\nayAS\AppData\Local\Google\Chrome\User Data\Default\Web data] - Nájdené [Search Provider] : hxxp://dts.search.ask.com/sr?src=ieb&gc ... nrs=AG1&q={searchTerms}
[C:\Users\nayAS\AppData\Local\Google\Chrome\User Data\Default\Web data] - Nájdené [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&c ... 8895778&q={searchTerms}&SSPV=

-\\ Opera v30.0.1835.88


*************************

AdwCleaner[R0].txt - [7129 bajtov] - [27/06/2015 21:23:40]
AdwCleaner[R1].txt - [7021 bajtov] - [27/06/2015 21:26:00]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [7081 bajtov] ##########

Reklama
Krantz
Level 3
Level 3
Příspěvky: 626
Registrován: duben 15
Pohlaví: Muž
Stav:
Offline

Re: Zalagovany notebook, sekajúce hry.

Příspěvekod Krantz » 27 čer 2015 21:29

TFC - DONE idem reštartovať PC.

Krantz
Level 3
Level 3
Příspěvky: 626
Registrován: duben 15
Pohlaví: Muž
Stav:
Offline

Re: Zalagovany notebook, sekajúce hry.

Příspěvekod Krantz » 27 čer 2015 21:32

TFC - DONE PC REŠTARTOVANÝ

Krantz
Level 3
Level 3
Příspěvky: 626
Registrován: duben 15
Pohlaví: Muž
Stav:
Offline

Re: Zalagovany notebook, sekajúce hry.

Příspěvekod Krantz » 27 čer 2015 21:35

CRYSTAL DISK:
----------------------------------------------------------------------------
CrystalDiskInfo 6.5.2 (C) 2008-2015 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 8.1 [6.3 Build 9600] (x64)
Date : 2015/06/27 21:35:15

-- Controller Map ----------------------------------------------------------
+ Intel(R) 7 Series Chipset Family SATA AHCI Controller [ATA]
- WDC WD7500BPVT-22HXZT3
- MATSHITA DVD-RAM UJ8E1
- Microsoft Storage Spaces Controller [SCSI]

-- Disk List ---------------------------------------------------------------
(1) WDC WD7500BPVT-22HXZT3 : 750,1 GB [0/0/0, pd1] - wd

----------------------------------------------------------------------------
(1) WDC WD7500BPVT-22HXZT3
----------------------------------------------------------------------------
Model : WDC WD7500BPVT-22HXZT3
Firmware : 01.01A01
Serial Number : WD-WXS1E32SSZKV
Disk Size : 750,1 GB (8,4/137,4/750,1/750,1)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 1465149168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : ---- | SATA/300
Power On Hours : 6702 hours
Power On Count : 1693 count
Temperature : 39 C (102 F)
Health Status : Good
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 00FEh [ON]
AAM Level : ----

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Read Error Rate
03 176 172 _21 00000000087F Spin-Up Time
04 _95 _95 __0 000000001510 Start/Stop Count
05 200 200 140 000000000000 Reallocated Sectors Count
07 200 200 __0 000000000000 Seek Error Rate
09 _91 _91 __0 000000001A2E Power-On Hours
0A 100 100 __0 000000000000 Spin Retry Count
0B 100 100 __0 000000000000 Recalibration Retries
0C _99 _99 __0 00000000069D Power Cycle Count
BF __1 __1 __0 000000001443 G-Sense Error Rate
C0 200 200 __0 00000000002B Power-off Retract Count
C1 181 181 __0 00000000E8AA Load/Unload Cycle Count
C2 108 102 __0 000000000027 Temperature
C4 200 200 __0 000000000000 Reallocation Event Count
C5 200 200 __0 000000000000 Current Pending Sector Count
C6 100 253 __0 000000000000 Uncorrectable Sector Count
C7 200 200 __0 000000000000 UltraDMA CRC Error Count
C8 100 253 __0 000000000000 Write Error Rate

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5758 5331 4533 3253 535A 4B56
020: 0000 4000 0032 3031 2E30 3141 3031 5744 4320 5744
030: 3735 3030 4250 5654 2D32 3248 585A 5433 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0100
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 1D06 0000 004C 0048
080: 01FE 0000 746B 7D09 6123 7469 BC09 6123 407F 0051
090: 0051 00FE FFFE 0000 0000 0000 0000 0000 0000 0000
100: 66F0 5754 0000 0000 0000 0000 6003 0000 5001 4EE2
110: B1F5 7170 0000 0000 0000 0000 0000 0000 0000 4018
120: 4018 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 16FE 012D 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 7035 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 101E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 88A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 B0 AC 7F 08 00 00 00 00 00 04 32 00 5F 5F 10
020: 15 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2E 00 C8 C8 00 00 00 00 00 00 00 09 32
040: 00 5B 5B 2E 1A 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 63 63 9D 06 00 00 00 00 00 BF 32
070: 00 01 01 43 14 00 00 00 00 00 C0 32 00 C8 C8 2B
080: 00 00 00 00 00 00 C1 32 00 B5 B5 AA E8 00 00 00
090: 00 00 C2 22 00 6C 66 27 00 00 00 00 00 00 C4 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C5 32 00 C8 C8 00
0B0: 00 00 00 00 00 00 C6 30 00 64 FD 00 00 00 00 00
0C0: 00 00 C7 32 00 C8 C8 00 00 00 00 00 00 00 C8 08
0D0: 00 64 FD 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 1C 3E 01 7B
170: 03 00 01 00 02 9C 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 04 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 31

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 C8 C8 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 00 C8 C8 C8 C8 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 BF 00
070: 00 00 00 00 00 00 00 00 00 00 C0 00 00 00 00 00
080: 00 00 00 00 00 00 C1 00 00 00 00 00 00 00 00 00
090: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C4 00
0A0: 00 00 00 00 00 00 00 00 00 00 C5 00 00 00 00 00
0B0: 00 00 00 00 00 00 C6 00 00 00 00 00 00 00 00 00
0C0: 00 00 C7 00 00 00 00 00 00 00 00 00 00 00 C8 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 BE

Krantz
Level 3
Level 3
Příspěvky: 626
Registrován: duben 15
Pohlaví: Muž
Stav:
Offline

Re: Zalagovany notebook, sekajúce hry.

Příspěvekod Krantz » 27 čer 2015 21:42

Mám dve USB a ani jedno nie je funkčné. Zajtra zbehnem kúpiť jedno. Já len dúfam, že sa mi nestane to isté, že niečo nabootujem a potom sa to USB tak pokazí že z 16GB malo len 600MB maximum pamäti ako si mi to stalo keď som sa pokúšal vymazávať heslo z jedného PC malo 8GB pri nabootovani išlo všetko ale keď som to chcel vymazať z USB tak už to USB pri FAT32 formatovaní malo už len 300MB.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Zalagovany notebook, sekajúce hry.

Příspěvekod jaro3 » 27 čer 2015 22:28

To je divný , a formát ntfs si dělal?

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

A Malwarebytes' Anti-Malware je kde?

00000000087F Spin-Up Time
zítra udělej CDI znovu , jestli se rychle nebude údaJ měnit.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Krantz
Level 3
Level 3
Příspěvky: 626
Registrován: duben 15
Pohlaví: Muž
Stav:
Offline

Re: Zalagovany notebook, sekajúce hry.

Příspěvekod Krantz » 28 čer 2015 09:48

# AdwCleaner v4.207 - Log vytvorený 28/06/2015 at 09:43:30
# Aktualizované 21/06/2015 by Xplode
# Databáza : 2015-06-23.1 [Server]
# Operačný systém : Windows 8.1 (x64)
# Uživateľské meno : nayAS - NAY
# Spustené z : C:\Users\nayAS\Downloads\AdwCleaner.exe
# Nastavenia : Čistenie

***** [ Služby ] *****


***** [ Súbory / Priečinky ] *****

Priečinok Zmazané : C:\ProgramData\ytd video downloader
Priečinok Zmazané : C:\ProgramData\{8626da00-acd8-abd2-8626-6da00acd6802}
Priečinok Zmazané : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader
Priečinok Zmazané : C:\Program Files (x86)\globalUpdate
Priečinok Zmazané : C:\Program Files (x86)\GreenTree Applications
Priečinok Zmazané : C:\Program Files (x86)\SealePPlus
Priečinok Zmazané : C:\Users\nayAS\AppData\Local\globalUpdate
Priečinok Zmazané : C:\Users\nayAS\AppData\LocalLow\Conduit
Priečinok Zmazané : C:\Users\nayAS\AppData\Roaming\OpenCandy
Priečinok Zmazané : C:\Users\nayAS\AppData\Roaming\Mozilla\Firefox\Profiles\2f09ydko.default\Extensions\ZDJ@Vw9xYt.net
Priečinok Zmazané : C:\ProgramData\mjdbadfngamkhcekeckbjofkchoakmlm
Súbor Zmazané : C:\Users\Public\Desktop\YTD Video Downloader.lnk

***** [ Naplánované úlohy ] *****


***** [ Zástupcovia ] *****

Zástupca Dezinfikované : C:\Users\nayAS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Zástupca Dezinfikované : C:\Users\nayAS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

***** [ Registre ] *****

Kľúč registra Zmazané : HKCU\Software\Classes\pokki
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\CLSID\{A75BE48D-BF58-4A8B-B96C-F9A09DFB9844}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Kľúč registra Zmazané : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Kľúč registra Zmazané : HKCU\Software\GlobalUpdate
Kľúč registra Zmazané : HKCU\Software\powerpack
Kľúč registra Zmazané : HKCU\Software\SafetyNut
Kľúč registra Zmazané : HKLM\SOFTWARE\GlobalUpdate
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe

***** [ Webové prehliadače ] *****

-\\ Internet Explorer v11.0.9600.17840


-\\ Mozilla Firefox v34.0.5 (x86 sk)


-\\ Google Chrome v43.0.2357.130


-\\ Opera v30.0.1835.88


*************************

AdwCleaner[R0].txt - [7129 bajtov] - [27/06/2015 21:23:40]
AdwCleaner[R1].txt - [7189 bajtov] - [27/06/2015 21:26:00]
AdwCleaner[R2].txt - [6734 bajtov] - [28/06/2015 09:41:24]
AdwCleaner[S0].txt - [5793 bajtov] - [28/06/2015 09:43:30]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5853 bajtov] ##########

Krantz
Level 3
Level 3
Příspěvky: 626
Registrován: duben 15
Pohlaví: Muž
Stav:
Offline

Re: Zalagovany notebook, sekajúce hry.

Příspěvekod Krantz » 28 čer 2015 09:49

----------------------------------------------------------------------------
CrystalDiskInfo 6.5.2 (C) 2008-2015 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 8.1 [6.3 Build 9600] (x64)
Date : 2015/06/28 9:49:15

-- Controller Map ----------------------------------------------------------
+ Intel(R) 7 Series Chipset Family SATA AHCI Controller [ATA]
- WDC WD7500BPVT-22HXZT3
- MATSHITA DVD-RAM UJ8E1
- Microsoft Storage Spaces Controller [SCSI]

-- Disk List ---------------------------------------------------------------
(1) WDC WD7500BPVT-22HXZT3 : 750,1 GB [0/0/0, pd1] - wd

----------------------------------------------------------------------------
(1) WDC WD7500BPVT-22HXZT3
----------------------------------------------------------------------------
Model : WDC WD7500BPVT-22HXZT3
Firmware : 01.01A01
Serial Number : WD-WXS1E32SSZKV
Disk Size : 750,1 GB (8,4/137,4/750,1/750,1)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 1465149168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : ---- | SATA/300
Power On Hours : 6703 hours
Power On Count : 1695 count
Temperature : 32 C (89 F)
Health Status : Good
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 00FEh [ON]
AAM Level : ----

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Read Error Rate
03 176 172 _21 00000000088F Spin-Up Time
04 _95 _95 __0 000000001512 Start/Stop Count
05 200 200 140 000000000000 Reallocated Sectors Count
07 200 200 __0 000000000000 Seek Error Rate
09 _91 _91 __0 000000001A2F Power-On Hours
0A 100 100 __0 000000000000 Spin Retry Count
0B 100 100 __0 000000000000 Recalibration Retries
0C _99 _99 __0 00000000069F Power Cycle Count
BF __1 __1 __0 000000001445 G-Sense Error Rate
C0 200 200 __0 00000000002C Power-off Retract Count
C1 181 181 __0 00000000E8B3 Load/Unload Cycle Count
C2 115 102 __0 000000000020 Temperature
C4 200 200 __0 000000000000 Reallocation Event Count
C5 200 200 __0 000000000000 Current Pending Sector Count
C6 100 253 __0 000000000000 Uncorrectable Sector Count
C7 200 200 __0 000000000000 UltraDMA CRC Error Count
C8 100 253 __0 000000000000 Write Error Rate

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5758 5331 4533 3253 535A 4B56
020: 0000 4000 0032 3031 2E30 3141 3031 5744 4320 5744
030: 3735 3030 4250 5654 2D32 3248 585A 5433 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0100
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 1D06 0000 004C 0048
080: 01FE 0000 746B 7D09 6123 7469 BC09 6123 407F 0051
090: 0051 00FE FFFE 0000 0000 0000 0000 0000 0000 0000
100: 66F0 5754 0000 0000 0000 0000 6003 0000 5001 4EE2
110: B1F5 7170 0000 0000 0000 0000 0000 0000 0000 4018
120: 4018 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 16FE 012D 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 7035 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 101E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 88A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 B0 AC 8F 08 00 00 00 00 00 04 32 00 5F 5F 12
020: 15 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2E 00 C8 C8 00 00 00 00 00 00 00 09 32
040: 00 5B 5B 2F 1A 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 63 63 9F 06 00 00 00 00 00 BF 32
070: 00 01 01 45 14 00 00 00 00 00 C0 32 00 C8 C8 2C
080: 00 00 00 00 00 00 C1 32 00 B5 B5 B3 E8 00 00 00
090: 00 00 C2 22 00 73 66 20 00 00 00 00 00 00 C4 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C5 32 00 C8 C8 00
0B0: 00 00 00 00 00 00 C6 30 00 64 FD 00 00 00 00 00
0C0: 00 00 C7 32 00 C8 C8 00 00 00 00 00 00 00 C8 08
0D0: 00 64 FD 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 1C 3E 01 7B
170: 03 00 01 00 02 9C 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 04 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 C8 C8 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 00 C8 C8 C8 C8 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 BF 00
070: 00 00 00 00 00 00 00 00 00 00 C0 00 00 00 00 00
080: 00 00 00 00 00 00 C1 00 00 00 00 00 00 00 00 00
090: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C4 00
0A0: 00 00 00 00 00 00 00 00 00 00 C5 00 00 00 00 00
0B0: 00 00 00 00 00 00 C6 00 00 00 00 00 00 00 00 00
0C0: 00 00 C7 00 00 00 00 00 00 00 00 00 00 00 C8 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 BE

Krantz
Level 3
Level 3
Příspěvky: 626
Registrován: duben 15
Pohlaví: Muž
Stav:
Offline

Re: Zalagovany notebook, sekajúce hry.

Příspěvekod Krantz » 28 čer 2015 09:53

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.1.9 (06.27.2015:2)
OS: Windows 8.1 x64
Ran by nayAS on ne 28.06.2015 at 9:49:50,27
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks

Successfully deleted: [Task] C:\WINDOWS\system32\tasks\DriverNavigator Scheduled Scan
Successfully deleted: [Task] C:\WINDOWS\tasks\DriverNavigator Scheduled Scan.job



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] C:\ProgramData\16031407206566633442



~~~ FireFox




~~~ Chrome


[C:\Users\nayAS\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\nayAS\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\nayAS\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\nayAS\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 28.06.2015 at 9:53:05,68
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Krantz
Level 3
Level 3
Příspěvky: 626
Registrován: duben 15
Pohlaví: Muž
Stav:
Offline

Re: Zalagovany notebook, sekajúce hry.

Příspěvekod Krantz » 28 čer 2015 09:59

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.1.9 (06.27.2015:2)
OS: Windows 8.1 x64
Ran by nayAS on ne 28.06.2015 at 9:55:57,61
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox




~~~ Chrome


[C:\Users\nayAS\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\nayAS\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\nayAS\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\nayAS\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 28.06.2015 at 9:58:39,96
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

VYPNUTY ANTI-VIRUS

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Zalagovany notebook, sekajúce hry.

Příspěvekod jerabina » 28 čer 2015 10:52

Co MBAM?
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Krantz
Level 3
Level 3
Příspěvky: 626
Registrován: duben 15
Pohlaví: Muž
Stav:
Offline

Re: Zalagovany notebook, sekajúce hry.

Příspěvekod Krantz » 28 čer 2015 11:06

Malwarebytes je ukonceny.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 30 hostů