Prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Prosím o kontrolu logu

Příspěvekod akiller » 22 črc 2015 19:42

Dobrý večer, prosím o kontrolu logu HJT, připadá mi, že se PC zpomaluje :inlove: :inlove:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:40:11, on 22.07.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17909)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
C:\Program Files\AVG\AVG2015\avgui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVG Web TuneUp\vprot.exe
C:\Users\Petr\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Windows\system32\GWX\GWX.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\COMODO\COMODO Internet Security\cis.exe
C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}\components\afom.exe
C:\Program Files\AVG Web TuneUp\avgcefrend.exe
G:\Instalačky\Správa počítače\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\CCleaner\CCleaner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://mysearch.avg.com/?cid={868E6B73-AB0F-4FC4-8FAF-57C774383EC9}&mid=bee1a8c956ce47d080d9d1543b4bc027-557114a9b0473eec7c50b6c225dbaa2fc37ba028&lang=cs&ds=AVG&coid=avgtbavg&cmpid=0715av&pr=fr&d=2015-07-20 11:41:39&v=4.1.4.948&pid=wtu&sg=&sap=hp
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll
O2 - BHO: AVG Web TuneUp - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Web TuneUp\4.1.4.948\AVG Web TuneUp.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvBackend] "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
O4 - HKLM\..\Run: [ShadowPlay] C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Web TuneUp\vprot.exe"
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Petr\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgwdsvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: FreemakeVideoCapture - Ellora Assets Corp. - C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: vToolbarUpdater18.7.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\ToolbarUpdater.exe
O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe

--
End of file - 6429 bytes
Keybord not present. Press Enter to continue

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 23 črc 2015 08:40

Z Comoda využíváš jen firewall?

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 23 črc 2015 13:52

Ano, z Comoda používám jen Firewall.

Zde je log z AdwCleaner:

# AdwCleaner v4.208 - Log vytvořen 23/07/2015 v 13:44:53
# Aktualizováno 09/07/2015 by Xplode
# Databáze : 2015-07-15.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x86)
# Uživatelské jméno : Petr - INTEL
# Spuštěno z : C:\Users\Petr\Desktop\adwcleaner_4.208.exe
# Nastavení : Čištění

***** [ Služby ] *****

[#] Služba Smazáno : vToolbarUpdater18.7.0

***** [ Soubory / Složky ] *****

Složka Smazáno : C:\ProgramData\AVG Secure Search
Složka Smazáno : C:\ProgramData\AVG Security Toolbar
Složka Smazáno : C:\Program Files\Common Files\AVG Secure Search
Složka Smazáno : C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\0khh5aex.default-1427958703254\Extensions\Avg@toolbar
Složka Smazáno : C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Složka Smazáno : C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\isreaditlater@ideashower.com
Soubor Smazáno : C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\foxydeal.sqlite
Soubor Smazáno : C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\0khh5aex.default-1427958703254\searchplugins\avg-secure-search.xml
Soubor Smazáno : C:\Program Files\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml

***** [ Naplánované úlohy ] *****


***** [ Zástupci ] *****


***** [ Registry ] *****

Klíč Smazáno : HKLM\SOFTWARE\Classes\S
Klíč Smazáno : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Klíč Smazáno : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Hodnota Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Klíč Smazáno : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Klíč Smazáno : HKCU\Software\Headlight
Klíč Smazáno : HKCU\Software\Avg Secure Update
Klíč Smazáno : HKU\.DEFAULT\Software\Avg Secure Update

***** [ Prohlížeče ] *****

-\\ Internet Explorer v11.0.9600.17909


-\\ Mozilla Firefox v39.0 (x86 cs)


-\\ Google Chrome v44.0.2403.89


*************************

AdwCleaner[R0].txt - [3038 bytů] - [23/07/2015 13:42:36]
AdwCleaner[S0].txt - [2942 bytů] - [23/07/2015 13:44:53]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3000 bytů] ##########
Keybord not present. Press Enter to continue

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 23 črc 2015 14:16

Zde je log z MBAM:

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 23.07.2015
Čas skenování: 13:55
Protokol: mbam.txt
Správce: Ano

Verze: 2.1.8.1057
Databáze malwaru: v2015.07.23.02
Databáze rootkitů: v2015.07.22.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x86
Souborový systém: NTFS
Uživatel: Petr

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 330357
Uplynulý čas: 17 min, 32 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Varovat
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 0
(Nenalezeny žádné škodlivé položky)

Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 0
(Nenalezeny žádné škodlivé položky)

Soubory: 0
(Nenalezeny žádné škodlivé položky)

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)
Keybord not present. Press Enter to continue

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 23 črc 2015 17:51

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 23 črc 2015 19:37

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.1 (07.16.2015:1)
OS: Windows 7 Home Premium x86
Ran by Petr on 23.07.2015 at 18:48:00,93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted the following from C:\Users\Petr\AppData\Roaming\mozilla\firefox\profiles\g82kcs7k.default-1430921114877\prefs.js

user_pref(extensions.foxcub.config.encodedConfig, {\core\:{\configUrl\:\hxxp://download.seznam.cz/software/conf/\,\configUrlSecure\:\hxxps://download.seznam.cz/sof
user_pref(extensions.foxcub.speedDial.RSS, false);
user_pref(extensions.foxcub.speedDial.enabled, false);
user_pref(extensions.foxcub.speedDial.items, [{\type\:\simple\,\bookmarkId\:-1,\url\:\hxxp://www.seznam.cz/\,\title\:\Seznam \\u2013 Najdu tam, co hled\\u00e1m
user_pref(extensions.foxcub.speedDial.nosync, );
user_pref(extensions.foxcub.speedDial.pageType, big);
user_pref(extensions.foxcub.speedDial.settings, {\background\:{\image\:\bg-grass-dog.png\,\color\:\transparent\,\position\:\right bottom\}});
user_pref(extensions.foxcub.speedDial.skin, 3);
Emptied folder: C:\Users\Petr\AppData\Roaming\mozilla\firefox\profiles\g82kcs7k.default-1430921114877\minidumps [3 files]



~~~ Chrome


[C:\Users\Petr\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Petr\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\Petr\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Petr\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.07.2015 at 18:55:14,47
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Keybord not present. Press Enter to continue

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 23 črc 2015 19:37

RogueKiller V10.9.3.0 [Jul 21 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno : Normální režim
Uživatel : Petr [Práva správce]
Started from : C:\Users\Petr\Desktop\RogueKiller.exe
Mód : Prohledat -- Datum : 07/23/2015 19:34:58

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 10 ¤¤¤
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_H_74FE\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_D_1ED6\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_H_74FE\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C6846616-3E73-45D0-840E-DAE156DADA32} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_H_74FE\ControlSet002\Services\Tcpip\Parameters\Interfaces\{903B650C-63A4-42E4-BAD6-EAC2B1AC0AC3} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_D_1ED6\ControlSet003\Services\Tcpip\Parameters\Interfaces\{48B26D70-1381-4150-B132-B1F047F4A497} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_H_74FE\ControlSet003\Services\Tcpip\Parameters\Interfaces\{903B650C-63A4-42E4-BAD6-EAC2B1AC0AC3} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{C6846616-3E73-45D0-840E-DAE156DADA32} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nalezeno

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost

¤¤¤ Antirootkit : 7 (Driver: Nahrán) ¤¤¤
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_CREATE[0] : Unknown @ 0x41e0d2563d000000
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_CLOSE[2] : Unknown @ 0x41e0d2563d000000
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_DEVICE_CONTROL[14] : Unknown @ 0x41e0d2563d000000
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_INTERNAL_DEVICE_CONTROL[15] : Unknown @ 0x41e0d2563d000000
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_POWER[22] : Unknown @ 0x41e0d2563d000000
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_SYSTEM_CONTROL[23] : Unknown @ 0x41e0d2563d000000
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_PNP[27] : Unknown @ 0x41e0d2563d000000

¤¤¤ Webové prohlížeče : 2 ¤¤¤
[PUP][FIREFX:Addon] g82kcs7k.default-1430921114877 : Seznam li?ti?ka [{ea614400-e918-4741-9a97-7a972ff7c30b}] -> Nalezeno
[PUM.HomePage][FIREFX:Config] 0khh5aex.default-1427958703254 : user_pref("browser.startup.homepage", "https://mysearch.avg.com/?cid={868E6B73-AB0F-4FC4-8FAF-57C774383EC9}&mid=bee1a8c956ce47d080d9d1543b4bc027-557114a9b0473eec7c50b6c225dbaa2fc37ba028&lang=cs&ds=AVG&coid=avgtbavg&cmpid=0715av&pr=fr&d=2015-07-20 11:41:39&v=4.1.4.948&pid=wtu&sg=&sap=hp"); -> Nalezeno

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST1000DL002-9TT153 ATA Device +++++
--- User ---
[MBR] 2e92f243d9cda3df34ee8b0f7197a587
[BSP] 6ea2a0a3240d75624aa44b632b008c0d : Empty|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 250003 MB [Windows XP Bootstrap | Windows XP Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 512007615 | Size: 703863 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: ST3320620AS ATA Device +++++
--- User ---
[MBR] 3d587ea86aab753af1ae05276d8313d8
[BSP] 84ca8f005dac36c956db86d60d557f65 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 149997 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 307195904 | Size: 155245 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: KINGSTON SHFS37A120G ATA Device +++++
--- User ---
[MBR] d6528846718121a403e533f444507270
[BSP] 33341d9755143a87c8bdd92eb2c0b221 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 114471 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
Keybord not present. Press Enter to continue

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jerabina » 23 črc 2015 20:11

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni antivir
Stáhni
Zoek.exe

a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

Vlož nový log z HJT + informuj o problémech.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 23 črc 2015 22:49

RogueKiller V10.9.3.0 [Jul 21 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno : Normální režim
Uživatel : Petr [Práva správce]
Started from : C:\Users\Petr\Desktop\RogueKiller.exe
Mód : Smazat -- Datum : 07/23/2015 21:16:31

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 10 ¤¤¤
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_H_74FE\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_D_1ED6\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_H_74FE\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C6846616-3E73-45D0-840E-DAE156DADA32} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_H_74FE\ControlSet002\Services\Tcpip\Parameters\Interfaces\{903B650C-63A4-42E4-BAD6-EAC2B1AC0AC3} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_D_1ED6\ControlSet003\Services\Tcpip\Parameters\Interfaces\{48B26D70-1381-4150-B132-B1F047F4A497} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_H_74FE\ControlSet003\Services\Tcpip\Parameters\Interfaces\{903B650C-63A4-42E4-BAD6-EAC2B1AC0AC3} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{C6846616-3E73-45D0-840E-DAE156DADA32} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][X]) -> Nahrazeno ()

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhostSmazáno

¤¤¤ Antirootkit : 7 (Driver: Nahrán) ¤¤¤
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_CREATE[0] : Unknown @ 0x41e0d2563d000000
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_CLOSE[2] : Unknown @ 0x41e0d2563d000000
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_DEVICE_CONTROL[14] : Unknown @ 0x41e0d2563d000000
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_INTERNAL_DEVICE_CONTROL[15] : Unknown @ 0x41e0d2563d000000
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_POWER[22] : Unknown @ 0x41e0d2563d000000
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_SYSTEM_CONTROL[23] : Unknown @ 0x41e0d2563d000000
[IRP:Addr(Hook.IRP)] \SystemRoot\System32\drivers\mountmgr.sys - IRP_MJ_PNP[27] : Unknown @ 0x41e0d2563d000000

¤¤¤ Webové prohlížeče : 2 ¤¤¤
[PUP][FIREFX:Addon] g82kcs7k.default-1430921114877 : Seznam li?ti?ka [{ea614400-e918-4741-9a97-7a972ff7c30b}] -> Smazáno
[PUM.HomePage][FIREFX:Config] 0khh5aex.default-1427958703254 : user_pref("browser.startup.homepage", "https://mysearch.avg.com/?cid={868E6B73-AB0F-4FC4-8FAF-57C774383EC9}&mid=bee1a8c956ce47d080d9d1543b4bc027-557114a9b0473eec7c50b6c225dbaa2fc37ba028&lang=cs&ds=AVG&coid=avgtbavg&cmpid=0715av&pr=fr&d=2015-07-20 11:41:39&v=4.1.4.948&pid=wtu&sg=&sap=hp"); -> Nahrazeno (about:home)

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST1000DL002-9TT153 ATA Device +++++
--- User ---
[MBR] 2e92f243d9cda3df34ee8b0f7197a587
[BSP] 6ea2a0a3240d75624aa44b632b008c0d : Empty|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 250003 MB [Windows XP Bootstrap | Windows XP Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 512007615 | Size: 703863 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: ST3320620AS ATA Device +++++
--- User ---
[MBR] 3d587ea86aab753af1ae05276d8313d8
[BSP] 84ca8f005dac36c956db86d60d557f65 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 149997 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 307195904 | Size: 155245 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: KINGSTON SHFS37A120G ATA Device +++++
--- User ---
[MBR] d6528846718121a403e533f444507270
[BSP] 33341d9755143a87c8bdd92eb2c0b221 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 114471 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
Keybord not present. Press Enter to continue

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 23 črc 2015 22:49

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Petr on 23.07.2015 at 21:17:02,94.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Petr\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

23.07.2015 21:18:20 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\Program Files\Kraken deleted successfully
C:\PROGRA~2\Shared Space deleted successfully
C:\Users\Petr\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\Petr\AppData\Local\EmieSiteList deleted successfully
C:\Users\Petr\AppData\Local\EmieUserList deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} deleted successfully
HKEY_USERS\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} deleted successfully

==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WtuSystemSupport deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\WtuSystemSupport deleted successfully

==== FireFox Fix ======================

Deleted from C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\0khh5aex.default-1427958703254\prefs.js:
user_pref("browser.startup.homepage", "about:home"about:home);
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\0khh5aex.default-1427958703254\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\prefs.js:

Deleted from C:\Users\Petr\AppData\Roaming\Mozilla\SeaMonkey\Profiles\s23qpowu.default\prefs.js:

Added to C:\Users\Petr\AppData\Roaming\Mozilla\SeaMonkey\Profiles\s23qpowu.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\0khh5aex.default-1427958703254

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs__2142_.backup

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs__2142_.backup

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\SeaMonkey\Profiles\s23qpowu.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs__2142_.backup

==== Deleting Files \ Folders ======================

C:\Program Files\Kraken not found
C:\Program Files\AVG Web TuneUp deleted
C:\PROGRA~2\AVG Web TuneUp deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\searchplugins\torrents-search.xml deleted
C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\extensions\firefox@ghostery.com.xpi deleted
C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\jetpack deleted
C:\Users\Petr\AppData\Roaming\Mozilla\SeaMonkey\Profiles\s23qpowu.default\extensions\staged deleted
"C:\Users\Petr\AppData\Roaming\mbin.jp\r960.ee" deleted
"C:\Users\Petr\AppData\Roaming\mbin.jp" deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\0khh5aex.default-1427958703254
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\SeaMonkey\Profiles\s23qpowu.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"ytfmdownloader@gmail.com"="C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com" [07.02.2014 10:31]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877
- esk slovnk pro kontrolu pravopisu - %ProfilePath%\extensions\cs@dictionaries.addons.mozilla.org
- EPUBReader - %ProfilePath%\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
- Memory Fox - %ProfilePath%\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}
- Classic Theme Restorer Customize UI - %ProfilePath%\extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi
- Element Hiding Helper for Adblock Plus - %ProfilePath%\extensions\elemhidehelper@adblockplus.org.xpi
- Undetermined - %ProfilePath%\extensions\ich@maltegoetz.de.xpi
- Restart My Fox - %ProfilePath%\extensions\Restart-My-Fox@8pecxstudios.com.xpi
- Thumbnail Zoom Plus - %ProfilePath%\extensions\thumbnailZoom@dadler.github.com.xpi
- Flagfox - %ProfilePath%\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi
- NoScript - %ProfilePath%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- Tab Mix Plus - %ProfilePath%\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
- Download Manager Tweak - %ProfilePath%\extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}.xpi

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\SeaMonkey\Profiles\s23qpowu.default
- DOM-granskaren DOM Inspector - %ProfilePath%\extensions\inspector@mozilla.org.xpi
- ChatZilla - %ProfilePath%\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877
0A1788EE70EF444DABA1E958092F4B85 - C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll - Adobe Acrobat
52CE0DBFD9738AE528CF525A0367EBEB - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
1F352B5944AF5C2204D9EFF7F845C5AF - C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll - Google Update
8E9A08E2092B3E1ADFF3C46BC1A5124B - C:\Program Files\TVUPlayer\npTVUAx.dll - TVU Web Player for FireFox
0D9C165C24FAFF82DFD354CBCC7A0ACD - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll - NVIDIA 3D Vision
36808C3D7F5B2408621CC7BBEB4F1660 - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll - NVIDIA 3D VISION
073A22FDCDAFD513DAD0D972BD2DF76E - C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll - Silverlight Plug-In
C7090AB2D8473D12D48B818FC1FE7AF9 - C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll - Java(TM) Platform SE 8 U51
95479782C832632116E0FC0C8373F43E - C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 8.0.510.16
0205ADAFFDDF04F0F69200E5CFB5FFD9 - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
1DE714BB4BB48B10BC94FF84C9BC6471 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll - DivX Web Player
E37EAD09D28AE19D8A39B6A95F47513A - C:\Windows\system32\Adobe\Director\np32dsw_1211151.dll - Shockwave for Director / Shockwave for Director
FD82108FD60B63010325D9AF6F00AF99 - C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll - Shockwave Flash
6D23BB87BCF88731959BF79082D442E6 - C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrlui.dll - Microsoft® Silverlight


==== Chromium Look ======================

Google Chrome Version: 44.0.2403.89



==== Chromium Startpages ======================

C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Preferences
{"browser":{"window_placement":{"bottom":550,"left":10,"maximized":false,"right":790,"top":10,"work_area_bottom":860,"work_area_left":0,"work_area_right":1440,"work_area_top":0}},"countryid_at_install":17242,"data_reduction":{"daily_original_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","1845","326721","2727"],"daily_original_length_via_data_reduction_proxy":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0"],"daily_original_length_with_data_reduction_proxy_enabled":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0"],"daily_received_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","1845","326721","2727"],"daily_received_length_https_with_data_reduction_proxy_enabled":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0"],"daily_received_length_long_bypass_with_data_reduction_proxy_enabled":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0"],"daily_received_length_short_bypass_with_data_reduction_proxy_enabled":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0"],"daily_received_length_unknown_with_data_reduction_proxy_enabled":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0"],"daily_received_length_via_data_reduction_proxy":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0"],"daily_received_length_with_data_reduction_proxy_enabled":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0"],"last_update_date":"13081989600000000"},"default_apps_install_state":3,"dns_prefetching":{"host_referral_list":[2,["https://webtuneup.avg.com/",["https://webtuneup.avg.com/",3.626212660877799]]],"startup_list":[1,"https://clients4.google.com/","https://webtuneup.avg.com/"]},"extensions":{"alerts":{"initialized":true},"autoupdate":{"next_check":"13082060792966012"},"chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]},"last_chrome_version":"43.0.2357.134"},"gcm":{"check_time":"13082060328433165"},"http_original_content_length":"331293","http_received_content_length":"331293","intl":{"accept_languages":"cs-CZ,cs"},"invalidator":{"client_id":"ptfsGDwOeCLhw4afFGNHcw=="},"media":{"device_id_salt":"JfiEOMh6COKChE/5FP+iNg=="},"net":{"http_server_properties":{"servers":{"chrome.google.com:443":{"alternative_service":[{"port":443,"probability":1,"protocol_str":"quic"}]},"clients2.google.com:443":{"alternative_service":[{"port":443,"probability":1,"protocol_str":"quic"}],"supports_spdy":true},"clients4.google.com:443":{"alternative_service":[{"port":443,"probability":1,"protocol_str":"quic"}],"network_stats":{"srtt":14416},"supports_spdy":true},"lh4.googleusercontent.com:443":{"alternative_service":[{"port":443,"probability":1,"protocol_str":"quic"}],"supports_spdy":true},"r1---sn-2gb7ln7k.gvt1.com:80":{"alternative_service":[{"port":80,"probability":0,"protocol_str":"quic"}]},"redirector.gvt1.com:80":{"alternative_service":[{"port":80,"probability":0,"protocol_str":"quic"}]}},"supports_quic":{"address":"192.168.1.10","used_quic":true},"version":3}},"plugins":{"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_index":0,"content_settings":{"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{},"geolocation":{},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{},"plugins":{},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{},"pref_version":1},"created_by_version":"43.0.2357.134","exit_type":"Normal","exited_cleanly":true,"icon_version":3,"managed_user_id":"","migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"PrvnĂ­ uĹľivatel","per_host_zoom_levels":{}},"protection":{"macs":{}},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13081859017851232"},"translate_blocked_languages":["cs"],"translate_whitelists":{}}
_locale":"cs","default_locale":"en","description":"Peněženka Google pro digitální zboží","display_in_launcher":false,"display_in_new_tab_page":false,"icons":{"128":"images/icon_128.png","16":"images/icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCrKfMnLqViEyokd1wk57FxJtW2XXpGXzIHBzv9vQI/01UsuP0IV5/lj0wx7zJ/xcibUgDeIxobvv9XD+zO1MdjMWuqJFcKuSS4Suqkje6u+pMrTSGOSHq1bmBVh0kpToN8YoJs/P/yrRd7FEtAXTaFTGxQL4C385MeXSjaQfiRiQIDAQAB","manifest_version":2,"minimum_chrome_version":"29","name":"Peněženka Google","oauth2":{"auto_approve":true,"client_id":"203784468217.apps.googleusercontent.com","scopes":["https://www.googleapis.com/auth/sierra","https://www.googleapis.com/auth/sierrasandbox","https://www.googleapis.com/auth/chromewebstore","https://www.googleapis.com/auth/chromewebstore.readonly"]},"permissions":["identity","webview","https://wallet.google.com/","https://wallet-web.sandbox.google.com/","https://www.google.com/","https://www.googleapis.com/*"],"update_url":"https://clients2.google.com/service/update2/crx","version":"0.1.1.0"},"path":"nmmhkkegccagdldgiimedpiccmgmieda\\0.1.1.0_0","preferences":{},"regular_only_preferences":{},"running":false,"state":1,"was_installed_by_default":true,"was_installed_by_oem":false},"pafkbggdmjlpgkdkcbjmhmfcdpncadgh":{"active_permissions":{"api":["alarms","gcm","identity","metricsPrivate","notifications","storage","tabs","webstorePrivate"],"explicit_host":["*://*.google.com/*","*://*.gstatic.com/*","https://*.googleapis.com/*","https://*.googleusercontent.com/*"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":["alarms.onAlarm","gcm.onMessage","identity.onSignInChanged","notifications.onButtonClicked","notifications.onClicked","notifications.onClosed","notifications.onPermissionLevelChanged","notifications.onShowSettings","runtime.onInstalled","runtime.onStartup","runtime.onSuspend","storage.onChanged"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13081973905090692","location":5,"manifest":{"background":{"persistent":false,"scripts":["utility.js","cards.js","background.js"]},"description":"Integrates Google Now into Chrome.","icons":{"128":"images/icon128.png","16":"images/icon16.png","48":"images/icon48.png"},"key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkhqJr32OFD/bMXW4Md7jMfd7LbwHXVc6x5bBQG5U+dloofoxrICDR20yur/40mQ8O//0sS1b8srvbab1CRlSrxoNCr9T80NAkfzx0gHyVS+p1Zow+1FzLMu9PiGwwFyN80HIB7GI/dIa0wC9K/2OrrzcHEhVH96DacTtWQqjfDVtZPjT7Xwv23dgoWcpbkRC86jMJot3dmX9xnn0KzoVc9gDOHSIkBLbkkr6Sp3LGXCCM4L0DJgxdFwaLr5WBzgC3y5x0/wwPIwN4PtIaK3BhH6njlksfnKwwIJ9iRT41V4BqbWu4mszO/7VJ3HJyw2DBpIc2grU9ZRRxrV3fRQG4wIDAQAB","manifest_version":2,"name":"Google Now","oauth2":{"auto_approve":true,"scopes":["https://www.googleapis.com/auth/gcm","https://www.googleapis.com/auth/googlenow"]},"optional_permissions":["background"],"permissions":["alarms","gcm","identity","metricsPrivate","notifications","storage","tabs","webstorePrivate","*://*.google.com/*","*://*.gstatic.com/*","https://*.googleapis.com/chromenow/v1/*","https://*.googleapis.com/gcm/*","https://*.googleusercontent.com/*"],"version":"1.2.0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\43.0.2357.134\\resources\\google_now","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":false,"was_installed_by_oem":false},"pjkljhegncpnkpknbcohdijeoejaedia":{"ack_external":true}}},"pinned_tabs":[],"protection":{"macs":{"browser":{"show_home_button":"995195657F7A9CEAF7712E57FEB38339A36920074BCD0273C832C7377C286DA8"},"default_search_provider":{"keyword":"43B0541EFF033077127E79713157062FB47ADAFD8F0688412D7B2A6FEFB4E089","name":"89FB3FAF3504D0A21BC7F699202F72ADC3985803BF6A3A37EAA4FB69B03764C0","search_url":"597967DDEE83DD8AA3CFEE1C590B2F78CE87CF9933FDDC73784DF90038B853BA"},"default_search_provider_data":{"template_url_data":"B23F58CAD169C615897A15A5EB2636EF3869306DEDABF0761041408E8EBE706D"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":"E4ABAF34AC2E09E5F8477C43DB8BEE7F46E2AB8D77D81EDBCE6F70FAB1CECA1F","aohghmighlieiainnegkcijnfilokake":"0886DCE8204399250FC63449DD499EB2C700CFAAF95683B08168D6BED9B5C105","apdfllckaahabafndbhieahigkjlhalf":"85CBEE0B24BB2A8C5701E628C315DBFAB0D9E9DE7006473B9916AB5C5537230D","bepbmhgboaologfdajaanbcjmnhjmhfn":"946EB6D7B1F12007BA2F1BE877CC76E38F9B4E594B723F66514C914BEC409F56","blpcfgokakmgnkcojhhkbfbldkacnbeo":"942017EA81A6ADFA0F5E2FBD84BDBB83878C4845512663F44F4F6D8FD90C9BE2","coobgpohoikkiipiblmjeljniedjpjpf":"603A314039BC360000EAA284545D5BB6CEEDEBE1962BD250B4662EC23BA6747B","eemcgdkfndhakfknompkggombfjjjeno":"7F9A55E46B71269F1C92D40D0B820585573D5A4AFD0731431B1C579F45494FEC","ennkphjdgehloodpbhlhldgbnhmacadg":"BDEEA3C339C391B11AFDD48A7BE961D9C62B41805BA6B4C76757B0EA60972561","gfdkimpbcpahaombhbimeihdjnejgicl":"C97855F6BFFB9ECD9BAFC0519326077771029AB9C129D02FE4D2BA21D90867D7","kmendfapggjehodndflmmgagdbamhnfd":"2F73464CCAE8A0A9B8FCEE646F2462EAF20FE9064BC512875354BAA5C541A8DE","mfehgcgbbipciphmccgaenjidiccnmng":"EE9FE48FF33708D037E540664EBC47BA33552EA9C7D1194137B12510CE23D72A","mgndgikekgjfcpckkfioiadnlibdjbkf":"F3902F8ED14B1E3F5CDF7F90FFF2DE3EDEC390431F6F4E71AA3729E84E38BDA2","mhjfbmdgcfjbbpaeojofohoefgiehjai":"9B76204EE3D5D8D74EAA4BE98AEB45158915DE87EEBC5378DD759D379A4531D2","neajdppkdcdipfabeoofebfddakdcjhd":"F70A03DE349706F7E689DF821904954A39623D749B7F8E29E2F7A1294C5B8C3C","nkeimhogjdpnpccoofpliimaahmaaome":"9C29834C9972C2ADE4CCF163D34247C0AEB7CFCAF4A53E0F4921837F491879A5","nmmhkkegccagdldgiimedpiccmgmieda":"249C5A016CE22EB71AFF47BF0114879A9CC5BDD32D75B8B5104FA65DA2FCFB03","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"AC366ED02E1762B99ADFF5BE81ABF485E2810DE31F0C49CA1AB67090BD739C53","pjkljhegncpnkpknbcohdijeoejaedia":"8D721149EB624A37FE908E1428EE9CB6F43707D84943F80003E1FC72D9F51AD9"}},"google":{"services":{"last_username":"3B53D867E0DFCFD401D483EFB21363EA5B4DB254581077D5C10CB3CA0ABFD7AB","username":"A2FE665DC5FFC9B9268E30D8AF3C8E19EA71AE2ADD51ECA77505A9DF222BBC97"}},"homepage":"0822339600223698D8F3D2971DC44C37956C5B8DED5E928C961704A51F718ACB","homepage_is_newtabpage":"CE1854A580D187F692E2F64A8FA1EA44D9E19B72717FFBDEDFC45A0A0CBA97DA","pinned_tabs":"53FEB332993AA72E485AC85E4C2F1504FFF338D87C316B52EB018C734C6F26AB","prefs":{"preference_reset_time":"6A280226A65407BDAD9AA877C89D4045830A946109842F24F46052D102D56758"},"profile":{"reset_prompt_memento":"E9A14551BD3150C87BBC49E1F74F16E63A5177E9BEF1D2A421A3C448CA4D5498"},"safebrowsing":{"incidents_sent":"3CD3071F7D826982BFF6E4238B5FAB7E7CC65223355A2E64D2B7F8A33DD38984"},"search_provider_overrides":"C5CEA7DC15FB6C05EC15D52EF7636DFA5A3F02122527F3F2728C6EDB5FAD7D6D","session":{"restore_on_startup":"B19CF0B22B79B1975795853C999EBAAA81BBE10B3DCC3BB39B712FF9E889C6C8","startup_urls":"5BE2AAA8F40BEDFD2E4348DC2ABFCD41DA4BA6571998D01AEFD45286E9586474"},"software_reporter":{"prompt_reason":"FEDF14EF647E7FEC6A74050300916A6E462DD439D48A4E3A69144CE306164413","prompt_seed":"04C696D337980E982FDD30AD330E40180D0021F91A0B876A1E3EEEA39B3FC4EB","prompt_version":"44FF51C6DDFB37ABFE07ADEDF869CC8383C4BF9538B37757E2B793B246D538E1"},"sync":{"remaining_rollback_tries":"01BB833C3FF33B68AA18FAC295A6A8342B83A6D91A1F1A937B2EE9E770DFD3AC"}},"super_mac":"9D571F165975787F5370BB0E9C01E4BC78880160C6CC9022BC1C27C7326ADDF1"}}


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\AVG Web TuneUp deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9JJKZLIC will be deleted at reboot
C:\Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C757N81U will be deleted at reboot
C:\Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZEU9MSNR will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Petr\AppData\Local\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================


==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Petr\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Petr\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied
C:\RECYCLER successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9JJKZLIC" not found
"C:\Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C757N81U" not found
"C:\Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZEU9MSNR" not found

==== EOF on 23.07.2015 at 21:54:06,67 ======================
Keybord not present. Press Enter to continue

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 23 črc 2015 22:52

Zde je nový log z HJT. Problémy... snad nejsou, pičítač se zdá být rychlejší, uvidíme během zítřka a víkendu.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:51:03, on 23.07.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17909)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
C:\Windows\system32\GWX\GWX.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG2015\avgui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Users\Petr\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\COMODO\COMODO Internet Security\cis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
G:\Instalačky\Správa počítače\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe

O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvBackend] "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
O4 - HKLM\..\Run: [ShadowPlay] C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Petr\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgwdsvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: FreemakeVideoCapture - Ellora Assets Corp. - C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 5469 bytes
Keybord not present. Press Enter to continue

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu  Vyřešeno

Příspěvekod jaro3 » 24 črc 2015 09:08

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"


Stáhni si zde DelFix
https://toolslib.net/downloads/viewdownload/2-delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt

Pokud nebudou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 68 hostů