Zlobí DNS a multimédia

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Jenda159
nováček
Příspěvky: 2
Registrován: červenec 15
Pohlaví: Nespecifikováno
Stav:
Offline

Zlobí DNS a multimédia

Příspěvekod Jenda159 » 23 črc 2015 18:32

Ahoj, chtěl bych poprosit o pomoc. Občas mi zlobí DNS, že mi to napíše, že platnost DNS vypršela a některé stránky mi vůbec nejdou načíst.. a dále mi občas hrozně zlobí multimédia, třeba když kliknu na spuštění videa, tak mi to občas trvá minutu, než se to spustí (třeba se celé načte za 5s, ale než se spustí tak to občas trvá). Díky za rady.

Zde je log:

Kód: Vybrat vše

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:21:43, on 23. 7. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)


Boot mode: Normal

Running processes:
C:\Users\Jenda\AppData\Local\FluxSoftware\Flux\flux.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Java\jre1.8.0_45\bin\javaw.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Jenda\Downloads\HijackThis.exe
C:\WINDOWS\SysWOW64\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.yahoo.com/?fr=vmn&type=vmn__webcompa__1_0__ya__hp_WCYID10099_swoc_campaign_150401__yaie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe /start
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [f.lux] "C:\Users\Jenda\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Web Companion] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SRSHDAudioLab] "C:\Program Files\SRS Labs\SRS HD Audio Lab\HDAL.exe" auto
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: @oem51.inf,%BcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000 (c2wts) - Unknown owner - C:\Program Files (x86)\Windows Identity Foundation\v3.5\c2wtshost.exe (file missing)
O23 - Service: Služba Vzdálené plochy Chrome (chromoting) - Google Inc. - C:\Program Files (x86)\Google\Chrome Remote Desktop\44.0.2403.25\remoting_host.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: @oem102.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\WINDOWS\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel® Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Service KMSELDI - Unknown owner - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14072 bytes

Reklama
Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Zlobí DNS a multimédia

Příspěvekod jerabina » 23 črc 2015 20:24

Ahoj, vítej na fóru PC-HELP!

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.

===================================================

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

===================================================

Stáhni AdwCleaner (by Xplode)

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

===================================================

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na Kopírovat do schránky a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Jenda159
nováček
Příspěvky: 2
Registrován: červenec 15
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Zlobí DNS a multimédia

Příspěvekod Jenda159 » 24 črc 2015 10:21

Ahoj, z toho programu to hodilo log: AdwCleaner (by Xplode), díky moc za pomoc!

Kód: Vybrat vše

# AdwCleaner v4.208 - Log vytvořen 24/07/2015 v 10:17:58
# Aktualizováno 09/07/2015 by Xplode
# Databáze : 2015-07-15.1 [Server]
# Operační system : Windows 8.1 Pro  (x64)
# Uživatelské jméno : Jenda - PC-JENDA
# Spuštěno z  : C:\Users\Jenda\Downloads\AdwCleaner.exe
# Nastavení : Sken

***** [ Služby ] *****


***** [ Soubory / Složky ] *****

Složka Nalezeno : C:\Program Files (x86)\globalUpdate
Složka Nalezeno : C:\Program Files (x86)\ParetoLogic
Složka Nalezeno : C:\ProgramData\ParetoLogic
Složka Nalezeno : C:\Users\Jenda\AppData\Local\globalUpdate
Složka Nalezeno : C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik
Složka Nalezeno : C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\khnpeclbnipcdacdkhejifenadikeghk
Složka Nalezeno : C:\Users\Jenda\AppData\Roaming\OpenCandy
Složka Nalezeno : C:\Users\Jenda\Favorites\Links\radio
Složka Nalezeno : C:\Users\Jenda\Favorites\Links\radio
Soubor Nalezeno : C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0
Soubor Nalezeno : C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0.localstorage
Soubor Nalezeno : C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0.localstorage-journal
Soubor Nalezeno : C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_khnpeclbnipcdacdkhejifenadikeghk_0.localstorage
Soubor Nalezeno : C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_khnpeclbnipcdacdkhejifenadikeghk_0.localstorage-journal

***** [ Naplánované úlohy ] *****


***** [ Zástupci ] *****


***** [ Registry ] *****

Klíč Nalezeno : HKCU\Software\AppDataLow\Software\Crossrider
Klíč Nalezeno : HKCU\Software\GlobalUpdate
Klíč Nalezeno : HKCU\Software\ParetoLogic
Klíč Nalezeno : [x64] HKCU\Software\GlobalUpdate
Klíč Nalezeno : [x64] HKCU\Software\ParetoLogic
Klíč Nalezeno : HKLM\SOFTWARE\Classes\pc-mechanic
Klíč Nalezeno : HKLM\SOFTWARE\GlobalUpdate
Klíč Nalezeno : HKLM\SOFTWARE\ParetoLogic
Klíč Nalezeno : HKLM\SOFTWARE\Uniblue
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}

***** [ Prohlížeče ] *****

-\\ Internet Explorer v11.0.9600.17840


-\\ Mozilla Firefox v

[0sir35v3.default] - Řádek Nalezeno : user_pref("extensions.crossrider.bic", "14bd9fed378db4d2d00e6ac2d2c46de2");

-\\ Google Chrome v44.0.2403.89


*************************

AdwCleaner[R0].txt - [3399 bytů] - [24/07/2015 10:17:58]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3457 bytů] ##########


A z programu Malwarebytes' Anti-Malware:

Kód: Vybrat vše

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 24. 7. 2015
Čas skenování: 10:52
Protokol:
Správce: Ano

Verze: 2.1.8.1057
Databáze malwaru: v2015.07.24.04
Databáze rootkitů: v2015.07.22.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows 8.1
CPU: x64
Souborový systém: NTFS
Uživatel: Jenda

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 403381
Uplynulý čas: 24 min, 5 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 8
PUP.Optional.CrossRider.C, HKLM\SOFTWARE\WOW6432NODE\APPDATALOW\SOFTWARE\Crossrider, , [395bd5104743e94dd7e22ce043c042be],
PUP.Optional.Cinema.A, HKU\S-1-5-18\SOFTWARE\CinemaP-1.9cV26.02-nv, , [8b09b53054360b2bad25bf6fbd466b95],
PUP.Optional.Cinema.A, HKU\S-1-5-18\SOFTWARE\CinemaP-1.9cV26.02-nv-ie, , [c5cf31b4800aea4c7f5343ebec17a25e],
PUP.Optional.InternetSpeedChecker.A, HKU\S-1-5-18\SOFTWARE\Internet Speed Checker-nv, , [96fe8e57b2d80d2951b858bd20e316ea],
PUP.Optional.Crossrider.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, , [890b0bda6a20f244d900f49efe066997],
PUP.Optional.Cinema.A, HKU\S-1-5-21-3206093283-3013643135-277779665-1001\SOFTWARE\CinemaP-1.9cV26.02-nv-ie, , [afe53baab0daa096ba18f43a47bcaf51],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3206093283-3013643135-277779665-1001\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [b3e1d213c0cac27497b8d2a8e123b24e],
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-3206093283-3013643135-277779665-1001\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, , [eba99f46404aaa8cf6e4030ba65d58a8],

Hodnoty registru: 1
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-3206093283-3013643135-277779665-1001\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|source, IE, , [eba99f46404aaa8cf6e4030ba65d58a8]

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 16
Stolen.Data, C:\Users\Jenda\AppData\Roaming\Imminent\Logs, , [f1a38461b1d9063015a951eba45f1ae6],
PUP.Optional.OpenCandy, C:\Users\Jenda\AppData\Roaming\OpenCandy, , [11834c9922680f27d47caa2d61a154ac],
PUP.Optional.OpenCandy, C:\Users\Jenda\AppData\Roaming\OpenCandy\11AD404206704BCD81590B01BC7DA097, , [11834c9922680f27d47caa2d61a154ac],
PUP.Optional.OpenCandy, C:\Users\Jenda\AppData\Roaming\OpenCandy\2FDD5AECD8C74059BBF653710BEF01DF, , [11834c9922680f27d47caa2d61a154ac],
PUP.Optional.OpenCandy, C:\Users\Jenda\AppData\Roaming\OpenCandy\454AD7186D444066B8EE4D4DA2EF68C6, , [11834c9922680f27d47caa2d61a154ac],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\defaults, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\defaults\preferences, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\userCode, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\locale, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\locale\en-US, , [880cb72e6129dd59a9a2b94029d96a96],

Soubory: 101
PUP.Optional.CrossRider.A, C:\Windows\SysWOW64\37.exe, , [187c29bc4644a88ecd8086f87b86e51b],
Stolen.Data, C:\Users\Jenda\AppData\Roaming\Imminent\Logs\18-04-2015, , [f1a38461b1d9063015a951eba45f1ae6],
Stolen.Data, C:\Users\Jenda\AppData\Roaming\Imminent\Logs\20-04-2015, , [f1a38461b1d9063015a951eba45f1ae6],
PUP.Optional.OpenCandy, C:\Users\Jenda\AppData\Roaming\OpenCandy\11AD404206704BCD81590B01BC7DA097\pcmechanicpmROW_p1v2.exe, , [11834c9922680f27d47caa2d61a154ac],
PUP.Optional.OpenCandy, C:\Users\Jenda\AppData\Roaming\OpenCandy\2FDD5AECD8C74059BBF653710BEF01DF\pcmechanicpmROW_p1v2.exe, , [11834c9922680f27d47caa2d61a154ac],
PUP.Optional.OpenCandy, C:\Users\Jenda\AppData\Roaming\OpenCandy\454AD7186D444066B8EE4D4DA2EF68C6\WebCompanionInstaller.exe, , [11834c9922680f27d47caa2d61a154ac],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome.manifest, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\install.rdf, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\3440c8416ff1f1d61edd4312a7686632.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\5feb33c5229d448545beb0affb049761.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\9215898fb9c0bf60ffc73b5f01555148.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\a0679e5063c9305395c06c56ff347419.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\b3a9666b471f7ff3478541bd736b0280.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\background.html, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\browser.xul, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\dialog.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\ffCoreFilesIndex.txt, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\options.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\options.xul, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\search_dialog.xul, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\0c1d5e354a48facae83d0aac6cec677e.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\210b951d3781c1a0dfa5d1d4b228743e.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\218fe3da7cc0097f46c5202f06cb3d19.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\2195dd4f20b6c286121fb41f7aa8987c.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\2acc4b58cfb7b5756a6041ab99fa46c9.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\7cead603ccab79b42572987d78dda2d7.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\7dcb2629261e91fb16f64b36514e9fac.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\88d8bdcdfbc3c549f148c20f408e7ad5.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\938cf34cd75ab109cc0bd1241656813f.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\9cfcc16a0db0d2b805b1a8b205018674.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\a0c3dcec12db283ab80bb3bcaad4b1b1.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\b0a7323bdea7a9de695012aeb1259cd7.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\b14a81d20b6de5bed25a942ef3c9e6b9.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\b562a2ca8ea89be51bf59b9350dc8715.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\b59a88618c1ac88cd1ab07979872b83b.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\ccfbd8a5af168633db412dd791d974ec.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\d9d4cff956c89ab91059ef08a3e58c14.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\f72413b061c279a7cf2d0da9a9eea9a2.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\f9f7beb8751cb66189d646b9d8b49979.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\ffee2cb099768d31212f559073993715.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\chrome\content\core\installer.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\defaults\preferences\prefs.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\manifest.xml, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins.json, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\262.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\102.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\104.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\119.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\123.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\13.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\14.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\16.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\17.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\178.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\179.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\180.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\184.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\191.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\195.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\200.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\217.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\220.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\221.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\223.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\231.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\232.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\234.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\242.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\246.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\252.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\253.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\260.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\263.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\273.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\281.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\286.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\288.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\289.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\290.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\300.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\334.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\335.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\342.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\344.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\345.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\354.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\356.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\380.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\4.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\47.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\64.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\7.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\78.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\9.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\91.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\plugins\93.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\userCode\background.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\extensionData\userCode\extension.js, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\extensions\NLQUCQ35648598@KRFIE97629948.com\locale\en-US\translations.dtd, , [880cb72e6129dd59a9a2b94029d96a96],
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\prefs.js, Dobré: (), Špatné: (user_pref("extensions.crossrider.bic", "14bd9fed378db4d2d00e6ac2d2c46de2");), ,[395ba1443555d5614eb7c8acb3524db3]
PUP.Optional.CrossRider.A, C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\0sir35v3.default\prefs.js, Dobré: (), Špatné: (js.ourinfoonlinestack.com/plugin/apps/71383/plugins/na/ff/plugins.json), ,[23719a4ba0eabf7706cfcda94eb74bb5]

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Zlobí DNS a multimédia

Příspěvekod jaro3 » 24 črc 2015 11:46

Nedávej logy do code!



Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 37 hostů