Start-Spustit a zadej ComboFix /Uninstall
Vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:
Kód: Vybrat vše
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\wx._core_.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\wx._controls_.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\wx._windows_.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\wx._gdi_.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\wx._misc_.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\unicodedata.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\pysqlite2._sqlite.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\windows._lib_cacheinvalidation.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\pythoncom27.dll ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32com.shell.shell.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32gui.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\pyexpat.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\wx._wizard.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32file.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32security.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32api.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\usb_ext.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\wx._animate.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\wx._html2.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32inet.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32process.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32pdh.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32pipe.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32ts.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32event.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\thumbnails_ext.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32profile.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\win32crypt.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\select.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\_ssl.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\_hashlib.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\_elementtree.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\PyWinTypes27.dll ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\_ctypes.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\_socket.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\_psutil_windows.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\_multiprocessing.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\_yappi.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\common.time34.pyd ()
MOD - C:\Users\JAG\AppData\Local\Temp\_MEI57602\hashobjs_ext.pyd ()
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {FFC82AB9-B5C2-430C-BD4D-F5C1AF43371A}
IE:64bit: - HKLM\..\SearchScopes\{FFC82AB9-B5C2-430C-BD4D-F5C1AF43371A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LNJB
IE - HKLM\..\SearchScopes,DefaultScope = {FFC82AB9-B5C2-430C-BD4D-F5C1AF43371A}
IE - HKLM\..\SearchScopes\{FFC82AB9-B5C2-430C-BD4D-F5C1AF43371A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LNJB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = E1 ED 6B 3F 61 C9 D1 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = Reg Error: Value error.
IE - HKCU\..\SearchScopes,DefaultScope = {FFC82AB9-B5C2-430C-BD4D-F5C1AF43371A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{FFC82AB9-B5C2-430C-BD4D-F5C1AF43371A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LNJB
[2016.03.17 20:19:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\JAG\AppData\Roaming\Mozilla\Extensions
CHR - Extension: No name found = C:\Users\JAG\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_1\
CHR - Extension: No name found = C:\Users\JAG\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_1\
CHR - Extension: No name found = C:\Users\JAG\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_1\
CHR - Extension: No name found = C:\Users\JAG\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_1\
CHR - Extension: No name found = C:\Users\JAG\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_1\
CHR - Extension: No name found = C:\Users\JAG\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\
CHR - Extension: No name found = C:\Users\JAG\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh\3.2_1\
CHR - Extension: No name found = C:\Users\JAG\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpdfbkehegfmedglgemnhbnpmfmioggj\4.60.3_0\
CHR - Extension: No name found = C:\Users\JAG\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.0_1\
CHR - Extension: No name found = C:\Users\JAG\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_1\
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Program Files\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\Program Files (x86)\*.tmp
C:\Users\JAG\AppData\Local\Temp\_MEI57602
C:\ProgramData\DP45977C.lfl
:Reg
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.