Prosím o kontrolu Logu - seká sa hudba Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

ROCK4891
Level 2.5
Level 2.5
Příspěvky: 307
Registrován: červenec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu Logu - seká sa hudba

Příspěvekod ROCK4891 » 22 črc 2016 15:06

Fix result of Farbar Recovery Scan Tool (x64) Version: 20-07-2016
Ran by domin (2016-07-22 15:01:19) Run:1
Running from C:\Users\domin\Desktop
Loaded Profiles: domin (Available Profiles: domin)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
SearchScopes: HKU\S-1-5-21-587641703-922834975-2764268489-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-587641703-922834975-2764268489-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

EmptyTemp:
End

*****************

Processes closed successfully.
HKU\S-1-5-21-587641703-922834975-2764268489-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-587641703-922834975-2764268489-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => key removed successfully
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki" => key removed successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 583648 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 11667603 B
Java, Flash, Steam htmlcache => 232311770 B
Windows/system/drivers => 117282 B
Edge => 0 B
Chrome => 491924111 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 814 B
NetworkService => 0 B
domin => 26291979 B

RecycleBin => 136492 B
EmptyTemp: => 727.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 15:01:28 ====

Reklama
ROCK4891
Level 2.5
Level 2.5
Příspěvky: 307
Registrován: červenec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu Logu - seká sa hudba

Příspěvekod ROCK4891 » 22 črc 2016 15:32

Ten AdsFix mi nefunguje...No ide ale skontroluje asi 30% a potom vyskočí tabuľka že program prestal pracovať...Skúsil som 3x a potom ešte raz po reštarte a to isté

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu Logu - seká sa hudba

Příspěvekod Orcus » 22 črc 2016 21:21

Zkus v nouzovém režimu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

ROCK4891
Level 2.5
Level 2.5
Příspěvky: 307
Registrován: červenec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu Logu - seká sa hudba

Příspěvekod ROCK4891 » 22 črc 2016 21:30

No to by som rád ale na tomto NB neviem ako ?

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu Logu - seká sa hudba

Příspěvekod Orcus » 23 črc 2016 06:31

Popis jak se do něj dostat bude v návodu k ntb. Případně google - výrobce + model + safe mode. :-)
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

ROCK4891
Level 2.5
Level 2.5
Příspěvky: 307
Registrován: červenec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu Logu - seká sa hudba

Příspěvekod ROCK4891 » 25 črc 2016 10:55

Nepomohlo ani v núdzovom režime...Skúsim to vymaazat a stiahnem nový...Možno sa ten prvý nejako nesprávne stiahol...občas sa to stáva

ROCK4891
Level 2.5
Level 2.5
Příspěvky: 307
Registrován: červenec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu Logu - seká sa hudba

Příspěvekod ROCK4891 » 25 črc 2016 11:53

No teraz to už vyzeralo dobre spravilo asi 70% našlo asi 14 vírusov ale potom zase to isté...pregram prestal pracovať

ROCK4891
Level 2.5
Level 2.5
Příspěvky: 307
Registrován: červenec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu Logu - seká sa hudba

Příspěvekod ROCK4891 » 25 črc 2016 15:11

Takže nakoniec to po asi 10 pokusoch došlo až na 100%
LOG:
--------- | AdsFix | g3n-h@ckm@n | 3_22.07.2016.1

----- Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- Start 15:10:36 - 22/07/2016

update on : 22/07/2016 | 10.00 by g3n-h@ckm@n
Contact : http://www.sosvirus.net
Assistance : http://www.sosvirus.net/forum-virus-securite.html
Feedbacks : http://www.sosvirus.net/feedbacks-t75915.html
Facebook : https://www.facebook.com/AdsFixAntiAdware
C:\Users\domin\Desktop\adsfix_3_22.07.2016.1.exe
Boot: Normal boot
[domin (Administrator)] - [DESKTOP-JBSL88G] - (Slovakia [041B])
SID = S-1-5-21-587641703-922834975-2764268489-1001 || [646f6d696e205e5e]
PC : Hewlett-Packard - 1966 - E2U49EA#UUZ
Processor : X64 - 2394 - Intel(R) Core(TM) i7-4700MQ CPU @ 2.40GHz
Bios : Insyde - 06/06/2016 - V.F.67
CoreTemp : 40 C


System : Windows 10 Home (64 bits) Core
RAM memory = Total (MB) : 8319 | Free (MB) : 6629
Pagefile = Total (MB) : 9630 | Free (MB) : 8036
Virtual = Total (MB) : 4194 | Free (MB) : 3898

C:\ -> [Fixed] | [] | Total : 468.06 Go | Free : 289.97 Go -> NTFS [SATA]
D:\ -> [Fixed] | [Hry, Filmy, atď] | Total : 440.49 Go | Free : 35.7 Go -> NTFS [SATA]

Registry saved, to restore : Click on Options & Restore the register (C:\AdsFix\Save\Registry [22.07.2016 @ 15_10_34]) or an element
Restore files or folders deleted by mistake : Click on Options & Restore Files | Folders, Select an item >> "restore"

---------- | Windows Updates

---------- | Browsers

IE : 11.0.10586.494 (© Microsoft Corporation. Všetky práva vyhradené.)
GC : 51.0.2704.103 (Copyright 2015 Google Inc. All rights reserved.)
MS-Edge : 11.0.10586.494 (© Microsoft Corporation. All rights reserved.)

---------- | Security (atcav : 0)

FW : avast! Antivirus Disabled
WMI : OK
WU: Windows Update Service [Manual(3)] = Order
AS: Windows Defender [Manual(3)] = Order
FW: Windows FireWall Service [Auto(2)] = Started
WMI: Windows Management Instrumentation (System Information) [Auto(2)] = Started

---------- | FlashPlayer

ActiveX : 22.0.0.209

---------- | Killed processes

1284 | [Owner : |Parent : 772(services.exe)] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 368.81.) - (8.17.13.6881) = C:\Windows\System32\nvvsvc.exe
1384 | [Owner : |Parent : 1284()] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) - (8.17.13.6881) = C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
1428 | [Owner : |Parent : 772(services.exe)] - (.Intel Corporation - igfxCUIService Module.) - (6.15.10.4248) = C:\Windows\System32\igfxCUIService.exe
1476 | [Owner : |Parent : 772(services.exe)] - (.IDT, Inc. - IDT PC Audio.) - (1.0.6491.0) = C:\Program Files\IDT\WDM\stacsv64.exe
1832 | [Owner : |Parent : 772(services.exe)] - (.Hewlett-Packard Company - HpService.) - (6.0.11.1) = C:\Windows\System32\hpservice.exe
1804 | [Owner : |Parent : 772(services.exe)] - (.Intel Corporation - IntelCpHeciSvc Executable.) - (9.0.31.9000) = C:\Windows\SysWOW64\IntelCpHeciSvc.exe
2112 | [Owner : |Parent : 772(services.exe)] - (.Microsoft Corporation - Spooler SubSystem App.) - (10.0.10586.122) = C:\Windows\System32\spoolsv.exe
2396 | [Owner : SYSTEM |Parent : 772(services.exe)] - (.NVIDIA Corporation - NVIDIA Network Service.) - (2.4.13.69) = C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
2464 | [Owner : SYSTEM |Parent : 772(services.exe)] - (.Synaptics Incorporated - SynapticsWBF Policy Service (EEM).) - (4.5.327.0) = C:\Windows\System32\valWBFPolicyService.exe
2524 | [Owner : SYSTEM |Parent : 772(services.exe)] - (.Synaptics Incorporated - 64-bit Synaptics Pointing Enhance Service.) - (19.2.4.0) = C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
2584 | [Owner : SYSTEM |Parent : 772(services.exe)] - (.NVIDIA Corporation - NVIDIA GeForce ExperienceService.) - (2.11.4.0) = C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
2656 | [Owner : SYSTEM |Parent : 772(services.exe)] - (.NVIDIA Corporation - NVIDIA Streamer Service.) - (7.1.2084.9592) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
3176 | [Owner : NETWORK SERVICE |Parent : 772(services.exe)] - (.NVIDIA Corporation - NVIDIA Network Stream Service.) - (7.1.2084.9592) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
3624 | [Owner : SYSTEM |Parent : 2656()] - (.NVIDIA Corporation - NVIDIA Streamer User Agent.) - (7.1.2084.9592) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
3632 | [Owner : SYSTEM |Parent : 1064(svchost.exe)] - (.Microsoft Corporation - Task Scheduler Engine.) - (10.0.10586.494) = C:\Windows\System32\taskeng.exe
3688 | [Owner : domin |Parent : 1064(svchost.exe)] - (.Microsoft Corporation - Host Process for Windows Tasks.) - (10.0.10586.0) = C:\Windows\System32\taskhostw.exe
3744 | [Owner : domin |Parent : 2524()] - (.Synaptics Incorporated - Synaptics TouchPad 64-bit Enhancements.) - (19.2.4.0) = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3796 | [Owner : SYSTEM |Parent : 3632()] - (.Google Inc. - Inštalačný program Google.) - (1.3.29.5) = C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
3804 | [Owner : LogonSessionId_0_216930 |Parent : 772(services.exe)] - (.Microsoft Corporation - PresentationFontCache.exe.) - (3.0.6920.8693) = C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
3984 | [Owner : domin |Parent : 956(svchost.exe)] - (.Microsoft Corporation - Runtime Broker.) - (10.0.10586.0) = C:\Windows\System32\RuntimeBroker.exe
4148 | [Owner : domin |Parent : 3900()] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) - (19.2.4.0) = C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
4916 | [Owner : domin |Parent : 4816()] - (.Intel Corporation - igfxEM Module.) - (6.15.10.4248) = C:\Windows\System32\igfxEM.exe
4924 | [Owner : domin |Parent : 4816()] - (.Intel Corporation - igfxHK Module.) - (6.15.10.4248) = C:\Windows\System32\igfxHK.exe
4984 | [Owner : domin |Parent : 4816()] - (.-.) - (0.0.0.0) = C:\Windows\System32\igfxTray.exe
5656 | [Owner : domin |Parent : 1384()] - (.NVIDIA Corporation - NVIDIA Settings.) - (7.17.13.6881) = C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
5936 | [Owner : domin |Parent : 4408(explorer.exe)] - (.NVIDIA Corporation - NVIDIA Backend.) - (20.16.6.0) = C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
6116 | [Owner : domin |Parent : 4408(explorer.exe)] - (.IDT, Inc. - IDT PC Audio.) - (1.0.6491.0) = C:\Program Files\IDT\WDM\sttray64.exe
5236 | [Owner : domin |Parent : 4408(explorer.exe)] - (.Microsoft Corporation - Microsoft OneDrive.) - (17.3.6390.509) = C:\Users\domin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
5956 | [Owner : SYSTEM |Parent : 856(winlogon.exe)] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.10586.420) = C:\Windows\System32\fontdrvhost.exe
5724 | [Owner : domin |Parent : 956(svchost.exe)] - (.Microsoft Corporation - Network UX Broker.) - (10.0.10586.420) = C:\Windows\System32\NetworkUXBroker.exe
3612 | [Owner : domin |Parent : 956(svchost.exe)] - (.Microsoft Corporation - Host Process for Setting Synchronization.) - (10.0.10586.494) = C:\Windows\System32\SettingSyncHost.exe
4196 | [Owner : domin |Parent : 772(services.exe)] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe
8924 | [Owner : domin |Parent : 956(svchost.exe)] - (.-.) - (10.1.2123.36) = C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
9128 | [Owner : SYSTEM |Parent : 772(services.exe)] - (.Hewlett-Packard Company - HP Support Solutions Framework Service.) - (8.2.18.7) = C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
4668 | [Owner : domin |Parent : 5376(avastui.exe)] - (.Microsoft Corporation - CTF Loader.) - (10.0.10586.0) = C:\Windows\SysWOW64\ctfmon.exe
6196 | [Owner : LogonSessionId_0_1193349 |Parent : 772(services.exe)] - (.Microsoft Corporation - Windows® installer.) - (5.0.10586.0) = C:\Windows\System32\msiexec.exe
8540 | [Owner : SYSTEM |Parent : 772(services.exe)] - (.Hewlett-Packard Company - HP Software Framework WMI Service.) - (6.5.6.1) = C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe

---------- | Tasks



---------- | Services


---------- | AppCertDlls | AppInit_DLLs


---------- | DNSapi.dll

C:\Windows\System32\dnsapi.dll : \drivers\etc\hosts
C:\Windows\SysWOW64\dnsapi.dll : \drivers\etc\hosts

---------- | Hosts


---------- | SafeBoot


---------- | Winsock


---------- | DNS


---------- | Register

---------- | AdsFix | g3n-h@ckm@n | 3_22.07.2016.1

----- Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- Start 15:13:39 - 22/07/2016

update on : 22/07/2016 | 10.00 by g3n-h@ckm@n
Contact : http://www.sosvirus.net
Assistance : http://www.sosvirus.net/forum-virus-securite.html
Feedbacks : http://www.sosvirus.net/feedbacks-t75915.html
Facebook : https://www.facebook.com/AdsFixAntiAdware
C:\Users\domin\Desktop\adsfix_3_22.07.2016.1.exe
Boot: Normal boot
[domin (Administrator)] - [DESKTOP-JBSL88G] - (Slovakia [041B])
SID = S-1-5-21-587641703-922834975-2764268489-1001 || [646f6d696e205e5e]
PC : Hewlett-Packard - 1966 - E2U49EA#UUZ
Processor : X64 - 2394 - Intel(R) Core(TM) i7-4700MQ CPU @ 2.40GHz
Bios : Insyde - 06/06/2016 - V.F.67
CoreTemp : 42 C


System : Windows 10 Home (64 bits) Core
RAM memory = Total (MB) : 8319 | Free (MB) : 6865
Pagefile = Total (MB) : 9630 | Free (MB) : 8249
Virtual = Total (MB) : 4194 | Free (MB) : 3903

C:\ -> [Fixed] | [] | Total : 468.06 Go | Free : 293.15 Go -> NTFS [SATA]
D:\ -> [Fixed] | [Hry, Filmy, atď] | Total : 440.49 Go | Free : 35.7 Go -> NTFS [SATA]

Registry saved, to restore : Click on Options & Restore the register (C:\AdsFix\Save\Registry [22.07.2016 @ 15_13_37]) or an element
Restore files or folders deleted by mistake : Click on Options & Restore Files | Folders, Select an item >> "restore"

---------- | Windows Updates

---------- | Browsers

IE : 11.0.10586.494 (© Microsoft Corporation. Všetky práva vyhradené.)
GC : 51.0.2704.103 (Copyright 2015 Google Inc. All rights reserved.)
MS-Edge : 11.0.10586.494 (© Microsoft Corporation. All rights reserved.)

---------- | Security (atcav : 0)

FW : avast! Antivirus Disabled
WMI : OK
WU: Windows Update Service [Manual(3)] = Order
AS: Windows Defender [Manual(3)] = Order
FW: Windows FireWall Service [Auto(2)] = Started
WMI: Windows Management Instrumentation (System Information) [Auto(2)] = Started

---------- | FlashPlayer

ActiveX : 22.0.0.209

---------- | Killed processes

3360 | [Owner : |Parent : 772(services.exe)] - (.Microsoft Corporation - PresentationFontCache.exe.) - (3.0.6920.8693) = C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
8644 | [Owner : domin |Parent : 956(svchost.exe)] - (.-.) - (10.1.2123.36) = C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
5416 | [Owner : domin |Parent : 956(svchost.exe)] - (.Microsoft Corporation - Runtime Broker.) - (10.0.10586.0) = C:\Windows\System32\RuntimeBroker.exe
8360 | [Owner : domin |Parent : 772(services.exe)] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe
1928 | [Owner : LogonSessionId_0_1536165 |Parent : 772(services.exe)] - (.Microsoft Corporation - Spooler SubSystem App.) - (10.0.10586.122) = C:\Windows\System32\spoolsv.exe
1944 | [Owner : domin |Parent : 956(svchost.exe)] - (.Microsoft Corporation - Host Process for Setting Synchronization.) - (10.0.10586.494) = C:\Windows\System32\SettingSyncHost.exe
8108 | [Owner : LogonSessionId_0_2689531 |Parent : 772(services.exe)] - (.Microsoft Corporation - Windows® installer.) - (5.0.10586.0) = C:\Windows\System32\msiexec.exe

---------- | Tasks



---------- | Services


---------- | AppCertDlls | AppInit_DLLs


---------- | DNSapi.dll

C:\Windows\System32\dnsapi.dll : \drivers\etc\hosts
C:\Windows\SysWOW64\dnsapi.dll : \drivers\etc\hosts

---------- | Hosts


---------- | SafeBoot


---------- | Winsock


---------- | DNS


---------- | Register

---------- | AdsFix | g3n-h@ckm@n | 3_22.07.2016.1

----- Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- Start 15:18:45 - 22/07/2016

update on : 22/07/2016 | 10.00 by g3n-h@ckm@n
Contact : http://www.sosvirus.net
Assistance : http://www.sosvirus.net/forum-virus-securite.html
Feedbacks : http://www.sosvirus.net/feedbacks-t75915.html
Facebook : https://www.facebook.com/AdsFixAntiAdware
C:\Users\domin\Desktop\adsfix_3_22.07.2016.1.exe
Boot: Normal boot
[domin (Administrator)] - [DESKTOP-JBSL88G] - (slovakia [041B])
SID = S-1-5-21-587641703-922834975-2764268489-1001 || [646f6d696e205e5e]
PC : Hewlett-Packard - 1966 - E2U49EA#UUZ
Processor : X64 - 2394 - Intel(R) Core(TM) i7-4700MQ CPU @ 2.40GHz
Bios : Insyde - 06/06/2016 - V.F.67
CoreTemp : 42 C


System : Windows 10 Home (64 bits) Core
RAM memory = Total (MB) : 8319 | Free (MB) : 6895
Pagefile = Total (MB) : 9630 | Free (MB) : 8304
Virtual = Total (MB) : 4194 | Free (MB) : 3903

C:\ -> [Fixed] | [] | Total : 468.06 Go | Free : 293.14 Go -> NTFS [SATA]
D:\ -> [Fixed] | [Hry, Filmy, atď] | Total : 440.49 Go | Free : 35.7 Go -> NTFS [SATA]

Registry saved, to restore : Click on Options & Restore the register (C:\AdsFix\Save\Registry [22.07.2016 @ 15_18_44]) or an element
Restore files or folders deleted by mistake : Click on Options & Restore Files | Folders, Select an item >> "restore"

---------- | Windows Updates

---------- | Browsers

IE : 11.0.10586.494 (© Microsoft Corporation. Všetky práva vyhradené.)
GC : 51.0.2704.103 (Copyright 2015 Google Inc. All rights reserved.)
MS-Edge : 11.0.10586.494 (© Microsoft Corporation. All rights reserved.)

---------- | Security (atcav : 0)

FW : avast! Antivirus Disabled
WMI : OK
WU: Windows Update Service [Manual(3)] = Order
AS: Windows Defender [Manual(3)] = Order
FW: Windows FireWall Service [Auto(2)] = Started
WMI: Windows Management Instrumentation (System Information) [Auto(2)] = Started

---------- | FlashPlayer

ActiveX : 22.0.0.209

---------- | Killed processes

9140 | [Owner : |Parent : 772(services.exe)] - (.Microsoft Corporation - Spooler SubSystem App.) - (10.0.10586.122) = C:\Windows\System32\spoolsv.exe
2764 | [Owner : domin |Parent : 772(services.exe)] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe
3352 | [Owner : LogonSessionId_0_4723357 |Parent : 772(services.exe)] - (.Microsoft Corporation - Windows® installer.) - (5.0.10586.0) = C:\Windows\System32\msiexec.exe
8100 | [Owner : domin |Parent : 956(svchost.exe)] - (.-.) - (10.1.2123.36) = C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
7892 | [Owner : domin |Parent : 8100()] - (.Microsoft Corporation - Hlásenie problémov systému Windows.) - (10.0.10586.0) = C:\Windows\SysWOW64\WerFault.exe

---------- | Tasks



---------- | Services


---------- | AppCertDlls | AppInit_DLLs


---------- | DNSapi.dll

C:\Windows\System32\dnsapi.dll : \drivers\etc\hosts
C:\Windows\SysWOW64\dnsapi.dll : \drivers\etc\hosts

---------- | Hosts


---------- | SafeBoot


---------- | Winsock


---------- | DNS


---------- | Register

---------- | AdsFix | g3n-h@ckm@n | 3_22.07.2016.1

----- Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- Start 15:25:45 - 22/07/2016

update on : 22/07/2016 | 10.00 by g3n-h@ckm@n
Contact : http://www.sosvirus.net
Assistance : http://www.sosvirus.net/forum-virus-securite.html
Feedbacks : http://www.sosvirus.net/feedbacks-t75915.html
Facebook : https://www.facebook.com/AdsFixAntiAdware
C:\Users\domin\Desktop\adsfix_3_22.07.2016.1.exe
Boot: Normal boot
[domin (Administrator)] - [DESKTOP-JBSL88G] - (Slovakia [041B])
SID = S-1-5-21-587641703-922834975-2764268489-1001 || [646f6d696e205e5e]
PC : Hewlett-Packard - 1966 - E2U49EA#UUZ
Processor : X64 - 2394 - Intel(R) Core(TM) i7-4700MQ CPU @ 2.40GHz
Bios : Insyde - 06/06/2016 - V.F.67
CoreTemp : 42 C


System : Windows 10 Home (64 bits) Core
RAM memory = Total (MB) : 8319 | Free (MB) : 6716
Pagefile = Total (MB) : 9630 | Free (MB) : 8126
Virtual = Total (MB) : 4194 | Free (MB) : 3903

C:\ -> [Fixed] | [] | Total : 468.06 Go | Free : 293.13 Go -> NTFS [SATA]
D:\ -> [Fixed] | [Hry, Filmy, atď] | Total : 440.49 Go | Free : 35.7 Go -> NTFS [SATA]

Registry saved, to restore : Click on Options & Restore the register (C:\AdsFix\Save\Registry [22.07.2016 @ 15_25_42]) or an element
Restore files or folders deleted by mistake : Click on Options & Restore Files | Folders, Select an item >> "restore"

---------- | Windows Updates

---------- | Browsers

IE : 11.0.10586.494 (© Microsoft Corporation. Všetky práva vyhradené.)
GC : 51.0.2704.103 (Copyright 2015 Google Inc. All rights reserved.)
MS-Edge : 11.0.10586.494 (© Microsoft Corporation. All rights reserved.)

---------- | Security (atcav : 0)

FW : avast! Antivirus Disabled
WMI : OK
WU: Windows Update Service [Manual(3)] = Order
AS: Windows Defender [Manual(3)] = Order
FW: Windows FireWall Service [Auto(2)] = Started
WMI: Windows Management Instrumentation (System Information) [Auto(2)] = Started

---------- | FlashPlayer

ActiveX : 22.0.0.209

---------- | Killed processes

1284 | [Owner : |Parent : 768(services.exe)] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 368.81.) - (8.17.13.6881) = C:\Windows\System32\nvvsvc.exe
1328 | [Owner : |Parent : 768(services.exe)] - (.Intel Corporation - igfxCUIService Module.) - (6.15.10.4248) = C:\Windows\System32\igfxCUIService.exe
1404 | [Owner : |Parent : 768(services.exe)] - (.IDT, Inc. - IDT PC Audio.) - (1.0.6491.0) = C:\Program Files\IDT\WDM\stacsv64.exe
1456 | [Owner : |Parent : 1284()] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) - (8.17.13.6881) = C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
1760 | [Owner : |Parent : 768(services.exe)] - (.Intel Corporation - IntelCpHeciSvc Executable.) - (9.0.31.9000) = C:\Windows\SysWOW64\IntelCpHeciSvc.exe
1984 | [Owner : |Parent : 768(services.exe)] - (.Hewlett-Packard Company - HpService.) - (6.0.11.1) = C:\Windows\System32\hpservice.exe
2164 | [Owner : |Parent : 768(services.exe)] - (.Microsoft Corporation - Spooler SubSystem App.) - (10.0.10586.122) = C:\Windows\System32\spoolsv.exe
2580 | [Owner : SYSTEM |Parent : 768(services.exe)] - (.NVIDIA Corporation - NVIDIA GeForce ExperienceService.) - (2.11.4.0) = C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
2776 | [Owner : SYSTEM |Parent : 768(services.exe)] - (.Synaptics Incorporated - 64-bit Synaptics Pointing Enhance Service.) - (19.2.4.0) = C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
2800 | [Owner : SYSTEM |Parent : 768(services.exe)] - (.Synaptics Incorporated - SynapticsWBF Policy Service (EEM).) - (4.5.327.0) = C:\Windows\System32\valWBFPolicyService.exe
2880 | [Owner : SYSTEM |Parent : 768(services.exe)] - (.NVIDIA Corporation - NVIDIA Network Service.) - (2.4.13.69) = C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
2916 | [Owner : SYSTEM |Parent : 768(services.exe)] - (.NVIDIA Corporation - NVIDIA Streamer Service.) - (7.1.2084.9592) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
3480 | [Owner : NETWORK SERVICE |Parent : 768(services.exe)] - (.NVIDIA Corporation - NVIDIA Network Stream Service.) - (7.1.2084.9592) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
3984 | [Owner : SYSTEM |Parent : 2916()] - (.NVIDIA Corporation - NVIDIA Streamer User Agent.) - (7.1.2084.9592) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
3992 | [Owner : SYSTEM |Parent : 716(svchost.exe)] - (.Microsoft Corporation - Task Scheduler Engine.) - (10.0.10586.494) = C:\Windows\System32\taskeng.exe
4004 | [Owner : domin |Parent : 2776()] - (.Synaptics Incorporated - Synaptics TouchPad 64-bit Enhancements.) - (19.2.4.0) = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
4020 | [Owner : domin |Parent : 716(svchost.exe)] - (.Microsoft Corporation - Host Process for Windows Tasks.) - (10.0.10586.0) = C:\Windows\System32\taskhostw.exe
3704 | [Owner : SYSTEM |Parent : 3992()] - (.Google Inc. - Inštalačný program Google.) - (1.3.29.5) = C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
3748 | [Owner : LogonSessionId_0_245075 |Parent : 768(services.exe)] - (.Microsoft Corporation - PresentationFontCache.exe.) - (3.0.6920.8693) = C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
3860 | [Owner : domin |Parent : 952(svchost.exe)] - (.Microsoft Corporation - Runtime Broker.) - (10.0.10586.0) = C:\Windows\System32\RuntimeBroker.exe
4188 | [Owner : domin |Parent : 952(svchost.exe)] - (.-.) - (10.1.2123.36) = C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
4672 | [Owner : domin |Parent : 4388()] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) - (19.2.4.0) = C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
4980 | [Owner : domin |Parent : 4912()] - (.Intel Corporation - igfxEM Module.) - (6.15.10.4248) = C:\Windows\System32\igfxEM.exe
5000 | [Owner : domin |Parent : 4912()] - (.Intel Corporation - igfxHK Module.) - (6.15.10.4248) = C:\Windows\System32\igfxHK.exe
5020 | [Owner : domin |Parent : 4912()] - (.-.) - (0.0.0.0) = C:\Windows\System32\igfxTray.exe
5812 | [Owner : domin |Parent : 1456()] - (.NVIDIA Corporation - NVIDIA Settings.) - (7.17.13.6881) = C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
5880 | [Owner : domin |Parent : 5812()] - (.NVIDIA Corporation - NVIDIA Backend.) - (20.16.6.0) = C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
5428 | [Owner : domin |Parent : 2308()] - (.NVIDIA Corporation - OpenAutomate wrapper cache.) - (30.0.0.0) = C:\Users\domin\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
4552 | [Owner : domin |Parent : 4292(explorer.exe)] - (.IDT, Inc. - IDT PC Audio.) - (1.0.6491.0) = C:\Program Files\IDT\WDM\sttray64.exe
5432 | [Owner : domin |Parent : 4292(explorer.exe)] - (.Microsoft Corporation - Microsoft OneDrive.) - (17.3.6390.509) = C:\Users\domin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
864 | [Owner : domin |Parent : 952(svchost.exe)] - (.Microsoft Corporation - Host Process for Setting Synchronization.) - (10.0.10586.494) = C:\Windows\System32\SettingSyncHost.exe
7376 | [Owner : SYSTEM |Parent : 852(winlogon.exe)] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.10586.420) = C:\Windows\System32\fontdrvhost.exe
8096 | [Owner : domin |Parent : 768(services.exe)] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe
6628 | [Owner : domin |Parent : 4556(avastui.exe)] - (.Microsoft Corporation - CTF Loader.) - (10.0.10586.0) = C:\Windows\SysWOW64\ctfmon.exe
5612 | [Owner : SYSTEM |Parent : 768(services.exe)] - (.Hewlett-Packard Company - HP Support Solutions Framework Service.) - (8.2.18.7) = C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe

---------- | Tasks



---------- | Services


---------- | AppCertDlls | AppInit_DLLs


---------- | DNSapi.dll

C:\Windows\System32\dnsapi.dll : \drivers\etc\hosts
C:\Windows\SysWOW64\dnsapi.dll : \drivers\etc\hosts

---------- | Hosts


---------- | SafeBoot


---------- | Winsock


---------- | DNS


---------- | Register

---------- | AdsFix | g3n-h@ckm@n | 3_22.07.2016.1

----- Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- Start 10:40:41 - 25/07/2016

update on : 22/07/2016 | 10.00 by g3n-h@ckm@n
Contact : http://www.sosvirus.net
Assistance : http://www.sosvirus.net/forum-virus-securite.html
Feedbacks : http://www.sosvirus.net/feedbacks-t75915.html
Facebook : https://www.facebook.com/AdsFixAntiAdware
C:\Users\domin\Desktop\adsfix_3_22.07.2016.1.exe
Boot: SafeMode
[domin (Administrator)] - [DESKTOP-JBSL88G] - (Slovakia [041B])
SID = S-1-5-21-587641703-922834975-2764268489-1001 || [646f6d696e205e5e]
PC : Hewlett-Packard - 1966 - E2U49EA#UUZ
Processor : X64 - 2394 - Intel(R) Core(TM) i7-4700MQ CPU @ 2.40GHz
Bios : Insyde - 06/06/2016 - V.F.67
CoreTemp : 37 C


System : Windows 10 Home (64 bits) Core
RAM memory = Total (MB) : 8319 | Free (MB) : 6909
Pagefile = Total (MB) : 9630 | Free (MB) : 8340
Virtual = Total (MB) : 4194 | Free (MB) : 3924

C:\ -> [Fixed] | [] | Total : 468.06 Go | Free : 292.44 Go -> NTFS [SATA]
D:\ -> [Fixed] | [Hry, Filmy, atď] | Total : 440.49 Go | Free : 35.7 Go -> NTFS [SATA]

Registry saved, to restore : Click on Options & Restore the register (C:\AdsFix\Save\Registry [25.07.2016 @ 10_40_39]) or an element
Restore files or folders deleted by mistake : Click on Options & Restore Files | Folders, Select an item >> "restore"

---------- | Windows Updates

---------- | Browsers

IE : 11.0.10586.494 (© Microsoft Corporation. Všetky práva vyhradené.)
GC : 51.0.2704.103 (Copyright 2015 Google Inc. All rights reserved.)
MS-Edge : 11.0.10586.494 (© Microsoft Corporation. All rights reserved.)

---------- | Security (atcav : 3)

AV : avast! Antivirus Enabled
AS : avast! Antivirus Enabled
FW : avast! Antivirus Enabled
WMI : OK
WU: Windows Update Service [Manual(3)] = Order
AS: Windows Defender [Manual(3)] = Order
FW: Windows FireWall Service [Auto(2)] = Order
WMI: Windows Management Instrumentation (System Information) [Auto(2)] = Started

---------- | FlashPlayer

ActiveX : 22.0.0.209

---------- | Killed processes

1604 | [Owner : domin |Parent : 1536(explorer.exe)] - (.Microsoft Corporation - CTF Loader.) - (10.0.10586.0) = C:\Windows\System32\ctfmon.exe
1852 | [Owner : domin |Parent : 792(svchost.exe)] - (.Microsoft Corporation - Runtime Broker.) - (10.0.10586.0) = C:\Windows\System32\RuntimeBroker.exe
2200 | [Owner : domin |Parent : 792(svchost.exe)] - (.Microsoft Corporation - Microsoft Help and Support.) - (10.0.10586.494) = C:\Windows\HelpPane.exe
2384 | [Owner : domin |Parent : 792(svchost.exe)] - (.Microsoft Corporation - Application Frame Host.) - (10.0.10586.0) = C:\Windows\System32\ApplicationFrameHost.exe
2780 | [Owner : domin |Parent : 1536(explorer.exe)] - (.AVAST Software - avast! Antivirus.) - (12.1.3076.6) = C:\Program Files\AVAST Software\Avast\avastui.exe

---------- | Tasks

Deleted successfully : CreateExplorerShellUnelevatedTask


---------- | Services


---------- | AppCertDlls | AppInit_DLLs


---------- | DNSapi.dll

C:\Windows\System32\dnsapi.dll : \drivers\etc\hosts
C:\Windows\SysWOW64\dnsapi.dll : \drivers\etc\hosts

---------- | Hosts


---------- | SafeBoot


---------- | Winsock


---------- | DNS


---------- | Register

---------- | AdsFix | g3n-h@ckm@n | 3_24.07.2016.2

----- Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- Start 10:57:35 - 25/07/2016

update on : 24/07/2016 | 23.55 by g3n-h@ckm@n
Contact : http://www.sosvirus.net
Assistance : http://www.sosvirus.net/forum-virus-securite.html
Feedbacks : http://www.sosvirus.net/feedbacks-t75915.html
Facebook : https://www.facebook.com/AdsFixAntiAdware
C:\Users\domin\Desktop\adsfix_3_24.07.2016.2.exe
Boot: Normal boot
[domin (Administrator)] - [DESKTOP-JBSL88G] - (Slovania [041B])
SID = S-1-5-21-587641703-922834975-2764268489-1001 || [646f6d696e205e5e]
PC : Hewlett-Packard - 1966 - E2U49EA#UUZ
Processor : X64 - 2394 - Intel(R) Core(TM) i7-4700MQ CPU @ 2.40GHz
Bios : Insyde - 06/06/2016 - V.F.67
CoreTemp : 40 C


System : Windows 10 Home (64 bits) Core
RAM memory = Total (MB) : 8319 | Free (MB) : 6714
Pagefile = Total (MB) : 9630 | Free (MB) : 8140
Virtual = Total (MB) : 4194 | Free (MB) : 3903

C:\ -> [Fixed] | [] | Total : 468.06 Go | Free : 292.21 Go -> NTFS [SATA]
D:\ -> [Fixed] | [Hry, Filmy, atď] | Total : 440.49 Go | Free : 35.7 Go -> NTFS [SATA]

Registry saved, to restore : Click on Options & Restore the register (C:\AdsFix\Save\Registry [25.07.2016 @ 10_57_34]) or an element
Restore files or folders deleted by mistake : Click on Options & Restore Files | Folders, Select an item >> "restore"

---------- | Windows Updates

---------- | Browsers

IE : 11.0.10586.494 (© Microsoft Corporation. Všetky práva vyhradené.)
GC : 51.0.2704.103 (Copyright 2015 Google Inc. All rights reserved.)
MS-Edge : 11.0.10586.494 (© Microsoft Corporation. All rights reserved.)

---------- | Security (atcav : 0)

FW : avast! Antivirus Disabled
WMI : OK
WU: Windows Update Service [Manual(3)] = Order
AS: Windows Defender [Manual(3)] = Order
FW: Windows FireWall Service [Auto(2)] = Started
WMI: Windows Management Instrumentation (System Information) [Auto(2)] = Started

---------- | FlashPlayer

ActiveX : 22.0.0.209

---------- | Killed processes

1316 | [Owner : |Parent : 836(services.exe)] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 368.81.) - (8.17.13.6881) = C:\Windows\System32\nvvsvc.exe
1384 | [Owner : |Parent : 836(services.exe)] - (.Intel Corporation - igfxCUIService Module.) - (6.15.10.4248) = C:\Windows\System32\igfxCUIService.exe
1472 | [Owner : |Parent : 836(services.exe)] - (.IDT, Inc. - IDT PC Audio.) - (1.0.6491.0) = C:\Program Files\IDT\WDM\stacsv64.exe
1608 | [Owner : |Parent : 836(services.exe)] - (.Intel Corporation - IntelCpHeciSvc Executable.) - (9.0.31.9000) = C:\Windows\SysWOW64\IntelCpHeciSvc.exe
1624 | [Owner : |Parent : 1316()] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) - (8.17.13.6881) = C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
1684 | [Owner : |Parent : 836(services.exe)] - (.Hewlett-Packard Company - HpService.) - (6.0.11.1) = C:\Windows\System32\hpservice.exe
2204 | [Owner : |Parent : 836(services.exe)] - (.Microsoft Corporation - Spooler SubSystem App.) - (10.0.10586.122) = C:\Windows\System32\spoolsv.exe
2640 | [Owner : SYSTEM |Parent : 836(services.exe)] - (.Synaptics Incorporated - SynapticsWBF Policy Service (EEM).) - (4.5.327.0) = C:\Windows\System32\valWBFPolicyService.exe
2648 | [Owner : SYSTEM |Parent : 836(services.exe)] - (.NVIDIA Corporation - NVIDIA Streamer Service.) - (7.1.2084.9592) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
2736 | [Owner : SYSTEM |Parent : 836(services.exe)] - (.NVIDIA Corporation - NVIDIA Network Service.) - (2.4.13.69) = C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
1912 | [Owner : SYSTEM |Parent : 836(services.exe)] - (.Synaptics Incorporated - 64-bit Synaptics Pointing Enhance Service.) - (19.2.4.0) = C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
3196 | [Owner : SYSTEM |Parent : 836(services.exe)] - (.NVIDIA Corporation - NVIDIA GeForce ExperienceService.) - (2.11.4.0) = C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
3868 | [Owner : SYSTEM |Parent : 644(svchost.exe)] - (.Microsoft Corporation - Task Scheduler Engine.) - (10.0.10586.494) = C:\Windows\System32\taskeng.exe
3888 | [Owner : domin |Parent : 1912()] - (.Synaptics Incorporated - Synaptics TouchPad 64-bit Enhancements.) - (19.2.4.0) = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3976 | [Owner : LogonSessionId_0_285745 |Parent : 836(services.exe)] - (.Microsoft Corporation - PresentationFontCache.exe.) - (3.0.6920.8693) = C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
3992 | [Owner : SYSTEM |Parent : 3868()] - (.Google Inc. - Inštalačný program Google.) - (1.3.29.5) = C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
652 | [Owner : domin |Parent : 968(svchost.exe)] - (.-.) - (10.1.2123.36) = C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
4152 | [Owner : domin |Parent : 3492()] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) - (19.2.4.0) = C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
4352 | [Owner : domin |Parent : 968(svchost.exe)] - (.Microsoft Corporation - Runtime Broker.) - (10.0.10586.0) = C:\Windows\System32\RuntimeBroker.exe
4796 | [Owner : domin |Parent : 644(svchost.exe)] - (.Microsoft Corporation - Host Process for Windows Tasks.) - (10.0.10586.0) = C:\Windows\System32\taskhostw.exe
4820 | [Owner : NETWORK SERVICE |Parent : 836(services.exe)] - (.NVIDIA Corporation - NVIDIA Network Stream Service.) - (7.1.2084.9592) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
5004 | [Owner : domin |Parent : 4812()] - (.Intel Corporation - igfxEM Module.) - (6.15.10.4248) = C:\Windows\System32\igfxEM.exe
4136 | [Owner : domin |Parent : 4812()] - (.Intel Corporation - igfxHK Module.) - (6.15.10.4248) = C:\Windows\System32\igfxHK.exe
4928 | [Owner : domin |Parent : 4812()] - (.-.) - (0.0.0.0) = C:\Windows\System32\igfxTray.exe
5192 | [Owner : SYSTEM |Parent : 2648()] - (.NVIDIA Corporation - NVIDIA Streamer User Agent.) - (7.1.2084.9592) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
5712 | [Owner : domin |Parent : 1624()] - (.NVIDIA Corporation - NVIDIA Settings.) - (7.17.13.6881) = C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
6052 | [Owner : domin |Parent : 1104(explorer.exe)] - (.NVIDIA Corporation - NVIDIA Backend.) - (20.16.6.0) = C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
2292 | [Owner : domin |Parent : 1104(explorer.exe)] - (.IDT, Inc. - IDT PC Audio.) - (1.0.6491.0) = C:\Program Files\IDT\WDM\sttray64.exe
2028 | [Owner : domin |Parent : 1104(explorer.exe)] - (.Microsoft Corporation - Microsoft OneDrive.) - (17.3.6390.509) = C:\Users\domin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
6716 | [Owner : SYSTEM |Parent : 868(winlogon.exe)] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.10586.420) = C:\Windows\System32\fontdrvhost.exe
5888 | [Owner : domin |Parent : 968(svchost.exe)] - (.Microsoft Corporation - Network UX Broker.) - (10.0.10586.420) = C:\Windows\System32\NetworkUXBroker.exe
6340 | [Owner : domin |Parent : 968(svchost.exe)] - (.Microsoft Corporation - Host Process for Setting Synchronization.) - (10.0.10586.494) = C:\Windows\System32\SettingSyncHost.exe
7968 | [Owner : SYSTEM |Parent : 836(services.exe)] - (.HP Inc. - HP Support Solutions Framework Service.) - (8.5.26.37) = C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
7532 | [Owner : domin |Parent : 836(services.exe)] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.10586.0) = C:\Windows\System32\svchost.exe
6040 | [Owner : domin |Parent : 5348(avastui.exe)] - (.Microsoft Corporation - CTF Loader.) - (10.0.10586.0) = C:\Windows\SysWOW64\ctfmon.exe

---------- | Tasks



---------- | Services


---------- | AppCertDlls | AppInit_DLLs


---------- | DNSapi.dll

C:\Windows\System32\dnsapi.dll : \drivers\etc\hosts
C:\Windows\SysWOW64\dnsapi.dll : \drivers\etc\hosts

---------- | Hosts


---------- | SafeBoot


---------- | Winsock


---------- | DNS


---------- | Register

Deleted successfully : HKLM\SOFTWARE\Microsoft\Tracing\DriverEasy_RASAPI32
Deleted successfully : HKLM\SOFTWARE\Microsoft\Tracing\DriverEasy_RASMANCS
Deleted successfully : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]~[DefaultScope] : {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Deleted successfully : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes]~[DefaultScope]
Deleted successfully : HKU\S-1-5-21-587641703-922834975-2764268489-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} : 1
Deleted successfully : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Deleted successfully : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

---------- | Folders | Files

Deleted successfully : C:\Program Files\IDT\HP_WRT_M12_SRS&BeatsV4.bld (.-.)
Deleted successfully : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Easy\Driver Easy.lnk (.-.)
Deleted successfully : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Easy\Uninstall Driver Easy.lnk (.-.)
Deleted successfully : C:\Users\domin\Downloads\DriverEasy_Setup.exe (Copyright © 2016 Easeware. .-.Driver Easy)
Deleted successfully : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Easy

---------- | .LNK


---------- | opening unknown extension


---------- | Proxy


---------- | Internet Explorer

Repaired : [HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]~[Local Page] : %11%\blank.htm -> C:\Windows\System32\blank.htm
Repaired : [HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]~[Local Page] : %11%\blank.htm -> C:\Windows\System32\blank.htm
Repaired : [HKU\S-1-5-21-587641703-922834975-2764268489-1001\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter]~[Enabled] : -> 2
Repaired : [HKU\S-1-5-21-587641703-922834975-2764268489-1001\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter]~[EnabledV8] : -> 1
---------- | AdsFix | g3n-h@ckm@n | 3_24.07.2016.2

----- Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- Start 13:24:07 - 25/07/2016

update on : 24/07/2016 | 23.55 by g3n-h@ckm@n
Contact : http://www.sosvirus.net
Assistance : http://www.sosvirus.net/forum-virus-securite.html
Feedbacks : http://www.sosvirus.net/feedbacks-t75915.html
Facebook : https://www.facebook.com/AdsFixAntiAdware
C:\Users\domin\Desktop\adsfix_3_24.07.2016.2.exe
Boot: SafeMode
[domin (Administrator)] - [DESKTOP-JBSL88G] - (Switzerland [041B])
SID = S-1-5-21-587641703-922834975-2764268489-1001 || [646f6d696e205e5e]
PC : Hewlett-Packard - 1966 - E2U49EA#UUZ
Processor : X64 - 2394 - Intel(R) Core(TM) i7-4700MQ CPU @ 2.40GHz
Bios : Insyde - 06/06/2016 - V.F.67
CoreTemp : 43 C


System : Windows 10 Home (64 bits) Core
RAM memory = Total (MB) : 8319 | Free (MB) : 6941
Pagefile = Total (MB) : 9630 | Free (MB) : 8368
Virtual = Total (MB) : 4194 | Free (MB) : 3924

C:\ -> [Fixed] | [] | Total : 468.06 Go | Free : 292.13 Go -> NTFS [SATA]
D:\ -> [Fixed] | [Hry, Filmy, atď] | Total : 440.49 Go | Free : 35.7 Go -> NTFS [SATA]

Registry saved, to restore : Click on Options & Restore the register (C:\AdsFix\Save\Registry [25.07.2016 @ 13_24_05]) or an element
Restore files or folders deleted by mistake : Click on Options & Restore Files | Folders, Select an item >> "restore"

---------- | Windows Updates

---------- | Browsers

IE : 11.0.10586.494 (© Microsoft Corporation. Všetky práva vyhradené.)
GC : 51.0.2704.103 (Copyright 2015 Google Inc. All rights reserved.)
MS-Edge : 11.0.10586.494 (© Microsoft Corporation. All rights reserved.)

---------- | Security (atcav : 3)

AV : avast! Antivirus Enabled
AS : avast! Antivirus Enabled
FW : avast! Antivirus Enabled
WMI : OK
WU: Windows Update Service [Manual(3)] = Order
AS: Windows Defender [Manual(3)] = Order
FW: Windows FireWall Service [Auto(2)] = Order
WMI: Windows Management Instrumentation (System Information) [Auto(2)] = Started

---------- | FlashPlayer

ActiveX : 22.0.0.209

---------- | Killed processes

1688 | [Owner : domin |Parent : 1600(explorer.exe)] - (.Microsoft Corporation - CTF Loader.) - (10.0.10586.0) = C:\Windows\System32\ctfmon.exe
1932 | [Owner : domin |Parent : 796(svchost.exe)] - (.Microsoft Corporation - Runtime Broker.) - (10.0.10586.0) = C:\Windows\System32\RuntimeBroker.exe
2376 | [Owner : domin |Parent : 796(svchost.exe)] - (.Microsoft Corporation - Microsoft Help and Support.) - (10.0.10586.494) = C:\Windows\HelpPane.exe
2432 | [Owner : domin |Parent : 796(svchost.exe)] - (.Microsoft Corporation - Application Frame Host.) - (10.0.10586.0) = C:\Windows\System32\ApplicationFrameHost.exe

---------- | Tasks

Deleted successfully : CreateExplorerShellUnelevatedTask


---------- | Services


---------- | AppCertDlls | AppInit_DLLs


---------- | DNSapi.dll

C:\Windows\System32\dnsapi.dll : \drivers\etc\hosts
C:\Windows\SysWOW64\dnsapi.dll : \drivers\etc\hosts

---------- | Hosts


---------- | SafeBoot


---------- | Winsock


---------- | DNS


---------- | Register


---------- | Folders | Files


---------- | .LNK


---------- | opening unknown extension


---------- | Proxy


---------- | Internet Explorer

Repaired : [HKU\S-1-5-21-587641703-922834975-2764268489-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet settings]~[WarNonBadCertReceving] : -> 1
Repaired : [HKU\S-1-5-21-587641703-922834975-2764268489-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet settings]~[WarNonHTTPSToHTTPRedirect] : -> 1
Repaired : [HKU\S-1-5-21-587641703-922834975-2764268489-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar]~[Locked] : 1 -> 0

---------- | Yandex



---------- | Google Chrome

Deleted successfully : C:\Users\domin\AppData\Local\Google\Chrome\User Data\Default\Web Data (.-.) Reseted successfully : SearchURL
Deleted successfully : C:\Users\domin\AppData\Local\Google\Chrome\User Data\Default\Preferences (.-.) Reseted successfully : Preferences
Deleted successfully : C:\Users\domin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (.-.) Reseted successfully : Preferences

C:\Users\domin\AppData\Local\Google\Chrome\User Data\Default\extensions\aohghmighlieiainnegkcijnfilokake = : Google & co - Google & co - https://clients2.google.com/service/update2/crx
C:\Users\domin\AppData\Local\Google\Chrome\User Data\Default\extensions\apdfllckaahabafndbhieahigkjlhalf = : Google & co - https://drive.google.com/?usp=chrome_app - Google & co - [http://docs.google.com/http://drive.google.com/https://docs.google.com/https://drive.google.com/] - https://clients2.google.com/service/update2/crx
C:\Users\domin\AppData\Local\Google\Chrome\User Data\Default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo = : Google & co - http://www.youtube.com - http://www.youtube.com - Google & co - http://clients2.google.com/service/update2/crx
C:\Users\domin\AppData\Local\Google\Chrome\User Data\Default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi = : __MSG_extDesc__ - __MSG_extName__ - https://clients2.google.com/service/update2/crx
C:\Users\domin\AppData\Local\Google\Chrome\User Data\Default\extensions\nmmhkkegccagdldgiimedpiccmgmieda = : Google & co - Google & co - 203784468217.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx
C:\Users\domin\AppData\Local\Google\Chrome\User Data\Default\extensions\pjkljhegncpnkpknbcohdijeoejaedia = : Google & co - https://mail.google.com/mail/ca - Google & co - [*://mail.google.com/mail/ca] - http://clients2.google.com/service/update2/crx

---------- | Chromium



---------- | Comodo Dragon



---------- | Firefox



---------- | SeaMonkey



---------- | Pale moon



---------- | Opera



---------- | Spark



---------- | StartMenuInternet

Repaired : [HKLM\SOFTWARE\Clients\StartMenuInternet\IExplore.exe\shell\open\command]~[] : C:\Program Files\Internet Explorer\iexplore.exe -> "C:\Program Files (x86)\Internet Explorer\iexplore.exe"
Repaired : [HKLM\SOFTWARE\Clients\StartMenuInternet\SafeZoneStable\Shell\open\Command]~[] : "C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" -> "C:\Program Files (x86)\AVAST Software\SZBrowser\Launcher.exe"
Repaired : [HKLM\SOFTWARE\Clients\StartMenuInternet\SafeZoneStable\InstallInfo]~[] : "C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" --makedefaultbrowser -> "C:\Program Files (x86)\AVAST Software\SZBrowser\Launcher.exe" --makedefaultbrowser
Repaired : [HKLM\SOFTWARE\WOW6432Node\Clients\StartMenuInternet\SafeZoneStable\InstallInfo]~[] : "C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" --makedefaultbrowser -> "C:\Program Files (x86)\AVAST Software\SZBrowser\Launcher.exe" --makedefaultbrowser

---------- | Javascript


---------- | Firewall


---------- | ADS


Other(s) report(s)


Analyzed : 254388 | Modified : 7 | Deleted : 4

---------- |EOF| ---------- | 14:26:02 | [45 Ko]

ROCK4891
Level 2.5
Level 2.5
Příspěvky: 307
Registrován: červenec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu Logu - seká sa hudba

Příspěvekod ROCK4891 » 25 črc 2016 15:19

No podľa mna tie reklamy má asi každý na youtube pretože odstrániť sa dajú tak že si zaplatíš za youtubeRED(sa to volá asi) a vtedy je to bez reklám...Väčšinou vyhodí reklamu po 15sek. videa na spodku ale to nieje až taký problém...Horšie je keď asi každé piate video pustí reklamu na celú obrazovku ktorá sa buď dá po 15sek. preskočiť alebo niekedy len po prejdení celej reklamy ( 1min až 2 ).
A to je neskutočne otravné. Ten blocker je super vec a blokuje aj reklamy iných web stránok ako napr. keď si na FB a niečo prezeráš a stále ti vyhadzuje reklamy na nové autá a podobné blbosti. Preto som to mal.
A Utorrent má hlavne z dôvodu vyskúšania hier ako pre nedávnom som si nebol istý či mi pojde Witcher tak som ho najskôr stiahol-odskúšal a potom som ho vymazal a kúpil. A samozrejme občas nejaký ten film. Ale nie nejako často.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu Logu - seká sa hudba

Příspěvekod jaro3 » 25 črc 2016 19:33

je to tak jak píšeš. S tím nic neuděláš.

Pokud nejsou jiné problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

ROCK4891
Level 2.5
Level 2.5
Příspěvky: 307
Registrován: červenec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu Logu - seká sa hudba

Příspěvekod ROCK4891 » 25 črc 2016 21:27

A je nejako ten bloker nebezpečný...má vírus alebo spomaluje NB...pretože by som ho rád nainštaloval aby som sa vyššie uvedenému problému vyhol.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu Logu - seká sa hudba

Příspěvekod jaro3 » 26 črc 2016 09:08

třeba adblock , ale já nic nepoužívám . Nic není na 100% a někdy to způsobuje , že blokuje i něco , co je OK.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Google [Bot] a 66 hostů