Ahoj natáhl sem si nějakou havěď do kompu. Antimalver našel asi 160 hrozeb. Díky za pomoc.Honza
log:
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 19:33:46, on 29.1.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18377)
Boot mode: Normal
Running processes:
C:\Windows\SysWOW64\regsvr32.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\Honza\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" 60
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Tw#D9N0zO8.exe] C:\ProgramData\{e01-03-93-414a8-a11e8-2be1-27365}\Tw#D9N0zO8.exe -r1_5 -r2_1
O4 - HKCU\..\Run: [YfjtRAXx5F.exe] C:\ProgramData\{e01-03-93-414a8-a11e8-2be1-27365}\YfjtRAXx5F.exe 1 5
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Honza\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [Apnlworks] regsvr32.exe C:\Users\Honza\AppData\Local\Apnlworks\MSMCuda.dll
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Global Startup: SOLIDWORKS 2016 Rychlé spuštění.lnk = ?
O4 - Global Startup: SOLIDWORKS Nástroj pro stahování na pozadí.lnk = ?
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DTSInterops (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Small Business Advantage (intelsba) - Intel Corporation - C:\Program Files\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Solver for Flow Simulation 2016 (RemoteSolverDispatcher) - Mentor Graphics Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9767 bytes
díky za help
Honza
havěť Vyřešeno
Re: havěť
log z ADW:
# AdwCleaner v6.042 - Log vytvořen 29/01/2017 v 19:48:35
# Aktualizováno dne 06/01/2017 z Malwarebytes
# Databáze : 2017-01-28.2 [Server]
# Operační systém : Windows 7 Ultimate Service Pack 1 (X64)
# Uživatelské jméno : Honza - HONZA-PC
# Spuštěno z : C:\Users\Honza\Desktop\AdwCleaner.exe
# Mod: Skenování
# Podpora : https://www.malwarebytes.com/support
***** [ Služby ] *****
Nebyly nalezeny žádné škodlivé služby.
***** [ Složky ] *****
Složka nalezena: C:\ProgramData\c55ace07-4855-1
Složka nalezena: C:\ProgramData\c55ace07-7395-0
Složka nalezena: C:\Users\Honza\AppData\Roaming\PC Clean Plus
Složka nalezena: C:\Users\Honza\AppData\Roaming\Event Monitor
Složka nalezena: C:\Users\Honza\AppData\Roaming\Microleaves
Složka nalezena: C:\ProgramData\Microleaves
Složka nalezena: C:\ProgramData\Application Data\Microleaves
Složka nalezena: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus
Složka nalezena: C:\Program Files (x86)\PC Clean Plus
Složka nalezena: C:\Program Files (x86)\SystemHealer
Složka nalezena: C:\Program Files (x86)\Microleaves
Složka nalezena: C:\Program Files (x86)\pccleanplus
***** [ Soubory ] *****
Nebyly nalezeny žádné škodlivé soubory.
***** [ DLL ] *****
Nebyly nalezeny žádné škodlivé DLL.
***** [ WMI ] *****
Nebyly nalezeny žádné škodlivé klíče.
***** [ Zástupci ] *****
Žádný infikovaný zástupce nenalezen.
***** [ Naplánované úlohy ] *****
Naplánovaná úloha nalezena: PPI Update
Naplánovaná úloha nalezena: Online Application v2 Guardian
Naplánovaná úloha nalezena: Online Application v2 Guard
Naplánovaná úloha nalezena: Online Application v2
Naplánovaná úloha nalezena: Online Application Guardian
Naplánovaná úloha nalezena: Online Application Guard
Naplánovaná úloha nalezena: Online Application
Naplánovaná úloha nalezena: Online Application Updater
***** [ Registry ] *****
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c.1
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c.1
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage.24
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c.1
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c.1
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c.1
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c.1
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c.1
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c.1
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage.24
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c.1
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c.1
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c.1
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c.1
Klíč nalezen: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\Conduit
Klíč nalezen: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\PC Clean Plus
Klíč nalezen: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\System Healer
Klíč nalezen: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\PC
Klíč nalezen: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\Event Monitor
Klíč nalezen: HKCU\Software\Conduit
Klíč nalezen: HKCU\Software\PC Clean Plus
Klíč nalezen: HKCU\Software\System Healer
Klíč nalezen: HKCU\Software\PC
Klíč nalezen: HKCU\Software\Event Monitor
Klíč nalezen: HKLM\SOFTWARE\Jawego
Klíč nalezen: HKLM\SOFTWARE\PC Clean Plus
Klíč nalezen: HKLM\SOFTWARE\PC
Klíč nalezen: HKLM\SOFTWARE\Event Monitor
Klíč nalezen: HKLM\SOFTWARE\Microleaves
Klíč nalezen: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Clean Plus_is1
Klíč nalezen: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
Klíč nalezen: [x64] HKCU\Software\Conduit
Klíč nalezen: [x64] HKCU\Software\PC Clean Plus
Klíč nalezen: [x64] HKCU\Software\System Healer
Klíč nalezen: [x64] HKCU\Software\PC
Klíč nalezen: [x64] HKCU\Software\Event Monitor
Klíč nalezen: [x64] HKLM\SOFTWARE\Microleaves
Klíč nalezen: HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
Klíč nalezen: HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
Klíč nalezen: HKLM\SYSTEM\ControlSet002\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
Klíč nalezen: HKLM\SYSTEM\ControlSet002\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
Klíč nalezen: HKLM\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
Klíč nalezen: HKLM\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
***** [ Internetové prohlížeče ] *****
Nebyly nalezeny žádné škodlivé položky prohlížeče Firefox.
Nebyly nalezeny žádné škodlivé položky prohlížeče Chromium.
*************************
C:\AdwCleaner\AdwCleaner[S0].txt - [6120 Bajty] - [29/01/2017 19:48:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6193 Bajty] ##########
# AdwCleaner v6.042 - Log vytvořen 29/01/2017 v 19:48:35
# Aktualizováno dne 06/01/2017 z Malwarebytes
# Databáze : 2017-01-28.2 [Server]
# Operační systém : Windows 7 Ultimate Service Pack 1 (X64)
# Uživatelské jméno : Honza - HONZA-PC
# Spuštěno z : C:\Users\Honza\Desktop\AdwCleaner.exe
# Mod: Skenování
# Podpora : https://www.malwarebytes.com/support
***** [ Služby ] *****
Nebyly nalezeny žádné škodlivé služby.
***** [ Složky ] *****
Složka nalezena: C:\ProgramData\c55ace07-4855-1
Složka nalezena: C:\ProgramData\c55ace07-7395-0
Složka nalezena: C:\Users\Honza\AppData\Roaming\PC Clean Plus
Složka nalezena: C:\Users\Honza\AppData\Roaming\Event Monitor
Složka nalezena: C:\Users\Honza\AppData\Roaming\Microleaves
Složka nalezena: C:\ProgramData\Microleaves
Složka nalezena: C:\ProgramData\Application Data\Microleaves
Složka nalezena: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus
Složka nalezena: C:\Program Files (x86)\PC Clean Plus
Složka nalezena: C:\Program Files (x86)\SystemHealer
Složka nalezena: C:\Program Files (x86)\Microleaves
Složka nalezena: C:\Program Files (x86)\pccleanplus
***** [ Soubory ] *****
Nebyly nalezeny žádné škodlivé soubory.
***** [ DLL ] *****
Nebyly nalezeny žádné škodlivé DLL.
***** [ WMI ] *****
Nebyly nalezeny žádné škodlivé klíče.
***** [ Zástupci ] *****
Žádný infikovaný zástupce nenalezen.
***** [ Naplánované úlohy ] *****
Naplánovaná úloha nalezena: PPI Update
Naplánovaná úloha nalezena: Online Application v2 Guardian
Naplánovaná úloha nalezena: Online Application v2 Guard
Naplánovaná úloha nalezena: Online Application v2
Naplánovaná úloha nalezena: Online Application Guardian
Naplánovaná úloha nalezena: Online Application Guard
Naplánovaná úloha nalezena: Online Application
Naplánovaná úloha nalezena: Online Application Updater
***** [ Registry ] *****
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c.1
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c.1
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage.24
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c.1
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c.1
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c.1
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c
Klíč nalezen: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c.1
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c.1
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c.1
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage.24
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c.1
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c.1
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c.1
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c
Klíč nalezen: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c.1
Klíč nalezen: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\Conduit
Klíč nalezen: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\PC Clean Plus
Klíč nalezen: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\System Healer
Klíč nalezen: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\PC
Klíč nalezen: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\Event Monitor
Klíč nalezen: HKCU\Software\Conduit
Klíč nalezen: HKCU\Software\PC Clean Plus
Klíč nalezen: HKCU\Software\System Healer
Klíč nalezen: HKCU\Software\PC
Klíč nalezen: HKCU\Software\Event Monitor
Klíč nalezen: HKLM\SOFTWARE\Jawego
Klíč nalezen: HKLM\SOFTWARE\PC Clean Plus
Klíč nalezen: HKLM\SOFTWARE\PC
Klíč nalezen: HKLM\SOFTWARE\Event Monitor
Klíč nalezen: HKLM\SOFTWARE\Microleaves
Klíč nalezen: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Clean Plus_is1
Klíč nalezen: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
Klíč nalezen: [x64] HKCU\Software\Conduit
Klíč nalezen: [x64] HKCU\Software\PC Clean Plus
Klíč nalezen: [x64] HKCU\Software\System Healer
Klíč nalezen: [x64] HKCU\Software\PC
Klíč nalezen: [x64] HKCU\Software\Event Monitor
Klíč nalezen: [x64] HKLM\SOFTWARE\Microleaves
Klíč nalezen: HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
Klíč nalezen: HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
Klíč nalezen: HKLM\SYSTEM\ControlSet002\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
Klíč nalezen: HKLM\SYSTEM\ControlSet002\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
Klíč nalezen: HKLM\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
Klíč nalezen: HKLM\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
***** [ Internetové prohlížeče ] *****
Nebyly nalezeny žádné škodlivé položky prohlížeče Firefox.
Nebyly nalezeny žádné škodlivé položky prohlížeče Chromium.
*************************
C:\AdwCleaner\AdwCleaner[S0].txt - [6120 Bajty] - [29/01/2017 19:48:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6193 Bajty] ##########
Re: havěť
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 29.1.2017
Čas skenování: 19:51
Protokol:
Správce: Ano
Verze: 2.2.1.1043
Databáze malwaru: v2017.01.29.05
Databáze rootkitů: v2016.11.20.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Honza
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 305180
Uplynulý čas: 18 min, 51 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 6
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe, 2564, , [9f0a3b469117063086e3616da9577b85]
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe, 2576, , [9f0a3b469117063086e3616da9577b85]
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe, 2560, , [9f0a3b469117063086e3616da9577b85]
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.exe, 2584, , [8d1c0180abfdc86ed891b915e818768a]
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.exe, 2592, , [8d1c0180abfdc86ed891b915e818768a]
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.exe, 2596, , [8d1c0180abfdc86ed891b915e818768a]
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 27
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROLEAVES\Online.io Application, , [9a0fe49d7f2963d3ef617ca70ff1b54b],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{09D142EA-9D36-418D-9470-C9870998AFF7}, , [77321e63e7c1013554e852d1b14f8080],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{32A7D01C-BA1A-4105-9BA1-89B7AD0C17CC}, , [dacfc1c0a9ffce682e0e1d0652aef30d],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{508ACD6F-24FD-41D8-9470-DCB6A46A6861}, , [6643c7bae8c056e0d765f92a31cf8080],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5AE12EA8-BC26-4B17-99B9-82FDC46E30C8}, , [c7e2e49d5c4c10262a12859e40c0a65a],
PUP.Optional.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{76B53755-E2EC-46B5-B289-2DDE04A7A21A}, , [3970374a60480b2bcc8dab11d42e12ee],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{A51D20F3-C1CD-4335-803A-FF57A641DF6F}, , [b2f7d0b15f49d75fdd5fff24b34d0bf5],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EFFEFBCC-40E3-461D-9065-AA1C34AF1609}, , [3772800137710a2c6ece82a1db25867a],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F3730572-CCC8-4EB1-9CCD-9DF757B97DD7}, , [f9b0b6cb961223137dbf52d167999967],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application, , [e4c51b66d8d0c96dc1a8d84bf010b947],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application Guard, , [c8e1f58ca4040531155469bac53bd32d],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application Guardian, , [decb6f127e2ac076d1988b9846ba6c94],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application Updater, , [ebbeb1d0e2c6eb4b6009ae75dc248e72],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application v2, , [fbae98e94f5989adc7a2c1622bd5fc04],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application v2 Guard, , [9b0ebcc5a10702343d2c1e05d9275ca4],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application v2 Guardian, , [3d6cdea38523c4722d3c20037d83e41c],
PUP.Optional.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\PPI Update, , [b0f9473abbed191d72e85c6070928a76],
PUP.Optional.PCCleanPlus, HKLM\SOFTWARE\WOW6432NODE\PC Clean Plus, , [7138077a4d5b38fec313dfc256adbb45],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROLEAVES\Online Application Installer, , [decbfb86f1b7b87ef24df47af10f8977],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROLEAVES\Online.io Application, , [8227fd844b5dac8a2f21e142e51b639d],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4C6314F6-2DE8-4354-856A-787679AEF407}, , [03a66b165b4d9f97c0aaf82116ea51af],
PUP.Optional.PCCleanPlus, HKLM\SOFTWARE\WOW6432NODE\PC\CLEAN\Plus, , [b0f9d0b15058ac8a81fd140908fc7c84],
PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\04262113-2A31-48E1-B4BB-3B42174BEA0F, , [a1081a67d4d48caaee75c698b749ae52],
PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\E24B7131-D039-43CB-9E6F-AD4BE601EC1F, , [3c6d6e130e9af046ee758cd2827e0cf4],
PUP.Optional.PCCleanPlus, HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\SOFTWARE\PC Clean Plus, , [1f8ac6bb70384de9f7dd0a97ff04956b],
PUP.Optional.PCCleanPlus, HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\SOFTWARE\PC\CLEAN\Plus, , [fcad0b76ecbcaf8710c51e839370bb45],
PUP.Optional.SystemHealer, HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\SOFTWARE\SYSTEM HEALER, , [d0d9176ad7d1a1952f77b9f87a89e719],
Hodnoty registru: 13
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{09D142EA-9D36-418D-9470-C9870998AFF7}|Path, \Online Application Guardian, , [77321e63e7c1013554e852d1b14f8080]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{32A7D01C-BA1A-4105-9BA1-89B7AD0C17CC}|Path, \Online Application Guard, , [dacfc1c0a9ffce682e0e1d0652aef30d]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{508ACD6F-24FD-41D8-9470-DCB6A46A6861}|Path, \Online Application v2 Guardian, , [6643c7bae8c056e0d765f92a31cf8080]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5AE12EA8-BC26-4B17-99B9-82FDC46E30C8}|Path, \Online Application v2 Guard, , [c7e2e49d5c4c10262a12859e40c0a65a]
PUP.Optional.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{76B53755-E2EC-46B5-B289-2DDE04A7A21A}|Path, \PPI Update, , [3970374a60480b2bcc8dab11d42e12ee]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{A51D20F3-C1CD-4335-803A-FF57A641DF6F}|Path, \Online Application, , [b2f7d0b15f49d75fdd5fff24b34d0bf5]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EFFEFBCC-40E3-461D-9065-AA1C34AF1609}|Path, \Online Application Updater, , [3772800137710a2c6ece82a1db25867a]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F3730572-CCC8-4EB1-9CCD-9DF757B97DD7}|Path, \Online Application v2, , [f9b0b6cb961223137dbf52d167999967]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4C6314F6-2DE8-4354-856A-787679AEF407}|Contact, contact@online.io, , [2d7c235e2f7990a66fedb3ad4cb4b14f]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4C6314F6-2DE8-4354-856A-787679AEF407}|URLInfoAbout, http://online.io/, , [03a66b165b4d9f97c0aaf82116ea51af]
PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\04262113-2a31-48e1-b4bb-3b42174bea0f|Description, One System Care battery save scheme., , [a1081a67d4d48caaee75c698b749ae52]
PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\e24b7131-d039-43cb-9e6f-ad4be601ec1f|Description, One System Care game scheme., , [3c6d6e130e9af046ee758cd2827e0cf4]
PUP.Optional.SystemHealer, HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\SOFTWARE\SYSTEM HEALER|CartURL, 1, , [d0d9176ad7d1a1952f77b9f87a89e719]
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 13
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\Partial Backups, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.OnlineIO, C:\ProgramData\Microleaves\Online.io Application, , [f2b7552c3771171fd29989f440c0a060],
PUP.Optional.OnlineIO, C:\ProgramData\Microleaves\Online.io Application\updates, , [f2b7552c3771171fd29989f440c0a060],
PUP.Optional.OnlineIO, C:\ProgramData\Microleaves\Online.io Application\updates\1.15.0, , [f2b7552c3771171fd29989f440c0a060],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application, , [6f3a4a373672e2546e6d346cc13fde22],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\pccleanplus, , [d6d35829a503c86eba5da810bf415ea2],
PUP.Optional.PCCleanPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus, , [2d7ccdb473356accdab65761e41e18e8],
PUP.Optional.DNSUnlocker.ACMB2, C:\ProgramData\c55ace07-4855-1, , [6643bbc6c4e484b2261304b68b77e818],
PUP.Optional.DNSUnlocker.ACMB2, C:\ProgramData\c55ace07-7395-0, , [f6b361207830dc5a78c18e2c44be9868],
PUP.Optional.SystemHealer, C:\Program Files (x86)\SystemHealer, , [d0d9b4cd1b8d290d098c06b4b25040c0],
Soubory: 99
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe, , [9f0a3b469117063086e3616da9577b85],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.exe, , [8d1c0180abfdc86ed891b915e818768a],
PUP.Optional.Amonetize, C:\Program Files (x86)\Removewat 2.2.7\Removewat Final__9774_il395.exe, , [4861542d3a6e45f193fbbb01b64b847c],
Ransom.Cerber, C:\Program Files (x86)\Removewat 2.2.7\Windows_Activaton.exe, , [55549fe270383303560a49882fd13ec2],
PUP.Optional.InstallCore, C:\Program Files (x86)\Removewat 2.2.7\windows_reg_ac.exe, , [8920acd52880d5617ea363a4000050b0],
PUP.Optional.SystemHealer, C:\Program Files (x86)\SystemHealer\RescueMonitor.exe, , [c4e54d34bfe9c175ce0a98a6e719a759],
PUP.Optional.EventMonitor, C:\Program Files (x86)\PC Clean Plus\emsetup.exe, , [a702bfc2b1f72313ad80244cab55e21e],
PUP.Optional.OnlineIO, C:\Windows\Temp\2eb9ee42e12d953bcdf487c7c30f4a51\Online Application Updater.exe, , [68413d44f3b550e63138705edc24e51b],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application, , [1594d0b15652cf67512359ca956bde22],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application Guard, , [9415acd54563d95dd79dd84bb64aae52],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application Guardian, , [91186e13c5e3c96d8aea56cdd62a10f0],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application Updater, , [9316fe83c5e3de5882f2c75c3fc13bc5],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application v2, , [66434a372e7ab0862d472cf7b24e2ed2],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application v2 Guard, , [7c2d4f32d2d637ff581c1b084eb218e8],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application v2 Guardian, , [cfdab0d1495f59dd076d939057a9db25],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\log_01-29-2017.log, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\backup0.bin, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\backup3.bin, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\backup6.bin, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\eng_pcp.dat, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\ExcludeList.pcp, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\results.pcp, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\TempHLList.pcp, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\Partial Backups\00000001.rmx, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\Partial Backups\00000001.rxb, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\eng_em.ini, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\French_em.ini, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\German_em.ini, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\ininotfound0.ini, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\isxdl.dll, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\japan_em.ini, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\log_01-29-2017.log, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.Downloader, C:\Windows\System32\Tasks\PPI Update, , [0d9cd3aebdeb072ff5623b81da2823dd],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.myway.com_0.localstorage, , [8029cab76543300611a1aebb0ef5d62a],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.myway.com_0.localstorage-journal, , [8524750c4167c6702d856efb51b24ab6],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.tb.ask.com_0.localstorage, , [34754b36416742f4654e2a3f08fb0cf4],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.tb.ask.com_0.localstorage-journal, , [2881473a2187c571981b2445a45fe41c],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\unins000.dat, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Finnish_pcp_fi.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Italian_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Portuguese_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Chinese_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Chinese_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Danish_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Danish_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Dutch_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Dutch_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\eng_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\eng_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\FileList.pcp, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Italian_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Japanese_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Japanese_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\korean_pcp_ko.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\korean_uninst_ko.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Norwegian_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Norwegian_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\PCCPUns.exe, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\polish_pcp_pl.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\polish_uninst_pl.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\portugese_pcp_pt.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\portugese_uninst_pt.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Finnish_uninst_fi.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\French_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\French_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\German_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\German_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\greek_pcp_el.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\greek_uninst_el.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\install_left_image.bmp, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\isxdl.dll, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Portuguese_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\RegList.pcp, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\russian_pcp_ru.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\russian_uninst_ru.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Spanish_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\spanish_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Swedish_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\swedish_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\TPS.ico, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\TraditionalCn_pcp_zh-tw.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\traditionalcn_uninst_zh-tw.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\turkish_pcp_tr.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Turkish_uninst_tr.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\unins000.msg, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\xmllite.dll, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.Amonetize.Gen, C:\ProgramData\c55ace07-4855-1\BITE769.tmp, , [70391071f0b840f65e478620e41f6a96],
PUP.Optional.Amonetize.Gen, C:\ProgramData\c55ace07-7395-0\BITE8D1.tmp, , [87223849e3c593a31293faac867ddf21],
PUP.Optional.OnlineIO, C:\ProgramData\Microleaves\Online.io Application\updates\updates.aiu, , [f2b7552c3771171fd29989f440c0a060],
PUP.Optional.OnlineIO, C:\ProgramData\Microleaves\Online.io Application\updates\1.15.0\Online.IO-installer1.15.0.exe, , [f2b7552c3771171fd29989f440c0a060],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online Application Updater.exe, , [6f3a4a373672e2546e6d346cc13fde22],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online Application Updater.ini, , [6f3a4a373672e2546e6d346cc13fde22],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online.io EULA.url, , [6f3a4a373672e2546e6d346cc13fde22],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online.io Privacy.url, , [6f3a4a373672e2546e6d346cc13fde22],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Uninstall Online Application.lnk, , [6f3a4a373672e2546e6d346cc13fde22],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\pccleanplus\uninstaller.exe.config, , [d6d35829a503c86eba5da810bf415ea2],
PUP.Optional.PCCleanPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus\PC Clean Plus.lnk, , [2d7ccdb473356accdab65761e41e18e8],
PUP.Optional.PCCleanPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus\Register PC Clean Plus.lnk, , [2d7ccdb473356accdab65761e41e18e8],
PUP.Optional.PCCleanPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus\Uninstall PC Clean Plus.lnk, , [2d7ccdb473356accdab65761e41e18e8],
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)
www.malwarebytes.org
Datum skenování: 29.1.2017
Čas skenování: 19:51
Protokol:
Správce: Ano
Verze: 2.2.1.1043
Databáze malwaru: v2017.01.29.05
Databáze rootkitů: v2016.11.20.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Honza
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 305180
Uplynulý čas: 18 min, 51 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 6
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe, 2564, , [9f0a3b469117063086e3616da9577b85]
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe, 2576, , [9f0a3b469117063086e3616da9577b85]
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe, 2560, , [9f0a3b469117063086e3616da9577b85]
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.exe, 2584, , [8d1c0180abfdc86ed891b915e818768a]
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.exe, 2592, , [8d1c0180abfdc86ed891b915e818768a]
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.exe, 2596, , [8d1c0180abfdc86ed891b915e818768a]
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 27
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROLEAVES\Online.io Application, , [9a0fe49d7f2963d3ef617ca70ff1b54b],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{09D142EA-9D36-418D-9470-C9870998AFF7}, , [77321e63e7c1013554e852d1b14f8080],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{32A7D01C-BA1A-4105-9BA1-89B7AD0C17CC}, , [dacfc1c0a9ffce682e0e1d0652aef30d],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{508ACD6F-24FD-41D8-9470-DCB6A46A6861}, , [6643c7bae8c056e0d765f92a31cf8080],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5AE12EA8-BC26-4B17-99B9-82FDC46E30C8}, , [c7e2e49d5c4c10262a12859e40c0a65a],
PUP.Optional.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{76B53755-E2EC-46B5-B289-2DDE04A7A21A}, , [3970374a60480b2bcc8dab11d42e12ee],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{A51D20F3-C1CD-4335-803A-FF57A641DF6F}, , [b2f7d0b15f49d75fdd5fff24b34d0bf5],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EFFEFBCC-40E3-461D-9065-AA1C34AF1609}, , [3772800137710a2c6ece82a1db25867a],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F3730572-CCC8-4EB1-9CCD-9DF757B97DD7}, , [f9b0b6cb961223137dbf52d167999967],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application, , [e4c51b66d8d0c96dc1a8d84bf010b947],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application Guard, , [c8e1f58ca4040531155469bac53bd32d],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application Guardian, , [decb6f127e2ac076d1988b9846ba6c94],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application Updater, , [ebbeb1d0e2c6eb4b6009ae75dc248e72],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application v2, , [fbae98e94f5989adc7a2c1622bd5fc04],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application v2 Guard, , [9b0ebcc5a10702343d2c1e05d9275ca4],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application v2 Guardian, , [3d6cdea38523c4722d3c20037d83e41c],
PUP.Optional.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\PPI Update, , [b0f9473abbed191d72e85c6070928a76],
PUP.Optional.PCCleanPlus, HKLM\SOFTWARE\WOW6432NODE\PC Clean Plus, , [7138077a4d5b38fec313dfc256adbb45],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROLEAVES\Online Application Installer, , [decbfb86f1b7b87ef24df47af10f8977],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROLEAVES\Online.io Application, , [8227fd844b5dac8a2f21e142e51b639d],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4C6314F6-2DE8-4354-856A-787679AEF407}, , [03a66b165b4d9f97c0aaf82116ea51af],
PUP.Optional.PCCleanPlus, HKLM\SOFTWARE\WOW6432NODE\PC\CLEAN\Plus, , [b0f9d0b15058ac8a81fd140908fc7c84],
PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\04262113-2A31-48E1-B4BB-3B42174BEA0F, , [a1081a67d4d48caaee75c698b749ae52],
PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\E24B7131-D039-43CB-9E6F-AD4BE601EC1F, , [3c6d6e130e9af046ee758cd2827e0cf4],
PUP.Optional.PCCleanPlus, HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\SOFTWARE\PC Clean Plus, , [1f8ac6bb70384de9f7dd0a97ff04956b],
PUP.Optional.PCCleanPlus, HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\SOFTWARE\PC\CLEAN\Plus, , [fcad0b76ecbcaf8710c51e839370bb45],
PUP.Optional.SystemHealer, HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\SOFTWARE\SYSTEM HEALER, , [d0d9176ad7d1a1952f77b9f87a89e719],
Hodnoty registru: 13
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{09D142EA-9D36-418D-9470-C9870998AFF7}|Path, \Online Application Guardian, , [77321e63e7c1013554e852d1b14f8080]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{32A7D01C-BA1A-4105-9BA1-89B7AD0C17CC}|Path, \Online Application Guard, , [dacfc1c0a9ffce682e0e1d0652aef30d]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{508ACD6F-24FD-41D8-9470-DCB6A46A6861}|Path, \Online Application v2 Guardian, , [6643c7bae8c056e0d765f92a31cf8080]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5AE12EA8-BC26-4B17-99B9-82FDC46E30C8}|Path, \Online Application v2 Guard, , [c7e2e49d5c4c10262a12859e40c0a65a]
PUP.Optional.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{76B53755-E2EC-46B5-B289-2DDE04A7A21A}|Path, \PPI Update, , [3970374a60480b2bcc8dab11d42e12ee]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{A51D20F3-C1CD-4335-803A-FF57A641DF6F}|Path, \Online Application, , [b2f7d0b15f49d75fdd5fff24b34d0bf5]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EFFEFBCC-40E3-461D-9065-AA1C34AF1609}|Path, \Online Application Updater, , [3772800137710a2c6ece82a1db25867a]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F3730572-CCC8-4EB1-9CCD-9DF757B97DD7}|Path, \Online Application v2, , [f9b0b6cb961223137dbf52d167999967]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4C6314F6-2DE8-4354-856A-787679AEF407}|Contact, contact@online.io, , [2d7c235e2f7990a66fedb3ad4cb4b14f]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4C6314F6-2DE8-4354-856A-787679AEF407}|URLInfoAbout, http://online.io/, , [03a66b165b4d9f97c0aaf82116ea51af]
PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\04262113-2a31-48e1-b4bb-3b42174bea0f|Description, One System Care battery save scheme., , [a1081a67d4d48caaee75c698b749ae52]
PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\e24b7131-d039-43cb-9e6f-ad4be601ec1f|Description, One System Care game scheme., , [3c6d6e130e9af046ee758cd2827e0cf4]
PUP.Optional.SystemHealer, HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\SOFTWARE\SYSTEM HEALER|CartURL, 1, , [d0d9176ad7d1a1952f77b9f87a89e719]
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 13
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\Partial Backups, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.OnlineIO, C:\ProgramData\Microleaves\Online.io Application, , [f2b7552c3771171fd29989f440c0a060],
PUP.Optional.OnlineIO, C:\ProgramData\Microleaves\Online.io Application\updates, , [f2b7552c3771171fd29989f440c0a060],
PUP.Optional.OnlineIO, C:\ProgramData\Microleaves\Online.io Application\updates\1.15.0, , [f2b7552c3771171fd29989f440c0a060],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application, , [6f3a4a373672e2546e6d346cc13fde22],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\pccleanplus, , [d6d35829a503c86eba5da810bf415ea2],
PUP.Optional.PCCleanPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus, , [2d7ccdb473356accdab65761e41e18e8],
PUP.Optional.DNSUnlocker.ACMB2, C:\ProgramData\c55ace07-4855-1, , [6643bbc6c4e484b2261304b68b77e818],
PUP.Optional.DNSUnlocker.ACMB2, C:\ProgramData\c55ace07-7395-0, , [f6b361207830dc5a78c18e2c44be9868],
PUP.Optional.SystemHealer, C:\Program Files (x86)\SystemHealer, , [d0d9b4cd1b8d290d098c06b4b25040c0],
Soubory: 99
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe, , [9f0a3b469117063086e3616da9577b85],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.exe, , [8d1c0180abfdc86ed891b915e818768a],
PUP.Optional.Amonetize, C:\Program Files (x86)\Removewat 2.2.7\Removewat Final__9774_il395.exe, , [4861542d3a6e45f193fbbb01b64b847c],
Ransom.Cerber, C:\Program Files (x86)\Removewat 2.2.7\Windows_Activaton.exe, , [55549fe270383303560a49882fd13ec2],
PUP.Optional.InstallCore, C:\Program Files (x86)\Removewat 2.2.7\windows_reg_ac.exe, , [8920acd52880d5617ea363a4000050b0],
PUP.Optional.SystemHealer, C:\Program Files (x86)\SystemHealer\RescueMonitor.exe, , [c4e54d34bfe9c175ce0a98a6e719a759],
PUP.Optional.EventMonitor, C:\Program Files (x86)\PC Clean Plus\emsetup.exe, , [a702bfc2b1f72313ad80244cab55e21e],
PUP.Optional.OnlineIO, C:\Windows\Temp\2eb9ee42e12d953bcdf487c7c30f4a51\Online Application Updater.exe, , [68413d44f3b550e63138705edc24e51b],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application, , [1594d0b15652cf67512359ca956bde22],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application Guard, , [9415acd54563d95dd79dd84bb64aae52],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application Guardian, , [91186e13c5e3c96d8aea56cdd62a10f0],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application Updater, , [9316fe83c5e3de5882f2c75c3fc13bc5],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application v2, , [66434a372e7ab0862d472cf7b24e2ed2],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application v2 Guard, , [7c2d4f32d2d637ff581c1b084eb218e8],
PUP.Optional.OnlineIO, C:\Windows\System32\Tasks\Online Application v2 Guardian, , [cfdab0d1495f59dd076d939057a9db25],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\log_01-29-2017.log, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\backup0.bin, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\backup3.bin, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\backup6.bin, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\eng_pcp.dat, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\ExcludeList.pcp, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\results.pcp, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\TempHLList.pcp, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\Partial Backups\00000001.rmx, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.PCCleanPlus, C:\Users\Honza\AppData\Roaming\PC Clean Plus\Partial Backups\00000001.rxb, , [8d1c730e3771999dcd7f07266d937c84],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\eng_em.ini, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\French_em.ini, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\German_em.ini, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\ininotfound0.ini, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\isxdl.dll, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\japan_em.ini, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.EventMonitor, C:\Users\Honza\AppData\Roaming\Event Monitor\log_01-29-2017.log, , [9a0fee934e5a979fcd030d5b827e30d0],
PUP.Optional.Downloader, C:\Windows\System32\Tasks\PPI Update, , [0d9cd3aebdeb072ff5623b81da2823dd],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.myway.com_0.localstorage, , [8029cab76543300611a1aebb0ef5d62a],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.myway.com_0.localstorage-journal, , [8524750c4167c6702d856efb51b24ab6],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.tb.ask.com_0.localstorage, , [34754b36416742f4654e2a3f08fb0cf4],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.tb.ask.com_0.localstorage-journal, , [2881473a2187c571981b2445a45fe41c],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\unins000.dat, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Finnish_pcp_fi.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Italian_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Portuguese_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Chinese_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Chinese_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Danish_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Danish_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Dutch_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Dutch_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\eng_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\eng_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\FileList.pcp, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Italian_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Japanese_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Japanese_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\korean_pcp_ko.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\korean_uninst_ko.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Norwegian_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Norwegian_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\PCCPUns.exe, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\polish_pcp_pl.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\polish_uninst_pl.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\portugese_pcp_pt.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\portugese_uninst_pt.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Finnish_uninst_fi.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\French_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\French_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\German_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\German_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\greek_pcp_el.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\greek_uninst_el.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\install_left_image.bmp, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\isxdl.dll, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Portuguese_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\RegList.pcp, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\russian_pcp_ru.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\russian_uninst_ru.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Spanish_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\spanish_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Swedish_pcp.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\swedish_uninst.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\TPS.ico, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\TraditionalCn_pcp_zh-tw.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\traditionalcn_uninst_zh-tw.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\turkish_pcp_tr.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\Turkish_uninst_tr.ini, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\unins000.msg, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\PC Clean Plus\xmllite.dll, , [3a6f2f526e3a4fe7d0f2623fe71c768a],
PUP.Optional.Amonetize.Gen, C:\ProgramData\c55ace07-4855-1\BITE769.tmp, , [70391071f0b840f65e478620e41f6a96],
PUP.Optional.Amonetize.Gen, C:\ProgramData\c55ace07-7395-0\BITE8D1.tmp, , [87223849e3c593a31293faac867ddf21],
PUP.Optional.OnlineIO, C:\ProgramData\Microleaves\Online.io Application\updates\updates.aiu, , [f2b7552c3771171fd29989f440c0a060],
PUP.Optional.OnlineIO, C:\ProgramData\Microleaves\Online.io Application\updates\1.15.0\Online.IO-installer1.15.0.exe, , [f2b7552c3771171fd29989f440c0a060],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online Application Updater.exe, , [6f3a4a373672e2546e6d346cc13fde22],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online Application Updater.ini, , [6f3a4a373672e2546e6d346cc13fde22],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online.io EULA.url, , [6f3a4a373672e2546e6d346cc13fde22],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Online.io Privacy.url, , [6f3a4a373672e2546e6d346cc13fde22],
PUP.Optional.OnlineIO, C:\Program Files (x86)\Microleaves\Online.io Application\Uninstall Online Application.lnk, , [6f3a4a373672e2546e6d346cc13fde22],
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\pccleanplus\uninstaller.exe.config, , [d6d35829a503c86eba5da810bf415ea2],
PUP.Optional.PCCleanPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus\PC Clean Plus.lnk, , [2d7ccdb473356accdab65761e41e18e8],
PUP.Optional.PCCleanPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus\Register PC Clean Plus.lnk, , [2d7ccdb473356accdab65761e41e18e8],
PUP.Optional.PCCleanPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus\Uninstall PC Clean Plus.lnk, , [2d7ccdb473356accdab65761e41e18e8],
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)
- jerabina
- člen Security týmu
-
Level 6
- Příspěvky: 3647
- Registrován: březen 13
- Bydliště: Litoměřice
- Pohlaví:
- Stav:
Offline
Re: havěť
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.
Spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.adlice.com/download/roguekil ... HlwZT14ODY
64bit.:
http://www.adlice.com/download/roguekil ... HlwZT14NjQ
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7,8,10 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Open Report “ , v okně pak na „Open TXT“ a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.
Spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.adlice.com/download/roguekil ... HlwZT14ODY
64bit.:
http://www.adlice.com/download/roguekil ... HlwZT14NjQ
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7,8,10 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Open Report “ , v okně pak na „Open TXT“ a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod
Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.
HJT návod
Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.
Re: havěť
# AdwCleaner v6.043 - Log vytvořen 29/01/2017 v 22:56:07
# Aktualizováno dne 27/01/2017 z Malwarebytes
# Databáze : 2017-01-29.1 [Server]
# Operační systém : Windows 7 Ultimate Service Pack 1 (X64)
# Uživatelské jméno : Honza - HONZA-PC
# Spuštěno z : C:\Users\Honza\Desktop\adwcleaner_6.043.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support
***** [ Služby ] *****
***** [ Složky ] *****
[-] Složka smazána: C:\ProgramData\c55ace07-4855-1
[-] Složka smazána: C:\ProgramData\c55ace07-7395-0
[-] Složka smazána: C:\Users\Honza\AppData\Roaming\PC Clean Plus
[-] Složka smazána: C:\Users\Honza\AppData\Roaming\Event Monitor
[-] Složka smazána: C:\Users\Honza\AppData\Roaming\Microleaves
[-] Složka smazána: C:\ProgramData\Microleaves
[#] Složka smazána po restartu: C:\ProgramData\Application Data\Microleaves
[-] Složka smazána: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus
[-] Složka smazána: C:\Program Files (x86)\PC Clean Plus
[-] Složka smazána: C:\Program Files (x86)\SystemHealer
[-] Složka smazána: C:\Program Files (x86)\Microleaves
[-] Složka smazána: C:\Program Files (x86)\pccleanplus
***** [ Soubory ] *****
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Zástupci ] *****
***** [ Naplánované úlohy ] *****
[-] Úloha smazána: PPI Update
[-] Úloha smazána: Online Application v2 Guardian
[-] Úloha smazána: Online Application v2 Guard
[-] Úloha smazána: Online Application v2
[-] Úloha smazána: Online Application Guardian
[-] Úloha smazána: Online Application Guard
[-] Úloha smazána: Online Application
[-] Úloha smazána: Online Application Updater
***** [ Registry ] *****
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage.24
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage.24
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c.1
[-] Klíč smazán: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\Conduit
[-] Klíč smazán: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\PC Clean Plus
[-] Klíč smazán: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\System Healer
[-] Klíč smazán: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\PC
[-] Klíč smazán: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\Event Monitor
[#] Klíč smazán po restartu: HKCU\Software\Conduit
[#] Klíč smazán po restartu: HKCU\Software\PC Clean Plus
[#] Klíč smazán po restartu: HKCU\Software\System Healer
[#] Klíč smazán po restartu: HKCU\Software\PC
[#] Klíč smazán po restartu: HKCU\Software\Event Monitor
[-] Klíč smazán: HKLM\SOFTWARE\Jawego
[-] Klíč smazán: HKLM\SOFTWARE\PC Clean Plus
[-] Klíč smazán: HKLM\SOFTWARE\PC
[-] Klíč smazán: HKLM\SOFTWARE\Event Monitor
[-] Klíč smazán: HKLM\SOFTWARE\Microleaves
[-] Klíč smazán: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Clean Plus_is1
[-] Klíč smazán: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
[#] Klíč smazán po restartu: [x64] HKCU\Software\Conduit
[#] Klíč smazán po restartu: [x64] HKCU\Software\PC Clean Plus
[#] Klíč smazán po restartu: [x64] HKCU\Software\System Healer
[#] Klíč smazán po restartu: [x64] HKCU\Software\PC
[#] Klíč smazán po restartu: [x64] HKCU\Software\Event Monitor
[-] Klíč smazán: [x64] HKLM\SOFTWARE\Microleaves
[-] Klíč smazán: HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
[-] Klíč smazán: HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
[-] Klíč smazán: HKLM\SYSTEM\ControlSet002\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
[-] Klíč smazán: HKLM\SYSTEM\ControlSet002\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
[#] Klíč smazán po restartu: HKLM\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
[#] Klíč smazán po restartu: HKLM\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
***** [ Prohlížeče ] *****
*************************
:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [6371 Bajty] - [29/01/2017 22:56:07]
C:\AdwCleaner\AdwCleaner[S0].txt - [6352 Bajty] - [29/01/2017 19:48:35]
C:\AdwCleaner\AdwCleaner[S1].txt - [6431 Bajty] - [29/01/2017 22:55:35]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [6590 Bajty] ##########
# Aktualizováno dne 27/01/2017 z Malwarebytes
# Databáze : 2017-01-29.1 [Server]
# Operační systém : Windows 7 Ultimate Service Pack 1 (X64)
# Uživatelské jméno : Honza - HONZA-PC
# Spuštěno z : C:\Users\Honza\Desktop\adwcleaner_6.043.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support
***** [ Služby ] *****
***** [ Složky ] *****
[-] Složka smazána: C:\ProgramData\c55ace07-4855-1
[-] Složka smazána: C:\ProgramData\c55ace07-7395-0
[-] Složka smazána: C:\Users\Honza\AppData\Roaming\PC Clean Plus
[-] Složka smazána: C:\Users\Honza\AppData\Roaming\Event Monitor
[-] Složka smazána: C:\Users\Honza\AppData\Roaming\Microleaves
[-] Složka smazána: C:\ProgramData\Microleaves
[#] Složka smazána po restartu: C:\ProgramData\Application Data\Microleaves
[-] Složka smazána: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus
[-] Složka smazána: C:\Program Files (x86)\PC Clean Plus
[-] Složka smazána: C:\Program Files (x86)\SystemHealer
[-] Složka smazána: C:\Program Files (x86)\Microleaves
[-] Složka smazána: C:\Program Files (x86)\pccleanplus
***** [ Soubory ] *****
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Zástupci ] *****
***** [ Naplánované úlohy ] *****
[-] Úloha smazána: PPI Update
[-] Úloha smazána: Online Application v2 Guardian
[-] Úloha smazána: Online Application v2 Guard
[-] Úloha smazána: Online Application v2
[-] Úloha smazána: Online Application Guardian
[-] Úloha smazána: Online Application Guard
[-] Úloha smazána: Online Application
[-] Úloha smazána: Online Application Updater
***** [ Registry ] *****
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage.24
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c
[-] Klíč smazán: HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDecoWizardPage_c.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshDoctorPage_c.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshManipulationPage.24
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshPrepCompPage_c.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshRelaxPage_c.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSmoothPage_c.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\SWNGRE.uiMeshSplitPage_c.1
[-] Klíč smazán: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\Conduit
[-] Klíč smazán: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\PC Clean Plus
[-] Klíč smazán: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\System Healer
[-] Klíč smazán: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\PC
[-] Klíč smazán: HKU\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\Event Monitor
[#] Klíč smazán po restartu: HKCU\Software\Conduit
[#] Klíč smazán po restartu: HKCU\Software\PC Clean Plus
[#] Klíč smazán po restartu: HKCU\Software\System Healer
[#] Klíč smazán po restartu: HKCU\Software\PC
[#] Klíč smazán po restartu: HKCU\Software\Event Monitor
[-] Klíč smazán: HKLM\SOFTWARE\Jawego
[-] Klíč smazán: HKLM\SOFTWARE\PC Clean Plus
[-] Klíč smazán: HKLM\SOFTWARE\PC
[-] Klíč smazán: HKLM\SOFTWARE\Event Monitor
[-] Klíč smazán: HKLM\SOFTWARE\Microleaves
[-] Klíč smazán: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Clean Plus_is1
[-] Klíč smazán: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
[#] Klíč smazán po restartu: [x64] HKCU\Software\Conduit
[#] Klíč smazán po restartu: [x64] HKCU\Software\PC Clean Plus
[#] Klíč smazán po restartu: [x64] HKCU\Software\System Healer
[#] Klíč smazán po restartu: [x64] HKCU\Software\PC
[#] Klíč smazán po restartu: [x64] HKCU\Software\Event Monitor
[-] Klíč smazán: [x64] HKLM\SOFTWARE\Microleaves
[-] Klíč smazán: HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
[-] Klíč smazán: HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
[-] Klíč smazán: HKLM\SYSTEM\ControlSet002\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
[-] Klíč smazán: HKLM\SYSTEM\ControlSet002\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
[#] Klíč smazán po restartu: HKLM\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
[#] Klíč smazán po restartu: HKLM\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
***** [ Prohlížeče ] *****
*************************
:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [6371 Bajty] - [29/01/2017 22:56:07]
C:\AdwCleaner\AdwCleaner[S0].txt - [6352 Bajty] - [29/01/2017 19:48:35]
C:\AdwCleaner\AdwCleaner[S1].txt - [6431 Bajty] - [29/01/2017 22:55:35]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [6590 Bajty] ##########
Re: havěť
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 29.1.2017
Čas skenování: 23:00
Protokol:
Správce: Ano
Verze: 2.2.1.1043
Databáze malwaru: v2017.01.29.06
Databáze rootkitů: v2016.11.20.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Honza
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 304616
Uplynulý čas: 12 min, 41 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Nenalezeny žádné škodlivé položky)
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 1
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4C6314F6-2DE8-4354-856A-787679AEF407}, Do karantény, [7139334ea3051422caa05bbe926e10f0],
Hodnoty registru: 2
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4C6314F6-2DE8-4354-856A-787679AEF407}|Contact, contact@online.io, Do karantény, [bfeb602125836cca97c5ce92a45c7c84]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4C6314F6-2DE8-4354-856A-787679AEF407}|URLInfoAbout, http://online.io/, Do karantény, [7139334ea3051422caa05bbe926e10f0]
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 0
(Nenalezeny žádné škodlivé položky)
Soubory: 8
PUP.Optional.Amonetize, C:\Program Files (x86)\Removewat 2.2.7\Removewat Final__9774_il395.exe, Do karantény, [5951532e1296999d13805369b64bf20e],
Ransom.Cerber, C:\Program Files (x86)\Removewat 2.2.7\Windows_Activaton.exe, Do karantény, [1397f58c9f09f046c39d5e738e729e62],
PUP.Optional.InstallCore, C:\Program Files (x86)\Removewat 2.2.7\windows_reg_ac.exe, Do karantény, [b2f8b5cc1a8eb08629f8c740996741bf],
PUP.Optional.OnlineIO, C:\Windows\Temp\2eb9ee42e12d953bcdf487c7c30f4a51\Online Application Updater.exe, Do karantény, [a703add44f59e84e83e6ede17a8652ae],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.myway.com_0.localstorage, Do karantény, [6149ea976f399f97ab0ceb7ea55e8c74],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.myway.com_0.localstorage-journal, Do karantény, [acfe077af1b76acc922581e88281f010],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.tb.ask.com_0.localstorage, Do karantény, [8b1fc1c0c7e1ec4a01b73c2d22e10ff1],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.tb.ask.com_0.localstorage-journal, Do karantény, [a2082958a20639fd823677f2ed16d828],
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)
www.malwarebytes.org
Datum skenování: 29.1.2017
Čas skenování: 23:00
Protokol:
Správce: Ano
Verze: 2.2.1.1043
Databáze malwaru: v2017.01.29.06
Databáze rootkitů: v2016.11.20.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Honza
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 304616
Uplynulý čas: 12 min, 41 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Nenalezeny žádné škodlivé položky)
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 1
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4C6314F6-2DE8-4354-856A-787679AEF407}, Do karantény, [7139334ea3051422caa05bbe926e10f0],
Hodnoty registru: 2
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4C6314F6-2DE8-4354-856A-787679AEF407}|Contact, contact@online.io, Do karantény, [bfeb602125836cca97c5ce92a45c7c84]
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4C6314F6-2DE8-4354-856A-787679AEF407}|URLInfoAbout, http://online.io/, Do karantény, [7139334ea3051422caa05bbe926e10f0]
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 0
(Nenalezeny žádné škodlivé položky)
Soubory: 8
PUP.Optional.Amonetize, C:\Program Files (x86)\Removewat 2.2.7\Removewat Final__9774_il395.exe, Do karantény, [5951532e1296999d13805369b64bf20e],
Ransom.Cerber, C:\Program Files (x86)\Removewat 2.2.7\Windows_Activaton.exe, Do karantény, [1397f58c9f09f046c39d5e738e729e62],
PUP.Optional.InstallCore, C:\Program Files (x86)\Removewat 2.2.7\windows_reg_ac.exe, Do karantény, [b2f8b5cc1a8eb08629f8c740996741bf],
PUP.Optional.OnlineIO, C:\Windows\Temp\2eb9ee42e12d953bcdf487c7c30f4a51\Online Application Updater.exe, Do karantény, [a703add44f59e84e83e6ede17a8652ae],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.myway.com_0.localstorage, Do karantény, [6149ea976f399f97ab0ceb7ea55e8c74],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.myway.com_0.localstorage-journal, Do karantény, [acfe077af1b76acc922581e88281f010],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.tb.ask.com_0.localstorage, Do karantény, [8b1fc1c0c7e1ec4a01b73c2d22e10ff1],
PUP.Optional.MindSpark, C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.tb.ask.com_0.localstorage-journal, Do karantény, [a2082958a20639fd823677f2ed16d828],
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)
Re: havěť
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.0 (12.05.2016)
Operating System: Windows 7 Ultimate x64
Ran by Honza (Administrator) on ne 29.01.2017 at 23:22:23,58
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 8
Successfully deleted: C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GQMN4CRW (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IKQTD1ZA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9PW903P (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TC1UQGWW (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GQMN4CRW (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IKQTD1ZA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9PW903P (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TC1UQGWW (Temporary Internet Files Folder)
Registry: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 29.01.2017 at 23:25:45,21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.0 (12.05.2016)
Operating System: Windows 7 Ultimate x64
Ran by Honza (Administrator) on ne 29.01.2017 at 23:22:23,58
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 8
Successfully deleted: C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GQMN4CRW (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IKQTD1ZA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9PW903P (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TC1UQGWW (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GQMN4CRW (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IKQTD1ZA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9PW903P (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TC1UQGWW (Temporary Internet Files Folder)
Registry: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 29.01.2017 at 23:25:45,21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Re: havěť
RogueKiller V12.9.5.0 (x64) [Jan 23 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : Honza [Práva správce]
Started from : C:\Users\Honza\Desktop\RogueKillerX64.exe
Mód : Prohledat -- Datum : 01/29/2017 23:35:19 (Duration : 00:21:38)
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 2 ¤¤¤
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\IM -> Nalezeno
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\IM -> Nalezeno
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST500DM002-1BD142 ATA Device +++++
--- User ---
[MBR] faa894f868e529e488b65d3b9f75ecdd
[BSP] 01a8045e2aec511136398fade3400db2 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 476938 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: Samsung S2 Portable +++++
--- User ---
[MBR] d19320cae105d11b38da33e646fca5dc
[BSP] 8b6f08e41154993b8e9cd9c887e118f9 : Windows XP|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 64 | Size: 610477 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : Honza [Práva správce]
Started from : C:\Users\Honza\Desktop\RogueKillerX64.exe
Mód : Prohledat -- Datum : 01/29/2017 23:35:19 (Duration : 00:21:38)
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 2 ¤¤¤
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\IM -> Nalezeno
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\IM -> Nalezeno
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST500DM002-1BD142 ATA Device +++++
--- User ---
[MBR] faa894f868e529e488b65d3b9f75ecdd
[BSP] 01a8045e2aec511136398fade3400db2 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 476938 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: Samsung S2 Portable +++++
--- User ---
[MBR] d19320cae105d11b38da33e646fca5dc
[BSP] 8b6f08e41154993b8e9cd9c887e118f9 : Windows XP|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 64 | Size: 610477 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: havěť
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“,
po jeho skončení - vše zatrhni (dej zatržítka vlevo od nálezů , do bílých políček)
- pak klikni na "Remove Selected"
- Počkej, dokud Status box nezobrazí " Removal finished, please review result "
- Klikni na "Open report " a pak na " Open TXT“ a zkopíruj ten log a vlož obsah té zprávy prosím sem. Log je možno nalézt v C:\ProgramData\RogueKiller\Logs - Zavři RogueKiller.
Vypni antivir i firewall.
Stáhni
Zoek.exe
a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:
klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Sophos Virus Removal Tool je praktický softwarový nástroj, který by mohl odstranit infekce, které antivirový program nedetekuje .
Stáhněte si ho zde z některého odkazu:
http://www.majorgeeks.com/mg/get/sophos ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,2.html
Viry mohou zpomalit počítač, nebo se snaží ukrást vaše data, a ani nevíte , že je máte. Co potřebujete, je rychlý a snadný způsob, jak je najít a zbavit se jich, pokud již máte antivirový program v počítači nainstalován , můžete nainstalovat i nástroj Sophos Virus Removal , který identifikuje a vyčistí zbylé infekce, které mohl Váš antivirový program přehlédnout.
K použití Sophos Virus Removal Tool na něj poklepejte a stiskněte tlačítko „Start scanning“ . Pak bude Sophos Virus Removal Tool vyhledávat a odstraňovat viry, které najde. Může být vyžadován restart.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“,
po jeho skončení - vše zatrhni (dej zatržítka vlevo od nálezů , do bílých políček)
- pak klikni na "Remove Selected"
- Počkej, dokud Status box nezobrazí " Removal finished, please review result "
- Klikni na "Open report " a pak na " Open TXT“ a zkopíruj ten log a vlož obsah té zprávy prosím sem. Log je možno nalézt v C:\ProgramData\RogueKiller\Logs - Zavři RogueKiller.
Vypni antivir i firewall.
Stáhni
Zoek.exe
a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:
Kód: Vybrat vše
autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;
klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Sophos Virus Removal Tool je praktický softwarový nástroj, který by mohl odstranit infekce, které antivirový program nedetekuje .
Stáhněte si ho zde z některého odkazu:
http://www.majorgeeks.com/mg/get/sophos ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,2.html
Viry mohou zpomalit počítač, nebo se snaží ukrást vaše data, a ani nevíte , že je máte. Co potřebujete, je rychlý a snadný způsob, jak je najít a zbavit se jich, pokud již máte antivirový program v počítači nainstalován , můžete nainstalovat i nástroj Sophos Virus Removal , který identifikuje a vyčistí zbylé infekce, které mohl Váš antivirový program přehlédnout.
K použití Sophos Virus Removal Tool na něj poklepejte a stiskněte tlačítko „Start scanning“ . Pak bude Sophos Virus Removal Tool vyhledávat a odstraňovat viry, které najde. Může být vyžadován restart.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: havěť
RogueKiller V12.9.5.0 (x64) [Jan 23 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : Honza [Práva správce]
Started from : C:\Users\Honza\Desktop\RogueKillerX64.exe
Mód : Prohledat -- Datum : 01/30/2017 11:19:24 (Duration : 00:19:33)
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 2 ¤¤¤
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\IM -> Nalezeno
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\IM -> Nalezeno
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST500DM002-1BD142 ATA Device +++++
--- User ---
[MBR] faa894f868e529e488b65d3b9f75ecdd
[BSP] 01a8045e2aec511136398fade3400db2 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 476938 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : Honza [Práva správce]
Started from : C:\Users\Honza\Desktop\RogueKillerX64.exe
Mód : Prohledat -- Datum : 01/30/2017 11:19:24 (Duration : 00:19:33)
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 2 ¤¤¤
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\IM -> Nalezeno
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1576092858-3754926046-2565673838-1000\Software\IM -> Nalezeno
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST500DM002-1BD142 ATA Device +++++
--- User ---
[MBR] faa894f868e529e488b65d3b9f75ecdd
[BSP] 01a8045e2aec511136398fade3400db2 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 476938 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
Re: havěť
Zoek.exe v5.0.0.1 Updated 19-September-2016
Tool run by Honza on po 30.01.2017 at 11:59:48,60.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Honza\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
30.1.2017 12:01:29 Zoek.exe System Restore Point Created Successfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
C:\PROGRA~3\DassaultSystemes deleted successfully
C:\PROGRA~3\PhotoStitch deleted successfully
C:\Users\Honza\AppData\Roaming\DassaultSystemes deleted successfully
C:\Users\Honza\AppData\Local\DassaultSystemes deleted successfully
C:\Users\Honza\AppData\Local\GHISLER deleted successfully
C:\Users\Honza\AppData\Local\Skype deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\rk7kq4j1.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Added to C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\rk7kq4j1.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Honza\AppData\Roaming\TomTom\HOME\Profiles\np5pg63u.default\prefs.js:
Added to C:\Users\Honza\AppData\Roaming\TomTom\HOME\Profiles\np5pg63u.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Deleting Files \ Folders ======================
C:\PROGRA~3\DivX deleted
C:\found.000 deleted
C:\Users\Honza\AppData\Roaming\HONZA-PC.MTBF.txt deleted
C:\Users\Honza\AppData\Roaming\__AvidCloudManager.log deleted
C:\Users\Honza\AppData\Roaming\__AvidCloudManagerPrevious.log deleted
C:\PROGRA~3\Package Cache deleted
==== Orphaned Tasks deleted from Registry ======================
avast Emergency Update deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\rk7kq4j1.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Honza\AppData\Roaming\TomTom\HOME\Profiles\np5pg63u.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [03.01.2017 08:57]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [03.01.2017 08:57]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\rk7kq4j1.default
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\Honza\AppData\Roaming\TomTom\HOME\Profiles\np5pg63u.default
- Map status indicator - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com
- TomTom HOME default theme - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\baseTheme@tomtom.com
==== Firefox Plugins ======================
==== Chromium Look ======================
Google Chrome Version: 31.0.1650.59
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
eofcbnmajmjmplflapaojjnihcjkigck - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx[]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[]
Adblock Plus Chrome Pro - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdhdafkoapngahpdbgbhfgjajnipieg
==== Chromium Fix ======================
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.audienceinsights.net_0.localstorage deleted successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.audienceinsights.net_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
==== Reset Google Chrome ======================
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
No Flash Cache Found
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=76 folders=80 29227516 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Honza\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Honza\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on po 30.01.2017 at 12:14:13,03 ======================
Tool run by Honza on po 30.01.2017 at 11:59:48,60.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Honza\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
30.1.2017 12:01:29 Zoek.exe System Restore Point Created Successfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
C:\PROGRA~3\DassaultSystemes deleted successfully
C:\PROGRA~3\PhotoStitch deleted successfully
C:\Users\Honza\AppData\Roaming\DassaultSystemes deleted successfully
C:\Users\Honza\AppData\Local\DassaultSystemes deleted successfully
C:\Users\Honza\AppData\Local\GHISLER deleted successfully
C:\Users\Honza\AppData\Local\Skype deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\rk7kq4j1.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Added to C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\rk7kq4j1.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Honza\AppData\Roaming\TomTom\HOME\Profiles\np5pg63u.default\prefs.js:
Added to C:\Users\Honza\AppData\Roaming\TomTom\HOME\Profiles\np5pg63u.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Deleting Files \ Folders ======================
C:\PROGRA~3\DivX deleted
C:\found.000 deleted
C:\Users\Honza\AppData\Roaming\HONZA-PC.MTBF.txt deleted
C:\Users\Honza\AppData\Roaming\__AvidCloudManager.log deleted
C:\Users\Honza\AppData\Roaming\__AvidCloudManagerPrevious.log deleted
C:\PROGRA~3\Package Cache deleted
==== Orphaned Tasks deleted from Registry ======================
avast Emergency Update deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\rk7kq4j1.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Honza\AppData\Roaming\TomTom\HOME\Profiles\np5pg63u.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [03.01.2017 08:57]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [03.01.2017 08:57]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\rk7kq4j1.default
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\Honza\AppData\Roaming\TomTom\HOME\Profiles\np5pg63u.default
- Map status indicator - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com
- TomTom HOME default theme - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\baseTheme@tomtom.com
==== Firefox Plugins ======================
==== Chromium Look ======================
Google Chrome Version: 31.0.1650.59
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
eofcbnmajmjmplflapaojjnihcjkigck - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx[]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[]
Adblock Plus Chrome Pro - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdhdafkoapngahpdbgbhfgjajnipieg
==== Chromium Fix ======================
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.audienceinsights.net_0.localstorage deleted successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.audienceinsights.net_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
==== Reset Google Chrome ======================
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
No Flash Cache Found
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=76 folders=80 29227516 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Honza\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Honza\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on po 30.01.2017 at 12:14:13,03 ======================
Re: havěť
Sophos Virus Removal Tool našel dva thready. nechal sem odstranit. ale nemůže vytvořit log, píše to: The log submission has failed. Please check your network connection and try again. (připojenej k netu jsem byl)
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 87 hostů