Dobrý deň,
V Chrome aj Firefoxe sa mi z ničoho nič začali zobrazovať otravné reklamy, používam adblock takže som na to prišiel až po nejakej dobe skúšal som už AdwCleaner, ručne mazať súbory atď. ale zatiaľ nič z toho nepomohlo a stále sa to vracia... dočasne pomôže zmazať rozšírenie v chrome ale to sa samo obnoví... predtým nešlo zmazať.
edit: rozšírenie sa volá CCOupScaNner
Prikladám log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2014 04
Ran by Martin (administrator) on MARTIN-NTB on 03-02-2014 12:37:19
Running from C:\Users\Martin\Desktop
Windows 8.1 Pro (X64) OS Language: 041B
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Validity Sensors, Inc.) C:\Program Files\Lenovo Fingerprint Reader\ValBioService.exe
() C:\Windows\System32\valWBFPolicyService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tposd.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(Validity Sensors, Inc.) C:\Program Files\Lenovo Fingerprint Reader\SwipeMonitor.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Password Manager\password_manager.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\Password Manager\pwm_ie_helper_desktop.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\Password Manager\pwm_ie_helper_metro.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\Password Manager\password_manager.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Google Inc.) C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\PowerMgr\PWMDBSVC.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\PowerMgr\SCHTASK.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_fa1dc1539b4180d8\TiWorker.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [PasswordManager] - C:\Program Files\Lenovo\Password Manager\password_manager.exe [1568104 2013-09-05] (Lenovo Group Limited)
HKLM\...\Run: [LenovoOptMouseUpdate] - C:\Program Files\Lenovo\HOTKEY\extapsup.exe [255480 2013-06-20] (Lenovo Group Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Power Manager Startup Utility] - C:\Program Files (x86)\Lenovo\PowerMgr\DPMHost.exe [27464 2013-04-24] ()
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3477640 2012-09-23] (Adobe Systems Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4241701525-623836703-3243463709-1001\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [457728 2013-09-30] (Microsoft Corporation)
HKU\S-1-5-21-4241701525-623836703-3243463709-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
HKU\S-1-5-21-4241701525-623836703-3243463709-1001\...\Run: [Google Update] - C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-10-16] (Google Inc.)
HKU\S-1-5-21-4241701525-623836703-3243463709-1001\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KN StrongDC.lnk
ShortcutTarget: KN StrongDC.lnk -> C:\Program Files\KN_StrongDC\StrongDC.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=13415
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE569A3115BCBCE01
SearchScopes: HKCU - {18FFA6D3-C4A6-4169-BDE8-9822316CE1DD} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13415
SearchScopes: HKCU - {1D879196-D91D-4DCD-85DF-2B38F1E1DE02} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13415
SearchScopes: HKCU - {4406616A-B08F-4909-9F8D-35049DA8305C} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {54A36E21-6318-4B39-B3F3-BF15600A3D28} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {96C67335-F9C6-41EC-A4FB-C69E0B8BE815} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKCU - {A3FD9080-508F-4AB7-9A17-2CF04D8B96AB} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {B5DE36C9-BF2C-4143-822A-A51E7C406DE3} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
SearchScopes: HKCU - {F7338662-B25E-4227-B187-188CFAA6242C} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: CeoolSaleCCooupon - {B9756AAA-669D-97C9-3E2B-5E3D0662485A} - C:\ProgramData\CeoolSaleCCooupon\MKy3C6PSk.x64.dll No File
BHO: CCOupScaNner - {F619EF73-DCD2-845B-B5FB-007CDDC108FB} - C:\ProgramData\CCOupScaNner\0Ph4xX5o.x64.dll No File
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: CeoolSaleCCooupon - {B9756AAA-669D-97C9-3E2B-5E3D0662485A} - C:\ProgramData\CeoolSaleCCooupon\MKy3C6PSk.dll No File
BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 255.255.255.255
FireFox:
========
FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\xsiphmro.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Martin\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Martin\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Martin\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Martin\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Martin\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Martin\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Martin\AppData\Roaming\mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin ProgramFiles/Appdata: C:\Users\Martin\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\zoznam-sk.xml
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2013-09-30]
FF HKCU\...\Firefox\Extensions: [{F74D5734-46F5-4B16-96F0-1E7FBF41B750}] - C:\Program Files (x86)\Lenovo\Password Manager\PWM Firefox Extension\2.0b12
FF Extension: ThinkVantage Password Manager - C:\Program Files (x86)\Lenovo\Password Manager\PWM Firefox Extension\2.0b12 [2013-09-27]
Chrome:
=======
CHR HomePage:
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Extension: (Angry Birds) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2013-09-27]
CHR Extension: (Dokumenty Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-09-27]
CHR Extension: (Disk Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-27]
CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-27]
CHR Extension: (Adblock Plus) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-01]
CHR Extension: (HþadaÃ
Â¥ v Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-27]
CHR Extension: (Adobe Acrobat â VytvoriÃ
Â¥ PDF) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2013-10-01]
CHR Extension: (ThinkVantage Password Manager) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\geempcnjhccnoepfmahaeemnnfnignab [2013-09-27]
CHR Extension: (Personal Trainer) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmgohkgndpahjklgpdihieeedjeneoke [2013-09-27]
CHR Extension: (Steambirds: Survival) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcdhpokmalcfjnfkjlfncgekebcojinn [2013-09-27]
CHR Extension: (Fieldrunners) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpikhjbfbffdblahfidklcohlaeabak [2013-09-27]
CHR Extension: (Plants vs Zombies) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina [2013-09-27]
CHR Extension: (PeÃ
ÂaÃ
¾enka Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-27]
CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-27]
CHR Extension: (CCOupScaNner) - C:\ProgramData\ndephcjjhlmfloigmjahgagihpcacpnc [2013-12-23]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2012-09-23]
CHR HKLM-x32\...\Chrome\Extension: [geempcnjhccnoepfmahaeemnnfnignab] - C:\Program Files (x86)\Lenovo\Password Manager\chrome_npapi_extension.crx [2013-09-05]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation)
R3 Power Manager DBC Service; C:\Program Files (x86)\Lenovo\PowerMgr\PWMDBSVC.EXE [63816 2013-04-24] (Lenovo)
S3 PwmEWSvc; C:\Program Files (x86)\Lenovo\PowerMgr\PWMEWSVC.EXE [186696 2013-04-24] (Lenovo Group Limited)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation)
R2 ValBioService; C:\Program Files\Lenovo Fingerprint Reader\ValBioService.exe [24112 2013-07-26] (Validity Sensors, Inc.)
R2 valWBFPolicyService; C:\Windows\system32\valWBFPolicyService.exe [28672 2013-07-26] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-10-08] (Microsoft Corporation)
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-09-04] (Intel Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146272 2013-08-22] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2013-06-04] (Synaptics Incorporated)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-03 12:36 - 2014-02-03 12:37 - 00019384 _____ () C:\Users\Martin\Desktop\FRST.txt
2014-02-03 12:35 - 2014-02-03 12:35 - 00029696 _____ () C:\Users\Martin\AppData\Local\MSGBOX.EXE
2014-02-03 12:26 - 2014-02-03 12:37 - 00000000 ____D () C:\FRST
2014-02-03 12:00 - 2014-02-03 12:00 - 02080256 _____ (Farbar) C:\Users\Martin\Desktop\FRST64.exe
2014-02-03 12:00 - 2014-02-03 12:00 - 00112640 _____ (forum.viry.cz) C:\Users\Martin\Desktop\FRSTLauncher.exe
2014-02-03 10:50 - 2014-02-03 10:50 - 13079688 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\Silverlight_x64 (1).exe
2014-02-03 10:50 - 2014-02-03 10:50 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-02-03 10:50 - 2014-02-03 10:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-02-02 21:08 - 2014-02-02 21:08 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Malwarebytes
2014-02-02 21:07 - 2014-02-02 21:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Martin\Downloads\mbam-setup-1.75.0.1300.exe
2014-02-02 19:48 - 2014-02-02 19:49 - 42070072 _____ (GridinSoft LLC) C:\Users\Martin\Downloads\gtk-2.2.1.3-setup.exe
2014-02-02 19:28 - 2014-02-02 19:28 - 01166132 _____ () C:\Users\Martin\Downloads\adwcleaner.exe
2014-02-02 19:28 - 2014-02-02 19:28 - 01037068 _____ (Thisisu) C:\Users\Martin\Downloads\JRT.exe
2014-02-02 18:54 - 2014-02-02 18:54 - 00000000 ____D () C:\WINDOWS\system32\appmgmt
2014-02-02 17:28 - 2014-02-02 17:28 - 00000000 ____D () C:\Users\Martin\Downloads\electrum_data
2014-02-02 17:27 - 2014-02-02 17:28 - 20969783 _____ () C:\Users\Martin\Downloads\electrum-1.9.7-portable.exe
2014-02-02 15:28 - 2014-02-02 15:28 - 00001019 _____ () C:\Users\Martin\Desktop\Electrum.lnk
2014-02-02 15:28 - 2014-02-02 15:28 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Electrum
2014-02-02 15:26 - 2014-02-02 15:27 - 39657741 _____ () C:\Users\Martin\Downloads\electrum-1.9.7-setup.exe
2014-02-02 15:21 - 2014-02-02 15:21 - 00001795 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-02-02 15:21 - 2014-02-02 15:21 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-02-02 15:21 - 2014-02-02 15:21 - 00000000 ____D () C:\Program Files\iTunes
2014-02-02 15:21 - 2014-02-02 15:21 - 00000000 ____D () C:\Program Files\iPod
2014-02-02 15:21 - 2014-02-02 15:21 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-02-01 20:01 - 2014-02-01 20:01 - 00011667 _____ () C:\Users\Martin\Downloads\bbtcz-s07e05_v1.zip
2014-02-01 17:07 - 2014-02-01 17:07 - 13079688 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\Silverlight_x64.exe
2014-02-01 00:44 - 2014-02-01 00:44 - 00000000 ____D () C:\Users\Martin\AppData\Local\Mozilla
2014-02-01 00:44 - 2014-02-01 00:44 - 00000000 ____D () C:\ProgramData\Mozilla
2014-02-01 00:44 - 2014-02-01 00:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-01 00:44 - 2014-02-01 00:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-01 00:22 - 2014-02-02 22:14 - 00000000 ____D () C:\AdwCleaner
2014-02-01 00:09 - 2014-02-01 00:09 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-01-31 21:31 - 2013-09-05 10:12 - 00066344 _____ (Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
2014-01-31 21:23 - 2014-01-31 21:24 - 00000000 ____D () C:\Users\Martin\AppData\Local\Lenovo
2014-01-31 21:22 - 2014-02-01 00:06 - 00000000 ____D () C:\ProgramData\Lenovo
2014-01-31 21:22 - 2014-01-31 21:22 - 00000000 ____D () C:\Program Files (x86)\ThinkPad
2014-01-31 21:19 - 2014-01-31 21:20 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\LSC
2014-01-28 22:40 - 2014-01-28 22:40 - 00000000 ____D () C:\ProgramData\TDM-GCC
2014-01-27 22:29 - 2014-02-02 15:28 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Electrum
2014-01-27 22:28 - 2014-02-02 15:28 - 00000000 ____D () C:\Program Files (x86)\Electrum
2014-01-14 17:08 - 2014-02-01 00:25 - 00000000 ____D () C:\Users\Martin\Desktop\How to Turn Your Windows 8 Laptop into a Wireless Access Point_files
==================== One Month Modified Files and Folders =======
2014-02-03 12:37 - 2014-02-03 12:36 - 00019384 _____ () C:\Users\Martin\Desktop\FRST.txt
2014-02-03 12:37 - 2014-02-03 12:26 - 00000000 ____D () C:\FRST
2014-02-03 12:36 - 2013-10-30 22:07 - 01757880 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-03 12:35 - 2014-02-03 12:35 - 00029696 _____ () C:\Users\Martin\AppData\Local\MSGBOX.EXE
2014-02-03 12:35 - 2013-10-30 22:16 - 00000000 __RDO () C:\Users\Martin\SkyDrive
2014-02-03 12:35 - 2013-09-27 21:56 - 00002906 _____ () C:\WINDOWS\System32\Tasks\AutoKMS
2014-02-03 12:35 - 2013-09-27 21:56 - 00000296 _____ () C:\WINDOWS\Tasks\AutoKMS.job
2014-02-03 12:35 - 2013-09-27 21:28 - 00002215 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-03 12:35 - 2013-09-27 21:27 - 00000954 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-03 12:35 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-03 12:34 - 2013-08-22 14:25 - 00786432 ___SH () C:\WINDOWS\system32\config\BBI
2014-02-03 12:00 - 2014-02-03 12:00 - 02080256 _____ (Farbar) C:\Users\Martin\Desktop\FRST64.exe
2014-02-03 12:00 - 2014-02-03 12:00 - 00112640 _____ (forum.viry.cz) C:\Users\Martin\Desktop\FRSTLauncher.exe
2014-02-03 12:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-02-03 11:54 - 2013-10-16 16:39 - 00000972 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4241701525-623836703-3243463709-1001UA.job
2014-02-03 11:42 - 2013-09-27 21:27 - 00000958 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-03 11:16 - 2013-09-27 21:17 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4241701525-623836703-3243463709-1001
2014-02-03 10:50 - 2014-02-03 10:50 - 13079688 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\Silverlight_x64 (1).exe
2014-02-03 10:50 - 2014-02-03 10:50 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-02-03 10:50 - 2014-02-03 10:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-02-02 22:19 - 2013-09-30 05:16 - 01024772 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-02 22:19 - 2013-09-27 21:39 - 00097050 _____ () C:\WINDOWS\system32\perfh01B.dat
2014-02-02 22:19 - 2013-09-27 21:39 - 00029954 _____ () C:\WINDOWS\system32\perfc01B.dat
2014-02-02 22:14 - 2014-02-01 00:22 - 00000000 ____D () C:\AdwCleaner
2014-02-02 21:12 - 2013-09-29 20:07 - 00004828 _____ () C:\WINDOWS\PFRO.log
2014-02-02 21:08 - 2014-02-02 21:08 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Malwarebytes
2014-02-02 21:08 - 2014-02-02 21:07 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Martin\Downloads\mbam-setup-1.75.0.1300.exe
2014-02-02 19:49 - 2014-02-02 19:48 - 42070072 _____ (GridinSoft LLC) C:\Users\Martin\Downloads\gtk-2.2.1.3-setup.exe
2014-02-02 19:28 - 2014-02-02 19:28 - 01166132 _____ () C:\Users\Martin\Downloads\adwcleaner.exe
2014-02-02 19:28 - 2014-02-02 19:28 - 01037068 _____ (Thisisu) C:\Users\Martin\Downloads\JRT.exe
2014-02-02 19:28 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-02-02 19:23 - 2013-09-27 21:11 - 00000000 ____D () C:\Users\Martin\AppData\Local\Packages
2014-02-02 18:54 - 2014-02-02 18:54 - 00000000 ____D () C:\WINDOWS\system32\appmgmt
2014-02-02 18:54 - 2013-09-27 21:45 - 00000000 ____D () C:\Program Files\Lenovo
2014-02-02 17:28 - 2014-02-02 17:28 - 00000000 ____D () C:\Users\Martin\Downloads\electrum_data
2014-02-02 17:28 - 2014-02-02 17:27 - 20969783 _____ () C:\Users\Martin\Downloads\electrum-1.9.7-portable.exe
2014-02-02 15:28 - 2014-02-02 15:28 - 00001019 _____ () C:\Users\Martin\Desktop\Electrum.lnk
2014-02-02 15:28 - 2014-02-02 15:28 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Electrum
2014-02-02 15:28 - 2014-01-27 22:29 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Electrum
2014-02-02 15:28 - 2014-01-27 22:28 - 00000000 ____D () C:\Program Files (x86)\Electrum
2014-02-02 15:27 - 2014-02-02 15:26 - 39657741 _____ () C:\Users\Martin\Downloads\electrum-1.9.7-setup.exe
2014-02-02 15:21 - 2014-02-02 15:21 - 00001795 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-02-02 15:21 - 2014-02-02 15:21 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-02-02 15:21 - 2014-02-02 15:21 - 00000000 ____D () C:\Program Files\iTunes
2014-02-02 15:21 - 2014-02-02 15:21 - 00000000 ____D () C:\Program Files\iPod
2014-02-02 15:21 - 2014-02-02 15:21 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-02-02 15:20 - 2013-12-05 21:20 - 00000000 ____D () C:\ProgramData\Apple
2014-02-02 15:14 - 2013-10-02 16:46 - 00000000 ___RD () C:\Users\Martin\Desktop\rosseta
2014-02-02 15:13 - 2013-10-30 23:34 - 00000000 ____D () C:\Users\Martin\Documents\Visual Studio 2012
2014-02-02 14:53 - 2013-10-28 21:56 - 00000000 ____D () C:\Users\Martin\Desktop\hovadiny
2014-02-01 22:32 - 2013-09-30 14:13 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\vlc
2014-02-01 20:01 - 2014-02-01 20:01 - 00011667 _____ () C:\Users\Martin\Downloads\bbtcz-s07e05_v1.zip
2014-02-01 17:07 - 2014-02-01 17:07 - 13079688 _____ (Microsoft Corporation) C:\Users\Martin\Downloads\Silverlight_x64.exe
2014-02-01 11:05 - 2013-09-27 21:45 - 00000000 ____D () C:\ldiag
2014-02-01 00:44 - 2014-02-01 00:44 - 00000000 ____D () C:\Users\Martin\AppData\Local\Mozilla
2014-02-01 00:44 - 2014-02-01 00:44 - 00000000 ____D () C:\ProgramData\Mozilla
2014-02-01 00:44 - 2014-02-01 00:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-01 00:44 - 2014-02-01 00:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-01 00:44 - 2013-11-09 23:49 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Mozilla
2014-02-01 00:28 - 2013-10-02 16:49 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Seznam.cz
2014-02-01 00:25 - 2014-01-14 17:08 - 00000000 ____D () C:\Users\Martin\Desktop\How to Turn Your Windows 8 Laptop into a Wireless Access Point_files
2014-02-01 00:09 - 2014-02-01 00:09 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-02-01 00:06 - 2014-01-31 21:22 - 00000000 ____D () C:\ProgramData\Lenovo
2014-02-01 00:05 - 2013-10-31 11:45 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\uTorrent
2014-02-01 00:05 - 2013-10-30 22:09 - 00000000 ____D () C:\Users\Martin
2014-02-01 00:05 - 2013-09-27 21:45 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Lenovo
2014-02-01 00:05 - 2013-08-22 16:36 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy
2014-02-01 00:05 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\sk-SK
2014-02-01 00:05 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\GroupPolicy
2014-02-01 00:05 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\WinMetadata
2014-02-01 00:05 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\WinBioPlugIns
2014-02-01 00:05 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sk-SK
2014-02-01 00:05 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-02-01 00:04 - 2013-09-27 22:51 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-02-01 00:04 - 2013-09-27 22:49 - 00000000 ____D () C:\Program Files\Common Files\lenovo
2014-02-01 00:04 - 2013-09-27 22:49 - 00000000 ____D () C:\Program Files (x86)\Lenovo
2014-02-01 00:04 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\registration
2014-02-01 00:04 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep
2014-01-31 21:35 - 2013-11-21 22:25 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-01-31 21:31 - 2013-09-27 22:23 - 00000000 ____D () C:\ProgramData\Validity
2014-01-31 21:24 - 2014-01-31 21:23 - 00000000 ____D () C:\Users\Martin\AppData\Local\Lenovo
2014-01-31 21:22 - 2014-01-31 21:22 - 00000000 ____D () C:\Program Files (x86)\ThinkPad
2014-01-31 21:20 - 2014-01-31 21:19 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\LSC
2014-01-30 12:22 - 2013-10-06 16:02 - 00383488 ___SH () C:\Users\Martin\Desktop\Thumbs.db
2014-01-28 22:40 - 2014-01-28 22:40 - 00000000 ____D () C:\ProgramData\TDM-GCC
2014-01-27 22:30 - 2014-01-01 20:03 - 00001162 _____ () C:\Users\Martin\Desktop\fsfwg.txt
2014-01-21 12:35 - 2013-08-22 15:46 - 00320450 _____ () C:\WINDOWS\setupact.log
2014-01-20 12:38 - 2013-10-02 16:47 - 00000000 ____D () C:\ProgramData\Rosetta Stone
2014-01-19 08:38 - 2013-09-27 21:57 - 00270496 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2014-01-07 07:54 - 2013-10-16 16:39 - 00000920 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4241701525-623836703-3243463709-1001Core.job
Some content of TEMP:
====================
C:\Users\Martin\AppData\Local\Temp\Quarantine.exe
C:\Users\Martin\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-02 22:25
==================== End Of Log ============================
Ads by keep now -adware
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Re: Ads by keep now -adware
Zdravim
Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: Ads by keep now -adware
Zoek.exe v5.0.0.0 Updated 31-January-2014
Tool run by Martin on po 03.02.2014 at 13:16:16,21.
Microsoft Windows 8.1 Pro 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Martin\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
3.2.2014 13:16:38 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
==== Creating Sample_03.02.2014_1321.zip ======================
Process rundll32.exe killed
Copied file C:\Users\Martin\AppData\Local\MSGBOX.EXE to sample\MSGBOX.EXE
sample\MSGBOX.EXE renamed to DD091A1C8075F061811515A1B13A5E07
C:\Users\Public\Desktop\sample_03.02.2014_1321.zip created successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-4241701525-623836703-3243463709-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_USERS\S-1-5-21-4241701525-623836703-3243463709-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\xsiphmro.default\prefs.js:
Added to C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\xsiphmro.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
==== Deleting Files \ Folders ======================
C:\ProgramData\ndephcjjhlmfloigmjahgagihpcacpnc deleted
C:\Users\Martin\AppData\LocalLow\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted
C:\Users\Martin\AppData\LocalLow\{F619EF73-DCD2-845B-B5FB-007CDDC108FB} deleted
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\LocalLow\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\LocalLow\{F619EF73-DCD2-845B-B5FB-007CDDC108FB} deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Packages\windows_ie_ac_001\AC\{ADAEA16F-5D1B-8D8D-5763-4373F2B80B27} deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Packages\windows_ie_ac_001\AC\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Packages\windows_ie_ac_001\AC\{F619EF73-DCD2-845B-B5FB-007CDDC108FB} deleted
C:\ProgramData\b61f497dcc3911a8 deleted
C:\Users\Martin\AppData\Local\MSGBOX.EXE deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"web2pdfextension@web2pdf.adobedotcom"="C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn" [30.09.2013 16:25]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{F74D5734-46F5-4B16-96F0-1E7FBF41B750}"="C:\Program Files (x86)\Lenovo\Password Manager\PWM Firefox Extension\2.0b12" [27.09.2013 22:49]
==== Firefox Extensions ======================
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\xsiphmro.default
C36444D7301A8C881FC7296B092609C7 - C:\Users\Martin\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll - Google Update
EE8D96E7899D12FC3AA5DB2034C0853C - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll - Shockwave Flash
68BCBB241EF254BC5100D9E6C06ECC71 - C:\Users\Martin\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll - Google Talk Plugin Video Accelerator
99FE6AFE80EB7FE3EEB75DC504A326A3 - C:\Users\Martin\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer
AF42019A3B0EDBFA6878F75B9377A792 - C:\Users\Martin\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
efaidnbmnnnibpcajpcglclefindmkaj - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx[23.09.2012 19:43]
geempcnjhccnoepfmahaeemnnfnignab - C:\Program Files (x86)\Lenovo\Password Manager\chrome_npapi_extension.crx[05.09.2013 09:50]
Angry Birds - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
ThinkVantage Password Manager - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\geempcnjhccnoepfmahaeemnnfnignab
Personal Trainer - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmgohkgndpahjklgpdihieeedjeneoke
Steambirds Survival - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcdhpokmalcfjnfkjlfncgekebcojinn
Fieldrunners - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpikhjbfbffdblahfidklcohlaeabak
Plants vs Zombies - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina
ThinkVantage Password Manager - C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\geempcnjhccnoepfmahaeemnnfnignab
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/?clid=13415"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/?clid=13415"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{18FFA6D3-C4A6-4169-BDE8-9822316CE1DD} Novinky.cz Url="http://www.novinky.cz/hledej?w={searchT ... arch_13415"
{1D879196-D91D-4DCD-85DF-2B38F1E1DE02} Firmy.cz Url="http://www.firmy.cz/?q={searchTerms}&so ... arch_13415"
{4406616A-B08F-4909-9F8D-35049DA8305C} Slovnˇk CZ/EN Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_13415"
{54A36E21-6318-4B39-B3F3-BF15600A3D28} Encyklopedie Seznam Url="http://encyklopedie.seznam.cz/search?q= ... arch_13415"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{96C67335-F9C6-41EC-A4FB-C69E0B8BE815} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_13415"
{A3FD9080-508F-4AB7-9A17-2CF04D8B96AB} Slovnˇk EN/CZ Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_13415"
{B5DE36C9-BF2C-4143-822A-A51E7C406DE3} Mapy.cz Url="http://www.mapy.cz/?query={searchTerms} ... arch_13415"
{F7338662-B25E-4227-B187-188CFAA6242C} Zbo§ˇ.cz Url="http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415"
==== Reset Google Chrome ======================
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Empty IE Cache ======================
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Martin\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Martin\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Martin\AppData\Local\Mozilla\Firefox\Profiles\xsiphmro.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=17 folders=9 121969 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Users\Martin\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\Users\Martin\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on po 03.02.2014 at 13:23:33,79 ======================
je to už v poriadku? Ďakujem veľmi pekne
Tool run by Martin on po 03.02.2014 at 13:16:16,21.
Microsoft Windows 8.1 Pro 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Martin\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
3.2.2014 13:16:38 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
==== Creating Sample_03.02.2014_1321.zip ======================
Process rundll32.exe killed
Copied file C:\Users\Martin\AppData\Local\MSGBOX.EXE to sample\MSGBOX.EXE
sample\MSGBOX.EXE renamed to DD091A1C8075F061811515A1B13A5E07
C:\Users\Public\Desktop\sample_03.02.2014_1321.zip created successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-4241701525-623836703-3243463709-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_USERS\S-1-5-21-4241701525-623836703-3243463709-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\xsiphmro.default\prefs.js:
Added to C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\xsiphmro.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
==== Deleting Files \ Folders ======================
C:\ProgramData\ndephcjjhlmfloigmjahgagihpcacpnc deleted
C:\Users\Martin\AppData\LocalLow\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted
C:\Users\Martin\AppData\LocalLow\{F619EF73-DCD2-845B-B5FB-007CDDC108FB} deleted
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\LocalLow\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\LocalLow\{F619EF73-DCD2-845B-B5FB-007CDDC108FB} deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Packages\windows_ie_ac_001\AC\{ADAEA16F-5D1B-8D8D-5763-4373F2B80B27} deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Packages\windows_ie_ac_001\AC\{B9756AAA-669D-97C9-3E2B-5E3D0662485A} deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Packages\windows_ie_ac_001\AC\{F619EF73-DCD2-845B-B5FB-007CDDC108FB} deleted
C:\ProgramData\b61f497dcc3911a8 deleted
C:\Users\Martin\AppData\Local\MSGBOX.EXE deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"web2pdfextension@web2pdf.adobedotcom"="C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn" [30.09.2013 16:25]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{F74D5734-46F5-4B16-96F0-1E7FBF41B750}"="C:\Program Files (x86)\Lenovo\Password Manager\PWM Firefox Extension\2.0b12" [27.09.2013 22:49]
==== Firefox Extensions ======================
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\xsiphmro.default
C36444D7301A8C881FC7296B092609C7 - C:\Users\Martin\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll - Google Update
EE8D96E7899D12FC3AA5DB2034C0853C - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll - Shockwave Flash
68BCBB241EF254BC5100D9E6C06ECC71 - C:\Users\Martin\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll - Google Talk Plugin Video Accelerator
99FE6AFE80EB7FE3EEB75DC504A326A3 - C:\Users\Martin\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer
AF42019A3B0EDBFA6878F75B9377A792 - C:\Users\Martin\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
efaidnbmnnnibpcajpcglclefindmkaj - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx[23.09.2012 19:43]
geempcnjhccnoepfmahaeemnnfnignab - C:\Program Files (x86)\Lenovo\Password Manager\chrome_npapi_extension.crx[05.09.2013 09:50]
Angry Birds - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
ThinkVantage Password Manager - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\geempcnjhccnoepfmahaeemnnfnignab
Personal Trainer - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmgohkgndpahjklgpdihieeedjeneoke
Steambirds Survival - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcdhpokmalcfjnfkjlfncgekebcojinn
Fieldrunners - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpikhjbfbffdblahfidklcohlaeabak
Plants vs Zombies - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina
ThinkVantage Password Manager - C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\geempcnjhccnoepfmahaeemnnfnignab
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/?clid=13415"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/?clid=13415"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{18FFA6D3-C4A6-4169-BDE8-9822316CE1DD} Novinky.cz Url="http://www.novinky.cz/hledej?w={searchT ... arch_13415"
{1D879196-D91D-4DCD-85DF-2B38F1E1DE02} Firmy.cz Url="http://www.firmy.cz/?q={searchTerms}&so ... arch_13415"
{4406616A-B08F-4909-9F8D-35049DA8305C} Slovnˇk CZ/EN Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_13415"
{54A36E21-6318-4B39-B3F3-BF15600A3D28} Encyklopedie Seznam Url="http://encyklopedie.seznam.cz/search?q= ... arch_13415"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{96C67335-F9C6-41EC-A4FB-C69E0B8BE815} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_13415"
{A3FD9080-508F-4AB7-9A17-2CF04D8B96AB} Slovnˇk EN/CZ Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_13415"
{B5DE36C9-BF2C-4143-822A-A51E7C406DE3} Mapy.cz Url="http://www.mapy.cz/?query={searchTerms} ... arch_13415"
{F7338662-B25E-4227-B187-188CFAA6242C} Zbo§ˇ.cz Url="http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415"
==== Reset Google Chrome ======================
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Empty IE Cache ======================
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Martin\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Martin\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Martin\AppData\Local\Mozilla\Firefox\Profiles\xsiphmro.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=17 folders=9 121969 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Users\Martin\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\Users\Martin\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on po 03.02.2014 at 13:23:33,79 ======================
je to už v poriadku? Ďakujem veľmi pekne
Re: Ads by keep now -adware
- Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
- Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
- Zaskrtnete okenko Pro vsechny uzivatele
- Zaskrtnete okenko Kontrola na havet "LOP"
- Zaskrtnete okenko Kontrola na havet "Purity"
- Stari souboru zmente z 30 dnu na 7 dnu
- Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
Kód: Vybrat vše
CREATERESTOREPOINT netsvcs drivers32 savembr:0 /md5start atapi.sys autochk.exe cdrom.sys explorer.exe hal.dll scecli.dll services.exe svchost.exe tcpip.sys userinit.exe winlogon.exe /md5stop %systemroot%*.* /U /s %SYSTEMDRIVE%\*.exe %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles %systemroot%\Tasks\*.job %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %systemroot%\system32\drivers\*.sys /3 %systemroot%\system32\*.* /3 %SYSTEMDRIVE%\*.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 %PROGRAMFILES%\Opera\opera.exe /md5 %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 %SystemDrive%\PhysicalMBR.bin /md5 *crack* /s *keygen* /s *loader* /s- Kliknete na tlacitko Prohledat
- Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
- Pokud budou logy dlouhe (forum bude kricet o prekroceni maximalniho poctu znaku), tak je rozdelte do vice prispevku



Přispějete na provoz fóra?