Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventivní kontrola

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
jmeno1
3. Stupeň Varování
Příspěvky: 99
Registrován: 06 led 2006 07:43

Preventivní kontrola

#1 Příspěvek od jmeno1 »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Jirka at 2014-03-01 15:09:10
Microsoft Windows 7 Professional
System drive C: has 56 GB (49%) free of 114 GB
Total RAM: 8140 MB (74% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:09:14, on 1.3.2014
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16526)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Overwolf\Overwolf.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrchMn.exe
C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\Common Files\Overwolf\OverwolfHelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Jirka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.tb.ask.com/index.jhtml?n=77 ... 8387E919B1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Free Games (4357) - {2977C29A-6723-4436-90BB-F7C5FDEF88A1} - C:\Program Files (x86)\Free Games (4357)\ScriptHost.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.3.1.204\AVG SafeGuard toolbar_toolbar.dll
O2 - BHO: Search Assistant BHO - {a4c2fb10-84c3-44eb-9f9e-860fa1d9a797} - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Toolbar BHO - {fbcbc43a-dca9-4192-a4c8-b57fd0f77d4d} - C:\PROGRA~2\ALLIN1~1\bar\1.bin\8hbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.3.1.204\AVG SafeGuard toolbar_toolbar.dll
O3 - Toolbar: Allin1Convert - {cd1a63ba-a08c-431b-9a34-f240aadc728d} - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbar.dll
O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
O4 - HKLM\..\Run: [Allin1Convert EPM Support] "C:\PROGRA~2\ALLIN1~1\bar\1.bin\8hmedint.exe" T8EPMSUP.DLL,S
O4 - HKLM\..\Run: [Allin1Convert Search Scope Monitor] "C:\PROGRA~2\ALLIN1~1\bar\1.bin\8hsrchmn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [Allin1Convert_8h Browser Plugin Loader] C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon.exe
O4 - HKLM\..\Run: [Allin1Convert_8h Browser Plugin Loader 64] C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon64.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKCU\..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Jirka\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3568989903-3585261540-3525969485-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3568989903-3585261540-3525969485-1001\..\Run: [LiveSupport] "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3568989903-3585261540-3525969485-1001\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.3.0\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: c:\progra~2\gs-ena~1\assist~1.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Allin1ConvertService (Allin1Convert_8hService) - COMPANYVERS_NAME - C:\PROGRA~2\ALLIN1~1\bar\1.bin\8hbarsvc.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Overwolf Updater Service (OverwolfUpdaterService) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater17.3.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13492 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
C:\PROGRA~2\AVG\AVG2014\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=844d7d3f-f185-4026-97af-1929cd013c59 /coreSdkOptions=4382 /logConfFile="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\77d87648-3279-403b-9367-8f5a270e423c-1f0-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2014\" /tempPath="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\PROGRA~2\ALLIN1~1\bar\1.bin\8hbarsvc.exe
"C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe"
"C:\Windows\system32\rundll32.exe" "c:\progra~2\gs-ena~1\AssistantSvc.dll",service
"C:\Windows\system32\rundll32.exe" "c:\progra~2\gs-ena~1\AssistantSvc.dll",service
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\loggingserver.exe" 72648 "C:\ProgramData\AVG SafeGuard toolbar\Logger\logger.properties"
\??\C:\Windows\system32\conhost.exe "1747471933-1294623630-16693366252052826618238531263-1105671396227037108-1374322792
WLIDSvcM.exe 2456
"C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgemca.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
taskeng.exe {61E4EA72-AF2D-427C-92AE-C0C5831CF6FD}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\AppIntegrator64.exe"
"C:\Program Files (x86)\Overwolf\Overwolf.exe" -silent
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
"C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
"C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrchMn.exe" /m=2 /w /h
"C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon.exe"
"C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon64.exe"
"C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe"
"C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Common Files\Overwolf\OverwolfHelper.exe" "path=C:\Program Files (x86)\Overwolf"
"C:\Program Files (x86)\Common Files\Overwolf\OverwolfHelper64.exe" "path=C:\Program Files (x86)\Overwolf\x64\OWExplorerLauncher.dll
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" -startup
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\system32\sppsvc.exe
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5180.0.1739355234\806242691" --disable-image-transport-surface --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,13,23,28 --gpu-vendor-id=0x10de --gpu-device-id=0x1184 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.2008 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/DeferBackgroundExtensionCreation/RateLimited/EmbeddedSearch/Group4 pct:10d stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/StandardR2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_60/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="5180.2.416286716\485097235" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/DeferBackgroundExtensionCreation/RateLimited/EmbeddedSearch/Group4 pct:10d stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ManagedModeLaunch/Active/OmniboxBundledExperimentV1/StandardR2/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderDisabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_60/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="5180.8.1947901675\1094117079" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 532 536 544 65536 540
"C:\Users\Jirka\Downloads\RSITx64 (1).exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\j6z32s7x.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "keyword.URL" - ""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.70 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Allin1Convert_8h.com/Plugin]
"Description"=Allin1Convert Plugin
"Path"=C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\NP8hStub.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.3.0\\npsitesafety.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn.me/esnsonar,version=0.70.4]
"Description"=ESN Sonar browser plugin
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.3.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.70 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll


C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\j6z32s7x.default\extensions\
8hffxtbr@Allin1Convert_8h.com
yoab0z@olwq-zfmr.org

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2977C29A-6723-4436-90BB-F7C5FDEF88A1}]
Free Games (4357) - C:\Program Files (x86)\Free Games (4357)\ScriptHost64.dll [2013-10-22 381760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-12-02 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2013-12-12 256080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg64.dll [2013-12-02 346576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-12-02 210856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2977C29A-6723-4436-90BB-F7C5FDEF88A1}]
Free Games (4357) - C:\Program Files (x86)\Free Games (4357)\ScriptHost.dll [2013-10-22 400704]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-02 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG SafeGuard toolbar - C:\Program Files (x86)\AVG SafeGuard toolbar\17.3.1.204\AVG SafeGuard toolbar_toolbar.dll [2014-02-05 3401752]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4c2fb10-84c3-44eb-9f9e-860fa1d9a797}]
Search Assistant BHO - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll [2013-12-31 140360]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-12 194128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll [2013-12-02 1001936]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-12-02 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fbcbc43a-dca9-4192-a4c8-b57fd0f77d4d}]
Toolbar BHO - C:\PROGRA~2\ALLIN1~1\bar\1.bin\8hbar.dll [2013-12-31 859720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2013-12-12 256080]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-12 194128]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG SafeGuard toolbar - C:\Program Files (x86)\AVG SafeGuard toolbar\17.3.1.204\AVG SafeGuard toolbar_toolbar.dll [2014-02-05 3401752]
{cd1a63ba-a08c-431b-9a34-f240aadc728d} - Allin1Convert - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbar.dll [2013-12-31 859720]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Allin1Convert Home Page Guard 64 bit"=C:\PROGRA~2\ALLIN1~1\bar\1.bin\AppIntegrator64.exe [2013-12-31 485448]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Overwolf"=C:\Program Files (x86)\Overwolf\Overwolf.exe [2014-02-16 37632]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"NextLive"=C:\Windows\SysWOW64\rundll32.exe [2009-07-14 44544]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14 20586656]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IMSS"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [2012-07-19 133440]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-05-20 291648]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2014\avgui.exe [2013-11-07 4956176]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"vProt"=C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2014-02-05 2535448]
"Allin1Convert EPM Support"=C:\PROGRA~2\ALLIN1~1\bar\1.bin\8hmedint.exe [2013-12-31 12872]
"Allin1Convert Search Scope Monitor"=C:\PROGRA~2\ALLIN1~1\bar\1.bin\8hsrchmn.exe [2013-12-31 55368]
"Allin1Convert_8h Browser Plugin Loader"=C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon.exe [2013-12-31 61512]
"Allin1Convert_8h Browser Plugin Loader 64"=C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon64.exe [2013-12-31 71752]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"hpqSRMon"=C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [2008-08-20 150016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\PROGRA~2\GS-ENA~1\ASSIST~2.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-03-01 15:09:10 ----D---- C:\rsit
2014-03-01 15:09:10 ----D---- C:\Program Files\trend micro
2014-02-25 18:01:36 ----D---- C:\Program Files (x86)\MSECache
2014-02-23 08:09:20 ----D---- C:\Users\Jirka\AppData\Roaming\dvdcss

======List of files/folders modified in the last 1 month======

2014-03-01 15:09:14 ----D---- C:\Windows\Prefetch
2014-03-01 15:09:10 ----RD---- C:\Program Files
2014-03-01 15:04:38 ----D---- C:\Windows\Logs
2014-03-01 15:04:38 ----D---- C:\Windows\inf
2014-03-01 15:04:38 ----D---- C:\Windows
2014-03-01 15:04:37 ----D---- C:\Windows\Temp
2014-03-01 14:22:17 ----D---- C:\Windows\System32
2014-03-01 14:22:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-03-01 14:18:27 ----A---- C:\Windows\SYSWOW64\log.txt
2014-03-01 14:16:37 ----D---- C:\Users\Jirka\AppData\Roaming\newnext.me
2014-03-01 14:16:23 ----D---- C:\ProgramData\NVIDIA
2014-03-01 14:11:39 ----D---- C:\Windows\system32\config
2014-03-01 09:55:34 ----D---- C:\ProgramData\MFAData
2014-02-28 23:04:44 ----D---- C:\Users\Jirka\AppData\Roaming\TS3Client
2014-02-25 18:02:07 ----SD---- C:\Users\Jirka\AppData\Roaming\Microsoft
2014-02-25 18:01:46 ----SHD---- C:\Windows\Installer
2014-02-25 18:01:46 ----HD---- C:\Config.Msi
2014-02-25 18:01:46 ----D---- C:\Windows\winsxs
2014-02-25 18:01:43 ----SHD---- C:\System Volume Information
2014-02-25 18:01:43 ----D---- C:\Program Files (x86)\Microsoft Office
2014-02-25 18:01:36 ----RD---- C:\Program Files (x86)
2014-02-23 13:27:31 ----D---- C:\Users\Jirka\AppData\Roaming\.minecraft
2014-02-23 08:10:37 ----D---- C:\Users\Jirka\AppData\Roaming\vlc
2014-02-21 10:52:12 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-20 21:24:42 ----D---- C:\Windows\SysWOW64
2014-02-20 21:24:40 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-02-20 15:45:41 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-02-17 09:04:25 ----D---- C:\Program Files (x86)\Overwolf
2014-02-13 16:28:09 ----D---- C:\Windows\system32\catroot2
2014-02-11 17:58:04 ----D---- C:\Windows\system32\FxsTmp
2014-02-11 17:38:31 ----D---- C:\ProgramData\HP
2014-02-11 17:37:12 ----D---- C:\Windows\twain_32
2014-02-05 20:19:06 ----D---- C:\Windows\Tasks
2014-02-05 20:19:06 ----D---- C:\Windows\system32\Tasks
2014-02-05 20:18:23 ----D---- C:\Program Files (x86)\AVG SafeGuard toolbar
2014-02-03 15:41:42 ----D---- C:\ProgramData\TubeADiblockeR

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2013-10-24 194872]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2013-10-31 294712]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2013-10-01 123704]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2013-09-10 31544]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2012-05-20 19264]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-12-14 871408]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2012-10-25 22680]
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2013-11-05 150808]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2013-11-04 240920]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2013-10-31 212280]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2013-08-01 251192]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2013-12-18 46368]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-12-06 283064]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2012-05-20 357184]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2012-05-20 789824]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2012-07-19 110744]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2012-07-02 62784]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-12-19 194488]
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2013-12-02 25640]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2013-12-02 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2013-12-02 30528]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 Allin1Convert_8hService;Allin1ConvertService; C:\PROGRA~2\ALLIN1~1\bar\1.bin\8hbarsvc.exe [2013-12-31 88648]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [2013-11-11 3478544]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [2013-09-24 348008]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 e81a9dc1;GS-Supporter; C:\Windows\syswow64\rundll32.exe [2009-07-14 44544]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-06-19 634632]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-07-05 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-19 277824]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-04-29 884512]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-04-29 1364256]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-04-29 412960]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2013-12-02 5316448]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-19 365376]
R2 vToolbarUpdater17.3.0;vToolbarUpdater17.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe [2014-01-06 1771544]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-02 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-20 257928]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-02 136176]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-12-02 194032]
S3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2011-08-30 160256]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-02-20 118896]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 OverwolfUpdaterService;Overwolf Updater Service; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2014-02-16 98560]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-12-11 569768]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------


Na PC se občas zapínají neznámé stránky, údajně je pomalejší. Vše by mělo být oficiální. Prosím o kontrolu.

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Preventivní kontrola

#2 Příspěvek od Roli »

Zdravím, v HJT fixni :

R3 - URLSearchHook: (no name) - {5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll
O2 - BHO: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.3.1.204\AVG SafeGuard toolbar_toolbar.dll
O2 - BHO: Search Assistant BHO - {a4c2fb10-84c3-44eb-9f9e-860fa1d9a797} - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll
O2 - BHO: Toolbar BHO - {fbcbc43a-dca9-4192-a4c8-b57fd0f77d4d} - C:\PROGRA~2\ALLIN1~1\bar\1.bin\8hbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.3.1.204\AVG SafeGuard toolbar_toolbar.dll
O3 - Toolbar: Allin1Convert - {cd1a63ba-a08c-431b-9a34-f240aadc728d} - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Allin1Convert EPM Support] "C:\PROGRA~2\ALLIN1~1\bar\1.bin\8hmedint.exe" T8EPMSUP.DLL,S
O4 - HKLM\..\Run: [Allin1Convert Search Scope Monitor] "C:\PROGRA~2\ALLIN1~1\bar\1.bin\8hsrchmn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [Allin1Convert_8h Browser Plugin Loader] C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon.exe
O4 - HKLM\..\Run: [Allin1Convert_8h Browser Plugin Loader 64] C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon64.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Jirka\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l


HJT najdeš zde :

C:\Program Files\trend micro\Jirka.exe

Fix znamená že spustíš HJT Obrázek jako admin

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Přes Start >> Všechny programy >> Příslušenství >> Spustit >> napiš - services.msc >> Enter. Najdi službu :

Allin1ConvertService

Služba Google Update (gupdate)

Služba Google Update (gupdatem)

Google Software Updater


dvojklikem se otevře karta kde nejprve službu zastav tlačítkem Zastavit u položky Typ spouštění vyber Zakázáno a klik na OK.


V Plánovači úloh zakaž Google Update bude to tam několikrát.


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

čištění registru je třeba několikrát zopakovat !

Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém


Stáhni a ulož na plochu AdwCleaner,

ukonči všechny programy včetně prohlížeče a dvojklikem spusť,

objeví se okno kde vlevo nahoře klikni na Scan.

Po té proběhne sken a po jeho skončení klikni na Report a to co na Tebe vypadne mi sem zkopíruj.


Pak použij Mbam z mého podpisu a dej mi sem z něj také log, předem nic nemazat !
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

jmeno1
3. Stupeň Varování
Příspěvky: 99
Registrován: 06 led 2006 07:43

Re: Preventivní kontrola

#3 Příspěvek od jmeno1 »

# AdwCleaner v3.020 - Report created 02/03/2014 at 14:20:16
# Updated 27/02/2014 by Xplode
# Operating System : Windows 7 Professional (64 bits)
# Username : Jirka - JIRKA-PC
# Running from : C:\Users\Jirka\Downloads\adwcleaner (1).exe
# Option : Scan

***** [ Services ] *****

Service Found : Allin1Convert_8hService
Service Found : vToolbarUpdater17.3.0

***** [ Files / Folders ] *****

File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml
File Found : C:\Windows\System32\roboot64.exe
Folder Found : C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Folder Found : C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\j6z32s7x.default\Extensions\8hffxtbr@Allin1Convert_8h.com
Folder Found : C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\j6z32s7x.default\Extensions\yoab0z@olwq-zfmr.org
Folder Found C:\Program Files (x86)\Allin1Convert_8h
Folder Found C:\Program Files (x86)\AVG SafeGuard toolbar
Folder Found C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found C:\Program Files (x86)\EZDownloader
Folder Found C:\Program Files (x86)\GS-Enabler
Folder Found C:\Program Files (x86)\MyPC Backup
Folder Found C:\ProgramData\AVG SafeGuard toolbar
Folder Found C:\ProgramData\AVG Security Toolbar
Folder Found C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZDownloader
Folder Found C:\ProgramData\QuickSet
Folder Found C:\ProgramData\TubeADiblockeR
Folder Found C:\Users\Jirka\AppData\Local\Allin1Convert_8h
Folder Found C:\Users\Jirka\AppData\Local\AVG SafeGuard toolbar
Folder Found C:\Users\Jirka\AppData\Local\genienext
Folder Found C:\Users\Jirka\AppData\Local\iac
Folder Found C:\Users\Jirka\AppData\Local\Mobogenie
Folder Found C:\Users\Jirka\AppData\LocalLow\Allin1Convert_8h
Folder Found C:\Users\Jirka\AppData\LocalLow\AVG SafeGuard toolbar
Folder Found C:\Users\Jirka\AppData\LocalLow\iac
Folder Found C:\Users\Jirka\AppData\Roaming\newnext.me
Folder Found C:\Users\Jirka\AppData\Roaming\PerformerSoft
Folder Found C:\Users\Jirka\Documents\Mobogenie
Folder Found C:\Users\Jirka\Documents\Optimizer Pro

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\allin1convert_8h
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\Software\allin1convert_8h
Key Found : HKCU\Software\AVG SafeGuard toolbar
Key Found : HKCU\Software\AVG Secure Search
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CD1A63BA-A08C-431B-9A34-F240AADC728D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7CAEFAFC-9A1E-4BCC-94DD-BC7D8D52717A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD1A63BA-A08C-431B-9A34-F240AADC728D}
Key Found : HKCU\Software\performersoft llc
Key Found : [x64] HKCU\Software\allin1convert_8h
Key Found : [x64] HKCU\Software\AVG SafeGuard toolbar
Key Found : [x64] HKCU\Software\AVG Secure Search
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : [x64] HKCU\Software\performersoft llc
Key Found : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKLM\Software\allin1convert_8h
Key Found : HKLM\Software\AVG SafeGuard toolbar
Key Found : HKLM\Software\AVG Security Toolbar
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.feedmanager
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.feedmanager.1
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.htmlmenu
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.htmlmenu.1
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.htmlpanel
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.htmlpanel.1
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.multiplebutton
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.multiplebutton.1
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.pseudotransparentplugin
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.pseudotransparentplugin.1
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.radio
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.radio.1
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.radiosettings
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.radiosettings.1
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.scriptbutton
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.scriptbutton.1
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.settingsplugin
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.settingsplugin.1
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.thirdpartyinstaller
Key Found : HKLM\SOFTWARE\Classes\allin1convert_8h.thirdpartyinstaller.1
Key Found : HKLM\SOFTWARE\Classes\Allin1Convert_8h.ToolbarProtector
Key Found : HKLM\SOFTWARE\Classes\Allin1Convert_8h.ToolbarProtector.1
Key Found : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
Key Found : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{248B3E95-17A4-482D-A8A8-6B3DF4D05C35}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{27F49273-DE3A-4111-90F9-6C474C37AEFB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{39D4F1A1-A94D-4B7D-BF1D-7446308800ED}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{443321F7-E46C-42F8-812B-F35E98CBB44F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5CDE4714-32DC-473C-8194-0645E62C2E96}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7CAEFAFC-9A1E-4BCC-94DD-BC7D8D52717A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7EB7381C-FB01-47FC-9C42-ED64122C1B92}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{889F49D2-6CEA-40BE-BE5F-7217485F9745}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8F83D657-5993-4FFA-9AEE-DA0B20D828A7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{C8EF8F70-3807-424A-83F7-DA06FD4DACF9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CD1A63BA-A08C-431B-9A34-F240AADC728D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE0F6787-9D1C-42B7-A0B9-EAC630F87902}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E4EF697F-434B-4DC7-A464-4412462206DB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{EF3F28C8-0330-4D18-B901-D24CB83E5AA1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{EF5DB804-585B-472E-B415-BC63F8F01BF6}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F2C368C5-9F44-4D43-89F3-A1CC87F1DA96}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F99DDD9A-07D0-47AB-86F1-193533DD2C60}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{16976E15-10EA-44FD-804A-6ECBC9EBBFC7}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2561FD25-FE31-4E56-A120-AF7FEAAE3124}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4BD0FCFF-AD64-4315-9F2C-960EF3C21623}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{507C73BB-FC69-425E-8A49-9204F886B328}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6EC57031-1740-4151-93C5-C465D6063DD2}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{76FC1003-0825-48BD-B59B-3B7A5754972C}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9D217B94-6FC9-44FE-94B1-30C711871266}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B48AC2CD-9662-47E0-A3C0-3B01BB3F463E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{BE698E51-830B-447A-954D-901D6E05DDE2}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{BFCF748F-A56E-451F-AA45-0D7EB699E416}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D617CF84-B0BC-441F-9984-B676AFBA1E8D}
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{248B3E95-17A4-482D-A8A8-6B3DF4D05C35}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\LiveSupport_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\livesupport_rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{27F49273-DE3A-4111-90F9-6C474C37AEFB}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7CAEFAFC-9A1E-4BCC-94DD-BC7D8D52717A}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7EB7381C-FB01-47FC-9C42-ED64122C1B92}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E4EF697F-434B-4DC7-A464-4412462206DB}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F99DDD9A-07D0-47AB-86F1-193533DD2C60}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\allin1convert_8hbar uninstall firefox
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar
Key Found : HKLM\SOFTWARE\MozillaPlugins\@Allin1Convert_8h.com/Plugin
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NextLive]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16526

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://home.tb.ask.com/index.jhtml?n=77FD35DB&p2=^AYY^man000^YYA^&ptb=B802C984-4E25-45EF-A750-CB8387E919B1

-\\ Mozilla Firefox v27.0.1 (cs)

[ File : C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\j6z32s7x.default\prefs.js ]

Line Found : user_pref("extensions.VrjO22z8YWL3.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||ur[...]

-\\ Google Chrome v32.0.1700.102

[ File : C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [15013 octets] - [02/03/2014 14:09:03]
AdwCleaner[R1].txt - [14265 octets] - [02/03/2014 14:20:16]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [14326 octets] ##########

jmeno1
3. Stupeň Varování
Příspěvky: 99
Registrován: 06 led 2006 07:43

Re: Preventivní kontrola

#4 Příspěvek od jmeno1 »

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2014.03.02.04

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Jirka :: JIRKA-PC [administrátor]

Ochrana: Povolena

2.3.2014 14:23:27
MBAM-log-2014-03-02 (14-25-38).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 268107
Uplynulý čas: 1 minut, 40 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 22
HKLM\SYSTEM\CurrentControlSet\Services\Allin1Convert_8hService (PUP.Optional.AudioToAudioToolBar.A) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{2977C29A-6723-4436-90BB-F7C5FDEF88A1} (PUP.Optional.BestToolbars) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{813FB3C5-A4D9-4CD8-BDD0-750F40E68908} (PUP.Optional.BestToolbars) -> Nebyla provedena žádná instrukce.
HKCR\Free Games (4357).ScriptHostObject.1 (PUP.Optional.BestToolbars) -> Nebyla provedena žádná instrukce.
HKCR\Free Games (4357).ScriptHostObject (PUP.Optional.BestToolbars) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2977C29A-6723-4436-90BB-F7C5FDEF88A1} (PUP.Optional.BestToolbars) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{2977C29A-6723-4436-90BB-F7C5FDEF88A1} (PUP.Optional.BestToolbars) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2977C29A-6723-4436-90BB-F7C5FDEF88A1} (PUP.Optional.BestToolbars) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252} (PUP.Optional.GreatSaver.A) -> Nebyla provedena žádná instrukce.
HKCR\Free Games (4357).BackgroundHostObject (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
HKCR\Free Games (4357).BackgroundHostObject.1 (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
HKCR\Free Games (4357).Navbar (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
HKCR\Free Games (4357).Navbar.1 (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
HKCR\Free Games (4357).Tool (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
HKCR\Free Games (4357).Tool.1 (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Google\Chrome\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1 (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{739CDEE7-D45D-426F-9776-8BC4F8C1A4AB} (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{4398032D-0040-451D-9AB9-5CE5597EB103} (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{5C71ACCF-F361-40F4-9E19-23D831490AAB} (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{DF776000-0872-4D61-B445-CAD0C227C731} (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Free Games (4357) (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NextLive (PUP.Optional.NextLive.A) -> Data: C:\Windows\SysWOW64\rundll32.exe "C:\Users\Jirka\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l -> Nebyla provedena žádná instrukce.

Nalezené datové položky v registru: 2
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs (PUP.Optional.GreatSaver.A) -> Špatný: (c:\progra~2\gs-ena~1\assist~1.dll) Dobrý: () -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.AskWebSearch) -> Špatný: (http://home.tb.ask.com/index.jhtml?n=77 ... 8387E919B1) Dobrý: (http://www.google.com) -> Nebyla provedena žádná instrukce.

Nalezené složky: 9
C:\Program Files (x86)\EZDownloader (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\newnext.me (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\newnext.me\cache (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\freegames4357 (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357) (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\mz (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\speedtest4354 (PUP.Optional.SpeedTest.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0 (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.

Nalezené soubory: 94
C:\Users\Jirka\AppData\Roaming\newnext.me\nengine.dll (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbarsvc.exe (PUP.Optional.AudioToAudioToolBar.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\ScriptHost.dll (PUP.Optional.BestToolbars) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\freegames4357\install_helper.exe (Trojan.BProtector) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\speedtest4354\install_helper.exe (Trojan.BProtector) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\Downloads\Download.exe (PUP.Optional.InstalleRex) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\Downloads\DTLite4481-0347.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\Downloads\GAGGIA BABY TWIN user guide provided through czechmanuals.com(1).exe (PUP.Optional.LiveSoftAction.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\Downloads\GAGGIA BABY TWIN user guide provided through czechmanuals.com.exe (PUP.Optional.LiveSoftAction.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\Downloads\GAGGIA BABY TWIN user guide provided through diplotop.cz(1).exe (PUP.Optional.LiveSoftAction.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\Downloads\GAGGIA BABY TWIN user guide provided through diplotop.cz.exe (PUP.Optional.LiveSoftAction.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\Downloads\VideoPerformerSetup (1).exe (PUP.Optional.InstallBrain) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\Downloads\VideoPerformerSetup (2).exe (PUP.Optional.InstallBrain) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\Downloads\VideoPerformerSetup (3).exe (PUP.Optional.InstallBrain) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\Downloads\VideoPerformerSetup.exe (PUP.Optional.InstallBrain) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\genienext\nengine.dll (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\GS-Enabler\Assistant.dll (PUP.Optional.GreatSaver.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\GS-Enabler\AssistantSvc.dll (PUP.Optional.GreatSaver.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.Core.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.exe (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.exe.config (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.Extension.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.Spider.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\ICSharpCode.SharpZipLib.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\Interop.SHDocVw.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\TabStrip.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\unins000.dat (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\unins000.exe (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\newnext.me\nengine.cookie (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\newnext.me\cache\spark.bin (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\freegames4357\freegames4357.crx (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\freegames4357\freegames4357.xpi (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\freegames4357\freegames4357DeskTopIcon.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\freegames4357\install_helper.exe (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\AddonsFramework.Typelib.dll (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\AddonsFramework.Typelib64.dll (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\background.html (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\BackgroundHost.exe (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\BackgroundHost64.exe (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\bg.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\ButtonSite.dll (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\ButtonSite64.dll (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\config.xml (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\content.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\icon128.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\icon128.png (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\icon16.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\icon16.png (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\icon18.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\icon18.png (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\icon24.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\icon24.png (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\icon32.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\icon32.png (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\icon48.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\icon48.png (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\jquery-1.9.1.min.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\json2.min.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\options.htm (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\ScriptHost64.dll (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\uninst.exe (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\uninstall.exe (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\updater.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\updaterWrapper.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\mz\background.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Free Games (4357)\mz\content.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\speedtest4354\install_helper.exe (PUP.Optional.SpeedTest.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\speedtest4354\speedtest4354.crx (PUP.Optional.SpeedTest.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\speedtest4354\speedtest4354.xpi (PUP.Optional.SpeedTest.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Roaming\speedtest4354\speedtest4354DeskTopIcon.ico (PUP.Optional.SpeedTest.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\background.html (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\button.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\ci.bg.pack.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\ci.browser.helper.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\ci.content.pack.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\content.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\icon128.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\icon128.png (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\icon16.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\icon16.png (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\icon18.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\icon18.png (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\icon24.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\icon24.png (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\icon32.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\icon32.png (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\icon48.ico (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\icon48.png (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\jquery-1.9.1.min.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\jquery.uuid.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\manifest.json (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\popup.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\rjs.js (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0_0\settings.json (PUP.Optional.FreeGames.A) -> Nebyla provedena žádná instrukce.

(konec)


Udělal jsem jen Rychlou kontrolu :shock: .

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Preventivní kontrola

#5 Příspěvek od Roli »

jmeno1 píše:Udělal jsem jen Rychlou kontrolu :shock: .
To je nálet šmejdů co ?


Znovu spusť AdwCleaner ale tentokrát klikni na Clean,

proběhne restart PC kdy dojde ke smazání nepořádku.

Po té mi sem zase zkopíruj Report.


To co Mbam našel nech smazat a pak mi sem dej zase log.


Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.


V případě nejasností je ZDE obrázkový návod.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

jmeno1
3. Stupeň Varování
Příspěvky: 99
Registrován: 06 led 2006 07:43

Re: Preventivní kontrola

#6 Příspěvek od jmeno1 »

# AdwCleaner v3.020 - Report created 03/03/2014 at 14:46:21
# Updated 27/02/2014 by Xplode
# Operating System : Windows 7 Professional (64 bits)
# Username : Jirka - JIRKA-PC
# Running from : C:\Users\Jirka\Downloads\adwcleaner (1).exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : Allin1Convert_8hService

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\AVG SafeGuard toolbar
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\ProgramData\QuickSet
Folder Deleted : C:\ProgramData\TubeADiblockeR
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZDownloader
Folder Deleted : C:\Program Files (x86)\Allin1Convert_8h
Folder Deleted : C:\Program Files (x86)\AVG SafeGuard toolbar
Folder Deleted : C:\Program Files (x86)\EZDownloader
[!] Folder Deleted : C:\Program Files (x86)\GS-Enabler
Folder Deleted : C:\Program Files (x86)\MyPC Backup
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Users\Jirka\AppData\Local\Allin1Convert_8h
[!] Folder Deleted : C:\Users\Jirka\AppData\Local\AVG SafeGuard toolbar
Folder Deleted : C:\Users\Jirka\AppData\Local\genienext
Folder Deleted : C:\Users\Jirka\AppData\Local\iac
Folder Deleted : C:\Users\Jirka\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Jirka\AppData\LocalLow\Allin1Convert_8h
Folder Deleted : C:\Users\Jirka\AppData\LocalLow\AVG SafeGuard toolbar
Folder Deleted : C:\Users\Jirka\AppData\LocalLow\iac
Folder Deleted : C:\Users\Jirka\AppData\Roaming\newnext.me
Folder Deleted : C:\Users\Jirka\AppData\Roaming\PerformerSoft
Folder Deleted : C:\Users\Jirka\Documents\Mobogenie
Folder Deleted : C:\Users\Jirka\Documents\Optimizer Pro
Folder Deleted : C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\j6z32s7x.default\Extensions\8hffxtbr@Allin1Convert_8h.com
Folder Deleted : C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\j6z32s7x.default\Extensions\yoab0z@olwq-zfmr.org
Folder Deleted : C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
File Deleted : C:\Windows\System32\roboot64.exe
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NextLive]
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.feedmanager
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.feedmanager.1
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.htmlmenu
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.htmlmenu.1
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.htmlpanel
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.htmlpanel.1
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.multiplebutton
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.multiplebutton.1
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.pseudotransparentplugin
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.pseudotransparentplugin.1
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.radio
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.radio.1
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.radiosettings
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.radiosettings.1
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.scriptbutton
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.scriptbutton.1
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.settingsplugin
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.settingsplugin.1
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.thirdpartyinstaller
Key Deleted : HKLM\SOFTWARE\Classes\allin1convert_8h.thirdpartyinstaller.1
Key Deleted : HKLM\SOFTWARE\Classes\Allin1Convert_8h.ToolbarProtector
Key Deleted : HKLM\SOFTWARE\Classes\Allin1Convert_8h.ToolbarProtector.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\LiveSupport_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\livesupport_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@Allin1Convert_8h.com/Plugin
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{248B3E95-17A4-482D-A8A8-6B3DF4D05C35}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{27F49273-DE3A-4111-90F9-6C474C37AEFB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{39D4F1A1-A94D-4B7D-BF1D-7446308800ED}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{443321F7-E46C-42F8-812B-F35E98CBB44F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5CDE4714-32DC-473C-8194-0645E62C2E96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7CAEFAFC-9A1E-4BCC-94DD-BC7D8D52717A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7EB7381C-FB01-47FC-9C42-ED64122C1B92}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{889F49D2-6CEA-40BE-BE5F-7217485F9745}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8F83D657-5993-4FFA-9AEE-DA0B20D828A7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C8EF8F70-3807-424A-83F7-DA06FD4DACF9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD1A63BA-A08C-431B-9A34-F240AADC728D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE0F6787-9D1C-42B7-A0B9-EAC630F87902}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E4EF697F-434B-4DC7-A464-4412462206DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF3F28C8-0330-4D18-B901-D24CB83E5AA1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF5DB804-585B-472E-B415-BC63F8F01BF6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F2C368C5-9F44-4D43-89F3-A1CC87F1DA96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F99DDD9A-07D0-47AB-86F1-193533DD2C60}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{16976E15-10EA-44FD-804A-6ECBC9EBBFC7}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2561FD25-FE31-4E56-A120-AF7FEAAE3124}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4BD0FCFF-AD64-4315-9F2C-960EF3C21623}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{507C73BB-FC69-425E-8A49-9204F886B328}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6EC57031-1740-4151-93C5-C465D6063DD2}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{76FC1003-0825-48BD-B59B-3B7A5754972C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9D217B94-6FC9-44FE-94B1-30C711871266}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B48AC2CD-9662-47E0-A3C0-3B01BB3F463E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{BE698E51-830B-447A-954D-901D6E05DDE2}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{BFCF748F-A56E-451F-AA45-0D7EB699E416}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D617CF84-B0BC-441F-9984-B676AFBA1E8D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7CAEFAFC-9A1E-4BCC-94DD-BC7D8D52717A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD1A63BA-A08C-431B-9A34-F240AADC728D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CD1A63BA-A08C-431B-9A34-F240AADC728D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{27F49273-DE3A-4111-90F9-6C474C37AEFB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7CAEFAFC-9A1E-4BCC-94DD-BC7D8D52717A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7EB7381C-FB01-47FC-9C42-ED64122C1B92}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E4EF697F-434B-4DC7-A464-4412462206DB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F99DDD9A-07D0-47AB-86F1-193533DD2C60}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{248B3E95-17A4-482D-A8A8-6B3DF4D05C35}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\allin1convert_8h
Key Deleted : HKCU\Software\AVG SafeGuard toolbar
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\performersoft llc
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKCU\Software\AppDataLow\Software\allin1convert_8h
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\allin1convert_8h
Key Deleted : HKLM\Software\AVG SafeGuard toolbar
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\allin1convert_8hbar uninstall firefox
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16526

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v27.0.1 (cs)

[ File : C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\j6z32s7x.default\prefs.js ]

Line Deleted : user_pref("extensions.VrjO22z8YWL3.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||ur[...]

*************************

AdwCleaner[R0].txt - [15013 octets] - [02/03/2014 14:09:03]
AdwCleaner[R1].txt - [14451 octets] - [02/03/2014 14:20:16]
AdwCleaner[R2].txt - [14557 octets] - [03/03/2014 14:45:54]
AdwCleaner[S0].txt - [14298 octets] - [03/03/2014 14:46:21]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14359 octets] ##########

jmeno1
3. Stupeň Varování
Příspěvky: 99
Registrován: 06 led 2006 07:43

Re: Preventivní kontrola

#7 Příspěvek od jmeno1 »

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2014.03.02.04

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Jirka :: JIRKA-PC [administrátor]

Ochrana: Povolena

3.3.2014 14:48:48
mbam-log-2014-03-03 (14-48-48).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 267778
Uplynulý čas: 1 minut, 40 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 20
HKCR\CLSID\{2977C29A-6723-4436-90BB-F7C5FDEF88A1} (PUP.Optional.BestToolbars) -> Přesun do karantény a smazání se zdařilo.
HKCR\TypeLib\{813FB3C5-A4D9-4CD8-BDD0-750F40E68908} (PUP.Optional.BestToolbars) -> Přesun do karantény a smazání se zdařilo.
HKCR\Free Games (4357).ScriptHostObject.1 (PUP.Optional.BestToolbars) -> Přesun do karantény a smazání se zdařilo.
HKCR\Free Games (4357).ScriptHostObject (PUP.Optional.BestToolbars) -> Přesun do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2977C29A-6723-4436-90BB-F7C5FDEF88A1} (PUP.Optional.BestToolbars) -> Přesun do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{2977C29A-6723-4436-90BB-F7C5FDEF88A1} (PUP.Optional.BestToolbars) -> Přesun do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2977C29A-6723-4436-90BB-F7C5FDEF88A1} (PUP.Optional.BestToolbars) -> Přesun do karantény a smazání se zdařilo.
HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252} (PUP.Optional.GreatSaver.A) -> Přesun do karantény a smazání se zdařilo.
HKCR\Free Games (4357).BackgroundHostObject (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
HKCR\Free Games (4357).BackgroundHostObject.1 (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
HKCR\Free Games (4357).Navbar (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
HKCR\Free Games (4357).Navbar.1 (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
HKCR\Free Games (4357).Tool (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
HKCR\Free Games (4357).Tool.1 (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Google\Chrome\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
HKCR\TypeLib\{739CDEE7-D45D-426F-9776-8BC4F8C1A4AB} (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
HKCR\TypeLib\{4398032D-0040-451D-9AB9-5CE5597EB103} (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
HKCR\CLSID\{5C71ACCF-F361-40F4-9E19-23D831490AAB} (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
HKCR\TypeLib\{DF776000-0872-4D61-B445-CAD0C227C731} (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Free Games (4357) (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 7
C:\Users\Jirka\AppData\Roaming\freegames4357 (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357) (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\mz (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Roaming\speedtest4354 (PUP.Optional.SpeedTest.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0 (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\mz (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.

Nalezené soubory: 78
C:\Program Files (x86)\Free Games (4357)\ScriptHost.dll (PUP.Optional.BestToolbars) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Roaming\freegames4357\install_helper.exe (Trojan.BProtector) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Roaming\speedtest4354\install_helper.exe (Trojan.BProtector) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\Downloads\Download.exe (PUP.Optional.InstalleRex) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\Downloads\DTLite4481-0347.exe (PUP.Optional.OpenCandy) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\Downloads\GAGGIA BABY TWIN user guide provided through czechmanuals.com(1).exe (PUP.Optional.LiveSoftAction.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\Downloads\GAGGIA BABY TWIN user guide provided through czechmanuals.com.exe (PUP.Optional.LiveSoftAction.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\Downloads\GAGGIA BABY TWIN user guide provided through diplotop.cz(1).exe (PUP.Optional.LiveSoftAction.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\Downloads\GAGGIA BABY TWIN user guide provided through diplotop.cz.exe (PUP.Optional.LiveSoftAction.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\Downloads\VideoPerformerSetup (1).exe (PUP.Optional.InstallBrain) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\Downloads\VideoPerformerSetup (2).exe (PUP.Optional.InstallBrain) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\Downloads\VideoPerformerSetup (3).exe (PUP.Optional.InstallBrain) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\Downloads\VideoPerformerSetup.exe (PUP.Optional.InstallBrain) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Roaming\freegames4357\freegames4357.crx (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Roaming\freegames4357\freegames4357.xpi (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Roaming\freegames4357\freegames4357DeskTopIcon.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Roaming\freegames4357\install_helper.exe (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\AddonsFramework.Typelib.dll (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\AddonsFramework.Typelib64.dll (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\background.html (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\BackgroundHost.exe (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\BackgroundHost64.exe (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\bg.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\ButtonSite.dll (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\ButtonSite64.dll (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\config.xml (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\content.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\icon128.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\icon128.png (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\icon16.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\icon16.png (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\icon18.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\icon18.png (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\icon24.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\icon24.png (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\icon32.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\icon32.png (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\icon48.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\icon48.png (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\jquery-1.9.1.min.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\json2.min.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\options.htm (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\ScriptHost64.dll (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\uninst.exe (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\uninstall.exe (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\updater.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\updaterWrapper.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\mz\background.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\Free Games (4357)\mz\content.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Roaming\speedtest4354\install_helper.exe (PUP.Optional.SpeedTest.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Roaming\speedtest4354\speedtest4354.crx (PUP.Optional.SpeedTest.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Roaming\speedtest4354\speedtest4354.xpi (PUP.Optional.SpeedTest.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Roaming\speedtest4354\speedtest4354DeskTopIcon.ico (PUP.Optional.SpeedTest.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\background.html (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\bg.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\ci.bg.pack.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\ci.browser.helper.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\ci.content.pack.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\content.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\icon128.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\icon128.png (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\icon16.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\icon16.png (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\icon18.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\icon18.png (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\icon24.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\icon24.png (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\icon32.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\icon32.png (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\icon48.ico (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\icon48.png (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\jquery-1.9.1.min.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\jquery.uuid.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\manifest.json (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\popup.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\settings.json (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\mz\background.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\1.0.0.0_0\mz\content.js (PUP.Optional.FreeGames.A) -> Přesun do karantény a smazání se zdařilo.

(konec)

jmeno1
3. Stupeň Varování
Příspěvky: 99
Registrován: 06 led 2006 07:43

Re: Preventivní kontrola

#8 Příspěvek od jmeno1 »

ComboFix 14-02-24.02 - Jirka 03.03.2014 14:59:19.1.8 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.8140.6074 [GMT 1:00]
Spuštěný z: c:\users\Jirka\Desktop\ComboFix.exe
AV: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bijneplbimddbnelicjognnhaedbofdh
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bijneplbimddbnelicjognnhaedbofdh\1.0_1\background.html
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bijneplbimddbnelicjognnhaedbofdh\1.0_1\content.js
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bijneplbimddbnelicjognnhaedbofdh\1.0_1\lsdb.js
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bijneplbimddbnelicjognnhaedbofdh\1.0_1\manifest.json
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bijneplbimddbnelicjognnhaedbofdh\1.0_1\mtHi6Ap7eE1b.js
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bijneplbimddbnelicjognnhaedbofdh_0.localstorage-journal
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bijneplbimddbnelicjognnhaedbofdh_0.localstorage
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\windows\SysWow64\X86
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-02-03 do 2014-03-03 )))))))))))))))))))))))))))))))
.
.
2014-03-02 13:22 . 2014-03-02 13:22 -------- d-----w- c:\users\Jirka\AppData\Roaming\Malwarebytes
2014-03-02 13:22 . 2014-03-02 13:22 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2014-03-02 13:22 . 2014-03-02 13:22 -------- d-----w- c:\programdata\Malwarebytes
2014-03-02 13:22 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-03-02 13:08 . 2014-03-03 13:46 -------- d-----w- C:\AdwCleaner
2014-03-01 14:09 . 2014-03-01 14:09 -------- d-----w- C:\rsit
2014-03-01 14:09 . 2014-03-01 14:09 -------- d-----w- c:\program files\trend micro
2014-02-25 17:01 . 2014-02-25 17:01 -------- d-----w- c:\program files (x86)\MSECache
2014-02-23 07:09 . 2014-02-23 07:09 -------- d-----w- c:\users\Jirka\AppData\Roaming\dvdcss
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-02 20:32 . 2013-12-18 18:26 50976 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2014-02-20 20:24 . 2013-12-04 13:50 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-02-20 20:24 . 2013-12-04 13:50 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-23 09:00 . 2013-12-23 09:00 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-12-23 09:00 . 2013-12-23 09:00 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-12-23 09:00 . 2013-12-23 09:00 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-12-23 09:00 . 2013-12-23 09:00 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-12-23 09:00 . 2013-12-23 09:00 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-12-23 09:00 . 2013-12-23 09:00 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-12-23 09:00 . 2013-12-23 09:00 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-12-23 09:00 . 2013-12-23 09:00 367104 ----a-w- c:\windows\SysWow64\html.iec
2013-12-23 09:00 . 2013-12-23 09:00 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-12-23 09:00 . 2013-12-23 09:00 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-12-23 09:00 . 2013-12-23 09:00 1806848 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-12-23 09:00 . 2013-12-23 09:00 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2013-12-23 09:00 . 2013-12-23 09:00 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2013-12-23 09:00 . 2013-12-23 09:00 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-12-23 09:00 . 2013-12-23 09:00 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-12-23 09:00 . 2013-12-23 09:00 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2013-12-23 09:00 . 2013-12-23 09:00 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-12-23 09:00 . 2013-12-23 09:00 96768 ----a-w- c:\windows\system32\mshtmled.dll
2013-12-23 09:00 . 2013-12-23 09:00 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-12-23 09:00 . 2013-12-23 09:00 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-12-23 09:00 . 2013-12-23 09:00 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2013-12-23 09:00 . 2013-12-23 09:00 85504 ----a-w- c:\windows\system32\jsproxy.dll
2013-12-23 09:00 . 2013-12-23 09:00 85504 ----a-w- c:\windows\system32\iesetup.dll
2013-12-23 09:00 . 2013-12-23 09:00 82432 ----a-w- c:\windows\system32\icardie.dll
2013-12-23 09:00 . 2013-12-23 09:00 816640 ----a-w- c:\windows\system32\jscript.dll
2013-12-23 09:00 . 2013-12-23 09:00 76800 ----a-w- c:\windows\system32\tdc.ocx
2013-12-23 09:00 . 2013-12-23 09:00 729088 ----a-w- c:\windows\system32\msfeeds.dll
2013-12-23 09:00 . 2013-12-23 09:00 65024 ----a-w- c:\windows\system32\pngfilt.dll
2013-12-23 09:00 . 2013-12-23 09:00 599040 ----a-w- c:\windows\system32\vbscript.dll
2013-12-23 09:00 . 2013-12-23 09:00 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-12-23 09:00 . 2013-12-23 09:00 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2013-12-23 09:00 . 2013-12-23 09:00 49664 ----a-w- c:\windows\system32\imgutil.dll
2013-12-23 09:00 . 2013-12-23 09:00 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-12-23 09:00 . 2013-12-23 09:00 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2013-12-23 09:00 . 2013-12-23 09:00 448512 ----a-w- c:\windows\system32\html.iec
2013-12-23 09:00 . 2013-12-23 09:00 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2013-12-23 09:00 . 2013-12-23 09:00 39936 ----a-w- c:\windows\system32\iernonce.dll
2013-12-23 09:00 . 2013-12-23 09:00 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-12-23 09:00 . 2013-12-23 09:00 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-12-23 09:00 . 2013-12-23 09:00 30720 ----a-w- c:\windows\system32\licmgr10.dll
2013-12-23 09:00 . 2013-12-23 09:00 282112 ----a-w- c:\windows\system32\dxtrans.dll
2013-12-23 09:00 . 2013-12-23 09:00 267776 ----a-w- c:\windows\system32\ieaksie.dll
2013-12-23 09:00 . 2013-12-23 09:00 249344 ----a-w- c:\windows\system32\webcheck.dll
2013-12-23 09:00 . 2013-12-23 09:00 248320 ----a-w- c:\windows\system32\ieui.dll
2013-12-23 09:00 . 2013-12-23 09:00 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-12-23 09:00 . 2013-12-23 09:00 237056 ----a-w- c:\windows\system32\url.dll
2013-12-23 09:00 . 2013-12-23 09:00 2334720 ----a-w- c:\windows\system32\jscript9.dll
2013-12-23 09:00 . 2013-12-23 09:00 222208 ----a-w- c:\windows\system32\msls31.dll
2013-12-23 09:00 . 2013-12-23 09:00 2147840 ----a-w- c:\windows\system32\iertutil.dll
2013-12-23 09:00 . 2013-12-23 09:00 197120 ----a-w- c:\windows\system32\msrating.dll
2013-12-23 09:00 . 2013-12-23 09:00 17847296 ----a-w- c:\windows\system32\mshtml.dll
2013-12-23 09:00 . 2013-12-23 09:00 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2013-12-23 09:00 . 2013-12-23 09:00 165888 ----a-w- c:\windows\system32\iexpress.exe
2013-12-23 09:00 . 2013-12-23 09:00 163840 ----a-w- c:\windows\system32\ieakui.dll
2013-12-23 09:00 . 2013-12-23 09:00 160256 ----a-w- c:\windows\system32\wextract.exe
2013-12-23 09:00 . 2013-12-23 09:00 160256 ----a-w- c:\windows\system32\ieakeng.dll
2013-12-23 09:00 . 2013-12-23 09:00 149504 ----a-w- c:\windows\system32\occache.dll
2013-12-23 09:00 . 2013-12-23 09:00 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2013-12-23 09:00 . 2013-12-23 09:00 145920 ----a-w- c:\windows\system32\iepeers.dll
2013-12-23 09:00 . 2013-12-23 09:00 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-12-23 09:00 . 2013-12-23 09:00 1392128 ----a-w- c:\windows\system32\wininet.dll
2013-12-23 09:00 . 2013-12-23 09:00 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-12-23 09:00 . 2013-12-23 09:00 1347072 ----a-w- c:\windows\system32\urlmon.dll
2013-12-23 09:00 . 2013-12-23 09:00 12288 ----a-w- c:\windows\system32\mshta.exe
2013-12-23 09:00 . 2013-12-23 09:00 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2013-12-23 09:00 . 2013-12-23 09:00 114176 ----a-w- c:\windows\system32\admparse.dll
2013-12-23 09:00 . 2013-12-23 09:00 111616 ----a-w- c:\windows\system32\iesysprep.dll
2013-12-23 09:00 . 2013-12-23 09:00 10926080 ----a-w- c:\windows\system32\ieframe.dll
2013-12-23 09:00 . 2013-12-23 09:00 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2013-12-23 09:00 . 2013-12-23 09:00 103936 ----a-w- c:\windows\system32\inseng.dll
2013-12-23 09:00 . 2013-12-23 09:00 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2013-12-06 12:42 . 2013-12-06 12:42 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Overwolf"="c:\program files (x86)\Overwolf\Overwolf.exe" [2014-02-16 37632]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2012-07-19 133440]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-05-20 291648]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"AVG_UI"="c:\program files (x86)\AVG\AVG2014\avgui.exe" [2013-11-07 4956176]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2014\avgidsagent.exe;c:\program files (x86)\AVG\AVG2014\avgidsagent.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 e81a9dc1;GS-Supporter;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x]
R2 vToolbarUpdater18.0.0;vToolbarUpdater18.0.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 OverwolfUpdaterService;Overwolf Updater Service;c:\program files (x86)\Overwolf\OverwolfUpdater.exe;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys [x]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 Avgdiska;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiska.sys;c:\windows\SYSNATIVE\DRIVERS\avgdiska.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2014\avgwdsvc.exe;c:\program files (x86)\AVG\AVG2014\avgwdsvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-29 18:26 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.102\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-03-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-04 20:24]
.
2014-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-02 18:09]
.
2014-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-02 18:09]
.
.
--------- X64 Entries -----------
.
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\j6z32s7x.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL -
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{2977C29A-6723-4436-90BB-F7C5FDEF88A1} - c:\program files (x86)\Free Games (4357)\ScriptHost64.dll
AddRemove-{5F189DF5-2D05-472B-9091-84D9848AE48B}{e81a9dc1} - c:\progra~2\GS-ENA~1\ASSIST~1.DLL
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-03-03 15:07:57
ComboFix-quarantined-files.txt 2014-03-03 14:07
.
Před spuštěním: Volných bajtů: 58 953 920 512
Po spuštění: Volných bajtů: 58 560 147 456
.
- - End Of File - - 838A695AA5B40CFA6CB87886B2362279
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Preventivní kontrola

#9 Příspěvek od Roli »

Ještě doladíme :)


Pokud jsi tak ještě neučinil, přesuň Combofix na plochu

otevři si Poznámkový blok

do něj zkopíruj skript z následujícího okna:

Kód: Vybrat vše

RegLock:: 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
ulož Tebou vytvořený TXT soubor jako CFScript.txt na plochu,

po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Obrázek

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,

v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

jmeno1
3. Stupeň Varování
Příspěvky: 99
Registrován: 06 led 2006 07:43

Re: Preventivní kontrola

#10 Příspěvek od jmeno1 »

ComboFix 14-03-04.01 - Jirka 04.03.2014 18:02:22.2.8 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.8138.6362 [GMT 1:00]
Spuštěný z: c:\users\Jirka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jirka\Desktop\CFScript.txt
AV: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bijneplbimddbnelicjognnhaedbofdh
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bijneplbimddbnelicjognnhaedbofdh\1.0_0\background.html
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bijneplbimddbnelicjognnhaedbofdh\1.0_0\content.js
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bijneplbimddbnelicjognnhaedbofdh\1.0_0\lsdb.js
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bijneplbimddbnelicjognnhaedbofdh\1.0_0\manifest.json
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bijneplbimddbnelicjognnhaedbofdh\1.0_0\mtHi6Ap7eE1b.js
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bijneplbimddbnelicjognnhaedbofdh_0.localstorage-journal
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bijneplbimddbnelicjognnhaedbofdh_0.localstorage
c:\users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\windows\msxml4-KB954430-enu.LOG
.
Nakažená kopie c:\windows\SysWow64\Version.dll byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\erdnt\cache86\version.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-02-04 do 2014-03-04 )))))))))))))))))))))))))))))))
.
.
2014-03-04 17:05 . 2014-03-04 17:05 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-03-04 17:05 . 2014-03-04 17:05 -------- d-----w- c:\users\Guest\AppData\Local\temp
2014-03-04 17:05 . 2014-03-04 17:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-03 14:43 . 2010-11-20 13:27 2018304 ----a-w- c:\windows\system32\WsmSvc.dll
2014-03-03 14:37 . 2011-03-11 06:41 189824 ----a-w- c:\windows\system32\drivers\storport.sys
2014-03-02 13:22 . 2014-03-02 13:22 -------- d-----w- c:\users\Jirka\AppData\Roaming\Malwarebytes
2014-03-02 13:22 . 2014-03-02 13:22 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2014-03-02 13:22 . 2014-03-02 13:22 -------- d-----w- c:\programdata\Malwarebytes
2014-03-02 13:22 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-03-02 13:08 . 2014-03-03 13:46 -------- d-----w- C:\AdwCleaner
2014-03-01 14:09 . 2014-03-01 14:09 -------- d-----w- C:\rsit
2014-03-01 14:09 . 2014-03-01 14:09 -------- d-----w- c:\program files\trend micro
2014-02-25 17:01 . 2014-02-25 17:01 -------- d-----w- c:\program files (x86)\MSECache
2014-02-23 07:09 . 2014-02-23 07:09 -------- d-----w- c:\users\Jirka\AppData\Roaming\dvdcss
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-03 15:17 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2014-03-03 15:17 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2014-03-02 20:32 . 2013-12-18 18:26 50976 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2014-02-20 20:24 . 2013-12-04 13:50 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-02-20 20:24 . 2013-12-04 13:50 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-02-04 18:09 . 2013-12-23 08:44 88567024 ----a-w- c:\windows\system32\MRT.exe
2013-12-23 09:00 . 2013-12-23 09:00 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-12-23 09:00 . 2013-12-23 09:00 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-12-23 09:00 . 2013-12-23 09:00 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-12-23 09:00 . 2013-12-23 09:00 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-12-23 09:00 . 2013-12-23 09:00 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-12-23 09:00 . 2013-12-23 09:00 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-12-23 09:00 . 2013-12-23 09:00 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-12-23 09:00 . 2013-12-23 09:00 367104 ----a-w- c:\windows\SysWow64\html.iec
2013-12-23 09:00 . 2013-12-23 09:00 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-12-23 09:00 . 2013-12-23 09:00 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-12-23 09:00 . 2013-12-23 09:00 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2013-12-23 09:00 . 2013-12-23 09:00 1806848 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-12-23 09:00 . 2013-12-23 09:00 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2013-12-23 09:00 . 2013-12-23 09:00 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2013-12-23 09:00 . 2013-12-23 09:00 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-12-23 09:00 . 2013-12-23 09:00 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-12-23 09:00 . 2013-12-23 09:00 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2013-12-23 09:00 . 2013-12-23 09:00 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-12-23 09:00 . 2013-12-23 09:00 96768 ----a-w- c:\windows\system32\mshtmled.dll
2013-12-23 09:00 . 2013-12-23 09:00 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-12-23 09:00 . 2013-12-23 09:00 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-12-23 09:00 . 2013-12-23 09:00 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2013-12-23 09:00 . 2013-12-23 09:00 85504 ----a-w- c:\windows\system32\jsproxy.dll
2013-12-23 09:00 . 2013-12-23 09:00 85504 ----a-w- c:\windows\system32\iesetup.dll
2013-12-23 09:00 . 2013-12-23 09:00 82432 ----a-w- c:\windows\system32\icardie.dll
2013-12-23 09:00 . 2013-12-23 09:00 816640 ----a-w- c:\windows\system32\jscript.dll
2013-12-23 09:00 . 2013-12-23 09:00 76800 ----a-w- c:\windows\system32\tdc.ocx
2013-12-23 09:00 . 2013-12-23 09:00 729088 ----a-w- c:\windows\system32\msfeeds.dll
2013-12-23 09:00 . 2013-12-23 09:00 65024 ----a-w- c:\windows\system32\pngfilt.dll
2013-12-23 09:00 . 2013-12-23 09:00 599040 ----a-w- c:\windows\system32\vbscript.dll
2013-12-23 09:00 . 2013-12-23 09:00 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-12-23 09:00 . 2013-12-23 09:00 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2013-12-23 09:00 . 2013-12-23 09:00 49664 ----a-w- c:\windows\system32\imgutil.dll
2013-12-23 09:00 . 2013-12-23 09:00 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-12-23 09:00 . 2013-12-23 09:00 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2013-12-23 09:00 . 2013-12-23 09:00 448512 ----a-w- c:\windows\system32\html.iec
2013-12-23 09:00 . 2013-12-23 09:00 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2013-12-23 09:00 . 2013-12-23 09:00 39936 ----a-w- c:\windows\system32\iernonce.dll
2013-12-23 09:00 . 2013-12-23 09:00 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-12-23 09:00 . 2013-12-23 09:00 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-12-23 09:00 . 2013-12-23 09:00 30720 ----a-w- c:\windows\system32\licmgr10.dll
2013-12-23 09:00 . 2013-12-23 09:00 282112 ----a-w- c:\windows\system32\dxtrans.dll
2013-12-23 09:00 . 2013-12-23 09:00 267776 ----a-w- c:\windows\system32\ieaksie.dll
2013-12-23 09:00 . 2013-12-23 09:00 249344 ----a-w- c:\windows\system32\webcheck.dll
2013-12-23 09:00 . 2013-12-23 09:00 248320 ----a-w- c:\windows\system32\ieui.dll
2013-12-23 09:00 . 2013-12-23 09:00 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-12-23 09:00 . 2013-12-23 09:00 237056 ----a-w- c:\windows\system32\url.dll
2013-12-23 09:00 . 2013-12-23 09:00 2334720 ----a-w- c:\windows\system32\jscript9.dll
2013-12-23 09:00 . 2013-12-23 09:00 222208 ----a-w- c:\windows\system32\msls31.dll
2013-12-23 09:00 . 2013-12-23 09:00 2147840 ----a-w- c:\windows\system32\iertutil.dll
2013-12-23 09:00 . 2013-12-23 09:00 197120 ----a-w- c:\windows\system32\msrating.dll
2013-12-23 09:00 . 2013-12-23 09:00 17847296 ----a-w- c:\windows\system32\mshtml.dll
2013-12-23 09:00 . 2013-12-23 09:00 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2013-12-23 09:00 . 2013-12-23 09:00 165888 ----a-w- c:\windows\system32\iexpress.exe
2013-12-23 09:00 . 2013-12-23 09:00 163840 ----a-w- c:\windows\system32\ieakui.dll
2013-12-23 09:00 . 2013-12-23 09:00 160256 ----a-w- c:\windows\system32\wextract.exe
2013-12-23 09:00 . 2013-12-23 09:00 160256 ----a-w- c:\windows\system32\ieakeng.dll
2013-12-23 09:00 . 2013-12-23 09:00 149504 ----a-w- c:\windows\system32\occache.dll
2013-12-23 09:00 . 2013-12-23 09:00 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2013-12-23 09:00 . 2013-12-23 09:00 145920 ----a-w- c:\windows\system32\iepeers.dll
2013-12-23 09:00 . 2013-12-23 09:00 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-12-23 09:00 . 2013-12-23 09:00 1392128 ----a-w- c:\windows\system32\wininet.dll
2013-12-23 09:00 . 2013-12-23 09:00 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-12-23 09:00 . 2013-12-23 09:00 1347072 ----a-w- c:\windows\system32\urlmon.dll
2013-12-23 09:00 . 2013-12-23 09:00 12288 ----a-w- c:\windows\system32\mshta.exe
2013-12-23 09:00 . 2013-12-23 09:00 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2013-12-23 09:00 . 2013-12-23 09:00 114176 ----a-w- c:\windows\system32\admparse.dll
2013-12-23 09:00 . 2013-12-23 09:00 111616 ----a-w- c:\windows\system32\iesysprep.dll
2013-12-23 09:00 . 2013-12-23 09:00 10926080 ----a-w- c:\windows\system32\ieframe.dll
2013-12-23 09:00 . 2013-12-23 09:00 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2013-12-23 09:00 . 2013-12-23 09:00 103936 ----a-w- c:\windows\system32\inseng.dll
2013-12-23 09:00 . 2013-12-23 09:00 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2013-12-06 12:42 . 2013-12-06 12:42 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Overwolf"="c:\program files (x86)\Overwolf\Overwolf.exe" [2014-02-16 37632]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2012-07-19 133440]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-05-20 291648]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"AVG_UI"="c:\program files (x86)\AVG\AVG2014\avgui.exe" [2013-11-07 4956176]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 e81a9dc1;GS-Supporter;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 OverwolfUpdaterService;Overwolf Updater Service;c:\program files (x86)\Overwolf\OverwolfUpdater.exe;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys [x]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 Avgdiska;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiska.sys;c:\windows\SYSNATIVE\DRIVERS\avgdiska.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2014\avgidsagent.exe;c:\program files (x86)\AVG\AVG2014\avgidsagent.exe [x]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2014\avgwdsvc.exe;c:\program files (x86)\AVG\AVG2014\avgwdsvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-29 18:26 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.102\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-03-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-04 20:24]
.
2014-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-02 18:09]
.
2014-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-02 18:09]
.
.
--------- X64 Entries -----------
.
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\j6z32s7x.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL -
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
BHO-{2977C29A-6723-4436-90BB-F7C5FDEF88A1} - (no file)
AddRemove-{5F189DF5-2D05-472B-9091-84D9848AE48B}{e81a9dc1} - c:\progra~2\GS-ENA~1\ASSIST~1.DLL
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
.
**************************************************************************
.
Celkový čas: 2014-03-04 18:08:06 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-03-04 17:08
ComboFix2.txt 2014-03-03 14:08
.
Před spuštěním: Volných bajtů: 60 179 050 496
Po spuštění: Volných bajtů: 60 241 293 312
.
- - End Of File - - E336CE1468CCDB0CDA694C09EFB9B9A4
A36C5E4F47E84449FF07ED3517B43A31

Nemám mu tam nainstalovat Comodo?

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Preventivní kontrola

#11 Příspěvek od Roli »

jmeno1 píše:Nemám mu tam nainstalovat Comodo?
Myslím že stačí Avast, jen pozor AVG se jen tak nedá, až ho odinstaluješ použij v Nouzáku AVG Remover.

Přes Start >> Spustit zkopíruj do okna:

ComboFix /Uninstall

a stiskni Enter

To odinstaluje ComboFix a smaže s ním související soubory a složky.


Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.

Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.


Pak ještě jednou použij Mbam, ale tentokrát kompletní sken, samozřejmě chci zase vidět log dříve než něco smažeš.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

jmeno1
3. Stupeň Varování
Příspěvky: 99
Registrován: 06 led 2006 07:43

Re: Preventivní kontrola

#12 Příspěvek od jmeno1 »

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2014.03.06.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Jirka :: JIRKA-PC [administrátor]

Ochrana: Povolena

6.3.2014 15:29:14
mbam-log-2014-03-06 (15-29-14).txt

Typ: Kompletní kontrola (C:\|E:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 453484
Uplynulý čas: 15 minut, 5 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Preventivní kontrola

#13 Příspěvek od Roli »

Bezva čisto, jaký je tedy stav PC ?
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Odpovědět