
- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
Moderátor: Moderátoři
Kód: Vybrat vše
:otl
SRV - [2014.03.03 14:32:36 | 002,454,816 | ---- | M] (Conduit) [Auto | Running] -- C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe -- (CltMngSvc)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-776073097-1473087821-1952639389-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.trovigo.com/?gd=&ctid=CT3314 ... 43F5&SSPV=
IE - HKU\S-1-5-21-776073097-1473087821-1952639389-1001\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-776073097-1473087821-1952639389-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
[2014.03.18 13:07:58 | 000,347,599 | ---- | M] () (No name found) -- C:\Users\big\AppData\Roaming\Mozilla\Firefox\Profiles\g8a46teo.default\extensions\translator@dontfollowme.net.xpi
[2014.03.18 13:06:54 | 000,060,307 | ---- | M] () (No name found) -- C:\Users\big\AppData\Roaming\Mozilla\Firefox\Profiles\g8a46teo.default\extensions\translator@zoli.bod.xpi
[2014.03.18 08:27:01 | 000,000,980 | ---- | M] () -- C:\Users\big\AppData\Roaming\Mozilla\Firefox\Profiles\g8a46teo.default\searchplugins\conduit-search.xml
O4 - HKU\S-1-5-21-776073097-1473087821-1952639389-1001..\Run: [8e3bc91142bd8d798a10a1667ae4d2be] "C:\Users\big\AppData\Local\Temp\Skype.exe" .. File not found
O13 - gopher Prefix: missing
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2014.03.18 17:42:05 | 000,000,000 | ---D | C] -- C:\UsbFix
[2014.03.18 17:41:40 | 001,144,875 | ---- | C] (El Desaparecido - SosVirus.net) -- C:\Users\big\Desktop\UsbFix.exe
[2014.03.18 17:14:02 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\big\Desktop\mbam-setup-1.75.0.1300.exe
[2 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\2347e1c1efb91df2d1b80df333ec27b3\*.tmp files -> C:\Windows\SoftwareDistribution\Download\2347e1c1efb91df2d1b80df333ec27b3\*.tmp -> ]
[2014.03.18 13:37:40 | 000,206,336 | ---- | M] () -- C:\Users\big\AppData\Roaming\Flashmedia\drvgenipro.exe
[2014.03.18 13:37:51 | 014,107,008 | ---- | M] (Driver-Soft Inc. ) -- C:\Users\big\AppData\Roaming\Flashmedia\drvgenpro.exe
:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^big^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^8e3bc91142bd8d798a10a1667ae4d2be.exe]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
:files
C:\PROGRA~1\SearchProtect
C:\Users\big\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\8e3bc91142bd8d798a10a1667ae4d2be.exe
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
:commands
[RESETHOSTS]
[EMPTYTEMP]
[EMPTYFLASH]
[EMPTYJAVA]