Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

FRST log prosím prokouknout

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Cizap
Návštěvník
Návštěvník
Příspěvky: 81
Registrován: 07 dub 2014 11:56

FRST log prosím prokouknout

#1 Příspěvek od Cizap »

Ahoj, dobrý den,

dávám sem log z FRST něco mi vlezlo do PC a nevim co to je tak prosím o pomoc jsem tady poprvý, minulý týden jsem si nechal kontrolovat logy na warforu tak tam nechci otravovat znova navíc mě moderátor často odkazoval sem, tak to zakládám tady. Ne že by mi tam nepomohl vše bylo v pořádku akorát teď mi Avira vyhodila nějakýho Miner.skdr (a nejen to). když jsem chtěl sputit scan antivirem tak problikla obrazovka a scan se neprovedl. Když jsem chtěl uploadnout ten soubor ze kterýho to hlásilo vir tak mi to hodilo že na to nemam právo nevim jestli je to administratorský nebo co ale nevim jak to tam mam hodit udělal jsem screen posílám odkaz. Taky jsem platil něco v chrome přes kreditku a na zabezpečených stránkách vodafonu mi to řeklo, že je certifikát neduvěryhodnej nebo tak nějak bylo škrtlý https tak jsem to radši neplatil (nikdy předtim mi to nehlásilo platitm tam za kredit každou chvíli). Předem díky za pomoc. No a tady je ten odkaz, log a addition:
Addition.rar
(12.27 KiB) Staženo 49 x

Kód: Vybrat vše

http://imageshack.com/a/img20/6678/lufk.jpg

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by Joe (administrator) on CIZAP on 07-04-2014 13:33:53
Running from C:\Users\Joe\Desktop
Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
() C:\Program Files\LG Soft India\forteManager\bin\Monitor.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Borland Software Corporation) D:\Programy\ibase\bin\ibguard.exe
(LogMeIn, Inc.) C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe
() C:\Windows\system32\PnkBstrA.exe
(Borland Software Corporation) D:\Programy\ibase\bin\ibserver.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\system32\StikyNot.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(DT Soft Ltd) D:\Programy\DAEMON Tools Lite\DTLite.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\javaw.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_12_0_0_77_ActiveX.exe
(forum.viry.cz) C:\Users\Joe\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [BCSSync] - D:\Programy\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254896 2012-09-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-03-13] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2345296 2013-10-01] (LogMeIn Inc.)
HKLM\...\Run: [EaseUS EPM tray] - C:\Program Files\EaseUS\EaseUS Partition Master 9.3.0\bin\EpmNews.exe [2081792 2013-03-29] (CHENGDU YIWO Tech Development Co., Ltd)
HKLM\...\Run: [MSStp] - C:\Windows\inf\msstp.vbe [1584 2014-03-05] ()
HKLM\...\Run: [mncdtklhgSrv] - C:\Windows\system32\mncdtklhg.vbe [7670 2014-03-05] ()
HKU\S-1-5-21-3743817662-1129281641-473641309-1000\...\Run: [HP Photosmart 5510 series (NET)] - C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe [1804648 2011-09-16] (Hewlett-Packard Co.)
HKU\S-1-5-21-3743817662-1129281641-473641309-1000\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-3743817662-1129281641-473641309-1000\...\Run: [GSplay.exe] - C:\Users\Joe\Downloads\GSplay\GSplay.exe [4772747 2014-03-12] ()
HKU\S-1-5-21-3743817662-1129281641-473641309-1000\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\system32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3743817662-1129281641-473641309-1003\...\Run: [ISUSPM Startup] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation)
HKU\S-1-5-21-3743817662-1129281641-473641309-1003\...\Run: [QuickTime Task] - D:\Programy\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKU\S-1-5-21-3743817662-1129281641-473641309-1003\...\Run: [OfficeSyncProcess] - D:\Programy\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6CFCD46C8935CB01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=UP97&ocid=UP97DHP
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKCU - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM - DefaultScope value is missing.
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll No File
BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Programy\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Programy\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: gameboxchrome - {494D4E3B-FA53-4487-8AF6-3F50FE1167A9} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ]
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default
FF SearchEngineOrder.1: Ask.com
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll No File
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - D:\Programy\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - D:\Programy\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @real.com/nppl3260;version=15.0.4.53 - d:\programy\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=15.0.4.53 - d:\programy\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=15.0.4.53 - d:\programy\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.2 - D:\Programy\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @citrixonline.com/appdetectorplugin - C:\Users\Joe\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Joe\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\searchplugins\searchplugins-backup
FF Extension: Battlefield Heroes Updater - C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\Extensions\battlefieldheroespatcher@ea.com [2010-10-05]
FF Extension: Giant Savings - C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\Extensions\crossriderapp4479@crossrider.com [2012-09-12]
FF Extension: Illimitux - C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\Extensions\illimitux@illimitux.net [2010-05-18]
FF Extension: Nelinka - C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\Extensions\nelinka@shabbi.cz [2009-12-04]
FF Extension: Check4Change - C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\Extensions\check4change-owner@mozdev.org.xpi [2014-01-31]
FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi [2013-08-22]
FF HKLM\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-06-08]
FF StartMenuInternet: FIREFOX.EXE - D:\Programz\Mozilla Firefox\firefox.exe

Chrome:
=======
CHR HomePage: hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (registryAccess) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj\7.15.28.48310_0\background/registryAccess.dll No File
CHR Plugin: (Battlefield Play4Free Updater) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.66.2_0\npBP4FUpdater.dll (EA Digital Illusions CE AB)
CHR Plugin: (EA Battlefield Heroes Updater) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdfjahpadlpfnfheehpddpcllihfkmm\5.0.142.0_0\npBFHUpdater.dll (EA Digital Illusions CE AB)
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - D:\Programy\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - D:\Programy\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - D:\Programy\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - D:\Programy\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - D:\Programy\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - D:\Programy\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - D:\Programy\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - D:\Programy\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (RealJukebox NS Plugin) - D:\Programy\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Download Plugin) - D:\Programy\Mozilla Firefox\plugins\nprpplugin.dll (RealPlayer)
CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - D:\Programz\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (DivX Player Netscape Plugin) - D:\Programz\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
CHR Plugin: (2007 Microsoft Office system) - D:\Programz\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U37) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.370.6) - C:\Windows\system32\npdeployJava1.dll No File
CHR Plugin: (Microsoft Office 2010) - D:\Programy\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - D:\Programy\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (VLC Web Plugin) - D:\Programy\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Extension: (YouTube) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-18]
CHR Extension: (McAfee Security Scan+) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-02-25]
CHR Extension: (Battlefield Heroes) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2013-12-03]
CHR Extension: (Vyhledávání Google) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-18]
CHR Extension: (Battlefield Play4Free) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei [2012-01-22]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2012-08-04]
CHR Extension: (Battlefield Heroes) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdfjahpadlpfnfheehpddpcllihfkmm [2011-12-17]
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2011-07-25]
CHR Extension: (Skype Click to Call) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-06-26]
CHR Extension: (Peněženka Google) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-12]
CHR Extension: (Gmail) - C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-18]
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2012-06-08]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-03-03]

========================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-03-13] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-03-13] (Avira Operations GmbH & Co. KG)
S2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1612112 2013-10-01] (LogMeIn Inc.)
R2 InterBaseGuardian; D:\Programy\ibase\bin\ibguard.exe [32768 2001-11-29] (Borland Software Corporation)
R3 InterBaseServer; D:\Programy\ibase\bin\ibserver.exe [1769472 2001-11-29] (Borland Software Corporation)
R2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [375056 2013-08-26] (LogMeIn, Inc.)
S3 Microsoft SharePoint Workspace Audit Service; D:\Programy\Microsoft Office\Office14\GROOVE.EXE [30814400 2013-12-19] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75136 2014-01-29] ()

==================== Drivers (Whitelisted) ====================

S3 apf001; D:\Hry\Softnyx\RakionIS\Bin\apf001.sys [10872 2011-07-21] ()
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [279712 2010-08-02] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-07] (Avira Operations GmbH & Co. KG)
S3 Dot4Scan; C:\Windows\System32\DRIVERS\Dot4Scan.sys [10752 2009-07-14] (Microsoft Corporation)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14920 2013-03-07] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9160 2013-03-07] ()
R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-09-23] (LogMeIn, Inc.)
S3 LGDDCDevice; C:\Program Files\LG Soft India\forteManager\bin\I2CDriver.sys [14336 2009-04-24] ()
S3 LGII2CDevice; C:\Program Files\LG Soft India\forteManager\bin\PII2CDriver.sys [18432 2009-04-24] ()
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2010-08-01] ()
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
R3 RTL8187; C:\Windows\System32\DRIVERS\RTL8187.sys [375808 2010-01-07] (Realtek Semiconductor Corporation )
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-07-31] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-13] (Avira GmbH)
U3 afnr62j4; C:\Windows\system32\Drivers\afnr62j4.sys [0 ] (Microsoft Corporation)
S3 CFcatchme; \??\C:\Users\Joe\AppData\Local\Temp\CFcatchme.sys [X]
S3 GarenaPEngine; \??\C:\Users\Joe\AppData\Local\Temp\EIG6A57.tmp [X]
S3 GGSAFERDriver; \??\D:\Programy\Garena\plugins\UI\safedrv.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-07 13:33 - 2014-04-07 13:34 - 00023201 _____ () C:\Users\Joe\Desktop\FRST.txt
2014-04-07 13:32 - 2014-04-07 13:33 - 00000000 ____D () C:\FRST
2014-04-07 13:31 - 2014-04-07 13:31 - 00112640 _____ (forum.viry.cz) C:\Users\Joe\Desktop\FRSTLauncher.exe
2014-04-07 13:29 - 2014-04-07 13:29 - 00112640 _____ (forum.viry.cz) C:\Users\Joe\Downloads\Nepotvrzeno 250667.crdownload
2014-04-07 13:28 - 2014-04-07 13:28 - 00112640 _____ (forum.viry.cz) C:\Users\Joe\Downloads\Nepotvrzeno 569979.crdownload
2014-04-07 13:28 - 2014-04-07 13:28 - 00112640 _____ (forum.viry.cz) C:\Users\Joe\Downloads\Nepotvrzeno 340812.crdownload
2014-04-07 13:25 - 2014-04-07 13:27 - 01145856 _____ (Farbar) C:\Users\Joe\Desktop\FRST.exe
2014-04-04 07:54 - 2014-04-04 07:54 - 00001048 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-04-02 21:53 - 2014-04-02 21:53 - 00001003 _____ () C:\Users\Joe\Desktop\MP3 Speed Changer.lnk
2014-04-02 21:53 - 2014-04-02 21:53 - 00000000 ____D () C:\Users\Joe\AppData\Local\Crazy_Boomerang_Software
2014-04-02 21:52 - 2014-04-02 21:53 - 00000000 ____D () C:\Program Files\MP3 Speed Changer
2014-03-31 16:32 - 2014-04-07 11:43 - 00004144 _____ () C:\Windows\setupact.log
2014-03-31 16:32 - 2014-03-31 16:32 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-31 12:02 - 2014-03-31 12:02 - 00165888 _____ () C:\Users\Joe\Downloads\T-Cleaner.exe
2014-03-31 07:28 - 2014-03-31 07:28 - 00000003 _____ () C:\Users\Joe\stut
2014-03-31 06:58 - 2014-04-07 12:51 - 00000510 _____ () C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3743817662-1129281641-473641309-1000.job
2014-03-30 21:59 - 2014-03-30 21:59 - 01031330 _____ () C:\Users\Joe\Desktop\Nátlakové skupiny.pptx
2014-03-30 19:43 - 2014-03-30 19:43 - 00000000 ____D () C:\Users\Joe\Desktop\modlitby počajevo
2014-03-30 17:47 - 2014-03-30 17:47 - 01954304 _____ () C:\Users\Joe\Downloads\Úvaha.lnk.ppt
2014-03-30 13:23 - 2014-03-30 21:56 - 01031310 _____ () C:\Users\Joe\Downloads\Nátlakové skupiny.pptx
2014-03-30 13:23 - 2014-03-30 13:23 - 00084880 _____ () C:\Users\Joe\Downloads\Nátlakové skupiny (1).pptx
2014-03-29 15:09 - 2014-03-31 07:27 - 00000330 _____ () C:\Users\Joe\rgut
2014-03-28 16:16 - 2014-03-28 16:16 - 00001540 _____ () C:\Users\Joe\Desktop\Minecraft.exe – zástupce (2).lnk
2014-03-28 16:13 - 2014-03-28 16:13 - 00000687 _____ () C:\Users\Public\Desktop\World of Tanks - Common Test.lnk
2014-03-28 16:11 - 2014-03-28 16:12 - 10983288 _____ (Wargaming.net ) C:\Users\Joe\Downloads\WoT_internet_install_ct.exe
2014-03-27 23:54 - 2014-03-28 02:48 - 00000000 ____D () C:\Users\Joe\GSplay
2014-03-27 23:54 - 2014-03-27 23:54 - 00000000 ____D () C:\ProgramData\Oracle
2014-03-27 23:53 - 2014-03-27 23:53 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-03-27 23:53 - 2014-03-27 23:53 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-03-27 23:50 - 2014-03-27 23:50 - 00921000 _____ (Oracle Corporation) C:\Users\Joe\Desktop\jxpiinstall.exe
2014-03-27 23:50 - 2014-03-27 23:50 - 00000000 ____D () C:\Users\Joe\Downloads\GSplay
2014-03-27 23:47 - 2014-03-27 23:48 - 04748905 _____ () C:\Users\Joe\Downloads\GSplay.zip
2014-03-27 23:40 - 2014-03-27 23:40 - 01106756 _____ () C:\Users\Joe\Downloads\KeiNett Launcher.exe
2014-03-27 23:31 - 2014-03-05 23:19 - 00007670 ____S () C:\Windows\system32\mncdtklhg.vbe
2014-03-27 23:31 - 2013-10-26 21:30 - 00972814 ____S () C:\Windows\system32\dcgmncdtklhg.exe
2014-03-27 23:31 - 2013-07-18 17:06 - 00187904 ____S () C:\Windows\system32\lcpmncdtklhg.exe
2014-03-27 23:30 - 2014-03-27 23:30 - 00000000 ____D () C:\Windows\system32\bitstreams
2014-03-27 23:30 - 2014-03-27 23:30 - 00000000 ____D () C:\Users\Joe\Downloads\Minecraft-1.7.2
2014-03-27 23:30 - 2014-03-27 23:30 - 00000000 ____D () C:\Program Files\Minecraft-1.7.2
2014-03-27 23:30 - 2013-12-10 01:30 - 10236928 ____S () C:\Windows\system32\acumncdtklhg.exe
2014-03-27 23:30 - 2013-10-26 21:30 - 01704448 ____S (The OpenSSL Project, http://www.openssl.org/) C:\Windows\system32\libeay32.dll
2014-03-27 23:30 - 2013-10-26 21:30 - 00538126 ____S () C:\Windows\system32\libcurl-4.dll
2014-03-27 23:30 - 2013-10-26 21:30 - 00364544 ____S (The OpenSSL Project, http://www.openssl.org/) C:\Windows\system32\ssleay32.dll
2014-03-27 23:30 - 2013-10-26 21:30 - 00192512 ____S () C:\Windows\system32\libidn-11.dll
2014-03-27 23:30 - 2013-10-26 21:30 - 00171008 ____S (The libssh2 library, http://www.libssh2.org/) C:\Windows\system32\libssh2.dll
2014-03-27 23:30 - 2013-10-26 21:30 - 00133632 ____S () C:\Windows\system32\librtmp.dll
2014-03-27 23:30 - 2013-10-26 21:30 - 00044727 ____S () C:\Windows\system32\diablo130302.cl
2014-03-27 23:30 - 2013-10-26 21:30 - 00043810 ____S () C:\Windows\system32\poclbm130302.cl
2014-03-27 23:30 - 2013-10-26 21:30 - 00030802 ____S () C:\Windows\system32\diakgcn121016.cl
2014-03-27 23:30 - 2013-10-26 21:30 - 00023825 ____S () C:\Windows\system32\scrypt130511.cl
2014-03-27 23:30 - 2013-10-26 21:30 - 00013062 ____S () C:\Windows\system32\phatk121016.cl
2014-03-27 23:30 - 2013-06-12 16:15 - 00100864 ____S () C:\Windows\system32\zlib1.dll
2014-03-27 23:30 - 2012-09-26 00:46 - 00472424 ____S (NVIDIA Corporation) C:\Windows\system32\cudart32_50_35.dll
2014-03-27 23:30 - 2012-05-27 02:36 - 00055808 ____S (Open Source Software community LGPL) C:\Windows\system32\pthreadVC2.dll
2014-03-27 23:29 - 2014-03-27 23:30 - 07531703 _____ () C:\Users\Joe\Downloads\Minecraft-1.7.2.zip
2014-03-27 23:27 - 2014-03-27 23:27 - 00000654 _____ () C:\Users\Joe\Downloads\Minecraft-Launcher-1.7.2.rar
2014-03-27 23:27 - 2014-03-27 23:27 - 00000000 ____D () C:\Users\Joe\Downloads\Minecraft-Launcher-1.7.2
2014-03-27 23:25 - 2014-03-27 23:25 - 01106756 _____ () C:\Users\Joe\Desktop\Minecraft-Warez-launcher-1.7.4.exe
2014-03-21 10:40 - 2014-04-05 11:06 - 00000000 ____D () C:\Users\Joe\AppData\Local\CrashDumps
2014-03-19 12:09 - 2014-03-19 12:09 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-03-19 11:49 - 2014-03-19 11:55 - 133561080 _____ () C:\Users\Joe\Downloads\setup_11.0.1.1245.x01_2014_03_14_23_53.exe
2014-03-19 11:44 - 2014-03-19 11:44 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-03-19 11:44 - 2014-03-19 11:44 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-19 11:43 - 2014-03-19 11:43 - 04765152 _____ (Piriform Ltd) C:\Users\Joe\Downloads\ccsetup411.exe
2014-03-17 14:24 - 2014-03-17 14:24 - 00000000 ____D () C:\Windows\ERUNT
2014-03-15 13:33 - 2014-03-15 13:33 - 00000000 ____D () C:\Users\Joe\Downloads\SC_T_PRAVNICH_VZT
2014-03-15 13:32 - 2014-03-15 13:32 - 00004539 _____ () C:\Users\Joe\Downloads\SC_T_PRAVNICH_VZT.zip
2014-03-14 21:23 - 2014-03-14 21:23 - 00177086 _____ () C:\Users\Joe\Downloads\The-Wolf-of-Wall-Street(0000233483).srt
2014-03-12 10:40 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-12 10:40 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-12 10:40 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-12 10:40 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-12 10:40 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-12 10:40 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-12 10:40 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-12 10:40 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-12 10:40 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-12 10:40 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-12 10:40 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-12 10:40 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-12 10:40 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-12 10:40 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-12 10:40 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-12 10:40 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-12 10:40 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-12 10:40 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-12 10:40 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-12 10:40 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-12 10:40 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-12 10:40 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-12 10:40 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-12 10:37 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-12 10:37 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-12 10:37 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-12 10:37 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-08 16:02 - 2014-03-08 16:02 - 00888320 _____ () C:\Users\Joe\Desktop\Extremismus.ppt
2014-03-08 16:02 - 2014-03-08 16:02 - 00552960 _____ () C:\Users\Joe\Desktop\volby, volební systém.ppt
2014-03-08 16:02 - 2014-03-08 16:02 - 00130560 _____ () C:\Users\Joe\Desktop\IDEOLOGIE+ extremismus.ppt

==================== One Month Modified Files and Folders =======

2014-04-07 13:34 - 2014-04-07 13:33 - 00023201 _____ () C:\Users\Joe\Desktop\FRST.txt
2014-04-07 13:33 - 2014-04-07 13:32 - 00000000 ____D () C:\FRST
2014-04-07 13:31 - 2014-04-07 13:31 - 00112640 _____ (forum.viry.cz) C:\Users\Joe\Desktop\FRSTLauncher.exe
2014-04-07 13:30 - 2009-12-02 17:02 - 00000000 ____D () C:\Users\Joe\AppData\Roaming\Skype
2014-04-07 13:29 - 2014-04-07 13:29 - 00112640 _____ (forum.viry.cz) C:\Users\Joe\Downloads\Nepotvrzeno 250667.crdownload
2014-04-07 13:28 - 2014-04-07 13:28 - 00112640 _____ (forum.viry.cz) C:\Users\Joe\Downloads\Nepotvrzeno 569979.crdownload
2014-04-07 13:28 - 2014-04-07 13:28 - 00112640 _____ (forum.viry.cz) C:\Users\Joe\Downloads\Nepotvrzeno 340812.crdownload
2014-04-07 13:28 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-04-07 13:27 - 2014-04-07 13:25 - 01145856 _____ (Farbar) C:\Users\Joe\Desktop\FRST.exe
2014-04-07 13:20 - 2009-07-14 06:34 - 00013792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-07 13:20 - 2009-07-14 06:34 - 00013792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-07 12:51 - 2014-03-31 06:58 - 00000510 _____ () C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3743817662-1129281641-473641309-1000.job
2014-04-07 12:51 - 2012-03-30 20:00 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-07 12:31 - 2010-02-11 13:02 - 00000000 ____D () C:\Users\Joe\AppData\Roaming\vlc
2014-04-07 11:43 - 2014-03-31 16:32 - 00004144 _____ () C:\Windows\setupact.log
2014-04-07 01:48 - 2012-09-12 10:41 - 00000000 ____D () C:\Users\Joe\AppData\Roaming\.minecraft
2014-04-06 12:43 - 2014-02-01 17:30 - 00000000 ____D () C:\Users\Joe\Desktop\ivča
2014-04-05 11:06 - 2014-03-21 10:40 - 00000000 ____D () C:\Users\Joe\AppData\Local\CrashDumps
2014-04-05 10:38 - 2009-09-27 23:44 - 01989099 _____ () C:\Windows\WindowsUpdate.log
2014-04-04 17:26 - 2009-09-27 18:14 - 00114904 _____ () C:\Users\Joe\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-04 07:55 - 2013-06-27 14:21 - 00000000 ____D () C:\Users\Joe\AppData\Roaming\TeamViewer
2014-04-04 07:54 - 2014-04-04 07:54 - 00001048 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-04-04 07:54 - 2013-06-26 15:05 - 00000000 ____D () C:\Program Files\TeamViewer
2014-04-03 19:41 - 2011-06-13 18:11 - 00000000 ____D () C:\Users\Joe\AppData\Local\PMB Files
2014-04-02 21:53 - 2014-04-02 21:53 - 00001003 _____ () C:\Users\Joe\Desktop\MP3 Speed Changer.lnk
2014-04-02 21:53 - 2014-04-02 21:53 - 00000000 ____D () C:\Users\Joe\AppData\Local\Crazy_Boomerang_Software
2014-04-02 21:53 - 2014-04-02 21:52 - 00000000 ____D () C:\Program Files\MP3 Speed Changer
2014-04-02 13:56 - 2014-02-11 16:26 - 00000000 ____D () C:\Program Files\MetaTrader FLOAT
2014-04-01 22:03 - 2011-06-13 18:11 - 00000000 ____D () C:\ProgramData\PMB Files
2014-03-31 17:26 - 2009-09-27 06:30 - 01584626 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-31 16:32 - 2014-03-31 16:32 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-31 12:09 - 2010-03-07 21:23 - 00000000 ____D () C:\Users\Joe\AppData\Local\LogMeIn Hamachi
2014-03-31 12:05 - 2009-09-27 06:27 - 00000000 ____D () C:\Users\Joe
2014-03-31 12:03 - 2013-11-14 14:12 - 00000000 ____D () C:\Program Files\trend micro
2014-03-31 12:03 - 2010-07-31 12:43 - 00000000 ____D () C:\Qoobox
2014-03-31 12:02 - 2014-03-31 12:02 - 00165888 _____ () C:\Users\Joe\Downloads\T-Cleaner.exe
2014-03-31 07:28 - 2014-03-31 07:28 - 00000003 _____ () C:\Users\Joe\stut
2014-03-31 07:27 - 2014-03-29 15:09 - 00000330 _____ () C:\Users\Joe\rgut
2014-03-31 07:24 - 2009-09-28 11:50 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-03-31 07:24 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-30 21:59 - 2014-03-30 21:59 - 01031330 _____ () C:\Users\Joe\Desktop\Nátlakové skupiny.pptx
2014-03-30 21:56 - 2014-03-30 13:23 - 01031310 _____ () C:\Users\Joe\Downloads\Nátlakové skupiny.pptx
2014-03-30 19:43 - 2014-03-30 19:43 - 00000000 ____D () C:\Users\Joe\Desktop\modlitby počajevo
2014-03-30 18:44 - 2012-01-25 20:25 - 00000000 ____D () C:\Users\Joe\AppData\Local\Microsoft Help
2014-03-30 17:47 - 2014-03-30 17:47 - 01954304 _____ () C:\Users\Joe\Downloads\Úvaha.lnk.ppt
2014-03-30 13:23 - 2014-03-30 13:23 - 00084880 _____ () C:\Users\Joe\Downloads\Nátlakové skupiny (1).pptx
2014-03-28 16:16 - 2014-03-28 16:16 - 00001540 _____ () C:\Users\Joe\Desktop\Minecraft.exe – zástupce (2).lnk
2014-03-28 16:13 - 2014-03-28 16:13 - 00000687 _____ () C:\Users\Public\Desktop\World of Tanks - Common Test.lnk
2014-03-28 16:13 - 2010-08-18 19:28 - 00000000 ____D () C:\Windows\system32\directx
2014-03-28 16:12 - 2014-03-28 16:11 - 10983288 _____ (Wargaming.net ) C:\Users\Joe\Downloads\WoT_internet_install_ct.exe
2014-03-28 02:48 - 2014-03-27 23:54 - 00000000 ____D () C:\Users\Joe\GSplay
2014-03-27 23:54 - 2014-03-27 23:54 - 00000000 ____D () C:\ProgramData\Oracle
2014-03-27 23:53 - 2014-03-27 23:53 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-03-27 23:53 - 2014-03-27 23:53 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-03-27 23:53 - 2012-10-22 15:01 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-03-27 23:53 - 2012-10-22 15:01 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-03-27 23:53 - 2010-08-11 12:11 - 00000000 ____D () C:\Program Files\Java
2014-03-27 23:50 - 2014-03-27 23:50 - 00921000 _____ (Oracle Corporation) C:\Users\Joe\Desktop\jxpiinstall.exe
2014-03-27 23:50 - 2014-03-27 23:50 - 00000000 ____D () C:\Users\Joe\Downloads\GSplay
2014-03-27 23:48 - 2014-03-27 23:47 - 04748905 _____ () C:\Users\Joe\Downloads\GSplay.zip
2014-03-27 23:40 - 2014-03-27 23:40 - 01106756 _____ () C:\Users\Joe\Downloads\KeiNett Launcher.exe
2014-03-27 23:30 - 2014-03-27 23:30 - 00000000 ____D () C:\Windows\system32\bitstreams
2014-03-27 23:30 - 2014-03-27 23:30 - 00000000 ____D () C:\Users\Joe\Downloads\Minecraft-1.7.2
2014-03-27 23:30 - 2014-03-27 23:30 - 00000000 ____D () C:\Program Files\Minecraft-1.7.2
2014-03-27 23:30 - 2014-03-27 23:29 - 07531703 _____ () C:\Users\Joe\Downloads\Minecraft-1.7.2.zip
2014-03-27 23:27 - 2014-03-27 23:27 - 00000654 _____ () C:\Users\Joe\Downloads\Minecraft-Launcher-1.7.2.rar
2014-03-27 23:27 - 2014-03-27 23:27 - 00000000 ____D () C:\Users\Joe\Downloads\Minecraft-Launcher-1.7.2
2014-03-27 23:25 - 2014-03-27 23:25 - 01106756 _____ () C:\Users\Joe\Desktop\Minecraft-Warez-launcher-1.7.4.exe
2014-03-27 22:51 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-03-27 22:48 - 2009-07-14 04:03 - 63963136 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-03-27 22:48 - 2009-07-14 04:03 - 32768000 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-03-27 22:48 - 2009-07-14 04:03 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-03-27 22:48 - 2009-07-14 04:03 - 00262144 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-03-27 22:48 - 2009-07-14 04:03 - 00102400 _____ () C:\Windows\system32\config\SAM.bak
2014-03-20 07:56 - 2013-08-01 18:51 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-20 07:53 - 2009-09-28 11:24 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-19 12:09 - 2014-03-19 12:09 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-03-19 11:55 - 2014-03-19 11:49 - 133561080 _____ () C:\Users\Joe\Downloads\setup_11.0.1.1245.x01_2014_03_14_23_53.exe
2014-03-19 11:53 - 2012-08-24 16:15 - 00000000 ____D () C:\Users\Joe\AppData\Roaming\FileZilla
2014-03-19 11:53 - 2010-03-04 17:01 - 00000000 ____D () C:\Users\Joe\AppData\Roaming\Azureus
2014-03-19 11:53 - 2009-10-01 19:13 - 00000000 ____D () C:\Users\Joe\AppData\Roaming\DAEMON Tools Lite
2014-03-19 11:50 - 2011-06-21 17:40 - 00000000 ____D () C:\Windows\Minidump
2014-03-19 11:50 - 2009-09-28 00:40 - 00000000 ____D () C:\Windows\Panther
2014-03-19 11:44 - 2014-03-19 11:44 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-03-19 11:44 - 2014-03-19 11:44 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-19 11:43 - 2014-03-19 11:43 - 04765152 _____ (Piriform Ltd) C:\Users\Joe\Downloads\ccsetup411.exe
2014-03-17 14:36 - 2009-12-02 17:01 - 00000000 ___RD () C:\Program Files\Skype
2014-03-17 14:33 - 2010-10-29 09:20 - 00000000 ____D () C:\ProgramData\ICQ
2014-03-17 14:24 - 2014-03-17 14:24 - 00000000 ____D () C:\Windows\ERUNT
2014-03-16 12:00 - 2010-08-05 18:00 - 00002129 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-15 13:33 - 2014-03-15 13:33 - 00000000 ____D () C:\Users\Joe\Downloads\SC_T_PRAVNICH_VZT
2014-03-15 13:32 - 2014-03-15 13:32 - 00004539 _____ () C:\Users\Joe\Downloads\SC_T_PRAVNICH_VZT.zip
2014-03-14 21:23 - 2014-03-14 21:23 - 00177086 _____ () C:\Users\Joe\Downloads\The-Wolf-of-Wall-Street(0000233483).srt
2014-03-13 04:25 - 2009-07-14 06:33 - 02353728 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-13 04:05 - 2012-01-25 20:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-11 21:52 - 2012-03-30 20:00 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-11 21:52 - 2011-05-22 18:13 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-09 10:21 - 2014-02-25 16:51 - 00000084 _____ () C:\Users\Joe\AppData\Roaming\WB.CFG
2014-03-08 16:02 - 2014-03-08 16:02 - 00888320 _____ () C:\Users\Joe\Desktop\Extremismus.ppt
2014-03-08 16:02 - 2014-03-08 16:02 - 00552960 _____ () C:\Users\Joe\Desktop\volby, volební systém.ppt
2014-03-08 16:02 - 2014-03-08 16:02 - 00130560 _____ () C:\Users\Joe\Desktop\IDEOLOGIE+ extremismus.ppt

Files to move or delete:
====================
C:\Users\Joe\AppData\Roaming\CamLayout.ini
C:\Users\Joe\AppData\Roaming\CamShapes.ini


Some content of TEMP:
====================
C:\Users\Joe\AppData\Local\temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3743817662-1129281641-473641309-1000.job => C:\Program Files\Citrix\GoToMeeting\1350\g2mupdate.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{B7C2079D-2FB1-48B0-BDA6-2F15A718F334}.job => C:\Windows\system32\msfeedssync.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Joe\Desktop" je 4726 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"D:\\Programy\\TriDef 3D\\TriDef\\TriDefMediaPlayer\\TriDefMediaPlayer.exe"="D:\\Programy\\TriDef 3D\\TriDef\\TriDefMediaPlayer\\TriDefMediaPlayer.exe:*:Enabled:TriDef 3D Media Player"
"D:\\Programy\\xchat\\xchat.exe"="D:\\Programy\\xchat\\xchat.exe:*:Enabled:XChat IRC Client"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15724
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: FRST log prosím prokouknout

#2 Příspěvek od JaRon »

ahoj
citat:
Tvorba fixlistu pro FRST

•Spustte poznamkovy blok (Start-spustit-notepad)
•Zkopirujte skript nize

Kód: Vybrat vše

Start
HKLM\...\Run: [MSStp] - C:\Windows\inf\msstp.vbe [1584 2014-03-05] ()
HKLM\...\Run: [mncdtklhgSrv] - C:\Windows\system32\mncdtklhg.vbe [7670 2014-03-05] ()

2014-03-27 23:31 - 2014-03-05 23:19 - 00007670 ____S () C:\Windows\system32\mncdtklhg.vbe
2014-03-27 23:31 - 2013-10-26 21:30 - 00972814 ____S () C:\Windows\system32\dcgmncdtklhg.exe
2014-03-27 23:31 - 2013-07-18 17:06 - 00187904 ____S () C:\Windows\system32\lcpmncdtklhg.exe
2014-03-27 23:30 - 2013-12-10 01:30 - 10236928 ____S () C:\Windows\system32\acumncdtklhg.exe




Hosts:
CMD: shutdown /r /f /t 2
End
•Ulozte vytvoreny TXT jako fixlist.txt
•Presunte vytvoreny fixlist vedle FRST

Spustte znovu FRST.exe

•Kliknete na Fix
•Probehne oprava a vytvori log Fixlog.txt

Restart PC a dejte mi sem fixlog.txt
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Cizap
Návštěvník
Návštěvník
Příspěvky: 81
Registrován: 07 dub 2014 11:56

Re: FRST log prosím prokouknout

#3 Příspěvek od Cizap »

Doufám, že ten restart neměl bejt automatickej. Fix se provedl vyhodilo mi to log a restart jsem udělal sám (antivir zase něco hlásí po zapnutí PC) jinak jsem ho neměl vyplej během toho fixu a psal, že něco zablokoval. Log zde:


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01
Ran by Joe at 2014-04-07 19:11:44 Run:1
Running from C:\Users\Joe\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [MSStp] - C:\Windows\inf\msstp.vbe [1584 2014-03-05] ()
HKLM\...\Run: [mncdtklhgSrv] - C:\Windows\system32\mncdtklhg.vbe [7670 2014-03-05] ()

2014-03-27 23:31 - 2014-03-05 23:19 - 00007670 ____S () C:\Windows\system32\mncdtklhg.vbe
2014-03-27 23:31 - 2013-10-26 21:30 - 00972814 ____S () C:\Windows\system32\dcgmncdtklhg.exe
2014-03-27 23:31 - 2013-07-18 17:06 - 00187904 ____S () C:\Windows\system32\lcpmncdtklhg.exe
2014-03-27 23:30 - 2013-12-10 01:30 - 10236928 ____S () C:\Windows\system32\acumncdtklhg.exe




Hosts:
CMD: shutdown /r /f /t 2
End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MSStp => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mncdtklhgSrv => Value deleted successfully.
C:\Windows\system32\mncdtklhg.vbe => Moved successfully.
C:\Windows\system32\dcgmncdtklhg.exe => Moved successfully.
C:\Windows\system32\lcpmncdtklhg.exe => Moved successfully.
C:\Windows\system32\acumncdtklhg.exe => Moved successfully.
"C:\Windows\System32\Drivers\etc\hosts" => Could not move.
Could not reset Hosts.

========= shutdown /r /f /t 2 =========


========= End of CMD: =========


==== End of Fixlog ====

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15724
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: FRST log prosím prokouknout

#4 Příspěvek od JaRon »

to najhorsie by malo byt fuc
prescanuj PC s MBAM
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Cizap
Návštěvník
Návštěvník
Příspěvky: 81
Registrován: 07 dub 2014 11:56

Re: FRST log prosím prokouknout

#5 Příspěvek od Cizap »

Tak konečně jsem se k tomu dostal. Snad jsem to udělal správně je to jiná verze než v tom návodu a nenabídlo mi to restart logy jsou tady:

tenhle po provedení testu před tim než jsem dal ty vybraný akce aby se provedli:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 21.4.2014
Scan Time: 14:50:20
Logfile: malwarebytes log.txt
Administrator: Yes

Version: 2.00.1.1004
Malware Database: v2014.04.21.03
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Joe

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 311861
Time Elapsed: 1 hr, 17 min, 13 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 16
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\defaults, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\defaults\preferences, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\locale, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\locale\en-US, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\defaults, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\defaults\preferences, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\locale, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\locale\en-US, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin, , [a255200c4239e84e69e0095c89791fe1],

Files: 69
Trojan.Agent.SCR, C:\Windows\inf\msstp.vbe, , [d81fd85429527db9ae4a77f417ebb050],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome.manifest, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\install.rdf, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\background.html, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\browser.xul, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\crossrider.js, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\crossriderapi.js, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\dialog.js, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\options.js, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\options.xul, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\search_dialog.xul, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\update.html, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\defaults\preferences\prefs.js, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\locale\en-US\translations.dtd, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\button1.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\button2.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\button3.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\button4.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\button5.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\crossrider_statusbar.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\icon128.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\icon16.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\icon24.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\icon48.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\panelarrow-up.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\popup.css, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\popup.html, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\popup_binding.xml, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\skin.css, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\update.css, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome.manifest, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\install.rdf, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\background.html, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\browser.xul, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\crossrider.js, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\crossriderapi.js, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\dialog.js, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\options.js, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\options.xul, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\search_dialog.xul, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\update.html, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\defaults\preferences\prefs.js, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\locale\en-US\translations.dtd, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\button1.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\button2.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\button3.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\button4.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\button5.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\crossrider_statusbar.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\icon128.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\icon16.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\icon24.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\icon48.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\panelarrow-up.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\popup.css, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\popup.html, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\popup_binding.xml, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\skin.css, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\update.css, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossrider.bic", "144d5e2cbe95f3912e8722fde9f9ef5a");), ,[f502a488215a62d42eb4ec68f50f9967]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.4479.InstallationTime", 1395157814);), ,[be391a127dfe88ae2fb4b89c59ab52ae]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.4479.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");), ,[38bfa983aecd0333bf240a4af0147d83]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.4479.cookie.InstallationTime.value", "1395157814");), ,[37c00b210f6c1b1b7370a1b305ff758b]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.bic", "144d5e2cbe95f3912e8722fde9f9ef5a");), ,[52a595970675f04621c296be29db629e]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.firstrun", false);), ,[10e7200c4437dc5a12d12f251be98d73]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.installationdate", 1395157814);), ,[40b7d15b5427221403e02b29c1437789]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.lastcheck", 23301322);), ,[bb3c4ce04b303cfa07dc86cef70d3ec2]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.lastcheckitem", 23301335);), ,[aa4d9894106b61d5edf656feee165aa6]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479@crossrider.com.install-event-fired", true);), ,[6592aa8287f43ff7a0433f15cf35fe02]

Physical Sectors: 0
(No malicious items detected)


(end)











a tenhle po tom co jsem dal aby se ty akce provedli:




Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 21.4.2014
Scan Time: 14:50:20
Logfile: malwarebytes log po.txt
Administrator: Yes

Version: 2.00.1.1004
Malware Database: v2014.04.21.03
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Joe

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 311861
Time Elapsed: 1 hr, 17 min, 13 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 16
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\defaults, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\defaults\preferences, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\locale, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\locale\en-US, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\defaults, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\defaults\preferences, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\locale, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\locale\en-US, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin, , [a255200c4239e84e69e0095c89791fe1],

Files: 69
Trojan.Agent.SCR, C:\Windows\inf\msstp.vbe, , [d81fd85429527db9ae4a77f417ebb050],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome.manifest, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\install.rdf, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\background.html, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\browser.xul, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\crossrider.js, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\crossriderapi.js, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\dialog.js, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\options.js, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\options.xul, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\search_dialog.xul, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\chrome\content\update.html, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\defaults\preferences\prefs.js, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\locale\en-US\translations.dtd, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\button1.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\button2.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\button3.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\button4.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\button5.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\crossrider_statusbar.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\icon128.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\icon16.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\icon24.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\icon48.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\panelarrow-up.png, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\popup.css, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\popup.html, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\popup_binding.xml, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\skin.css, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\extensions\crossriderapp4479@crossrider.com\skin\update.css, , [8a6d3def96e51b1b2e1b313459a9f709],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome.manifest, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\install.rdf, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\background.html, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\browser.xul, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\crossrider.js, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\crossriderapi.js, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\dialog.js, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\options.js, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\options.xul, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\search_dialog.xul, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\chrome\content\update.html, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\defaults\preferences\prefs.js, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\locale\en-US\translations.dtd, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\button1.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\button2.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\button3.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\button4.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\button5.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\crossrider_statusbar.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\icon128.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\icon16.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\icon24.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\icon48.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\panelarrow-up.png, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\popup.css, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\popup.html, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\popup_binding.xml, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\skin.css, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossFire.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\extensions\crossriderapp4479@crossrider.com\skin\update.css, , [a255200c4239e84e69e0095c89791fe1],
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossrider.bic", "144d5e2cbe95f3912e8722fde9f9ef5a");), ,[f502a488215a62d42eb4ec68f50f9967]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.4479.InstallationTime", 1395157814);), ,[be391a127dfe88ae2fb4b89c59ab52ae]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.4479.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");), ,[38bfa983aecd0333bf240a4af0147d83]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.4479.cookie.InstallationTime.value", "1395157814");), ,[37c00b210f6c1b1b7370a1b305ff758b]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.bic", "144d5e2cbe95f3912e8722fde9f9ef5a");), ,[52a595970675f04621c296be29db629e]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.firstrun", false);), ,[10e7200c4437dc5a12d12f251be98d73]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.installationdate", 1395157814);), ,[40b7d15b5427221403e02b29c1437789]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.lastcheck", 23301322);), ,[bb3c4ce04b303cfa07dc86cef70d3ec2]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479.lastcheckitem", 23301335);), ,[aa4d9894106b61d5edf656feee165aa6]
PUP.Optional.CrossRider.A, C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossriderapp4479@crossrider.com.install-event-fired", true);), ,[6592aa8287f43ff7a0433f15cf35fe02]

Physical Sectors: 0
(No malicious items detected)


(end)

Cizap
Návštěvník
Návštěvník
Příspěvky: 81
Registrován: 07 dub 2014 11:56

Re: FRST log prosím prokouknout

#6 Příspěvek od Cizap »

Hodilo mě to na druhou stránku. Mrknete prosím někdo na ten Log z malwerbytes? :) díky

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: FRST log prosím prokouknout

#7 Příspěvek od motji »

Nechal jste vše smazat?

:arrow: Stáhněte Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
-Uložte program na plochu a spusťte . Pak se zobrazí se licenční podminky - potvrďte start libovolnou klávesou.
- vytvoří se záloha a proběhne skenování.
Po skončení skenování na Vás vyběhne log (bude uložen v c:\JRT jako JRT.txt) - zkopírujte jej sem

:arrow: Stáhněte AdwCleaner http://www.bleepingcomputer.com/download/adwcleaner/
-Uložte program na plochu a ukončete všechny spuštěné programy .
-spusťte AdwCleaner, klikněte na Scan a po dokončení skenu na Clean
- provede se oprava, restartuje se pc - (případně restartujte) a objeví se log C:\AdwCleaner\AdwCleaner.txt , obsah logu zkopírujte zde.

:arrow: Použijte :arrow: CCleaner http://forum.viry.cz/viewtopic.php?f=46&t=7478
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Cizap
Návštěvník
Návštěvník
Příspěvky: 81
Registrován: 07 dub 2014 11:56

Re: FRST log prosím prokouknout

#8 Příspěvek od Cizap »

Ano z malwerbytes jsem nechal vše smazat.
Ccleaner jsem provedl na konec a tady jsou logy:



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Professional x86
Ran by Joe on p  02.05.2014 at 13:28:51,79
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p  02.05.2014 at 13:32:21,53
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~







Z AdwCleaneru mi to vyhodilo jeden log S1 a pak jsem našel log R1 ten asi nepotřebujete ale dávám ho sem taky takže R1:





# AdwCleaner v3.205 - Report created 02/05/2014 at 13:33:23
# Updated 28/04/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
# Username : Joe - CIZAP
# Running from : C:\Users\Joe\Desktop\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Found : C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\Extensions\staged\{5ebdca98-43b3-45bb-87e0-716029fb42ab}
Folder Found : C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17041


-\\ Mozilla Firefox v27.0.1 (cs)

[ File : C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\prefs.js ]


[ File : C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js ]

Line Found : user_pref("extensions.crossriderapp4479.lastcheckitem", 23301342);
Line Found : user_pref("extensions.crossriderapp4479@crossrider.com.install-event-fired", true);

-\\ Google Chrome v34.0.1847.131

[ File : C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}

[ File : C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found [Extension] : bopakagnckmlgajfccecajhnimjiiedh

*************************

AdwCleaner[R1].txt - [1668 octets] - [02/05/2014 13:33:23]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [1728 octets] ##########






a tady je S1 z AdwCleaner:





# AdwCleaner v3.205 - Report created 02/05/2014 at 13:34:40
# Updated 28/04/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
# Username : Joe - CIZAP
# Running from : C:\Users\Joe\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\Extensions\staged\{5ebdca98-43b3-45bb-87e0-716029fb42ab}
Folder Deleted : C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17041


-\\ Mozilla Firefox v27.0.1 (cs)

[ File : C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\197y6lof.default\prefs.js ]


[ File : C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\prefs.js ]

Line Deleted : user_pref("extensions.crossriderapp4479.lastcheckitem", 23301342);
Line Deleted : user_pref("extensions.crossriderapp4479@crossrider.com.install-event-fired", true);

-\\ Google Chrome v34.0.1847.131

[ File : C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}

[ File : C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Extension] : bopakagnckmlgajfccecajhnimjiiedh

*************************

AdwCleaner[R1].txt - [1808 octets] - [02/05/2014 13:33:23]
AdwCleaner[S1].txt - [1745 octets] - [02/05/2014 13:34:40]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1805 octets] ##########

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: FRST log prosím prokouknout

#9 Příspěvek od motji »

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Cizap
Návštěvník
Návštěvník
Příspěvky: 81
Registrován: 07 dub 2014 11:56

Re: FRST log prosím prokouknout

#10 Příspěvek od Cizap »

Tak už jsem se zas dostal k PC. Tady je log z combofixu:


ComboFix 14-05-07.03 - Joe 07.05.2014 17:19:07.7.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3327.2084 [GMT 2:00]
Spuštěný z: c:\users\Joe\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Joe\Downloads\GSplay\GSplay.exe
.
Nakažená kopie c:\windows\system32\drivers\ntfs.sys byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.1.7601.18378_none_a83b9ab47b5adef3\ntfs.sys
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-04-07 do 2014-05-07 )))))))))))))))))))))))))))))))
.
.
2014-05-07 15:26 . 2014-05-07 15:26 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-05-07 15:26 . 2014-05-07 15:26 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-05-07 15:26 . 2014-05-07 15:26 -------- d-----w- c:\users\Iris\AppData\Local\temp
2014-05-07 15:26 . 2014-05-07 15:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-05-07 13:48 . 2014-04-17 03:32 8050496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E9BC5A63-9EB7-44E6-8322-08EB84F083D9}\mpengine.dll
2014-05-03 08:58 . 2014-04-29 12:34 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-02 11:33 . 2010-08-30 06:34 536576 ----a-w- c:\windows\system32\sqlite3.dll
2014-05-02 11:33 . 2014-05-02 11:35 -------- d-----w- C:\AdwCleaner
2014-05-01 10:19 . 2014-04-14 18:13 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-04-30 21:48 . 2014-04-30 21:48 -------- d-s---w- c:\windows\system32\CompatTel
2014-04-30 14:14 . 2014-04-14 02:11 361984 ----a-w- c:\windows\system32\aepdu.dll
2014-04-30 14:14 . 2014-04-14 02:07 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-04-21 11:31 . 2014-04-03 07:51 51416 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-04-21 11:31 . 2014-04-03 07:51 73432 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-04-21 11:31 . 2014-04-21 11:31 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-04-20 18:53 . 2014-04-20 18:53 -------- d-----w- c:\users\Joe\AppData\Local\Skype
2014-04-20 18:52 . 2014-04-20 18:52 -------- d-----w- c:\program files\Common Files\Skype
2014-04-15 23:51 . 2014-04-15 23:51 -------- d-sh--w- c:\users\Joe\AppData\Local\EmieUserList
2014-04-15 23:51 . 2014-04-15 23:51 -------- d-sh--w- c:\users\Joe\AppData\Local\EmieSiteList
2014-04-10 20:26 . 2014-04-10 20:26 -------- d-----w- c:\users\Joe\AppData\Roaming\Unity
2014-04-09 09:52 . 2014-01-24 02:18 1212352 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-04-09 09:51 . 2014-02-04 02:07 149440 ----a-w- c:\windows\system32\drivers\storport.sys
2014-04-09 09:51 . 2014-02-04 02:07 234432 ----a-w- c:\windows\system32\drivers\msiscsi.sys
2014-04-09 09:51 . 2014-02-04 02:07 27072 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2014-04-09 09:51 . 2014-02-04 02:00 2048 ----a-w- c:\windows\system32\iologmsg.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-07 15:17 . 2010-05-04 12:49 107736 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2014-04-30 20:44 . 2012-03-30 18:00 692400 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-04-30 20:44 . 2011-05-22 16:13 70832 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-04-03 07:50 . 2010-05-04 12:49 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-03-31 07:35 . 2009-10-03 10:05 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-02-20 18:06 . 2009-12-23 19:13 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2014-02-20 18:06 . 2009-10-02 19:33 214520 ----a-w- c:\windows\system32\PnkBstrB.ex0
2014-02-20 18:04 . 2009-10-02 19:34 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2014-02-20 18:04 . 2009-10-02 19:33 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2014-02-07 01:07 . 2014-03-12 08:37 2349056 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Photosmart 5510 series (NET)"="c:\program files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" [2011-09-16 1804648]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-02-10 20922016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="d:\programy\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-05-31 152392]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2014-03-13 689744]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-10-01 2345296]
"EaseUS EPM tray"="c:\program files\EaseUS\EaseUS Partition Master 9.3.0\bin\EpmNews.exe" [2013-03-29 2081792]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
forteManager.lnk - c:\program files\LG Soft India\forteManager\bin\Monitor.exe -startup [2010-5-18 1683456]
GamePark klient 2.lnk - d:\hry\GamePark2\gpcl.exe [2011-8-19 409088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2013-10-01 1612112]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [2014-04-03 857912]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 apf001;apf001;d:\hry\Softnyx\RakionIS\Bin\apf001.sys [2011-07-21 10872]
R3 CFcatchme;CFcatchme;c:\users\Joe\AppData\Local\Temp\CFcatchme.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2013-03-07 14920]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2013-03-07 9160]
R3 GarenaPEngine;GarenaPEngine;c:\users\Joe\AppData\Local\Temp\EIG6A57.tmp [x]
R3 GGSAFERDriver;GGSAFER Driver;d:\programy\Garena\plugins\UI\safedrv.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-03-06 108032]
R3 LGDDCDevice;LGDDCDevice;c:\program files\LG Soft India\forteManager\bin\I2CDriver.sys [2009-04-24 14336]
R3 LGII2CDevice;LGII2CDevice;c:\program files\LG Soft India\forteManager\bin\PII2CDriver.sys [2009-04-24 18432]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-03 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-07-31 691696]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-12-07 37352]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2014-03-13 440400]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn Hamachi\LMIGuardianSvc.exe [2013-08-26 375056]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2014-04-02 4972864]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-04-03 23256]
S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [2010-01-07 375808]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-04-30 14:07 1078088 ----a-w- c:\program files\Google\Chrome\Application\34.0.1847.131\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-05-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 20:46]
.
2014-05-07 c:\windows\Tasks\G2MUpdateTask-S-1-5-21-3743817662-1129281641-473641309-1000.job
- c:\program files\Citrix\GoToMeeting\1350\g2mupdate.exe [2014-03-31 04:57]
.
2013-10-24 c:\windows\Tasks\User_Feed_Synchronization-{B7C2079D-2FB1-48B0-BDA6-2F15A718F334}.job
- c:\windows\system32\msfeedssync.exe [2013-12-03 20:58]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - d:\programy\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - d:\programy\MICROS~1\Office14\ONBttnIE.dll/105
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - d:\programy\ICQ7.5\ICQ.exe
TCP: Interfaces\{6A699DC3-5B9E-40F4-8DF1-F6FA030CE7D5}: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\3rkrtyxj.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-GSplay.exe - c:\users\Joe\Downloads\GSplay\GSplay.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\services\GarenaPEngine]
"ImagePath"="\??\c:\users\Joe\AppData\Local\Temp\EIG6A57.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3743817662-1129281641-473641309-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:3b,00,6e,c8,a6,0e,3c,98,3c,ad,b9,e1,a1,2e,25,76,3a,c2,96,fe,5b,30,ec,
40,b0,dd,fc,15,b4,f1,0e,ef,5a,18,5c,bb,8e,c8,75,57,fc,03,27,da,62,77,fa,06,\
"??"=hex:d5,78,ec,ed,82,ea,6e,1b,13,1e,57,10,66,cf,87,f8
.
[HKEY_USERS\S-1-5-21-3743817662-1129281641-473641309-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:cb,5c,87,6f,b5,dd,8f,c1,64,b2,a2,ce,65,5b,dc,4e,79,3e,ee,bf,3e,
be,9a,26,2c,59,39,88,d4,9d,9a,0e,ef,c6,ff,75,f5,a9,a5,d2,55,2e,2c,32,4f,59,\
"rkeysecu"=hex:69,06,31,e0,b0,57,0f,09,27,5a,0b,46,1c,ba,73,bf
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
d:\programy\ibase\bin\ibguard.exe
c:\program files\Malwarebytes Anti-Malware\mbamscheduler.exe
c:\windows\system32\PnkBstrA.exe
d:\programy\ibase\bin\ibserver.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
.
**************************************************************************
.
Celkový čas: 2014-05-07 17:49:56 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-05-07 15:49
.
Před spuštěním: Volných bajtů: 18 314 280 960
Po spuštění: Volných bajtů: 18 074 378 240
.
- - End Of File - - 4704D2077116146C3E85ED87788C0364
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: FRST log prosím prokouknout

#11 Příspěvek od motji »

Otestujte na www.virustotal.com
c:\windows\system32\drivers\ntfs.sys
-dejte reanalyze a odkaz k výsledku vložte zde.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Cizap
Návštěvník
Návštěvník
Příspěvky: 81
Registrován: 07 dub 2014 11:56

Re: FRST log prosím prokouknout

#12 Příspěvek od Cizap »


Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: FRST log prosím prokouknout

#13 Příspěvek od motji »

To vypadá dobře, jak je na tom počítač?

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://tharifas.sweb.cz/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: stahněte Ccleanerhttp://forum.viry.cz/viewtopic.php?f=46&t=7478
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Cizap
Návštěvník
Návštěvník
Příspěvky: 81
Registrován: 07 dub 2014 11:56

Re: FRST log prosím prokouknout

#14 Příspěvek od Cizap »

PC šlape jak má žádný problémy to nehlásí a už to není ani pomalé :) udělal jsem teď to poslední čištění, provedl se restart a pak ještě odinstaluju nějaký programy přes ten Ccleaner, protože jsem koukal, že tu mam dost blbostí. Tak moc děkuju :thumbsup: hrozně jste mi usnadnili práci já bych to asi dokázal jen zálohovat a zformátovat tak asi už se může zamknout :) možná ještě přijdu pro pomoc se segry PC pokud jí to nevyřeší v práci. Zatím se mějte hezky :)

/edit: ještě se chci zeptat v CCleaneru je v nástrojích čistič disku. Je to znát když to nechám udělat?

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: FRST log prosím prokouknout

#15 Příspěvek od motji »

Zkuste, sám uvidíte, zda to má smysl.
I za kolegu není zač a mějte se hezky :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět