Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Banery na FF prohlížeči

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
ovninja
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 02 dub 2013 15:16

Banery na FF prohlížeči

#1 Příspěvek od ovninja »

Zdravím, objevily se mibanery vyskakující v prohlížeči. Dostaly se do PC pravděpodobně při stahování, přestože jsem měl zapnutý FW,Spyware i Aviru... soubor Addition.txt se mi nevytvořil, RSIT mi nejede ...děkuji



Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:13-07-2014 01
Ran by User (administrator) on STOLNÍ on 13-07-2014 20:39:33
Running from C:\Documents and Settings\User\Plocha
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(AVerMedia) C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
() C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
(AVerMedia TECHNOLOGIES, Inc.) C:\Program Files\AVerMedia\AVerUpdate\AVerUpdateServer.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Prolific Technology Inc.) C:\WINDOWS\system32\IoctlSvc.exe
(AVerMedia Technologies, Inc.) C:\Program Files\SnugTV\SnugTV Station\AMAServer.exe
() C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
(Crawler.com) C:\Program Files\Spyware Terminator\st_rsser.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
() C:\Program Files\Yawtix\updateYawtix.exe
() C:\Program Files\Yawtix\bin\utilYawtix.exe
() C:\Program Files\Yawtix\bin\Yawtix.PurBrowse.exe
() C:\Program Files\Yawtix\bin\Yawtix.BrowserAdapter.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe
(Microsoft Corporation) C:\WINDOWS\system32\cmd.exe
(Microsoft Corporation) C:\WINDOWS\system32\ping.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [20143688 2013-03-12] (Realtek Semiconductor Corp.)
HKLM\...\Run: [amd_dc_opt] => C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2007-07-23] (AMD)
HKLM\...\Run: [NvCplDaemon] => C:\WINDOWS\system32\NvCpl.dll [15677728 2013-06-21] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] => C:\WINDOWS\system32\NvMcTray.dll [223008 2013-06-21] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2586912 2013-06-21] ()
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [750160 2014-07-04] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [PPort11reminder] => C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe [328992 2007-08-31] (Nuance Communications, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-08-23] (Crawler.com)
HKLM\...\Run: [ZoneAlarm] => C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe [137352 2014-05-30] (Check Point Software Technologies Ltd.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Status Monitor.lnk

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Yawtix - {f9c8ce1b-66a0-4f45-af10-5f24ef19bc4e} - C:\Program Files\Yawtix\Yawtixbho.dll (Yawtix)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 9078065390
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 10.152.40.4 10.152.40.5

FireFox:
========
FF ProfilePath: C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\w9d3jsc2.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\w9d3jsc2.default\searchplugins\zonealarm.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Disconnect - C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\w9d3jsc2.default\Extensions\2.0@disconnect.me.xpi [2014-05-04]
FF Extension: Yawtix - C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\w9d3jsc2.default\Extensions\{16d667ee-6782-4b21-81df-8ded8ebc3868}.xpi [2014-07-13]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-09-18]

Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR StartupUrls: "hxxp://www.seznam.cz/"
CHR Extension: (Peněženka Google) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-08]

========================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-07-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-04] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1028688 2014-07-04] (Avira Operations GmbH & Co. KG)
R2 AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [348160 2010-04-27] (AVerMedia) [File not signed]
R2 AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [403456 2011-04-01] () [File not signed]
R2 AVerUpdateServer; C:\Program Files\AVerMedia\AVerUpdate\AVerUpdateServer.exe [168448 2011-01-06] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-09-11] (Oracle Corporation)
R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 SnugTV Service; C:\Program Files\SnugTV\SnugTV Station\AMAServer.exe [571904 2011-02-14] (AVerMedia Technologies, Inc.) [File not signed]
R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [587912 2013-08-23] (Crawler.com)
R2 Update Yawtix; C:\Program Files\Yawtix\updateYawtix.exe [321816 2014-07-12] ()
R2 Util Yawtix; C:\Program Files\Yawtix\bin\utilYawtix.exe [321816 2014-07-13] ()
S2 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [3592120 2014-05-30] (Check Point Software Technologies Ltd.)
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [90936 2014-05-29] (Check Point Software Technologies, Ltd.)

==================== Drivers (Whitelisted) ====================

S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R1 AmdPPM; C:\WINDOWS\System32\DRIVERS\AmdPPM.sys [33792 2007-04-16] (Advanced Micro Devices)
R3 AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [96704 2007-08-04] (SlySoft, Inc.)
R3 AVerAF35; C:\WINDOWS\System32\Drivers\AVerAF35.sys [642560 2010-04-02] (AVerMedia TECHNOLOGIES, Inc.)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [97648 2014-07-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [136216 2014-06-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 BrScnUsb; C:\WINDOWS\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2014-01-08] (Disc Soft Ltd)
R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [26024 2009-12-18] (Elaborate Bytes AG)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
S3 MPE; C:\WINDOWS\System32\DRIVERS\MPE.sys [15232 2008-04-14] (Microsoft Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 npf; C:\WINDOWS\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [66688 2009-07-01] (NVIDIA Corporation)
R3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [128672 2013-02-25] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [13824 2009-07-01] (NVIDIA Corporation)
S3 silabenm; C:\WINDOWS\System32\DRIVERS\silabenm.sys [17920 2009-03-20] (Silicon Laboratories, Inc.)
S3 silabser; C:\WINDOWS\System32\DRIVERS\silabser.sys [62592 2009-03-20] (Silicon Laboratories)
R1 sp_rsdrv2; C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed]
R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [28520 2013-09-11] (Avira GmbH)
R1 Vsdatant; C:\WINDOWS\System32\vsdatant.sys [534024 2014-05-30] (Check Point Software Technologies Ltd.)
R1 {16d667ee-6782-4b21-81df-8ded8ebc3868}Gt; C:\WINDOWS\System32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gt.sys [55224 2014-07-08] (StdLib)
S4 IntelIde; No ImagePath
U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
U1 WS2IFSL;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-13 20:39 - 2014-07-13 20:39 - 00013808 _____ () C:\Documents and Settings\User\Plocha\FRST.txt
2014-07-13 20:38 - 2014-07-13 20:38 - 00015327 _____ () C:\Documents and Settings\User\Plocha\LM.bat
2014-07-13 20:35 - 2014-07-13 20:35 - 01076736 _____ (Farbar) C:\Documents and Settings\User\Plocha\FRST.exe
2014-07-13 20:35 - 2014-07-13 20:35 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe
2014-07-13 19:25 - 2014-07-08 18:42 - 00055224 _____ (StdLib) C:\WINDOWS\system32\Drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gt.sys
2014-07-13 18:23 - 2014-07-13 19:24 - 00000000 ____D () C:\Program Files\Yawtix
2014-07-13 18:23 - 2014-07-13 18:24 - 00000000 ____D () C:\Program Files\MKV Player
2014-07-13 18:23 - 2014-07-13 18:23 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\MKV Player
2014-07-08 14:55 - 2014-07-08 14:55 - 00000403 _____ () C:\WINDOWS\wmsetup.log
2014-06-22 13:25 - 2014-06-22 13:25 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Data aplikací\Adobe
2014-06-22 13:17 - 2014-06-22 13:28 - 00000000 ____D () C:\Documents and Settings\User\Plocha\Nová složka (2)
2014-06-18 12:31 - 2014-06-18 12:32 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-18 10:22 - 2014-06-18 10:22 - 00000000 _____ () C:\Documents and Settings\User\Plocha\Nový objekt - Textový dokument.txt

==================== One Month Modified Files and Folders =======

2014-07-13 20:39 - 2014-07-13 20:39 - 00013808 _____ () C:\Documents and Settings\User\Plocha\FRST.txt
2014-07-13 20:39 - 2014-03-27 20:05 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Temp
2014-07-13 20:39 - 2014-03-27 19:27 - 00000000 ____D () C:\FRST
2014-07-13 20:39 - 2013-09-11 18:38 - 00000000 ____D () C:\Documents and Settings\User\Plocha
2014-07-13 20:38 - 2014-07-13 20:38 - 00015327 _____ () C:\Documents and Settings\User\Plocha\LM.bat
2014-07-13 20:38 - 2013-09-11 18:38 - 00000000 ___HD () C:\Documents and Settings\User\Local Settings\Data aplikací
2014-07-13 20:37 - 2013-09-11 21:11 - 00000000 ____D () C:\Documents and Settings\User\Dokumenty\Stažené soubory
2014-07-13 20:36 - 2013-09-11 22:23 - 00009942 _____ () C:\WINDOWS\system32\nvAppTimestamps
2014-07-13 20:35 - 2014-07-13 20:35 - 01076736 _____ (Farbar) C:\Documents and Settings\User\Plocha\FRST.exe
2014-07-13 20:35 - 2014-07-13 20:35 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe
2014-07-13 20:34 - 2013-09-18 11:07 - 00000000 ____D () C:\Program Files\trend micro
2014-07-13 20:32 - 2014-03-28 10:14 - 00000940 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-13 20:28 - 2001-10-25 14:00 - 00000684 _____ () C:\WINDOWS\win.ini
2014-07-13 20:03 - 2013-09-11 22:26 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-07-13 19:24 - 2014-07-13 18:23 - 00000000 ____D () C:\Program Files\Yawtix
2014-07-13 18:43 - 2013-09-17 14:13 - 00000000 ____D () C:\Program Files\utorrent
2014-07-13 18:24 - 2014-07-13 18:23 - 00000000 ____D () C:\Program Files\MKV Player
2014-07-13 18:23 - 2014-07-13 18:23 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\MKV Player
2014-07-13 18:23 - 2013-09-11 20:26 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-07-13 12:27 - 2013-09-11 18:33 - 01648862 _____ () C:\WINDOWS\WindowsUpdate.log
2014-07-13 09:55 - 2014-03-28 10:14 - 00000936 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-13 09:55 - 2013-09-11 20:28 - 00000157 _____ () C:\WINDOWS\wiadebug.log
2014-07-13 09:55 - 2013-09-11 20:28 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-07-13 09:55 - 2013-09-11 18:36 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-07-13 09:55 - 2001-10-25 14:00 - 00002300 _____ () C:\WINDOWS\system32\wpa.dbl
2014-07-12 23:39 - 2013-09-17 18:32 - 00524288 _____ () C:\WINDOWS\system32\config\AVer Med.evt
2014-07-12 23:39 - 2013-09-17 18:32 - 00196608 _____ () C:\WINDOWS\system32\config\AVer Aut.evt
2014-07-12 23:39 - 2013-09-11 18:38 - 00000178 ___SH () C:\Documents and Settings\User\ntuser.ini
2014-07-12 23:39 - 2013-09-11 18:36 - 00032542 _____ () C:\WINDOWS\SchedLgU.Txt
2014-07-11 09:28 - 2013-09-12 22:02 - 00000000 ___RD () C:\Documents and Settings\User\Plocha\Mbank
2014-07-10 23:16 - 2013-09-13 14:12 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-07-10 23:15 - 2013-09-13 14:12 - 93585272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-07-10 23:14 - 2013-09-12 18:16 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-07-09 16:03 - 2013-09-11 22:26 - 00699056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-07-09 16:03 - 2013-09-11 22:26 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-07-08 18:42 - 2014-07-13 19:25 - 00055224 _____ (StdLib) C:\WINDOWS\system32\Drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gt.sys
2014-07-08 15:00 - 2014-03-27 20:04 - 00000214 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-07-08 14:55 - 2014-07-08 14:55 - 00000403 _____ () C:\WINDOWS\wmsetup.log
2014-07-06 21:50 - 2014-05-10 19:48 - 00000000 ____D () C:\Documents and Settings\User\Data aplikací\TS3Client
2014-07-04 22:30 - 2014-02-26 16:43 - 00000000 ___RD () C:\Documents and Settings\User\Plocha\Biofeedback
2014-07-04 22:30 - 2013-09-11 18:38 - 00000000 ___RD () C:\Documents and Settings\User\Dokumenty\Obrázky
2014-07-04 08:15 - 2013-09-11 23:04 - 00097648 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2014-06-25 18:19 - 2013-09-11 20:27 - 01521712 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-06-22 13:28 - 2014-06-22 13:17 - 00000000 ____D () C:\Documents and Settings\User\Plocha\Nová složka (2)
2014-06-22 13:25 - 2014-06-22 13:25 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Data aplikací\Adobe
2014-06-19 07:29 - 2014-03-28 00:05 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-06-18 12:55 - 2014-05-10 00:31 - 00000000 ____D () C:\Program Files\Mozilla Firefox.bak
2014-06-18 12:32 - 2014-06-18 12:31 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-18 10:22 - 2014-06-18 10:22 - 00000000 _____ () C:\Documents and Settings\User\Plocha\Nový objekt - Textový dokument.txt

Some content of TEMP:
====================
C:\Documents and Settings\User\Local Settings\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Banery na FF prohlížeči

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ovninja
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 02 dub 2013 15:16

Re: Banery na FF prohlížeči

#3 Příspěvek od ovninja »

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Microsoft Windows XP x86
Ran by User on ne 13.07.2014 at 21:19:03,40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}



~~~ Files



~~~ Folders

Budu online, dokud se to nevyřeší....

~~~ FireFox

Successfully deleted: [Folder] C:\Documents and Settings\User\Data aplikacˇ\mozilla\firefox\profiles\w9d3jsc2.default\extensions\staged





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 13.07.2014 at 21:22:04,21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

ovninja
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 02 dub 2013 15:16

Re: Banery na FF prohlížeči

#4 Příspěvek od ovninja »

Reklamy jsou od Yawtix...smazal jsem to už předtím ručně, ale reklamy vyskají stále...i teď i na všem fóru...

# AdwCleaner v3.215 - Report created 13/07/2014 at 21:28:31
# Updated 09/07/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : User - STOLNÍ
# Running from : C:\Documents and Settings\User\Dokumenty\Stažené soubory\adwcleaner_3.215.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

File Deleted : C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\w9d3jsc2.default\searchplugins\zonealarm.xml

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Key Deleted : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v30.0 (cs)

[ File : C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\w9d3jsc2.default\prefs.js ]


-\\ Google Chrome v35.0.1916.153

[ File : C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [1621 octets] - [19/09/2013 10:11:37]
AdwCleaner[R1].txt - [1764 octets] - [23/09/2013 15:18:02]
AdwCleaner[R2].txt - [2194 octets] - [13/07/2014 21:27:54]
AdwCleaner[S0].txt - [1851 octets] - [23/09/2013 15:18:28]
AdwCleaner[S1].txt - [2139 octets] - [13/07/2014 21:28:31]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2199 octets] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Banery na FF prohlížeči

#5 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ovninja
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 02 dub 2013 15:16

Re: Banery na FF prohlížeči

#6 Příspěvek od ovninja »

Zoek.exe v5.0.0.0 Updated 13-July-2014
Tool run by User on ne 13.07.2014 at 21:38:47,20.
Systém Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Documents and Settings\User\Plocha\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

13.7.2014 21:39:18 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f9c8ce1b-66a0-4f45-af10-5f24ef19bc4e} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Program Files\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\Program Files\ComPlus Applications deleted
C:\WINDOWS\System32\SET26.tmp deleted
C:\Documents and Settings\User\Plocha\FreemakeVideoDownloaderSetup.exe deleted
"C:\WINDOWS\Installer\25a68.msi" deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [18.09.2013 19:12]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"

==== Reset Google Chrome ======================

Nothing found to reset

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F60730A4A66673047777F5728467D401 deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce deleted successfully

==== Empty IE Cache ======================

C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\User\Local Settings\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=5 folders=1 5468671 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\User\LOCALS~1\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\RECYCLER successfully emptied

==== Deleting Files / Folders ======================

"C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found

==== EOF on ne 13.07.2014 at 21:50:07,26 ======================

ovninja
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 02 dub 2013 15:16

Re: Banery na FF prohlížeči

#7 Příspěvek od ovninja »

reklamy stále

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Banery na FF prohlížeči

#8 Příspěvek od vyosek »

Poprosim o novy log z FRST
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ovninja
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 02 dub 2013 15:16

Re: Banery na FF prohlížeči

#9 Příspěvek od ovninja »

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:13-07-2014 01
Ran by User (administrator) on STOLNÍ on 13-07-2014 21:58:58
Running from C:\Documents and Settings\User\Plocha
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(AVerMedia) C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
() C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
(AVerMedia TECHNOLOGIES, Inc.) C:\Program Files\AVerMedia\AVerUpdate\AVerUpdateServer.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Prolific Technology Inc.) C:\WINDOWS\system32\IoctlSvc.exe
(AVerMedia Technologies, Inc.) C:\Program Files\SnugTV\SnugTV Station\AMAServer.exe
(Crawler.com) C:\Program Files\Spyware Terminator\st_rsser.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
() C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [20143688 2013-03-12] (Realtek Semiconductor Corp.)
HKLM\...\Run: [amd_dc_opt] => C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2007-07-23] (AMD)
HKLM\...\Run: [NvCplDaemon] => C:\WINDOWS\system32\NvCpl.dll [15677728 2013-06-21] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] => C:\WINDOWS\system32\NvMcTray.dll [223008 2013-06-21] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2586912 2013-06-21] ()
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [750160 2014-07-04] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [PPort11reminder] => C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe [328992 2007-08-31] (Nuance Communications, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [ZoneAlarm] => C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe [137352 2014-05-30] (Check Point Software Technologies Ltd.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Status Monitor.lnk

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 9078065390
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.152.40.4 10.152.40.5

FireFox:
========
FF ProfilePath: C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\w9d3jsc2.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Disconnect - C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\w9d3jsc2.default\Extensions\2.0@disconnect.me.xpi [2014-05-04]
FF Extension: Yawtix - C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\w9d3jsc2.default\Extensions\{16d667ee-6782-4b21-81df-8ded8ebc3868}.xpi [2014-07-13]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-09-18]

Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR StartupUrls: "hxxp://www.seznam.cz/"
CHR Extension: (Peněženka Google) - C:\Documents and Settings\User\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-08]

========================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-07-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-04] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1028688 2014-07-04] (Avira Operations GmbH & Co. KG)
R2 AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [348160 2010-04-27] (AVerMedia) [File not signed]
R2 AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [403456 2011-04-01] () [File not signed]
R2 AVerUpdateServer; C:\Program Files\AVerMedia\AVerUpdate\AVerUpdateServer.exe [168448 2011-01-06] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-09-11] (Oracle Corporation)
R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 SnugTV Service; C:\Program Files\SnugTV\SnugTV Station\AMAServer.exe [571904 2011-02-14] (AVerMedia Technologies, Inc.) [File not signed]
R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [587912 2013-08-23] (Crawler.com)
S2 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [3592120 2014-05-30] (Check Point Software Technologies Ltd.)
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [90936 2014-05-29] (Check Point Software Technologies, Ltd.)

==================== Drivers (Whitelisted) ====================

S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R1 AmdPPM; C:\WINDOWS\System32\DRIVERS\AmdPPM.sys [33792 2007-04-16] (Advanced Micro Devices)
R3 AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [96704 2007-08-04] (SlySoft, Inc.)
R3 AVerAF35; C:\WINDOWS\System32\Drivers\AVerAF35.sys [642560 2010-04-02] (AVerMedia TECHNOLOGIES, Inc.)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [97648 2014-07-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [136216 2014-06-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 BrScnUsb; C:\WINDOWS\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2014-01-08] (Disc Soft Ltd)
R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [26024 2009-12-18] (Elaborate Bytes AG)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
S3 MPE; C:\WINDOWS\System32\DRIVERS\MPE.sys [15232 2008-04-14] (Microsoft Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [66688 2009-07-01] (NVIDIA Corporation)
R3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [128672 2013-02-25] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [13824 2009-07-01] (NVIDIA Corporation)
S3 silabenm; C:\WINDOWS\System32\DRIVERS\silabenm.sys [17920 2009-03-20] (Silicon Laboratories, Inc.)
S3 silabser; C:\WINDOWS\System32\DRIVERS\silabser.sys [62592 2009-03-20] (Silicon Laboratories)
R1 sp_rsdrv2; C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed]
R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [28520 2013-09-11] (Avira GmbH)
R1 Vsdatant; C:\WINDOWS\System32\vsdatant.sys [534024 2014-05-30] (Check Point Software Technologies Ltd.)
R1 {16d667ee-6782-4b21-81df-8ded8ebc3868}Gt; C:\WINDOWS\System32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gt.sys [55224 2014-07-08] (StdLib)
S4 IntelIde; No ImagePath
U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
U1 WS2IFSL;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-13 21:44 - 2014-07-13 21:59 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Temp
2014-07-13 21:44 - 2014-07-13 21:38 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-07-13 21:39 - 2014-07-13 21:50 - 00006235 _____ () C:\zoek-results.log
2014-07-13 21:38 - 2014-07-13 21:43 - 00000000 ____D () C:\zoek_backup
2014-07-13 21:37 - 2014-07-13 21:37 - 01285120 _____ () C:\Documents and Settings\User\Plocha\zoek.exe
2014-07-13 21:28 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\system32\sqlite3.dll
2014-07-13 20:39 - 2014-07-13 21:59 - 00012584 _____ () C:\Documents and Settings\User\Plocha\FRST.txt
2014-07-13 20:38 - 2014-07-13 20:38 - 00015327 _____ () C:\Documents and Settings\User\Plocha\LM.bat
2014-07-13 20:35 - 2014-07-13 20:35 - 01076736 _____ (Farbar) C:\Documents and Settings\User\Plocha\FRST.exe
2014-07-13 20:35 - 2014-07-13 20:35 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe
2014-07-13 19:25 - 2014-07-08 18:42 - 00055224 _____ (StdLib) C:\WINDOWS\system32\Drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gt.sys
2014-07-13 18:23 - 2014-07-13 18:24 - 00000000 ____D () C:\Program Files\MKV Player
2014-07-13 18:23 - 2014-07-13 18:23 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\MKV Player
2014-07-08 14:55 - 2014-07-08 14:55 - 00000403 _____ () C:\WINDOWS\wmsetup.log
2014-06-22 13:25 - 2014-06-22 13:25 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Data aplikací\Adobe
2014-06-22 13:17 - 2014-06-22 13:28 - 00000000 ____D () C:\Documents and Settings\User\Plocha\Nová složka (2)
2014-06-18 12:31 - 2014-06-18 12:32 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-18 10:22 - 2014-06-18 10:22 - 00000000 _____ () C:\Documents and Settings\User\Plocha\Nový objekt - Textový dokument.txt

==================== One Month Modified Files and Folders =======

2014-07-13 21:59 - 2014-07-13 21:44 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Temp
2014-07-13 21:59 - 2014-07-13 20:39 - 00012584 _____ () C:\Documents and Settings\User\Plocha\FRST.txt
2014-07-13 21:59 - 2014-03-27 19:27 - 00000000 ____D () C:\FRST
2014-07-13 21:58 - 2013-09-11 18:38 - 00000000 ____D () C:\Documents and Settings\User\Plocha
2014-07-13 21:51 - 2013-09-11 22:23 - 00009942 _____ () C:\WINDOWS\system32\nvAppTimestamps
2014-07-13 21:50 - 2014-07-13 21:39 - 00006235 _____ () C:\zoek-results.log
2014-07-13 21:47 - 2013-09-11 18:33 - 01661526 _____ () C:\WINDOWS\WindowsUpdate.log
2014-07-13 21:46 - 2013-09-11 20:28 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-07-13 21:46 - 2013-09-11 20:28 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-07-13 21:45 - 2014-03-28 10:14 - 00000936 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-13 21:45 - 2013-09-11 18:36 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-07-13 21:44 - 2013-09-17 18:32 - 00524288 _____ () C:\WINDOWS\system32\config\AVer Med.evt
2014-07-13 21:44 - 2013-09-17 18:32 - 00196608 _____ () C:\WINDOWS\system32\config\AVer Aut.evt
2014-07-13 21:44 - 2013-09-11 18:38 - 00000178 ___SH () C:\Documents and Settings\User\ntuser.ini
2014-07-13 21:44 - 2013-09-11 18:36 - 00032542 _____ () C:\WINDOWS\SchedLgU.Txt
2014-07-13 21:43 - 2014-07-13 21:38 - 00000000 ____D () C:\zoek_backup
2014-07-13 21:38 - 2014-07-13 21:44 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-07-13 21:37 - 2014-07-13 21:37 - 01285120 _____ () C:\Documents and Settings\User\Plocha\zoek.exe
2014-07-13 21:37 - 2013-09-11 21:11 - 00000000 ____D () C:\Documents and Settings\User\Dokumenty\Stažené soubory
2014-07-13 21:36 - 2013-09-17 14:13 - 00000000 ____D () C:\Program Files\utorrent
2014-07-13 21:32 - 2014-03-28 10:14 - 00000940 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-13 21:28 - 2013-09-19 10:11 - 00000000 ____D () C:\AdwCleaner
2014-07-13 21:16 - 2013-09-11 23:20 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2014-07-13 21:12 - 2013-09-11 18:31 - 00000000 ____D () C:\WINDOWS\Registration
2014-07-13 21:03 - 2013-09-11 22:26 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-07-13 20:48 - 2001-10-25 14:00 - 00000684 _____ () C:\WINDOWS\win.ini
2014-07-13 20:38 - 2014-07-13 20:38 - 00015327 _____ () C:\Documents and Settings\User\Plocha\LM.bat
2014-07-13 20:38 - 2013-09-11 18:38 - 00000000 ___HD () C:\Documents and Settings\User\Local Settings\Data aplikací
2014-07-13 20:35 - 2014-07-13 20:35 - 01076736 _____ (Farbar) C:\Documents and Settings\User\Plocha\FRST.exe
2014-07-13 20:35 - 2014-07-13 20:35 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe
2014-07-13 20:34 - 2013-09-18 11:07 - 00000000 ____D () C:\Program Files\trend micro
2014-07-13 18:24 - 2014-07-13 18:23 - 00000000 ____D () C:\Program Files\MKV Player
2014-07-13 18:23 - 2014-07-13 18:23 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\MKV Player
2014-07-13 18:23 - 2013-09-11 20:26 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-07-13 09:55 - 2001-10-25 14:00 - 00002300 _____ () C:\WINDOWS\system32\wpa.dbl
2014-07-11 09:28 - 2013-09-12 22:02 - 00000000 ___RD () C:\Documents and Settings\User\Plocha\Mbank
2014-07-10 23:16 - 2013-09-13 14:12 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-07-10 23:15 - 2013-09-13 14:12 - 93585272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-07-10 23:14 - 2013-09-12 18:16 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-07-09 16:03 - 2013-09-11 22:26 - 00699056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-07-09 16:03 - 2013-09-11 22:26 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-07-08 18:42 - 2014-07-13 19:25 - 00055224 _____ (StdLib) C:\WINDOWS\system32\Drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gt.sys
2014-07-08 15:00 - 2014-03-27 20:04 - 00000214 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-07-08 14:55 - 2014-07-08 14:55 - 00000403 _____ () C:\WINDOWS\wmsetup.log
2014-07-06 21:50 - 2014-05-10 19:48 - 00000000 ____D () C:\Documents and Settings\User\Data aplikací\TS3Client
2014-07-04 22:30 - 2014-02-26 16:43 - 00000000 ___RD () C:\Documents and Settings\User\Plocha\Biofeedback
2014-07-04 22:30 - 2013-09-11 18:38 - 00000000 ___RD () C:\Documents and Settings\User\Dokumenty\Obrázky
2014-07-04 08:15 - 2013-09-11 23:04 - 00097648 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2014-06-25 18:19 - 2013-09-11 20:27 - 01521712 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-06-22 13:28 - 2014-06-22 13:17 - 00000000 ____D () C:\Documents and Settings\User\Plocha\Nová složka (2)
2014-06-22 13:25 - 2014-06-22 13:25 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Data aplikací\Adobe
2014-06-19 07:29 - 2014-03-28 00:05 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-06-18 12:55 - 2014-05-10 00:31 - 00000000 ____D () C:\Program Files\Mozilla Firefox.bak
2014-06-18 12:32 - 2014-06-18 12:31 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-18 10:22 - 2014-06-18 10:22 - 00000000 _____ () C:\Documents and Settings\User\Plocha\Nový objekt - Textový dokument.txt

Some content of TEMP:
====================
C:\Documents and Settings\User\Local Settings\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Banery na FF prohlížeči

#10 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
    Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk)
    
    SearchScopes: HKLM - DefaultScope value is missing.
    SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
    SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
    
    FF Extension: Yawtix - C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\w9d3jsc2.default\Extensions\{16d667ee-6782-4b21-81df-8ded8ebc3868}.xpi [2014-07-13]
    
    2014-07-13 21:44 - 2014-07-13 21:38 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
    2014-07-13 21:39 - 2014-07-13 21:50 - 00006235 _____ () C:\zoek-results.log
    2014-07-13 21:38 - 2014-07-13 21:43 - 00000000 ____D () C:\zoek_backup
    2014-07-13 21:37 - 2014-07-13 21:37 - 01285120 _____ () C:\Documents and Settings\User\Plocha\zoek.exe
    2014-07-13 21:28 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\system32\sqlite3.dll
    2014-07-13 20:39 - 2014-07-13 21:59 - 00012584 _____ () C:\Documents and Settings\User\Plocha\FRST.txt
    2014-07-13 20:38 - 2014-07-13 20:38 - 00015327 _____ () C:\Documents and Settings\User\Plocha\LM.bat
    2014-07-13 20:35 - 2014-07-13 20:35 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe
    
    Hosts:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ovninja
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 02 dub 2013 15:16

Re: Banery na FF prohlížeči

#11 Příspěvek od ovninja »

Reklamy zmizely... :) co byl teda za problém...

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:13-07-2014 01
Ran by User at 2014-07-13 22:19:16 Run:2
Running from C:\Documents and Settings\User\Plocha
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk)

SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}

FF Extension: Yawtix - C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\w9d3jsc2.default\Extensions\{16d667ee-6782-4b21-81df-8ded8ebc3868}.xpi [2014-07-13]

2014-07-13 21:44 - 2014-07-13 21:38 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-07-13 21:39 - 2014-07-13 21:50 - 00006235 _____ () C:\zoek-results.log
2014-07-13 21:38 - 2014-07-13 21:43 - 00000000 ____D () C:\zoek_backup
2014-07-13 21:37 - 2014-07-13 21:37 - 01285120 _____ () C:\Documents and Settings\User\Plocha\zoek.exe
2014-07-13 21:28 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\system32\sqlite3.dll
2014-07-13 20:39 - 2014-07-13 21:59 - 00012584 _____ () C:\Documents and Settings\User\Plocha\FRST.txt
2014-07-13 20:38 - 2014-07-13 20:38 - 00015327 _____ () C:\Documents and Settings\User\Plocha\LM.bat
2014-07-13 20:35 - 2014-07-13 20:35 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\User\Plocha\FRSTLauncher.exe

Hosts:
Reboot:
End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk) not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}' => Key deleted successfully.
'HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}'=> Key not found.
'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}' => Key deleted successfully.
'HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}'=> Key not found.
C:\Documents and Settings\User\Data aplikací\Mozilla\Firefox\Profiles\w9d3jsc2.default\Extensions\{16d667ee-6782-4b21-81df-8ded8ebc3868}.xpi => Moved successfully.



C:\WINDOWS\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Documents and Settings\User\Plocha\zoek.exe => Moved successfully.
C:\WINDOWS\system32\sqlite3.dll => Moved successfully.
C:\Documents and Settings\User\Plocha\FRST.txt => Moved successfully.
C:\Documents and Settings\User\Plocha\LM.bat => Moved successfully.
C:\Documents and Settings\User\Plocha\FRSTLauncher.exe => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.


The system needed a reboot.

==== End of Fixlog ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Banery na FF prohlížeči

#12 Příspěvek od vyosek »

:arrow: Byl tam reklamni SW, ktery bylo treba Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|odpalit rucne pres skript¨¨
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ovninja
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 02 dub 2013 15:16

Re: Banery na FF prohlížeči

#13 Příspěvek od ovninja »

Děkuji mockrát

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Banery na FF prohlížeči

#14 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek

A na zaklade Pravidla o zamykani temat :lock:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno