
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
preventivni kontrola
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: preventivni kontrola


- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [uTorrent] => C:\Users\Tepan\AppData\Roaming\uTorrent\uTorrent.exe [1322832 2014-07-04] (BitTorrent Inc.) HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [SPDriver] => C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.199\jsdrv.exe HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [key] => wscript.exe //B "C:\Users\Tepan\AppData\Roaming\key.vbs" HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [45cd603ee23d7c7a771df421f5721e99] => C:\Users\Tepan\AppData\Local\Temp\win.exe [138240 2014-07-19] () <===== ATTENTION HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\MountPoints2: {b1f4c1dc-5803-11e3-9023-d43d7e500c5b} - G:\AutoRun.exe HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\MountPoints2: {b1f4c1e7-5803-11e3-9023-d43d7e500c5b} - G:\AutoRun.exe HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\MountPoints2: {b1f4c1fd-5803-11e3-9023-d43d7e500c5b} - G:\AutoRun.exe Startup: C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\45cd603ee23d7c7a771df421f5721e99.exe () Startup: C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01 StartMenuInternet: IEXPLORE.EXE - c:\program files (x86)\internet explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKLM-x32 - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 SearchScopes: HKCU - DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 BHO: Shop_an_Upi_1.6 -> {11111111-1111-1111-1111-110411281122} -> C:\Program Files (x86)\Shop_an_Upi_1.6\Shop_an_Upi_1.6-bho64.dll No File CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION DisableService: Nero BackItUp Scheduler 3 R2 SpyHunter 4 Service; C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe [770432 2013-06-27] (Enigma Software Group USA, LLC.) S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [X] S3 esgiguard; C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [13088 2011-03-02] () S3 EsgScanner; C:\Windows\SysWOW64\DRIVERS\EsgScanner.sys [19984 2012-06-22] () S3 cpuz130; \??\C:\Users\Tepan\AppData\Local\Temp\cpuz130\cpuz_x64.sys [X] S3 cpuz134; \??\C:\Users\Tepan\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] S3 cpuz135; \??\C:\Users\Tepan\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X] S2 SPDRIVER_1.37.0.199; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.199\jsdrv.sys [X] C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs C:\Users\Tepan\AppData\Roaming\key.vbs C:\Program Files (x86)\ShopperPro C:\Users\Tepan\AppData\Local\Temp\win.exe C:\Program Files\Reimage C:\Program Files (x86)\Enigma Software Group 2014-07-19 19:02 - 2014-05-18 18:47 - 00102663 _____ () C:\Users\Tepan\AppData\Roaming\key.vbs 2014-07-18 23:07 - 2014-07-18 22:16 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-07-18 22:39 - 2014-07-18 23:13 - 00031966 _____ () C:\zoek-results.log 2014-07-18 22:16 - 2014-07-18 23:02 - 00000000 ____D () C:\zoek_backup 2014-07-18 22:14 - 2014-07-18 22:14 - 01287168 _____ () C:\Users\Tepan\Desktop\zoek.exe 2014-07-18 18:51 - 2014-07-18 18:51 - 00002248 _____ () C:\Users\Tepan\Desktop\SpyHunter.lnk 2014-07-18 18:51 - 2014-07-18 18:51 - 00000000 ____D () C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter 2014-07-18 18:51 - 2014-07-18 18:51 - 00000000 ____D () C:\sh4ldr 2014-07-18 16:39 - 2014-07-18 16:39 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group 2014-07-18 15:33 - 2014-07-18 16:44 - 00000000 ____D () C:\Program Files\Enigma Software Group Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe Task: C:\Windows\Tasks\Oxy.job => C:\Users\Tepan\AppData\Roaming\Oxy\Updater.exe Task: C:\Windows\Tasks\ReimageUpdater.job => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe Task: C:\Windows\Tasks\RunAsStdUser Task.job => C:\Users\Tepan\AppData\Local\Oxy\Application\oxy.exe Task: C:\Windows\Tasks\SPBIW_UpdateTask_Time_313137363632353534382d50552d6c455a37575a417834.job => C:\ProgramData\ShopperPro\spbihe.js" spbiu.exe Task: C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe AlternateDataStreams: C:\Temp:pid1 AlternateDataStreams: C:\Temp:pid2 AlternateDataStreams: C:\Temp:srv AlternateDataStreams: C:\ProgramData\TEMP:373E1720 Hosts: Reboot: End
- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST

- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt

Re: preventivni kontrola
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-07-2014
Ran by Tepan at 2014-07-19 21:50:27 Run:1
Running from C:\Users\Tepan\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [uTorrent] => C:\Users\Tepan\AppData\Roaming\uTorrent\uTorrent.exe [1322832 2014-07-04] (BitTorrent Inc.)
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [SPDriver] => C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.199\jsdrv.exe
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [key] => wscript.exe //B "C:\Users\Tepan\AppData\Roaming\key.vbs"
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [45cd603ee23d7c7a771df421f5721e99] => C:\Users\Tepan\AppData\Local\Temp\win.exe [138240 2014-07-19] () <===== ATTENTION
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\MountPoints2: {b1f4c1dc-5803-11e3-9023-d43d7e500c5b} - G:\AutoRun.exe
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\MountPoints2: {b1f4c1e7-5803-11e3-9023-d43d7e500c5b} - G:\AutoRun.exe
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\MountPoints2: {b1f4c1fd-5803-11e3-9023-d43d7e500c5b} - G:\AutoRun.exe
Startup: C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\45cd603ee23d7c7a771df421f5721e99.exe ()
Startup: C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01
StartMenuInternet: IEXPLORE.EXE - c:\program files (x86)\internet explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
SearchScopes: HKCU - DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
BHO: Shop_an_Upi_1.6 -> {11111111-1111-1111-1111-110411281122} -> C:\Program Files (x86)\Shop_an_Upi_1.6\Shop_an_Upi_1.6-bho64.dll No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
DisableService: Nero BackItUp Scheduler 3
R2 SpyHunter 4 Service; C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe [770432 2013-06-27] (Enigma Software Group USA, LLC.)
S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [X]
S3 esgiguard; C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [13088 2011-03-02] ()
S3 EsgScanner; C:\Windows\SysWOW64\DRIVERS\EsgScanner.sys [19984 2012-06-22] ()
S3 cpuz130; \??\C:\Users\Tepan\AppData\Local\Temp\cpuz130\cpuz_x64.sys [X]
S3 cpuz134; \??\C:\Users\Tepan\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 cpuz135; \??\C:\Users\Tepan\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X]
S2 SPDRIVER_1.37.0.199; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.199\jsdrv.sys [X]
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs
C:\Users\Tepan\AppData\Roaming\key.vbs
C:\Program Files (x86)\ShopperPro
C:\Users\Tepan\AppData\Local\Temp\win.exe
C:\Program Files\Reimage
C:\Program Files (x86)\Enigma Software Group
2014-07-19 19:02 - 2014-05-18 18:47 - 00102663 _____ () C:\Users\Tepan\AppData\Roaming\key.vbs
2014-07-18 23:07 - 2014-07-18 22:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-07-18 22:39 - 2014-07-18 23:13 - 00031966 _____ () C:\zoek-results.log
2014-07-18 22:16 - 2014-07-18 23:02 - 00000000 ____D () C:\zoek_backup
2014-07-18 22:14 - 2014-07-18 22:14 - 01287168 _____ () C:\Users\Tepan\Desktop\zoek.exe
2014-07-18 18:51 - 2014-07-18 18:51 - 00002248 _____ () C:\Users\Tepan\Desktop\SpyHunter.lnk
2014-07-18 18:51 - 2014-07-18 18:51 - 00000000 ____D () C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-07-18 18:51 - 2014-07-18 18:51 - 00000000 ____D () C:\sh4ldr
2014-07-18 16:39 - 2014-07-18 16:39 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group
2014-07-18 15:33 - 2014-07-18 16:44 - 00000000 ____D () C:\Program Files\Enigma Software Group
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\Windows\Tasks\Oxy.job => C:\Users\Tepan\AppData\Roaming\Oxy\Updater.exe
Task: C:\Windows\Tasks\ReimageUpdater.job => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
Task: C:\Windows\Tasks\RunAsStdUser Task.job => C:\Users\Tepan\AppData\Local\Oxy\Application\oxy.exe
Task: C:\Windows\Tasks\SPBIW_UpdateTask_Time_313137363632353534382d50552d6c455a37575a417834.job => C:\ProgramData\ShopperPro\spbihe.js" spbiu.exe
Task: C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe
AlternateDataStreams: C:\Temp:pid1
AlternateDataStreams: C:\Temp:pid2
AlternateDataStreams: C:\Temp:srv
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
Hosts:
Reboot:
End
*****************
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent => value deleted successfully.
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\SPDriver => Value not found.
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\key => value deleted successfully.
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\45cd603ee23d7c7a771df421f5721e99 => value deleted successfully.
'HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b1f4c1dc-5803-11e3-9023-d43d7e500c5b}' => Key deleted successfully.
'HKCR\CLSID\{b1f4c1dc-5803-11e3-9023-d43d7e500c5b}'=> Key not found.
'HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b1f4c1e7-5803-11e3-9023-d43d7e500c5b}' => Key deleted successfully.
'HKCR\CLSID\{b1f4c1e7-5803-11e3-9023-d43d7e500c5b}'=> Key not found.
'HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b1f4c1fd-5803-11e3-9023-d43d7e500c5b}' => Key deleted successfully.
'HKCR\CLSID\{b1f4c1fd-5803-11e3-9023-d43d7e500c5b}'=> Key not found.
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\45cd603ee23d7c7a771df421f5721e99.exe => Moved successfully.
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs => Moved successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
'HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}' => Key deleted successfully.
'HKCR\Wow6432Node\CLSID\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}'=> Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411281122}' => Key deleted successfully.
'HKCR\CLSID\{11111111-1111-1111-1111-110411281122}' => Key deleted successfully.
'HKLM\SOFTWARE\Policies\Google' => Key deleted successfully.
'HKCU\SOFTWARE\Policies\Google' => Key deleted successfully.
Nero BackItUp Scheduler 3 service was disabled
SpyHunter 4 Service => Service stopped successfully.
SpyHunter 4 Service => Service deleted successfully.
ReimageRealTimeProtector => Service not found.
esgiguard => Service deleted successfully.
EsgScanner => Service deleted successfully.
cpuz130 => Service deleted successfully.
cpuz134 => Service deleted successfully.
cpuz135 => Service deleted successfully.
SPDRIVER_1.37.0.199 => Service deleted successfully.
"C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs" => File/Directory not found.
Could not move "C:\Users\Tepan\AppData\Roaming\key.vbs" => Scheduled to move on reboot.
"C:\Program Files (x86)\ShopperPro" => File/Directory not found.
C:\Users\Tepan\AppData\Local\Temp\win.exe => Moved successfully.
"C:\Program Files\Reimage" => File/Directory not found.
C:\Program Files (x86)\Enigma Software Group => Moved successfully.
Could not move "C:\Users\Tepan\AppData\Roaming\key.vbs" => Scheduled to move on reboot.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Tepan\Desktop\zoek.exe => Moved successfully.
C:\Users\Tepan\Desktop\SpyHunter.lnk => Moved successfully.
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter => Moved successfully.
C:\sh4ldr => Moved successfully.
"C:\Program Files (x86)\Enigma Software Group" => File/Directory not found.
C:\Program Files\Enigma Software Group => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\avast! Emergency Update.job => Moved successfully.
C:\Windows\Tasks\Oxy.job not found.
C:\Windows\Tasks\ReimageUpdater.job not found.
C:\Windows\Tasks\RunAsStdUser Task.job not found.
C:\Windows\Tasks\SPBIW_UpdateTask_Time_313137363632353534382d50552d6c455a37575a417834.job => Moved successfully.
C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job => Moved successfully.
C:\Temp => ":pid1" ADS removed successfully.
C:\Temp => ":pid2" ADS removed successfully.
C:\Temp => ":srv" ADS removed successfully.
C:\ProgramData\TEMP => ":373E1720" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-07-19 21:51:48)<=
C:\Users\Tepan\AppData\Roaming\key.vbs => Is moved successfully.
C:\Users\Tepan\AppData\Roaming\key.vbs => Is moved successfully.
==== End of Fixlog ====
Ran by Tepan at 2014-07-19 21:50:27 Run:1
Running from C:\Users\Tepan\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [uTorrent] => C:\Users\Tepan\AppData\Roaming\uTorrent\uTorrent.exe [1322832 2014-07-04] (BitTorrent Inc.)
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [SPDriver] => C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.199\jsdrv.exe
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [key] => wscript.exe //B "C:\Users\Tepan\AppData\Roaming\key.vbs"
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [45cd603ee23d7c7a771df421f5721e99] => C:\Users\Tepan\AppData\Local\Temp\win.exe [138240 2014-07-19] () <===== ATTENTION
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\MountPoints2: {b1f4c1dc-5803-11e3-9023-d43d7e500c5b} - G:\AutoRun.exe
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\MountPoints2: {b1f4c1e7-5803-11e3-9023-d43d7e500c5b} - G:\AutoRun.exe
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\MountPoints2: {b1f4c1fd-5803-11e3-9023-d43d7e500c5b} - G:\AutoRun.exe
Startup: C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\45cd603ee23d7c7a771df421f5721e99.exe ()
Startup: C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01
StartMenuInternet: IEXPLORE.EXE - c:\program files (x86)\internet explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
SearchScopes: HKCU - DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
BHO: Shop_an_Upi_1.6 -> {11111111-1111-1111-1111-110411281122} -> C:\Program Files (x86)\Shop_an_Upi_1.6\Shop_an_Upi_1.6-bho64.dll No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
DisableService: Nero BackItUp Scheduler 3
R2 SpyHunter 4 Service; C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe [770432 2013-06-27] (Enigma Software Group USA, LLC.)
S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [X]
S3 esgiguard; C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [13088 2011-03-02] ()
S3 EsgScanner; C:\Windows\SysWOW64\DRIVERS\EsgScanner.sys [19984 2012-06-22] ()
S3 cpuz130; \??\C:\Users\Tepan\AppData\Local\Temp\cpuz130\cpuz_x64.sys [X]
S3 cpuz134; \??\C:\Users\Tepan\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 cpuz135; \??\C:\Users\Tepan\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X]
S2 SPDRIVER_1.37.0.199; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.199\jsdrv.sys [X]
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs
C:\Users\Tepan\AppData\Roaming\key.vbs
C:\Program Files (x86)\ShopperPro
C:\Users\Tepan\AppData\Local\Temp\win.exe
C:\Program Files\Reimage
C:\Program Files (x86)\Enigma Software Group
2014-07-19 19:02 - 2014-05-18 18:47 - 00102663 _____ () C:\Users\Tepan\AppData\Roaming\key.vbs
2014-07-18 23:07 - 2014-07-18 22:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-07-18 22:39 - 2014-07-18 23:13 - 00031966 _____ () C:\zoek-results.log
2014-07-18 22:16 - 2014-07-18 23:02 - 00000000 ____D () C:\zoek_backup
2014-07-18 22:14 - 2014-07-18 22:14 - 01287168 _____ () C:\Users\Tepan\Desktop\zoek.exe
2014-07-18 18:51 - 2014-07-18 18:51 - 00002248 _____ () C:\Users\Tepan\Desktop\SpyHunter.lnk
2014-07-18 18:51 - 2014-07-18 18:51 - 00000000 ____D () C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-07-18 18:51 - 2014-07-18 18:51 - 00000000 ____D () C:\sh4ldr
2014-07-18 16:39 - 2014-07-18 16:39 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group
2014-07-18 15:33 - 2014-07-18 16:44 - 00000000 ____D () C:\Program Files\Enigma Software Group
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\Windows\Tasks\Oxy.job => C:\Users\Tepan\AppData\Roaming\Oxy\Updater.exe
Task: C:\Windows\Tasks\ReimageUpdater.job => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
Task: C:\Windows\Tasks\RunAsStdUser Task.job => C:\Users\Tepan\AppData\Local\Oxy\Application\oxy.exe
Task: C:\Windows\Tasks\SPBIW_UpdateTask_Time_313137363632353534382d50552d6c455a37575a417834.job => C:\ProgramData\ShopperPro\spbihe.js" spbiu.exe
Task: C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe
AlternateDataStreams: C:\Temp:pid1
AlternateDataStreams: C:\Temp:pid2
AlternateDataStreams: C:\Temp:srv
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
Hosts:
Reboot:
End
*****************
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent => value deleted successfully.
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\SPDriver => Value not found.
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\key => value deleted successfully.
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\45cd603ee23d7c7a771df421f5721e99 => value deleted successfully.
'HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b1f4c1dc-5803-11e3-9023-d43d7e500c5b}' => Key deleted successfully.
'HKCR\CLSID\{b1f4c1dc-5803-11e3-9023-d43d7e500c5b}'=> Key not found.
'HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b1f4c1e7-5803-11e3-9023-d43d7e500c5b}' => Key deleted successfully.
'HKCR\CLSID\{b1f4c1e7-5803-11e3-9023-d43d7e500c5b}'=> Key not found.
'HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b1f4c1fd-5803-11e3-9023-d43d7e500c5b}' => Key deleted successfully.
'HKCR\CLSID\{b1f4c1fd-5803-11e3-9023-d43d7e500c5b}'=> Key not found.
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\45cd603ee23d7c7a771df421f5721e99.exe => Moved successfully.
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs => Moved successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
'HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}' => Key deleted successfully.
'HKCR\Wow6432Node\CLSID\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}'=> Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411281122}' => Key deleted successfully.
'HKCR\CLSID\{11111111-1111-1111-1111-110411281122}' => Key deleted successfully.
'HKLM\SOFTWARE\Policies\Google' => Key deleted successfully.
'HKCU\SOFTWARE\Policies\Google' => Key deleted successfully.
Nero BackItUp Scheduler 3 service was disabled
SpyHunter 4 Service => Service stopped successfully.
SpyHunter 4 Service => Service deleted successfully.
ReimageRealTimeProtector => Service not found.
esgiguard => Service deleted successfully.
EsgScanner => Service deleted successfully.
cpuz130 => Service deleted successfully.
cpuz134 => Service deleted successfully.
cpuz135 => Service deleted successfully.
SPDRIVER_1.37.0.199 => Service deleted successfully.
"C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs" => File/Directory not found.
Could not move "C:\Users\Tepan\AppData\Roaming\key.vbs" => Scheduled to move on reboot.
"C:\Program Files (x86)\ShopperPro" => File/Directory not found.
C:\Users\Tepan\AppData\Local\Temp\win.exe => Moved successfully.
"C:\Program Files\Reimage" => File/Directory not found.
C:\Program Files (x86)\Enigma Software Group => Moved successfully.
Could not move "C:\Users\Tepan\AppData\Roaming\key.vbs" => Scheduled to move on reboot.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Tepan\Desktop\zoek.exe => Moved successfully.
C:\Users\Tepan\Desktop\SpyHunter.lnk => Moved successfully.
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter => Moved successfully.
C:\sh4ldr => Moved successfully.
"C:\Program Files (x86)\Enigma Software Group" => File/Directory not found.
C:\Program Files\Enigma Software Group => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\avast! Emergency Update.job => Moved successfully.
C:\Windows\Tasks\Oxy.job not found.
C:\Windows\Tasks\ReimageUpdater.job not found.
C:\Windows\Tasks\RunAsStdUser Task.job not found.
C:\Windows\Tasks\SPBIW_UpdateTask_Time_313137363632353534382d50552d6c455a37575a417834.job => Moved successfully.
C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job => Moved successfully.
C:\Temp => ":pid1" ADS removed successfully.
C:\Temp => ":pid2" ADS removed successfully.
C:\Temp => ":srv" ADS removed successfully.
C:\ProgramData\TEMP => ":373E1720" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-07-19 21:51:48)<=
C:\Users\Tepan\AppData\Roaming\key.vbs => Is moved successfully.
C:\Users\Tepan\AppData\Roaming\key.vbs => Is moved successfully.
==== End of Fixlog ====
Re: preventivni kontrola
Jak se chova PC???
Re: preventivni kontrola
po restartu žádné hlášky nevyskakují,firefox nabíhá normálně,internet běží v pořádku..už jen budu muset doladit programy při startu Windows.Vypadá to tedy,že je vše o.k. ,tak zatím moc děkuji.Snad to nezakřiknu.Asi můžete vlákno zamčít.
PS:mohu svá vlákna nějak zamykat i já?
PS:mohu svá vlákna nějak zamykat i já?
Re: preventivni kontrola
Tak jeste uklidime
T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
Temata mohou zamykat jen Radci a MODi
A pokud nejsou problemy ci dotazy, je to z me strany vse 


- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy



Re: preventivni kontrola
Vyčištěno podle návodu..můžete zamknout..Díky mějte se.