Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

problem s prohlizecem(reklamy)

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Erutan
Návštěvník
Návštěvník
Příspěvky: 133
Registrován: 16 čer 2008 18:51

problem s prohlizecem(reklamy)

#1 Příspěvek od Erutan »

zdravim mam takovy neprijemny problem.v prohlizeci nektere slova zmodraji(internetovy odkaz) a kdyz pres ne prejedu mysi vyskoci mi reklama. mozilu mam nejaktualnejsi a ani reinstal mi nepomohl:( dokladam foto(nekdy mi na strance zmodra i 10slov a vice)
Bez názvu.png
Bez názvu.png (40.5 KiB) Zobrazeno 1801 x
a log rsit.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Erutan at 2014-09-05 09:27:06
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 61 GB (54%) free of 114 GB
Total RAM: 8189 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:27:07, on 5.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\trend micro\Erutan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [logagent] "C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe"
O4 - HKCU\..\RunOnce: [logagent] "C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: logagent.lnk = C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe
O4 - Startup: µTorrent.lnk = C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: JMB36X - Unknown owner - C:\Windows\SysWOW64\XSrvSetup.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8020 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE"
C:\Windows\SysWOW64\XSrvSetup.exe
atieclxx
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\SearchIndexer.exe /Embedding
taskeng.exe {12C9FD94-3B66-4B18-BA19-C0898ECFF0AB}
"taskhost.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\SpeedFan\speedfan.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
WLIDSvcM.exe 1684
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe" silentrun
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Windows\System32\StikyNot.exe"
"C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe"
"C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe" -standalone 131074 "-new_session"
ctfmon.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"D:\Download\RSITx64(1).exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default

prefs.js - "browser.search.useDBForOrder" - "false"
prefs.js - "browser.startup.homepage" - "http://www.google.com"
prefs.js - "keyword.URL" - "http://www.google.com/search?btnG=Google+Search&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.179 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.3.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.179 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll
nppluginrichmediaplayer.dll

C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\
{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}
{bda388db-b4e9-4193-b83a-bca1947df5c3}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-10-06 11474024]
"XboxStat"=C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2009-09-30 825184]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
"uTorrent"=C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe [2014-07-02 1322832]
"logagent"=C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe [2010-11-21 133632]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"logagent"=C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe [2010-11-21 133632]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-09-07 43608]
"NUSB3MON"=C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2009-11-20 106496]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2013-03-28 642656]

C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
logagent.lnk - C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe
µTorrent.lnk - C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"Run"="C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-09-05 09:27:06 ----D---- C:\rsit
2014-09-05 09:21:47 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-04 08:47:02 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-02 22:43:00 ----D---- C:\Users\Erutan\AppData\Roaming\WebExtend
2014-08-26 17:50:49 ----D---- C:\Users\Erutan\AppData\Roaming\2K Sports
2014-08-24 19:49:21 ----D---- C:\Users\Erutan\AppData\Roaming\Disney Interactive Studios
2014-08-24 19:43:49 ----A---- C:\Windows\disney.ini
2014-08-22 21:02:48 ----A---- C:\Windows\SYSWOW64\FAP3D86.tmp
2014-08-22 21:00:33 ----A---- C:\Windows\SYSWOW64\FAP300D.tmp
2014-08-22 20:57:40 ----A---- C:\Windows\SYSWOW64\FAP8A69.tmp
2014-08-19 18:37:09 ----D---- C:\Users\Erutan\AppData\Roaming\.mono
2014-08-19 18:37:00 ----D---- C:\Users\Erutan\AppData\Roaming\Steam
2014-08-16 20:00:47 ----D---- C:\ProgramData\McAfee
2014-08-16 14:50:21 ----D---- C:\Users\Erutan\AppData\Roaming\uSihUgkD
2014-08-16 14:49:25 ----D---- C:\Program Files (x86)\SopCast
2014-08-15 10:31:17 ----D---- C:\Program Files (x86)\NVIDIA Corporation

======List of files/folders modified in the last 1 month======

2014-09-05 09:27:06 ----D---- C:\Windows\Temp
2014-09-05 09:27:06 ----D---- C:\Program Files\trend micro
2014-09-05 09:26:58 ----D---- C:\Users\Erutan\AppData\Roaming\uTorrent
2014-09-05 09:21:47 ----RD---- C:\Program Files (x86)
2014-09-05 09:17:20 ----D---- C:\Windows\Logs
2014-09-05 09:17:20 ----D---- C:\Windows\inf
2014-09-05 09:17:20 ----D---- C:\Windows
2014-09-05 09:11:22 ----D---- C:\Program Files (x86)\SpeedFan
2014-09-04 23:48:12 ----SHD---- C:\Windows\Installer
2014-09-04 23:48:12 ----SHD---- C:\Config.Msi
2014-09-04 23:48:12 ----D---- C:\Windows\winsxs
2014-09-04 23:48:09 ----D---- C:\Windows\system32\config
2014-09-04 23:48:07 ----SHD---- C:\System Volume Information
2014-09-04 23:33:42 ----D---- C:\Users\Erutan\AppData\Roaming\vlc
2014-09-04 11:58:07 ----D---- C:\ProgramData\Origin
2014-09-04 09:54:35 ----D---- C:\Program Files (x86)\Origin
2014-09-04 09:40:32 ----D---- C:\Windows\Prefetch
2014-09-03 07:24:53 ----D---- C:\Program Files (x86)\The KMPlayer
2014-09-01 10:27:05 ----D---- C:\Windows\SYSWOW64\directx
2014-09-01 10:00:33 ----D---- C:\Users\Erutan\AppData\Roaming\Skype
2014-08-27 20:40:00 ----HD---- C:\ProgramData
2014-08-27 20:39:12 ----RD---- C:\Program Files
2014-08-27 20:35:23 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2014-08-27 20:32:26 ----D---- C:\Users\Erutan\AppData\Roaming\DAEMON Tools Lite
2014-08-27 20:31:11 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-08-26 17:50:15 ----RSD---- C:\Windows\assembly
2014-08-26 16:07:14 ----D---- C:\ProgramData\PMB Files
2014-08-25 18:57:22 ----D---- C:\Windows\system32\catroot2
2014-08-22 21:02:48 ----D---- C:\Windows\SysWOW64
2014-08-19 15:21:42 ----D---- C:\Windows\SoftwareDistribution
2014-08-19 15:20:04 ----D---- C:\Windows\system32\drivers
2014-08-16 20:54:56 ----D---- C:\Windows\Offline Web Pages
2014-08-16 20:01:09 ----SD---- C:\ProgramData\Microsoft
2014-08-16 20:01:09 ----D---- C:\Program Files (x86)\Microsoft
2014-08-16 20:00:45 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-08-16 14:50:21 ----D---- C:\Windows\system32\Tasks
2014-08-13 08:30:01 ----D---- C:\Users\Erutan\AppData\Roaming\dvdcss
2014-08-11 11:23:24 ----D---- C:\ProgramData\Codemasters
2014-08-10 15:43:39 ----D---- C:\ProgramData\Malwarebytes
2014-08-10 11:15:05 ----D---- C:\Windows\System32
2014-08-09 16:11:33 ----D---- C:\ProgramData\Skype
2014-08-09 16:11:32 ----RD---- C:\Program Files (x86)\Skype
2014-08-07 17:50:31 ----D---- C:\Windows\Minidump
2014-08-07 15:38:14 ----D---- C:\Users\Erutan\AppData\Roaming\ViberPC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-09-07 121432]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 RzFilter;RzFilter; C:\Windows\system32\drivers\RzFilter.sys [2013-07-31 74456]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-07-14 834544]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2010-04-27 21544]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R2 AODDriver4.2;AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-09 57472]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-03-29 11658752]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-03-29 581120]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-02-14 96768]
R3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2014-09-05 25640]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-10-06 2511464]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2009-11-20 75776]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2009-11-20 177152]
R3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver; C:\Windows\system32\DRIVERS\Rtnic64.sys [2009-06-10 51712]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-09-03 349800]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
R3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2009-08-13 73984]
S3 AODDriver;AODDriver; \??\C:\Program Files (x86)\Gigabyte\ET6\amd64\AODDriver.sys [2010-03-12 52280]
S3 auc2wnrr;auc2wnrr; C:\Windows\system32\drivers\auc2wnrr.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2013-07-14 30528]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2010-05-25 253728]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-03-29 241152]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-03-28 361984]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ES lite Service;ES lite Service for program management.; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
R2 JMB36X;JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [2010-09-07 72280]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-07-17 76888]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-16 262320]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-08-26 114288]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-07-16 542912]
S3 TuneUp.Defrag;@C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [2013-07-14 607048]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: problem s prohlizecem(reklamy)

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stale nelegalni Windows Ultimate?? :?:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Erutan
Návštěvník
Návštěvník
Příspěvky: 133
Registrován: 16 čer 2008 18:51

Re: problem s prohlizecem(reklamy)

#3 Příspěvek od Erutan »

Jinak bych tu nepsal ;)
mam kamarada co si koupil win 8, a prodal mi win7 ultimate 64bit, kdyztak mi hod ten program na zjisteni :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: problem s prohlizecem(reklamy)

#4 Příspěvek od vyosek »

:arrow: Ja to v prubehu nejak proverim :)

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Erutan
Návštěvník
Návštěvník
Příspěvky: 133
Registrován: 16 čer 2008 18:51

Re: problem s prohlizecem(reklamy)

#5 Příspěvek od Erutan »

AdwCleaner
# AdwCleaner v3.309 - Report created 05/09/2014 at 10:17:36
# Updated 02/09/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Erutan - ERUTAN-PC
# Running from : C:\Users\Erutan\Desktop\adwcleaner_3.309.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Deleted : HKCU\Software\Softonic

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.7601.17514


-\\ Mozilla Firefox v32.0 (x86 cs)

[ File : C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\prefs.js ]


*************************

AdwCleaner[R2].txt - [1176 octets] - [05/09/2014 10:17:13]
AdwCleaner[S2].txt - [948 octets] - [05/09/2014 10:17:36]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1007 octets] ##########

JRT
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x64
Ran by Erutan on p  05.09.2014 at 10:20:54,89
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\simplitec"
Successfully deleted: [Folder] "C:\Users\Erutan\AppData\Roaming\simplitec"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"



~~~ FireFox

Emptied folder: C:\Users\Erutan\AppData\Roaming\mozilla\firefox\profiles\7rsi9my6.default\minidumps [30 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p  05.09.2014 at 10:24:22,72
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: problem s prohlizecem(reklamy)

#6 Příspěvek od vyosek »

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Erutan
Návštěvník
Návštěvník
Příspěvky: 133
Registrován: 16 čer 2008 18:51

Re: problem s prohlizecem(reklamy)

#7 Příspěvek od Erutan »

Rkill
Rkill 2.6.8 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 09/05/2014 11:59:23 AM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe (PID: 2772) [UP-HEUR]

1 proccess terminated!

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* No issues found.

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 09/05/2014 11:59:31 AM
Execution time: 0 hours(s), 0 minute(s), and 8 seconds(s)

ComboFix
ComboFix 14-09-05.01 - Erutan 05.09.2014 12:03:44.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.8189.6497 [GMT 2:00]
Spuštěný z: c:\users\Erutan\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe
c:\windows\SysWow64\tmpD164.tmp
c:\windows\SysWow64\tmpD165.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-05 do 2014-09-05 )))))))))))))))))))))))))))))))
.
.
2014-09-05 10:06 . 2014-09-05 10:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-05 08:40 . 2014-09-05 08:40 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1F0F98EF-5F43-4764-885E-9E1021E3572F}\offreg.dll
2014-09-05 08:17 . 2014-09-05 08:17 -------- d-----w- C:\AdwCleaner
2014-09-05 08:16 . 2014-09-05 08:16 0 ----a-w- c:\windows\SysWow64\FAP319.tmp
2014-09-05 08:15 . 2014-09-05 08:15 0 ----a-w- c:\windows\SysWow64\FAP8447.tmp
2014-09-05 08:14 . 2014-09-05 08:14 0 ----a-w- c:\windows\SysWow64\FAP416C.tmp
2014-09-05 08:14 . 2014-09-05 08:14 0 ----a-w- c:\windows\SysWow64\FAP1E60.tmp
2014-09-05 08:14 . 2014-09-05 08:14 0 ----a-w- c:\windows\SysWow64\FAPFA0C.tmp
2014-09-05 08:06 . 2014-09-05 08:06 0 ----a-w- c:\windows\SysWow64\FAPF13.tmp
2014-09-05 08:06 . 2014-09-05 08:06 0 ----a-w- c:\windows\SysWow64\FAP7967.tmp
2014-09-05 07:27 . 2014-09-05 07:27 -------- d-----w- C:\rsit
2014-09-05 07:21 . 2014-09-05 07:21 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-09-02 20:43 . 2014-09-02 20:43 -------- d-----w- c:\users\Erutan\AppData\Roaming\WebExtend
2014-08-27 11:06 . 2014-08-27 11:06 -------- d-----w- c:\users\Erutan\AppData\Local\Aspyr
2014-08-26 15:50 . 2014-08-26 15:50 -------- d-----w- c:\users\Erutan\AppData\Roaming\2K Sports
2014-08-25 11:12 . 2014-08-25 11:12 -------- d-----w- c:\users\Erutan\AppData\Local\Adobe
2014-08-24 17:49 . 2014-08-24 17:49 -------- d-----w- c:\users\Erutan\AppData\Roaming\Disney Interactive Studios
2014-08-22 19:02 . 2014-08-22 19:02 0 ----a-w- c:\windows\SysWow64\FAP3D86.tmp
2014-08-22 19:00 . 2014-08-22 19:00 0 ----a-w- c:\windows\SysWow64\FAP300D.tmp
2014-08-22 18:57 . 2014-08-22 18:57 0 ----a-w- c:\windows\SysWow64\FAP8A69.tmp
2014-08-19 16:37 . 2014-08-19 16:37 -------- d-----w- c:\users\Erutan\AppData\Roaming\.mono
2014-08-19 16:37 . 2014-08-19 16:37 -------- d-----w- c:\users\Erutan\AppData\Roaming\Steam
2014-08-16 18:00 . 2014-08-16 18:00 -------- d-----w- c:\programdata\McAfee
2014-08-16 12:50 . 2014-08-16 12:50 -------- d-----w- c:\users\Erutan\AppData\Roaming\uSihUgkD
2014-08-16 12:49 . 2014-08-16 12:49 -------- d-----w- c:\program files (x86)\SopCast
2014-08-15 08:31 . 2014-08-15 08:31 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2014-08-09 14:11 . 2014-08-09 14:11 -------- d-----w- c:\users\Erutan\AppData\Local\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-05 08:18 . 2013-07-14 13:54 25640 ----a-w- c:\windows\gdrv.sys
2014-08-16 18:00 . 2013-07-14 17:16 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-08-16 18:00 . 2013-07-14 17:16 699568 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-07-20 09:15 . 2014-01-22 16:04 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2014-07-20 09:15 . 2014-01-22 16:04 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2014-07-20 09:15 . 2014-01-22 16:04 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2014-07-20 09:15 . 2014-01-22 16:04 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2014-07-19 17:35 . 2014-07-17 19:53 298032 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-07-19 17:35 . 2013-07-14 16:05 298032 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-07-19 14:37 . 2014-07-17 19:53 298032 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-07-17 19:53 . 2014-07-17 19:53 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"uTorrent"="c:\users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe" [2014-07-02 1322832]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-03-28 642656]
.
c:\users\Erutan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
µTorrent.lnk - c:\users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe [2013-7-14 1322832]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"Run"= "c:\users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 AODDriver;AODDriver;c:\program files (x86)\Gigabyte\ET6\amd64\AODDriver.sys;c:\program files (x86)\Gigabyte\ET6\amd64\AODDriver.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
S0 RzFilter;RzFilter;c:\windows\system32\drivers\RzFilter.sys;c:\windows\SYSNATIVE\drivers\RzFilter.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 ES lite Service;ES lite Service for program management.;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE [x]
S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe;c:\windows\SysWOW64\XSrvSetup.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver;c:\windows\system32\DRIVERS\Rtnic64.sys;c:\windows\SYSNATIVE\DRIVERS\Rtnic64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-09-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-14 18:00]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-10-06 11474024]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-10 - (no file)
Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe
Wow6432Node-HKCU-Run-logagent - c:\users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe
c:\users\Erutan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\logagent.lnk - c:\users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe
Toolbar-10 - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1926684632-688041120-732502126-1000\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
.
[HKEY_USERS\S-1-5-21-1926684632-688041120-732502126-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:7e,f2,ef,8b,1c,a1,ab,b8,67,73,23,a5,53,6e,fe,53,9f,b9,e3,57,24,8e,43,
6b,d9,e6,30,8a,5f,90,12,0e,94,27,0f,02,db,82,c5,fe,ff,fb,69,b3,d6,22,0a,8e,\
"??"=hex:03,cc,74,63,15,f0,3a,be,3d,0b,6f,cb,4e,76,99,4d
.
[HKEY_USERS\S-1-5-21-1926684632-688041120-732502126-1000\Software\SecuROM\License information*]
"datasecu"=hex:25,00,38,64,38,71,c6,52,66,aa,e6,f2,46,ae,25,25,2a,b2,06,e2,1e,
7f,21,b2,47,2c,28,e4,4f,ef,46,ac,84,ce,d1,d5,3d,0d,1c,a6,6f,93,f0,a0,bd,cc,\
"rkeysecu"=hex:50,a5,06,39,4f,f0,93,86,ca,94,a3,a1,d0,bc,c4,b5
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.14"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-09-05 12:07:26
ComboFix-quarantined-files.txt 2014-09-05 10:07
.
Před spuštěním: Volných bajtů: 63 377 924 096
Po spuštění: Volných bajtů: 62 994 194 432
.
- - End Of File - - 62E458BD13C9A091B12068A4B99DE371

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: problem s prohlizecem(reklamy)

#8 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    File::
    c:\windows\Tasks\Adobe Flash Player Updater.job
    c:\windows\SysWow64\FAP319.tmp
    c:\windows\SysWow64\FAP8447.tmp
    c:\windows\SysWow64\FAP416C.tmp
    c:\windows\SysWow64\FAP1E60.tmp
    c:\windows\SysWow64\FAPFA0C.tmp
    c:\windows\SysWow64\FAPF13.tmp
    c:\windows\SysWow64\FAP7967.tmp
    c:\windows\SysWow64\FAP3D86.tmp
    c:\windows\SysWow64\FAP300D.tmp
    c:\windows\SysWow64\FAP8A69.tmp
    
    Folder::
    c:\users\Erutan\AppData\Roaming\uSihUgkD
    c:\users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate
    
    Collect::
    c:\users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate\logagent.exe
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "uTorrent"=-
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "Run"=-
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
    "Adobe ARM"=
    
    RegNull::
    [HKEY_USERS\S-1-5-21-1926684632-688041120-732502126-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    [HKEY_USERS\S-1-5-21-1926684632-688041120-732502126-1000\Software\SecuROM\License information*]
    
    RegLock::
    [HKEY_USERS\S-1-5-21-1926684632-688041120-732502126-1000\Software\Microsoft\Internet Explorer\Approved Extensions]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Erutan
Návštěvník
Návštěvník
Příspěvky: 133
Registrován: 16 čer 2008 18:51

Re: problem s prohlizecem(reklamy)

#9 Příspěvek od Erutan »

ComboFix 14-09-05.01 - Erutan 05.09.2014 23:03:32.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.8189.6671 [GMT 2:00]
Spuštěný z: c:\users\Erutan\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Erutan\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\SysWow64\FAP1E60.tmp"
"c:\windows\SysWow64\FAP300D.tmp"
"c:\windows\SysWow64\FAP319.tmp"
"c:\windows\SysWow64\FAP3D86.tmp"
"c:\windows\SysWow64\FAP416C.tmp"
"c:\windows\SysWow64\FAP7967.tmp"
"c:\windows\SysWow64\FAP8447.tmp"
"c:\windows\SysWow64\FAP8A69.tmp"
"c:\windows\SysWow64\FAPF13.tmp"
"c:\windows\SysWow64\FAPFA0C.tmp"
"c:\windows\Tasks\Adobe Flash Player Updater.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Erutan\AppData\Roaming\Microsoft\Windows\IEUpdate
c:\users\Erutan\AppData\Roaming\uSihUgkD
c:\users\Erutan\AppData\Roaming\uSihUgkD\jaEdCvwW\rqrumxFQ\mdiFFpMMv.exe
c:\windows\SysWow64\FAP1E60.tmp
c:\windows\SysWow64\FAP300D.tmp
c:\windows\SysWow64\FAP319.tmp
c:\windows\SysWow64\FAP3D86.tmp
c:\windows\SysWow64\FAP416C.tmp
c:\windows\SysWow64\FAP7967.tmp
c:\windows\SysWow64\FAP8447.tmp
c:\windows\SysWow64\FAP8A69.tmp
c:\windows\SysWow64\FAPF13.tmp
c:\windows\SysWow64\FAPFA0C.tmp
c:\windows\Tasks\Adobe Flash Player Updater.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-05 do 2014-09-05 )))))))))))))))))))))))))))))))
.
.
2014-09-05 08:18 . 2014-09-05 21:06 -------- d-----w- c:\users\Erutan\AppData\Local\Temp
2014-09-05 08:17 . 2014-09-05 08:17 -------- d-----w- C:\AdwCleaner
2014-09-05 07:27 . 2014-09-05 07:27 -------- d-----w- C:\rsit
2014-09-05 07:21 . 2014-09-05 07:21 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-09-02 20:43 . 2014-09-02 20:43 -------- d-----w- c:\users\Erutan\AppData\Roaming\WebExtend
2014-08-27 11:06 . 2014-08-27 11:06 -------- d-----w- c:\users\Erutan\AppData\Local\Aspyr
2014-08-26 15:50 . 2014-08-26 15:50 -------- d-----w- c:\users\Erutan\AppData\Roaming\2K Sports
2014-08-25 11:12 . 2014-08-25 11:12 -------- d-----w- c:\users\Erutan\AppData\Local\Adobe
2014-08-24 17:49 . 2014-08-24 17:49 -------- d-----w- c:\users\Erutan\AppData\Roaming\Disney Interactive Studios
2014-08-19 16:37 . 2014-08-19 16:37 -------- d-----w- c:\users\Erutan\AppData\Roaming\.mono
2014-08-19 16:37 . 2014-08-19 16:37 -------- d-----w- c:\users\Erutan\AppData\Roaming\Steam
2014-08-16 18:00 . 2014-08-16 18:00 -------- d-----w- c:\programdata\McAfee
2014-08-16 12:49 . 2014-08-16 12:49 -------- d-----w- c:\program files (x86)\SopCast
2014-08-15 08:31 . 2014-08-15 08:31 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2014-08-09 14:11 . 2014-08-09 14:11 -------- d-----w- c:\users\Erutan\AppData\Local\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-05 21:06 . 2013-07-14 13:54 25640 ----a-w- c:\windows\gdrv.sys
2014-08-16 18:00 . 2013-07-14 17:16 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-08-16 18:00 . 2013-07-14 17:16 699568 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-07-20 09:15 . 2014-01-22 16:04 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2014-07-20 09:15 . 2014-01-22 16:04 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2014-07-20 09:15 . 2014-01-22 16:04 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2014-07-20 09:15 . 2014-01-22 16:04 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2014-07-19 17:35 . 2014-07-17 19:53 298032 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-07-19 17:35 . 2013-07-14 16:05 298032 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-07-19 14:37 . 2014-07-17 19:53 298032 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-07-17 19:53 . 2014-07-17 19:53 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"uTorrent"="c:\users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe" [2014-07-02 1322832]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-03-28 642656]
.
c:\users\Erutan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
µTorrent.lnk - c:\users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe [2013-7-14 1322832]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 AODDriver;AODDriver;c:\program files (x86)\Gigabyte\ET6\amd64\AODDriver.sys;c:\program files (x86)\Gigabyte\ET6\amd64\AODDriver.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
S0 RzFilter;RzFilter;c:\windows\system32\drivers\RzFilter.sys;c:\windows\SYSNATIVE\drivers\RzFilter.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 ES lite Service;ES lite Service for program management.;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE [x]
S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe;c:\windows\SysWOW64\XSrvSetup.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver;c:\windows\system32\DRIVERS\Rtnic64.sys;c:\windows\SYSNATIVE\DRIVERS\Rtnic64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-10-06 11474024]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-10 - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Celkový čas: 2014-09-05 23:07:45 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-09-05 21:07
ComboFix2.txt 2014-09-05 10:07
.
Před spuštěním: Volných bajtů: 63 350 276 096
Po spuštění: Volných bajtů: 63 242 997 760
.
- - End Of File - - 7DF3393132EEB24EAA77A914EC548296

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: problem s prohlizecem(reklamy)

#10 Příspěvek od vyosek »

Jak se chova PC???
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Erutan
Návštěvník
Návštěvník
Příspěvky: 133
Registrován: 16 čer 2008 18:51

Re: problem s prohlizecem(reklamy)

#11 Příspěvek od Erutan »

zadna zmena :( zde je foto ale omlouvam se ze je otocene. udelal jsem to aby se to vlezlo a zstalo v lepsi kvalite :)
Bez názvu.png
Bez názvu.png (306.96 KiB) Zobrazeno 1750 x

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: problem s prohlizecem(reklamy)

#12 Příspěvek od vyosek »

:arrow: Problem je jen ve Firefoxu??

:arrow: Dejte FRST http://forum.viry.cz/viewtopic.php?f=13&t=133100
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Erutan
Návštěvník
Návštěvník
Příspěvky: 133
Registrován: 16 čer 2008 18:51

Re: problem s prohlizecem(reklamy)

#13 Příspěvek od Erutan »

ano v mozile firefox :(
Addition.rar
(8.13 KiB) Staženo 39 x
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-09-2014
Ran by Erutan (administrator) on ERUTAN-PC on 06-09-2014 11:37:55
Running from C:\Users\Erutan\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 8
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
() C:\Program Files (x86)\Gigabyte\EasySaver\essvr.exe
() C:\Windows\SysWOW64\XSrvSetup.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Almico Software (http://www.almico.com)) C:\Program Files (x86)\SpeedFan\speedfan.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(BitTorrent Inc.) C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe
(NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe
(forum.viry.cz) C:\Users\Erutan\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11474024 2010-10-06] (Realtek Semiconductor)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [JMB36X IDE Setup] => C:\Windows\RaidTool\xInsIDE.exe [43608 2010-09-07] ()
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2009-11-20] (NEC Electronics Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-1926684632-688041120-732502126-1000\...\Run: [uTorrent] => C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe [1322832 2014-07-02] (BitTorrent Inc.)
Startup: C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\µTorrent.lnk
ShortcutTarget: µTorrent.lnk -> C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/s ... wflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.3.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Erutan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppluginrichmediaplayer.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Settings Manager - C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\Extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7} [2014-05-04]
FF Extension: Website Tipster - C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\Extensions\{bda388db-b4e9-4193-b83a-bca1947df5c3} [2014-09-02]
FF Extension: Adblock Plus - C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-07-14]

Chrome:
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-28] (Advanced Micro Devices, Inc.) [File not signed]
R2 ES lite Service; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [68136 2009-08-24] ()
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [72280 2010-09-07] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-07-17] ()
S3 TuneUp.Defrag; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [607048 2013-07-14] (TuneUp Software)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 AODDriver; C:\Program Files (x86)\Gigabyte\ET6\amd64\AODDriver.sys [52280 2010-03-12] (Advanced Micro Devices)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21544 2010-04-27] ()
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-07-14] ()
R3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [51712 2009-06-10] (Realtek Semiconductor Corporation )
R0 RzFilter; C:\Windows\System32\drivers\RzFilter.sys [74456 2013-07-31] (Razer USA Ltd)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2013-07-14] () [File not signed]
U3 a6ak1wwf; C:\Windows\System32\Drivers\a6ak1wwf.sys [0 ] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-06 11:37 - 2014-09-06 11:38 - 00009578 _____ () C:\Users\Erutan\Desktop\FRST.txt
2014-09-06 11:37 - 2014-09-06 11:37 - 00000000 ____D () C:\FRST
2014-09-06 11:36 - 2014-09-06 11:36 - 02104832 _____ (Farbar) C:\Users\Erutan\Desktop\FRST64.exe
2014-09-06 11:36 - 2014-09-06 11:36 - 00112640 _____ (forum.viry.cz) C:\Users\Erutan\Desktop\FRSTLauncher.exe
2014-09-06 10:06 - 2014-09-06 10:06 - 00000168 _____ () C:\Windows\setupact.log
2014-09-06 10:06 - 2014-09-06 10:06 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-06 00:49 - 2014-09-06 00:49 - 00018511 _____ () C:\Windows\DirectX.log
2014-09-05 23:07 - 2014-09-05 23:07 - 00011829 _____ () C:\ComboFix.txt
2014-09-05 12:02 - 2014-09-05 23:07 - 00000000 ____D () C:\Qoobox
2014-09-05 12:02 - 2014-09-05 23:06 - 00000000 ____D () C:\Windows\erdnt
2014-09-05 12:02 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-05 12:02 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-05 12:02 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-05 12:02 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-05 12:02 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-05 12:02 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-05 12:02 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-05 12:02 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-05 12:01 - 2014-09-05 12:01 - 05576440 ____R (Swearware) C:\Users\Erutan\Desktop\ComboFix.exe
2014-09-05 11:59 - 2014-09-05 11:59 - 00002198 _____ () C:\Users\Erutan\Desktop\Rkill.txt
2014-09-05 10:17 - 2014-09-05 10:17 - 00000000 ____D () C:\AdwCleaner
2014-09-05 09:27 - 2014-09-05 09:27 - 00000000 ____D () C:\rsit
2014-09-05 09:21 - 2014-09-05 09:21 - 00001168 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-05 09:21 - 2014-09-05 09:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-04 08:47 - 2014-09-05 11:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-02 22:43 - 2014-09-02 22:43 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\WebExtend
2014-09-02 10:27 - 2014-09-02 10:45 - 00000000 ____D () C:\Users\Erutan\Documents\Assetto Corsa
2014-08-27 13:06 - 2014-08-27 13:06 - 00000000 ____D () C:\Users\Erutan\AppData\Local\Aspyr
2014-08-26 17:50 - 2014-08-26 17:50 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\2K Sports
2014-08-26 16:44 - 2014-08-26 16:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mortal Kombat Komplete Edition
2014-08-25 13:12 - 2014-08-25 13:12 - 00000000 ____D () C:\Users\Erutan\AppData\Local\Adobe
2014-08-24 19:49 - 2014-08-24 19:49 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\Disney Interactive Studios
2014-08-24 19:43 - 2014-08-27 20:31 - 00000159 _____ () C:\Windows\disney.ini
2014-08-19 18:37 - 2014-08-19 18:37 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\Steam
2014-08-19 18:37 - 2014-08-19 18:37 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\.mono
2014-08-19 15:20 - 2014-09-06 11:33 - 00116227 _____ () C:\Windows\WindowsUpdate.log
2014-08-17 17:21 - 2014-08-17 17:23 - 00000000 ____D () C:\Users\Erutan\Documents\SHIFT 2 UNLEASHED
2014-08-16 20:00 - 2014-08-16 20:00 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-16 14:50 - 2014-08-16 14:50 - 00003050 _____ () C:\Windows\System32\Tasks\{5F8C6D1C-6432-0ACB-1460-F1105E087B6F}
2014-08-16 14:49 - 2014-08-16 14:49 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SopCast
2014-08-16 14:49 - 2014-08-16 14:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast
2014-08-16 14:49 - 2014-08-16 14:49 - 00000000 ____D () C:\Program Files (x86)\SopCast
2014-08-15 10:36 - 2014-08-27 13:06 - 00000000 ____D () C:\Users\Erutan\Documents\Aspyr
2014-08-15 10:31 - 2014-08-15 10:31 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-08-09 16:11 - 2014-08-09 16:11 - 00000000 ____D () C:\Users\Erutan\AppData\Local\Skype
2014-08-09 16:11 - 2014-08-09 16:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-06 11:38 - 2014-09-06 11:37 - 00009578 _____ () C:\Users\Erutan\Desktop\FRST.txt
2014-09-06 11:37 - 2014-09-06 11:37 - 00000000 ____D () C:\FRST
2014-09-06 11:37 - 2013-07-14 16:17 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\uTorrent
2014-09-06 11:36 - 2014-09-06 11:36 - 02104832 _____ (Farbar) C:\Users\Erutan\Desktop\FRST64.exe
2014-09-06 11:36 - 2014-09-06 11:36 - 00112640 _____ (forum.viry.cz) C:\Users\Erutan\Desktop\FRSTLauncher.exe
2014-09-06 11:33 - 2014-08-19 15:20 - 00116227 _____ () C:\Windows\WindowsUpdate.log
2014-09-06 10:13 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-06 10:13 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-06 10:06 - 2014-09-06 10:06 - 00000168 _____ () C:\Windows\setupact.log
2014-09-06 10:06 - 2014-09-06 10:06 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-06 10:06 - 2014-04-12 09:14 - 00000000 ____D () C:\Program Files (x86)\SpeedFan
2014-09-06 10:06 - 2014-02-03 00:16 - 00000144 _____ () C:\service.log
2014-09-06 10:06 - 2013-07-14 15:54 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2014-09-06 10:06 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-06 02:08 - 2014-05-09 19:25 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\vlc
2014-09-06 00:51 - 2013-12-19 16:00 - 00000000 ____D () C:\Users\Erutan\AppData\Local\CrashDumps
2014-09-06 00:49 - 2014-09-06 00:49 - 00018511 _____ () C:\Windows\DirectX.log
2014-09-06 00:49 - 2014-07-20 11:43 - 00000000 ___RD () C:\Users\Erutan\Desktop\Games
2014-09-06 00:45 - 2013-08-24 09:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hry
2014-09-06 00:45 - 2013-07-14 16:06 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\DAEMON Tools Lite
2014-09-06 00:43 - 2013-07-16 19:23 - 00000000 ____D () C:\Users\Erutan\Documents\My Games
2014-09-05 23:07 - 2014-09-05 23:07 - 00011829 _____ () C:\ComboFix.txt
2014-09-05 23:07 - 2014-09-05 12:02 - 00000000 ____D () C:\Qoobox
2014-09-05 23:06 - 2014-09-05 12:02 - 00000000 ____D () C:\Windows\erdnt
2014-09-05 23:06 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-09-05 12:07 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-09-05 12:01 - 2014-09-05 12:01 - 05576440 ____R (Swearware) C:\Users\Erutan\Desktop\ComboFix.exe
2014-09-05 11:59 - 2014-09-05 11:59 - 00002198 _____ () C:\Users\Erutan\Desktop\Rkill.txt
2014-09-05 11:57 - 2014-09-04 08:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-05 10:17 - 2014-09-05 10:17 - 00000000 ____D () C:\AdwCleaner
2014-09-05 09:27 - 2014-09-05 09:27 - 00000000 ____D () C:\rsit
2014-09-05 09:27 - 2014-05-04 13:20 - 00000000 ____D () C:\Program Files\trend micro
2014-09-05 09:21 - 2014-09-05 09:21 - 00001168 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-05 09:21 - 2014-09-05 09:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-04 11:58 - 2013-07-14 16:34 - 00000000 ____D () C:\ProgramData\Origin
2014-09-04 10:31 - 2013-12-02 23:17 - 00000000 ____D () C:\Users\Erutan\Documents\FIFA 14
2014-09-04 09:54 - 2013-07-14 16:34 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-09-03 07:24 - 2013-07-14 16:29 - 00000000 ____D () C:\Program Files (x86)\The KMPlayer
2014-09-02 22:43 - 2014-09-02 22:43 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\WebExtend
2014-09-02 11:00 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-09-02 10:45 - 2014-09-02 10:27 - 00000000 ____D () C:\Users\Erutan\Documents\Assetto Corsa
2014-09-01 10:27 - 2013-08-24 09:50 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-09-01 10:00 - 2013-07-14 18:20 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\Skype
2014-08-31 18:51 - 2014-04-29 12:11 - 00000000 ____D () C:\Users\Erutan\Documents\Telltale Games
2014-08-27 20:31 - 2014-08-24 19:43 - 00000159 _____ () C:\Windows\disney.ini
2014-08-27 20:31 - 2013-07-14 15:47 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-08-27 13:06 - 2014-08-27 13:06 - 00000000 ____D () C:\Users\Erutan\AppData\Local\Aspyr
2014-08-27 13:06 - 2014-08-15 10:36 - 00000000 ____D () C:\Users\Erutan\Documents\Aspyr
2014-08-26 17:50 - 2014-08-26 17:50 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\2K Sports
2014-08-26 16:44 - 2014-08-26 16:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mortal Kombat Komplete Edition
2014-08-26 16:07 - 2013-12-14 18:10 - 00000000 ____D () C:\Users\Erutan\AppData\Local\PMB Files
2014-08-26 16:07 - 2013-12-14 18:10 - 00000000 ____D () C:\ProgramData\PMB Files
2014-08-25 13:12 - 2014-08-25 13:12 - 00000000 ____D () C:\Users\Erutan\AppData\Local\Adobe
2014-08-24 19:49 - 2014-08-24 19:49 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\Disney Interactive Studios
2014-08-19 18:37 - 2014-08-19 18:37 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\Steam
2014-08-19 18:37 - 2014-08-19 18:37 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\.mono
2014-08-17 17:23 - 2014-08-17 17:21 - 00000000 ____D () C:\Users\Erutan\Documents\SHIFT 2 UNLEASHED
2014-08-16 20:54 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\Offline Web Pages
2014-08-16 20:00 - 2014-08-16 20:00 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-16 20:00 - 2013-11-27 12:17 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-16 20:00 - 2013-07-14 19:16 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-16 20:00 - 2013-07-14 19:16 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-16 14:50 - 2014-08-16 14:50 - 00003050 _____ () C:\Windows\System32\Tasks\{5F8C6D1C-6432-0ACB-1460-F1105E087B6F}
2014-08-16 14:49 - 2014-08-16 14:49 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SopCast
2014-08-16 14:49 - 2014-08-16 14:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast
2014-08-16 14:49 - 2014-08-16 14:49 - 00000000 ____D () C:\Program Files (x86)\SopCast
2014-08-15 10:31 - 2014-08-15 10:31 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-08-13 10:55 - 2013-07-16 19:23 - 00000000 ____D () C:\Users\Erutan\AppData\Local\SKIDROW
2014-08-13 08:53 - 2014-05-09 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-08-13 08:30 - 2013-07-15 14:34 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\dvdcss
2014-08-11 11:23 - 2014-05-03 10:12 - 00000000 ____D () C:\ProgramData\Codemasters
2014-08-10 15:43 - 2014-02-27 11:58 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-09 16:11 - 2014-08-09 16:11 - 00000000 ____D () C:\Users\Erutan\AppData\Local\Skype
2014-08-09 16:11 - 2014-08-09 16:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-09 16:11 - 2013-07-14 18:20 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-08-09 16:11 - 2013-07-14 18:20 - 00000000 ____D () C:\ProgramData\Skype
2014-08-08 23:15 - 2014-07-13 21:53 - 00000000 ____D () C:\Users\Erutan\Documents\CAPCOM
2014-08-07 17:50 - 2013-12-29 02:49 - 00000000 ____D () C:\Windows\Minidump
2014-08-07 15:38 - 2013-10-20 18:10 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\ViberPC
2014-08-07 15:38 - 2013-10-20 18:09 - 00000000 ____D () C:\Users\Erutan\AppData\Local\Viber

Some content of TEMP:
====================
C:\Users\Erutan\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Erutan\AppData\Local\Temp\sfareca00001.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-02 09:45




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: (Systemovy) (Fixed) (Total:111.79 GB) (Free:59.77 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Datovy) (Fixed) (Total:931.41 GB) (Free:376 GB) NTFS
Drive e: (Video) (Fixed) (Total:1863.01 GB) (Free:452.75 GB) NTFS
Drive f: (Hry) (Fixed) (Total:111.79 GB) (Free:82.65 GB) NTFS

Available physical RAM: 6389.14 MB
Total physical RAM: 8188.52 MB
Percentage of memory in use: 21%

==================== MBR and Partition Table ==================

Disk: 0 (Size: 111.8 GB) (Disk ID: C06AC06A)
Partition 1: (Not Active) - (Size=111.8 GB) - (Type=07 NTFS)
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 60F765CF)
Partition 1: (Active) - (Size=111.8 GB) - (Type=07 NTFS)
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 5BD7BB9E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
Disk: 3 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: EB571E53)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================


==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:DocumentSummaryInformation
AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:SummaryInformation
AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

==================== Security Center ==================

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Erutan\Desktop" je 7 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: problem s prohlizecem(reklamy)

#14 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKU\S-1-5-21-1926684632-688041120-732502126-1000\...\Run: [uTorrent] => C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe [1322832 2014-07-02] (BitTorrent Inc.)
    
    FF Extension: Settings Manager - C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\Extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7} [2014-05-04]
    FF Extension: Website Tipster - C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\Extensions\{bda388db-b4e9-4193-b83a-bca1947df5c3} [2014-09-02]
    
    S3 catchme; \??\C:\ComboFix\catchme.sys [X]
    S3 VGPU; System32\drivers\rdvgkmd.sys [X]
    
    2014-09-06 11:37 - 2014-09-06 11:38 - 00009578 _____ () C:\Users\Erutan\Desktop\FRST.txt
    2014-09-06 11:36 - 2014-09-06 11:36 - 00112640 _____ (forum.viry.cz) C:\Users\Erutan\Desktop\FRSTLauncher.exe
    2014-09-06 10:06 - 2014-09-06 10:06 - 00000168 _____ () C:\Windows\setupact.log
    2014-09-06 10:06 - 2014-09-06 10:06 - 00000000 _____ () C:\Windows\setuperr.log
    2014-09-06 00:49 - 2014-09-06 00:49 - 00018511 _____ () C:\Windows\DirectX.log
    2014-09-05 23:07 - 2014-09-05 23:07 - 00011829 _____ () C:\ComboFix.txt
    2014-09-05 11:59 - 2014-09-05 11:59 - 00002198 _____ () C:\Users\Erutan\Desktop\Rkill.txt
    2014-09-05 10:17 - 2014-09-05 10:17 - 00000000 ____D () C:\AdwCleaner
    2014-09-05 09:27 - 2014-09-05 09:27 - 00000000 ____D () C:\rsit
    2014-09-02 22:43 - 2014-09-02 22:43 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\WebExtend
    
    AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:DocumentSummaryInformation
    AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:SummaryInformation
    AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
    
    Hosts:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Erutan
Návštěvník
Návštěvník
Příspěvky: 133
Registrován: 16 čer 2008 18:51

Re: problem s prohlizecem(reklamy)

#15 Příspěvek od Erutan »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 06-09-2014
Ran by Erutan at 2014-09-06 12:43:01 Run:1
Running from C:\Users\Erutan\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKU\S-1-5-21-1926684632-688041120-732502126-1000\...\Run: [uTorrent] => C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe [1322832 2014-07-02] (BitTorrent Inc.)

FF Extension: Settings Manager - C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\Extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7} [2014-05-04]
FF Extension: Website Tipster - C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\Extensions\{bda388db-b4e9-4193-b83a-bca1947df5c3} [2014-09-02]

S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

2014-09-06 11:37 - 2014-09-06 11:38 - 00009578 _____ () C:\Users\Erutan\Desktop\FRST.txt
2014-09-06 11:36 - 2014-09-06 11:36 - 00112640 _____ (forum.viry.cz) C:\Users\Erutan\Desktop\FRSTLauncher.exe
2014-09-06 10:06 - 2014-09-06 10:06 - 00000168 _____ () C:\Windows\setupact.log
2014-09-06 10:06 - 2014-09-06 10:06 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-06 00:49 - 2014-09-06 00:49 - 00018511 _____ () C:\Windows\DirectX.log
2014-09-05 23:07 - 2014-09-05 23:07 - 00011829 _____ () C:\ComboFix.txt
2014-09-05 11:59 - 2014-09-05 11:59 - 00002198 _____ () C:\Users\Erutan\Desktop\Rkill.txt
2014-09-05 10:17 - 2014-09-05 10:17 - 00000000 ____D () C:\AdwCleaner
2014-09-05 09:27 - 2014-09-05 09:27 - 00000000 ____D () C:\rsit
2014-09-02 22:43 - 2014-09-02 22:43 - 00000000 ____D () C:\Users\Erutan\AppData\Roaming\WebExtend

AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:DocumentSummaryInformation
AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:SummaryInformation
AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

Hosts:
Reboot:
End
*****************

HKU\S-1-5-21-1926684632-688041120-732502126-1000\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent => value deleted successfully.
C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\Extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7} => Moved successfully.
C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\Extensions\{bda388db-b4e9-4193-b83a-bca1947df5c3} => Moved successfully.
catchme => Service deleted successfully.
VGPU => Service deleted successfully.
C:\Users\Erutan\Desktop\FRST.txt => Moved successfully.
C:\Users\Erutan\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\Windows\DirectX.log => Moved successfully.
C:\ComboFix.txt => Moved successfully.
"C:\Users\Erutan\Desktop\Rkill.txt" => File/Directory not found.
C:\AdwCleaner => Moved successfully.
C:\rsit => Moved successfully.
C:\Users\Erutan\AppData\Roaming\WebExtend => Moved successfully.
C:\Windows\SysWOW64\zlib.dll => ":DocumentSummaryInformation" ADS removed successfully.
C:\Windows\SysWOW64\zlib.dll => ":SummaryInformation" ADS removed successfully.
C:\Windows\SysWOW64\zlib.dll => ":{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.


The system needed a reboot.

==== End of Fixlog ====

Zamčeno