Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Zavirovany notebook

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
zima
1. Stupeň Varování
Příspěvky: 66
Registrován: 15 říj 2008 20:21

Zavirovany notebook

#1 Příspěvek od zima »

Dobrý den, přítelkyně ma ntb a když si pustí prohlížeč tak jí tam vyskakujou reklamy na erekci atd....
Mohl by jste se mi na to prosím podívat :)

Děkuji moc
PS:log byl prilis dlouhy tak jsem ho nahral na ulozto

Tady je url: http://ulozto.cz/xGR7NQXT/log-txt
heslo:forum

Dekuji moc :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Zavirovany notebook

#2 Příspěvek od Rudy »

Zdravím!
Spusťte nejprve tuto utilitu:

Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

zima
1. Stupeň Varování
Příspěvky: 66
Registrován: 15 říj 2008 20:21

Re: Zavirovany notebook

#3 Příspěvek od zima »

# AdwCleaner v3.309 - Report created 09/09/2014 at 16:54:12
# Updated 02/09/2014 by Xplode
# Operating System : Windows 8.1 Pro (64 bits)
# Username : Adriana - ADRIANA
# Running from : C:\Users\Adriana\Desktop\adwcleaner_3.309.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : 1a34a8e0
[#] Service Deleted : BackupStack
Service Deleted : d0e87c27

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Conduit
Folder Deleted : C:\ProgramData\NewSaVer
Folder Deleted : C:\ProgramData\SNT
Folder Deleted : C:\ProgramData\topapp soft
Folder Deleted : C:\ProgramData\BestSavaeForiYouu
Folder Deleted : C:\ProgramData\DigoiCoUpon
Folder Deleted : C:\ProgramData\GGreatSavve4U
Folder Deleted : C:\ProgramData\NEwSaveerr
Folder Deleted : C:\ProgramData\sAve on
Folder Deleted : C:\ProgramData\YoutubeAdblocker
Folder Deleted : C:\Program Files (x86)\BS_Player_ControlBar
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\MyPC Backup
Folder Deleted : C:\Program Files (x86)\SNT
Folder Deleted : C:\Program Files (x86)\sw-booster
Folder Deleted : C:\Program Files (x86)\sAve on
Folder Deleted : C:\Program Files (x86)\YoutubeAdblocker
Folder Deleted : C:\Users\Administrator\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Adriana\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Adriana\AppData\Local\Conduit
Folder Deleted : C:\Users\Adriana\AppData\Local\torch
Folder Deleted : C:\Users\Adriana\AppData\Local\Temp\BS_Player_ControlBar
Folder Deleted : C:\Users\Adriana\AppData\LocalLow\BS_Player_ControlBar
Folder Deleted : C:\Users\Adriana\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Adriana\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Adriana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Folder Deleted : C:\Users\Guest\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
Folder Deleted : C:\Users\Adriana\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
Folder Deleted : C:\Users\Adriana\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
[!] Folder Deleted : C:\Users\Adriana\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
[!] Folder Deleted : C:\Users\Adriana\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
Folder Deleted : C:\Users\Adriana\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdojbbpbnnlgnkegkecdcgpjfllppdap
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
[!] Folder Deleted : C:\Users\Adriana\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
[!] Folder Deleted : C:\Users\Adriana\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
[!] Folder Deleted : C:\Users\Adriana\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\eohlfpmfnnacabcdolnfhjmkehoilohp
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
[!] Folder Deleted : C:\Users\Adriana\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbfnpjfafdhdedjpilpmgihoghkkkfjl
File Deleted : C:\END
File Deleted : C:\Program Files (x86)\Assistant.dll
File Deleted : C:\Program Files (x86)\AssistantSvc.dll
File Deleted : C:\Users\Adriana\AppData\Roaming\LiveSupport.exe_log.txt
File Deleted : C:\Users\Adriana\AppData\Roaming\regsvr32.exe_log.txt
File Deleted : C:\Users\Adriana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
File Deleted : C:\Users\Adriana\Desktop\MyPC Backup.lnk

***** [ Scheduled Tasks ] *****

Task Deleted : SW-Booster-S-698646803
Task Deleted : Upd Inst-S-5029066965

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\conduit.com
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BackgroundContainerV2]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [livesupport]
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Key Deleted : HKLM\SOFTWARE\Classes\DIegiCouponu.DIegiCouponu
Key Deleted : HKLM\SOFTWARE\Classes\DIegiCouponu.DIegiCouponu.5.3
Key Deleted : HKLM\SOFTWARE\Classes\NewSaver.NewSaver
Key Deleted : HKLM\SOFTWARE\Classes\NewSaver.NewSaver.1.1
Key Deleted : HKLM\SOFTWARE\Classes\GreateSSaavve4U.GreateSSaavve4U
Key Deleted : HKLM\SOFTWARE\Classes\GreateSSaavve4U.GreateSSaavve4U.2.3
Key Deleted : HKLM\SOFTWARE\Classes\NewSaveir.NewSaveir
Key Deleted : HKLM\SOFTWARE\Classes\NewSaveir.NewSaveir.1.1
Key Deleted : HKLM\SOFTWARE\Classes\BestSaveFeoirYooua.BestSaveFeoirYooua
Key Deleted : HKLM\SOFTWARE\Classes\BestSaveFeoirYooua.BestSaveFeoirYooua.2.3
Key Deleted : HKLM\SOFTWARE\Classes\YoutubeAdblocker.YoutubeAdblocker
Key Deleted : HKLM\SOFTWARE\Classes\YoutubeAdblocker.YoutubeAdblocker.1.0
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IECT1750559
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-5029066965
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-698646803
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{1a34a8e0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1750559
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{160CE145-593B-78BA-6913-FD0A637C8DC8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{55454320-DF87-F8F7-5B18-6D397C3EA709}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{719E3AB1-500E-F5D4-EE6D-CF78C65BE583}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7EB34337-E9BB-D7A0-7748-85CCC3DED535}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9B3EF75F-37E8-1970-461F-2D8CF4111314}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EAACBEC1-DD1D-12A6-7095-C6D45E092FDD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F8AADEB8-E563-077C-4A94-33DC0CB70034}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{055DD326-956C-4827-9467-A172509E81B3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{160CE145-593B-78BA-6913-FD0A637C8DC8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{55454320-DF87-F8F7-5B18-6D397C3EA709}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{719E3AB1-500E-F5D4-EE6D-CF78C65BE583}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7EB34337-E9BB-D7A0-7748-85CCC3DED535}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9B3EF75F-37E8-1970-461F-2D8CF4111314}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EAACBEC1-DD1D-12A6-7095-C6D45E092FDD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F8AADEB8-E563-077C-4A94-33DC0CB70034}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EAACBEC1-DD1D-12A6-7095-C6D45E092FDD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F8AADEB8-E563-077C-4A94-33DC0CB70034}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EAACBEC1-DD1D-12A6-7095-C6D45E092FDD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F8AADEB8-E563-077C-4A94-33DC0CB70034}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{160CE145-593B-78BA-6913-FD0A637C8DC8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{55454320-DF87-F8F7-5B18-6D397C3EA709}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{719E3AB1-500E-F5D4-EE6D-CF78C65BE583}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7EB34337-E9BB-D7A0-7748-85CCC3DED535}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9B3EF75F-37E8-1970-461F-2D8CF4111314}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EAACBEC1-DD1D-12A6-7095-C6D45E092FDD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F8AADEB8-E563-077C-4A94-33DC0CB70034}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{055DD326-956C-4827-9467-A172509E81B3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{73FDC044-0F58-432D-8E98-1D4E09E213F4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{244386E7-9510-42A4-A9A6-C7E830BC638D}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{160CE145-593B-78BA-6913-FD0A637C8DC8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{55454320-DF87-F8F7-5B18-6D397C3EA709}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{719E3AB1-500E-F5D4-EE6D-CF78C65BE583}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{7EB34337-E9BB-D7A0-7748-85CCC3DED535}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{9B3EF75F-37E8-1970-461F-2D8CF4111314}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{EAACBEC1-DD1D-12A6-7095-C6D45E092FDD}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{F8AADEB8-E563-077C-4A94-33DC0CB70034}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{160CE145-593B-78BA-6913-FD0A637C8DC8}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{55454320-DF87-F8F7-5B18-6D397C3EA709}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{719E3AB1-500E-F5D4-EE6D-CF78C65BE583}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7EB34337-E9BB-D7A0-7748-85CCC3DED535}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9B3EF75F-37E8-1970-461F-2D8CF4111314}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EAACBEC1-DD1D-12A6-7095-C6D45E092FDD}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F8AADEB8-E563-077C-4A94-33DC0CB70034}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\Tbccint_HKLM
Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\BS_Player_ControlBar
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\SW-Booster
Key Deleted : HKLM\SOFTWARE\Upd Inst
Key Deleted : HKLM\SOFTWARE\BS_Player_ControlBar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{45606A90-3363-3A3B-1C15-C40E77F4DAA0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6A08B379-76FB-B4CF-0C70-CAFCD3635A77}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{993EA8F6-6E55-7E4E-39DE-5796E3226DB9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CE94DD89-7404-B4B9-E713-E55CC0AB6C3B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F6A71DC7-28F4-C6C7-8FA9-8A56C80FC96A}
Key Deleted : [x64] HKLM\SOFTWARE\Speedchecker Limited
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\assist~1.dll
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\ASSIST~2.DLL

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17239

Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

-\\ Google Chrome v35.0.1916.114

[ File : C:\Users\Adriana\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Startup_urls] : hxxp://search.gboxapp.com/
Deleted [Extension] : eohlfpmfnnacabcdolnfhjmkehoilohp
Deleted [Extension] : hbfnpjfafdhdedjpilpmgihoghkkkfjl
Deleted [Extension] : jdojbbpbnnlgnkegkecdcgpjfllppdap

*************************

AdwCleaner[R0].txt - [19747 octets] - [09/09/2014 16:51:50]
AdwCleaner[R1].txt - [19808 octets] - [09/09/2014 16:53:14]
AdwCleaner[S0].txt - [18509 octets] - [09/09/2014 16:54:12]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [18570 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Zavirovany notebook

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

zima
1. Stupeň Varování
Příspěvky: 66
Registrován: 15 říj 2008 20:21

Re: Zavirovany notebook

#5 Příspěvek od zima »

Tak tady to je, dekuji moc :)

http://ulozto.cz/xNzKQwX8/log-txt

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Zavirovany notebook

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\ProgramData\Iasaver
C:\ProgramData\RoboSavoear
C:\ProgramData\Iasaver

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2AA61131-2CA1-B87E-B3C0-155ECDF98400}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{953CC8BD-6751-F410-DBCE-4E80181BF0D6}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA394458-4BEA-710E-DB06-AD94B804E550}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2AA61131-2CA1-B87E-B3C0-155ECDF98400}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{953CC8BD-6751-F410-DBCE-4E80181BF0D6}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA394458-4BEA-710E-DB06-AD94B804E550}]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

zima
1. Stupeň Varování
Příspěvky: 66
Registrován: 15 říj 2008 20:21

Re: Zavirovany notebook

#7 Příspěvek od zima »


Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Zavirovany notebook

#8 Příspěvek od Rudy »

Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět