Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

vyskakuje Outlookexpress

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Peter251
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 07 led 2014 13:19

vyskakuje Outlookexpress

#1 Příspěvek od Peter251 »

Prosím o pomoc spouští se mi sám od sebe OutlookExpress vše jsem prošel a nikde nenašel možnost vypnutí. Děkuji

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-12-2014 02
Ran by Petr (administrator) on PETER on 07-12-2014 00:00:43
Running from E:\Documents and Settings\Petr\Plocha\nepoužívané odkazy - registrace\Údržba počítače
Loaded Profile: Petr (Available profiles: Petr & Administrator)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 6
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() E:\WINDOWS\system32\ati2evxx.exe
(AVAST Software) E:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Oracle Corporation) E:\Program Files\Java\jre7\bin\jqs.exe
() E:\WINDOWS\system32\PAStiSvc.exe
(Synaptics, Inc.) E:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ATI Technologies, Inc.) E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
(Dritek System Inc.) E:\Program Files\QBU\QtZwLMng.EXE
(Agere Systems) E:\WINDOWS\AGRSMMSG.exe
(Synaptics, Inc.) E:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(CANON INC.) E:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Pinnacle Systems) E:\Program Files\Pinnacle\Shared Files\Programs\Remote\remoterm.exe
(AVAST Software) E:\PROGRA~1\ALWILS~1\Avast5\AvastUI.exe
(Safer-Networking Ltd.) E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
(Microsoft Corporation) E:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
(Microsoft Corporation) E:\Program Files\Messenger\msmsgs.exe
(Pinnacle Systems) E:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
() E:\Program Files\Wireless Device\MulMouse.exe
() E:\Program Files\Wireless Device\Magickey.exe
(Microsoft Corporation) E:\WINDOWS\system32\wbem\unsecapp.exe
(Mozilla Corporation) E:\Program Files\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => E:\Program Files\Synaptics\SynTP\SynTPEnh.exe [610304 2003-04-19] (Synaptics, Inc.)
HKLM\...\Run: [ATIModeChange] => E:\WINDOWS\system32\Ati2mdxx.exe [28672 2001-09-05] (ATI Technologies, Inc.)
HKLM\...\Run: [ATIPTA] => E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [335872 2003-12-12] (ATI Technologies, Inc.)
HKLM\...\Run: [QtZwLMng] => E:\Program Files\QBU\QtZwLMng.EXE [196608 2003-04-03] (Dritek System Inc.)
HKLM\...\Run: [AGRSMMSG] => E:\WINDOWS\AGRSMMSG.exe [88363 2003-11-20] (Agere Systems)
HKLM\...\Run: [PinnacleDriverCheck] => E:\WINDOWS\system32\PSDrvCheck.exe [406016 2004-03-10] ()
HKLM\...\Run: [CanonMyPrinter] => E:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1603152 2007-09-14] (CANON INC.)
HKLM\...\Run: [SynTPLpr] => E:\Program Files\Synaptics\SynTP\SynTPLpr.exe [110592 2003-04-18] (Synaptics, Inc.)
HKLM\...\Run: [PMCRemote] => E:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe [94208 2006-04-27] (Pinnacle Systems)
HKLM\...\Run: [Pinnacle WebUpdater] => E:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe [380928 2006-03-26] (Pinnacle Systems)
HKLM\...\Run: [AvastUI.exe] => E:\Program Files\Alwil Software\Avast5\AvastUI.exe [5225064 2014-11-19] (AVAST Software)
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [SpybotSD TeaTimer] => E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [H/PC Connection Agent] => E:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE [401491 2004-02-03] (Microsoft Corporation)
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [OEXPRESS] => [X]
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [WEBTRAN] => [X]
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [MSMSGS] => E:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [PMCS] => E:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe [65536 2006-04-27] (Pinnacle Systems)
Startup: E:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Povolit bezdrátovou myš.lnk
ShortcutTarget: Povolit bezdrátovou myš.lnk -> E:\Program Files\Wireless Device\MulMouse.exe ()
Startup: E:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Povolit bezdrátovou numerickou klávesnici.lnk
ShortcutTarget: Povolit bezdrátovou numerickou klávesnici.lnk -> E:\Program Files\Wireless Device\Magickey.exe ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => E:\Program Files\Alwil Software\Avast5\ashShell.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Internet Explorer\Main,Vyhledávací stránka = http://www.msn.com/access/allinone.asp
HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... R}&ar=home
URLSearchHook: HKU\S-1-5-21-448539723-839522115-854245398-1004 - Modul přiřazení adres URL - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\WINDOWS\System32\shdocvw.dll (Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "" <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: AcroIEHlprObj Class -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> E:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: WebTransBHO Class -> {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} -> E:\WINDOWS\WebIE.dll ()
BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> E:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: AcroIEToolbarHelper Class -> {AE7CD045-E861-484f-8273-0445EE161910} -> E:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> E:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
Toolbar: HKLM - WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - E:\WINDOWS\WebIE.dll ()
Toolbar: HKU\S-1-5-21-448539723-839522115-854245398-1004 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - E:\WINDOWS\System32\browseui.dll (Společnost Microsoft)
Toolbar: HKU\S-1-5-21-448539723-839522115-854245398-1004 -> Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
DPF: {62789780-B744-11D0-986B-00609731A21D} http://195.28.70.134/kapor2/lib/mgaxctrl.cab
DPF: {672EE252-D813-4F5E-81BB-5DD163DD4FA5} https://www.mojedatovaschranka.cz/stati ... ?3,16,13,0
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash2/cabs/swflash.cab
Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - E:\Program Files\Microsoft ActiveSync\aatp.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.208.10.208 10.208.10.209

FireFox:
========
FF ProfilePath: E:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\u2dhtqv9.default-1411748277773
FF NewTab: https://www.google.cz/?gws_rd=ssl
FF Homepage: https://www.google.cz/?gws_rd=ssl
FF Plugin: @adobe.com/FlashPlayer -> E:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> E:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin -> E:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 -> E:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @software602.cz/602XML Filler -> E:\Program Files\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
FF Plugin: @tools.google.com/Google Update;version=3 -> E:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> E:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=1.1.4 -> E:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF Extension: Java Console - E:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-09-05]
FF Extension: Java Console - E:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-12-10]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - E:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: Avast Online Security - E:\Program Files\Alwil Software\Avast5\WebRep\FF [2013-01-06]
FF HKLM\...\Firefox\Extensions: [quickprint@hp.com] - E:\Program Files\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: HP Smart Print - E:\Program Files\Hewlett-Packard\SmartPrint\QPExtension [2013-09-03]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - e:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - e:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-10-16]

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - E:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2014-11-19]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 602XML Updater; E:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 Ati HotKey Poller; E:\WINDOWS\System32\Ati2evxx.exe [397312 2003-12-12] ()
R2 avast! Antivirus; E:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2014-11-19] (AVAST Software)
R2 JavaQuickStarterService; E:\Program Files\Java\jre7\bin\jqs.exe [161768 2012-12-10] (Oracle Corporation)
S3 SandraAgentSrv; E:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP2\RpcAgentSrv.exe [95896 2009-02-04] (SiSoftware) [File not signed]
R2 STI Simulator; E:\WINDOWS\System32\PAStiSvc.exe [53248 2005-01-14] ()
S3 TabletService; E:\WINDOWS\system32\Tablet.exe [430080 2000-06-01] (Wacom Technology, Corp.) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 61883; E:\WINDOWS\System32\DRIVERS\61883.sys [48128 2008-04-13] (Microsoft Corporation)
R3 ALCXSENS; E:\WINDOWS\System32\drivers\ALCXSENS.SYS [401152 2003-10-04] (Sensaura Ltd)
R3 ALCXWDM; E:\WINDOWS\System32\drivers\ALCXWDM.SYS [475788 2003-10-09] (Realtek Semiconductor Corp.)
R3 ASAPIW2k; E:\WINDOWS\System32\drivers\ASAPIW2k.sys [11264 2003-12-04] (Pinnacle Systems GmbH) [File not signed]
R2 aswHwid; E:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-11-19] ()
R2 aswMonFlt; E:\WINDOWS\system32\drivers\aswMonFlt.sys [70384 2014-11-19] (AVAST Software)
R1 aswRdr; E:\WINDOWS\system32\drivers\aswRdr.sys [55240 2014-11-19] (AVAST Software)
R0 aswRvrt; E:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-11-19] ()
R1 aswSnx; E:\WINDOWS\system32\drivers\aswSnx.sys [787800 2014-11-19] (AVAST Software)
R1 aswSP; E:\WINDOWS\system32\drivers\aswSP.sys [422760 2014-11-19] (AVAST Software)
R1 aswTdi; E:\WINDOWS\system32\drivers\aswTdi.sys [57928 2014-11-19] (AVAST Software)
R0 aswVmm; E:\WINDOWS\system32\Drivers\aswVmm.sys [206248 2014-11-19] ()
S3 AVSim; E:\WINDOWS\System32\DRIVERS\AVSim.sys [13312 2006-01-04] (YUAN High-Tech Development Co. Ltd.)
S3 CCDECODE; E:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R0 Daemon; E:\WINDOWS\System32\DRIVERS\daemon.sys [71968 2002-01-19] (VeNoM386 and SwENSkE) [File not signed]
S3 MPE; E:\WINDOWS\System32\DRIVERS\MPE.sys [15232 2008-04-13] (Microsoft Corporation)
R1 MUsbFltr; E:\WINDOWS\system32\Drivers\MUsbFltr.sys [8704 2004-12-15] (Waytech Development, Inc.) [File not signed]
S3 NdisIP; E:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 OmniTV; E:\WINDOWS\System32\DRIVERS\OmniTV.sys [198528 2006-01-04] (YUAN High-Tech Development Co. Ltd.)
S3 PAC207; E:\WINDOWS\System32\DRIVERS\pfc027.sys [162176 2005-04-08] ()
R0 PenClass; E:\WINDOWS\System32\Drivers\PenClass.sys [8145 2000-04-05] (Wacom Technology Corporation) [File not signed]
S3 SANDRA; E:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP2\WNt500x86\Sandra.sys [23112 2009-08-07] (SiSoftware)
S3 TfBulk; E:\WINDOWS\System32\DRIVERS\TfBulk.sys [13312 2008-12-20] (Topfield (visit www.topfield.co.kr)) [File not signed]
R1 UsbFltr; E:\WINDOWS\system32\Drivers\UsbFltr.sys [8960 2005-02-21] (Waytech Development, Inc.) [File not signed]
S3 w22n51; E:\WINDOWS\System32\DRIVERS\w22n51.sys [1646720 2004-01-02] (Intel® Corporation)
R3 w29n51; E:\WINDOWS\System32\DRIVERS\w29n51.sys [2216064 2008-12-09] (Intel® Corporation) [File not signed]
S3 wceusbsh; E:\WINDOWS\System32\DRIVERS\wceusbsh.sys [104064 2003-12-22] (Microsoft Corporation)
S3 hSONYPVh; \??\E:\DOCUME~1\Petr\LOCALS~1\Temp\hSONYPVh.sys [X]
S4 s24trans; System32\DRIVERS\s24trans.sys [X]
U5 ScsiPort; E:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-06 23:48 - 2014-12-06 23:52 - 00001423 _____ () E:\WINDOWS\setupapi.log
2014-12-05 00:34 - 2014-12-05 09:15 - 00000000 ____D () E:\Documents and Settings\Petr\Plocha\Tábor klokoty
2014-12-03 23:51 - 2014-12-03 23:51 - 00000000 ____D () E:\Documents and Settings\Petr\Dokumenty\STORMWARE
2014-11-25 13:18 - 2014-11-25 13:18 - 00000000 ____D () E:\Documents and Settings\Petr\Data aplikací\Protector_PDF_Viewer
2014-11-19 12:31 - 2014-11-19 12:31 - 00000000 ____D () E:\WINDOWS\jumpshot.com
2014-11-19 12:31 - 2014-11-19 12:31 - 00000000 ____D () E:\Documents and Settings\Petr\Data aplikací\AVAST Software
2014-11-19 12:26 - 2014-11-19 12:25 - 00291352 _____ (AVAST Software) E:\WINDOWS\system32\aswBoot.exe
2014-11-19 12:26 - 2014-11-19 12:25 - 00024184 _____ () E:\WINDOWS\system32\Drivers\aswHwid.sys
2014-11-19 12:25 - 2014-11-19 12:25 - 00043152 _____ (AVAST Software) E:\WINDOWS\avastSS.scr
2014-11-19 12:21 - 2014-11-19 12:21 - 00000000 ____D () E:\Documents and Settings\All Users\Data aplikací\AVAST Software
2014-11-19 12:20 - 2014-11-19 12:25 - 00206248 _____ () E:\WINDOWS\system32\Drivers\aswVmm.sys
2014-11-19 12:19 - 2014-11-19 12:25 - 00070384 _____ (AVAST Software) E:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-11-19 12:19 - 2014-11-19 12:25 - 00049944 _____ () E:\WINDOWS\system32\Drivers\aswRvrt.sys

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-07 00:01 - 2014-01-07 11:59 - 00000000 ____D () E:\FRST
2014-12-07 00:01 - 2008-12-07 00:36 - 00000000 ____D () E:\Documents and Settings\Petr\Local Settings\Temp
2014-12-06 23:59 - 2008-12-08 18:14 - 00001870 _____ () E:\WINDOWS\MAILTRAN.INI
2014-12-06 23:47 - 2008-12-08 15:59 - 00000000 ____D () E:\Documents and Settings\Petr\Local Settings\Data aplikací\Adobe
2014-12-06 23:46 - 2012-04-24 17:59 - 00701104 _____ (Adobe Systems Incorporated) E:\WINDOWS\system32\FlashPlayerApp.exe
2014-12-06 23:46 - 2011-12-08 17:36 - 00071344 _____ (Adobe Systems Incorporated) E:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-12-06 23:45 - 2011-12-12 09:36 - 00000000 ____D () E:\Documents and Settings\Petr\Dokumenty\Stažené soubory
2014-12-06 23:37 - 2008-12-07 00:36 - 00000000 ____D () E:\Documents and Settings\Petr
2014-12-06 23:32 - 2011-12-04 12:07 - 00000000 ____D () E:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
2014-12-06 23:32 - 2008-12-09 23:40 - 00000000 ____D () E:\Program Files\CCleaner
2014-12-06 23:32 - 2008-12-09 23:40 - 00000000 ____D () E:\Documents and Settings\Petr\Nabídka Start\Programy\CCleaner
2014-12-06 23:22 - 2011-06-09 08:48 - 00000000 ____D () E:\Documents and Settings\Petr\Plocha\PROVIZORNÍ KOŠ
2014-12-06 23:20 - 2008-12-08 22:23 - 00000000 ___RD () E:\Documents and Settings\Petr\Plocha\nepoužívané odkazy - registrace
2014-12-06 23:20 - 2008-12-07 00:36 - 00000000 ____D () E:\Documents and Settings\Petr\Plocha
2014-12-06 22:52 - 2008-12-08 10:42 - 00000349 _____ () E:\Documents and Settings\All Users\Dokumenty\PCLECHAL.INI
2014-12-06 22:52 - 2008-12-07 01:24 - 00000159 ____N () E:\WINDOWS\wiadebug.log
2014-12-06 22:52 - 2008-12-07 01:24 - 00000049 ____N () E:\WINDOWS\wiaservc.log
2014-12-06 19:24 - 2008-12-07 00:36 - 00000178 ___SH () E:\Documents and Settings\Petr\ntuser.ini
2014-12-06 12:11 - 2002-09-23 13:00 - 00002206 _____ () E:\WINDOWS\system32\wpa.dbl
2014-12-05 09:16 - 2008-12-09 09:14 - 00239496 _____ () E:\WINDOWS\Petr8.xlb
2014-12-03 23:51 - 2008-12-07 00:36 - 00000000 ___RD () E:\Documents and Settings\Petr\Dokumenty
2014-12-03 22:39 - 2008-12-08 15:59 - 00000000 ____D () E:\Documents and Settings\Petr\Data aplikací\AdobeUM
2014-12-03 21:54 - 2008-12-08 15:57 - 00002333 _____ () E:\Documents and Settings\All Users\Nabídka Start\Acrobat Distiller 6.0.lnk
2014-12-02 22:24 - 2008-12-08 16:29 - 00000000 ____D () E:\Program Files\RTSStavitel
2014-11-25 13:18 - 2008-12-07 00:36 - 00000000 __RHD () E:\Documents and Settings\Petr\Data aplikací
2014-11-25 00:09 - 2008-12-08 18:46 - 00000000 ____D () E:\3darch.sko
2014-11-20 00:40 - 2011-07-07 22:32 - 00000000 ____D () E:\Documents and Settings\Petr\Local Settings\Data aplikací\Temp
2014-11-20 00:12 - 2008-12-08 00:09 - 00000000 ___SD () E:\Documents and Settings\Petr\UserData
2014-11-20 00:05 - 2008-12-07 00:30 - 00000006 ____H () E:\WINDOWS\Tasks\SA.DAT
2014-11-20 00:03 - 2011-12-04 12:07 - 00000940 _____ () E:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-19 13:46 - 2008-12-07 01:23 - 00000000 ____D () E:\Documents and Settings\All Users\Plocha
2014-11-19 12:56 - 2013-01-06 14:06 - 00000366 ____H () E:\WINDOWS\Tasks\avast! Emergency Update.job
2014-11-19 12:29 - 2011-12-04 12:07 - 00000936 _____ () E:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-19 12:29 - 2008-12-08 16:21 - 00013365 _____ () E:\WINDOWS\system32\wacom.dat
2014-11-19 12:27 - 2008-12-07 01:23 - 00000000 ___RD () E:\Documents and Settings\All Users\Nabídka Start\Programy
2014-11-19 12:25 - 2013-01-06 14:05 - 00787800 _____ (AVAST Software) E:\WINDOWS\system32\Drivers\aswSnx.sys
2014-11-19 12:25 - 2008-12-08 00:25 - 00422760 _____ (AVAST Software) E:\WINDOWS\system32\Drivers\aswSP.sys
2014-11-19 12:25 - 2008-12-08 00:25 - 00057928 _____ (AVAST Software) E:\WINDOWS\system32\Drivers\aswTdi.sys
2014-11-19 12:25 - 2008-12-08 00:25 - 00055240 _____ (AVAST Software) E:\WINDOWS\system32\Drivers\aswRdr.sys
2014-11-19 12:21 - 2008-12-07 01:22 - 00000000 __RHD () E:\Documents and Settings\All Users\Data aplikací
2014-11-19 12:19 - 2008-12-07 01:23 - 00002504 _____ () E:\WINDOWS\system32\CONFIG.NT
2014-11-18 20:03 - 2008-12-07 00:36 - 00000000 ___HD () E:\Documents and Settings\Petr\Local Settings\Data aplikací
2014-11-18 12:26 - 2013-09-06 07:52 - 00000000 ____D () E:\Documents and Settings\All Users\Data aplikací\firebird
2014-11-18 11:10 - 2013-09-06 07:32 - 00000000 ____D () E:\Documents and Settings\Petr\Dokumenty\Optimik
2014-11-07 12:22 - 2008-12-07 01:23 - 01048670 ____C () E:\WINDOWS\system32\PerfStringBackup.INI

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

E:\WINDOWS\explorer.exe => File is digitally signed
E:\WINDOWS\system32\winlogon.exe => File is digitally signed
E:\WINDOWS\system32\svchost.exe => File is digitally signed
E:\WINDOWS\system32\services.exe => File is digitally signed
E:\WINDOWS\system32\User32.dll => File is digitally signed
E:\WINDOWS\system32\userinit.exe => File is digitally signed
E:\WINDOWS\system32\rpcss.dll => File is digitally signed
E:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: vyskakuje Outlookexpress

#2 Příspěvek od Márty84 »

Zdravim :)

:arrow: Odinstalujte Spybota, program je zastaraly a k nicemu.

:!: Presunte FRST primo na plochu, jinak to nebude fungovat.
:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

Start
CloseProcesses:

HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [SpybotSD TeaTimer] => E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [OEXPRESS] => [X]
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [WEBTRAN] => [X]
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [MSMSGS] => E:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)

HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Internet Explorer\Main,Vyhledávací stránka = http://www.msn.com/access/allinone.asp
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "" <======= ATTENTION
BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

Hosts:
EmptyTemp:
Reboot:
End
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev fixlist a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Spustte FRST, kliknete na napis Fix a program vykona prikazy.
Po restartu pc by se mel objevit novy log - s nazvem fixlog, ten mi sem zase zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Peter251
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 07 led 2014 13:19

Re: vyskakuje Outlookexpress

#3 Příspěvek od Peter251 »

Tak jsem to udělal tady je fixlog
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 06-12-2014 02
Ran by Petr at 2014-12-08 23:46:46 Run:2
Running from E:\Documents and Settings\Petr\Plocha
Loaded Profile: Petr (Available profiles: Petr & Administrator)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
CloseProcesses:

HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [SpybotSD TeaTimer] => E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [OEXPRESS] => [X]
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [WEBTRAN] => [X]
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [MSMSGS] => E:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)

HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Internet Explorer\Main,Vyhledávací stránka = http://www.msn.com/access/allinone.asp
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "" <======= ATTENTION
BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\\SpybotSD TeaTimer => Value not found.
HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\\OEXPRESS => value deleted successfully.
HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\\WEBTRAN => value deleted successfully.
HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\\MSMSGS => value deleted successfully.
HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Internet Explorer\Main\\Vyhledávací stránka => value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\Tabs => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}" => Key not found.
"HKCR\CLSID\{53707962-6F74-2D53-2644-206D7942484F}" => Key not found.
E:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 228.3 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: vyskakuje Outlookexpress

#4 Příspěvek od Márty84 »

:???: Co Outlook, jeste se spousti?


:arrow: Stahnete AdwCleaner https://toolslib.net/downloads/finish/1/ a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Spustte ho.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Peter251
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 07 led 2014 13:19

Re: vyskakuje Outlookexpress

#5 Příspěvek od Peter251 »

tady je log, vyskakování Outlooku přestalo, ale začal se automaticky otvírat při spuštění Mozilly

# AdwCleaner v4.105 - Report created 10/12/2014 at 20:25:17
# Updated 08/12/2014 by Xplode
# Database : 2014-12-08.2 [Local]
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Petr - PETER
# Running from : E:\Documents and Settings\Petr\Plocha\adwcleaner_4.105.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : STI Simulator

***** [ Files / Folders ] *****

Folder Deleted : E:\Documents and Settings\All Users\Data aplikací\Ask
File Deleted : E:\WINDOWS\system32\PAStiSvc.exe

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\YahooPartnerToolbar

***** [ Browsers ] *****

-\\ Internet Explorer v6.0.2900.5512


-\\ Mozilla Firefox v30.0 (cs)


*************************

AdwCleaner[R0].txt - [1022 octets] - [10/12/2014 20:20:56]
AdwCleaner[S0].txt - [887 octets] - [10/12/2014 20:25:17]

########## EOF - E:\AdwCleaner\AdwCleaner[S0].txt - [946 octets] ##########

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: vyskakuje Outlookexpress

#6 Příspěvek od Márty84 »

:arrow: Postupujte podle navodu kolegy
vyosek píše: :arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte

:arrow: Postupujte podle navodu kolegy
vyosek píše: :arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Peter251
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 07 led 2014 13:19

Re: vyskakuje Outlookexpress

#7 Příspěvek od Peter251 »

dlouho jsem tu nebyl, omlouvám se moc práce - Outlook vyskakuje pořád ale s delším intervalem tady jsou logy :

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 06-12-2014 02
Ran by Petr at 2014-12-08 23:46:46 Run:2
Running from E:\Documents and Settings\Petr\Plocha
Loaded Profile: Petr (Available profiles: Petr & Administrator)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
CloseProcesses:

HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [SpybotSD TeaTimer] => E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [OEXPRESS] => [X]
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [WEBTRAN] => [X]
HKU\S-1-5-21-448539723-839522115-854245398-1004\...\Run: [MSMSGS] => E:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)

HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Internet Explorer\Main,Vyhledávací stránka = http://www.msn.com/access/allinone.asp
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "" <======= ATTENTION
BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\\SpybotSD TeaTimer => Value not found.
HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\\OEXPRESS => value deleted successfully.
HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\\WEBTRAN => value deleted successfully.
HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\\MSMSGS => value deleted successfully.
HKU\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Internet Explorer\Main\\Vyhledávací stránka => value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\Tabs => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}" => Key not found.
"HKCR\CLSID\{53707962-6F74-2D53-2644-206D7942484F}" => Key not found.
E:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 228.3 MB temporary data.


log z zoek

Zoek.exe v5.0.0.0 Updated 17-December-2014
Tool run by Petr on źt 18.12.2014 at 22:37:32,79.
Microsoft Windows XP Home Edition 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: E:\Documents and Settings\Petr\Plocha\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

18.12.2014 22:38:48 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

E:\Program Files\Realtek Sound Manager deleted successfully
E:\Program Files\SmartSound Software Inc deleted successfully
E:\DOCUME~1\ALLUSE~1\DATAAP~1\UDL deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_USERS\S-1-5-21-448539723-839522115-854245398-1004\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully

==== Deleting Services ======================


==== Deleting Files \ Folders ======================

E:\DOCUME~1\ALLUSE~1\NABDKA~1\Programy\Sada bezdrátového príslušenství Labtec pro prenosný pocítac not found
E:\Program Files\ComPlus Applications deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="e:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [17.10.2013 20:32]

==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - E:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx[19.11.2014 12:25]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.cz/"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://www.google.com/search?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.google.cz/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"

==== Reset Google Chrome ======================

Nothing found to reset

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Print2PDF Print Monitor deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched deleted successfully

==== Empty IE Cache ======================

E:\Documents and Settings\Petr\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
E:\Documents and Settings\Petr\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== E:\zoek_backup content ======================

E:\zoek_backup (files=1 folders=1 85 bytes)

==== Empty Temp Folders ======================

E:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

E:\WINDOWS\Temp successfully emptied
E:\DOCUME~1\Petr\LOCALS~1\Temp successfully emptied

==== Empty Recycle Bin ======================

E:\RECYCLER successfully emptied

==== Deleting Files / Folders ======================

"E:\Documents and Settings\Petr\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found

==== EOF on źt 18.12.2014 at 23:32:11,35 ======================

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: vyskakuje Outlookexpress

#8 Příspěvek od Márty84 »

:arrow: Udelejte !!!kompletni!!! kontrolu s MBAM http://www.bleepingcomputer.com/downloa ... re/dl/241/ (musite stahnout verzi 1.75, odmitnout upgrade a aktualizovat jen virovou databazi) a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce. Navod zde http://forum.viry.cz/viewtopic.php?f=29&t=115222





18.1. pro neaktivitu :lock: http://forum.viry.cz/viewtopic.php?f=12&t=123975
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno