Prosím o kontrolu logů. Problém s reklamama

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému hned. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
Sedivec111
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 16 Bře 2015 12:09

Prosím o kontrolu logů. Problém s reklamama

#1 Příspěvek od Sedivec111 »

Zdravím

Přítelkyni se zahltil počítač nějakým bordýlkem a má na internetu nekontorlovatelné množství reklam. Prosím o kontrolu logu.
Počítač sem projel jejím antivirem a kompletně CCcleanerem.

Donate SMS jistá

Logfile of random's system information tool 1.10 (written by random/random)
Run by Terka at 2015-03-16 12:15:11
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 90 GB (36%) free of 252 GB
Total RAM: 3038 MB (51% free)

HijackThis download failed

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3927468761-2713022208-1274307167-1000Core.job - C:\Users\Terka\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3927468761-2713022208-1274307167-1000UA.job - C:\Users\Terka\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-01 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09 4502400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [2009-10-25 657904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [2009-10-25 522224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-01 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-01-06 6703648]
"Apoint"=C:\Program Files\Apoint\Apoint.exe [2008-09-30 122880]
"ISBMgr.exe"=C:\Program Files\Sony\ISB Utility\ISBMgr.exe [2008-12-18 317288]
"MarketingTools"=C:\Program Files\Sony\Marketing Tools\MarketingTools.exe [2009-10-25 26112]
"AML"=C:\Program Files\Sony\VAIO Launcher\AML.exe [2009-03-09 1101824]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-05-04 102400]
""= []
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2015-01-30 978520]
"eDealPop"=C:\Program Files\eDealPop\eDealPop.exe [2014-12-03 6144]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"Google Update"=C:\Users\Terka\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-12 116648]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon]
C:\Windows\system32\VESWinlogon.dll [2009-01-19 98304]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.dvsd"=C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll
"VIDC.FFDS"=C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"msacm.siren"=sirenacm.dll
"vidc.VP60"=C:\Windows\system32\vp6vfw.dll
"vidc.VP61"=C:\Windows\system32\vp6vfw.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-03-16 12:07:03 ----D---- C:\Program Files\trend micro
2015-03-16 12:07:02 ----D---- C:\rsit
2015-03-16 12:03:45 ----A---- C:\Windows\system32\FNTCACHE.DAT
2015-03-16 07:51:21 ----D---- C:\Program Files\eDealPop
2015-03-16 07:44:35 ----A---- C:\Program Files\wauctla-setup.exe
2015-03-16 07:44:33 ----A---- C:\Program Files\ExtensionsInstallerAsUpdate.exe
2015-03-16 07:44:31 ----A---- C:\Program Files\distribution-installer.exe
2015-03-16 07:37:56 ----D---- C:\AdwCleaner
2015-03-16 07:30:33 ----D---- C:\Program Files\CCleaner
2015-03-14 13:49:31 ----A---- C:\Windows\system32\WMPhoto.dll
2015-03-14 13:46:45 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-14 13:41:53 ----A---- C:\Windows\system32\win32k.sys
2015-03-14 13:14:13 ----A---- C:\Windows\system32\atmlib.dll
2015-03-14 13:14:13 ----A---- C:\Windows\system32\atmfd.dll
2015-03-14 13:11:39 ----A---- C:\Windows\system32\smss.exe
2015-03-14 13:11:39 ----A---- C:\Windows\system32\ntkrnlpa.exe
2015-03-14 13:11:39 ----A---- C:\Windows\system32\csrsrv.dll
2015-03-14 13:11:38 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-14 13:11:08 ----A---- C:\Windows\system32\msctf.dll
2015-03-14 13:09:36 ----A---- C:\Windows\system32\schannel.dll
2015-03-14 13:08:27 ----A---- C:\Windows\system32\msi.dll
2015-03-14 13:07:13 ----A---- C:\Windows\system32\shell32.dll
2015-03-11 11:47:17 ----A---- C:\Windows\system32\vbscript.dll
2015-03-11 11:47:17 ----A---- C:\Windows\system32\urlmon.dll
2015-03-11 11:47:17 ----A---- C:\Windows\system32\mshta.exe
2015-03-11 11:47:17 ----A---- C:\Windows\system32\msfeedssync.exe
2015-03-11 11:47:16 ----A---- C:\Windows\system32\msfeedsbs.dll
2015-03-11 11:47:16 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-11 11:47:16 ----A---- C:\Windows\system32\jsproxy.dll
2015-03-11 11:47:16 ----A---- C:\Windows\system32\dxtmsft.dll
2015-03-11 11:47:15 ----A---- C:\Windows\system32\ieUnatt.exe
2015-03-11 11:47:14 ----A---- C:\Windows\system32\url.dll
2015-03-11 11:47:14 ----A---- C:\Windows\system32\jscript.dll
2015-03-11 11:47:14 ----A---- C:\Windows\system32\iertutil.dll
2015-03-11 11:47:14 ----A---- C:\Windows\system32\ieframe.dll
2015-03-11 11:47:13 ----A---- C:\Windows\system32\wininet.dll
2015-03-11 11:47:13 ----A---- C:\Windows\system32\jscript9.dll
2015-03-11 11:47:10 ----A---- C:\Windows\system32\ieui.dll
2015-03-11 11:47:10 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-11 11:47:09 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-11 11:47:08 ----A---- C:\Windows\system32\mshtml.dll
2015-03-01 19:44:49 ----A---- C:\Windows\taskmgr.exe
2015-03-01 19:43:55 ----A---- C:\Windows\wauctla-setup.exe
2015-02-25 21:03:32 ----D---- C:\ProgramData\Avg_Update_0215tb
2015-02-17 16:04:46 ----A---- C:\Windows\system32\FM20.DLL

======List of files/folders modified in the last 1 month======

2015-03-16 12:15:04 ----D---- C:\Windows\Temp
2015-03-16 12:11:22 ----D---- C:\Windows\System32
2015-03-16 12:11:22 ----D---- C:\Windows\inf
2015-03-16 12:11:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-03-16 12:07:03 ----RD---- C:\Program Files
2015-03-16 11:59:12 ----D---- C:\Windows
2015-03-16 11:52:49 ----D---- C:\Program Files\Steam
2015-03-16 11:52:44 ----D---- C:\Users\Terka\AppData\Roaming\Media Player Classic
2015-03-16 11:52:38 ----D---- C:\Users\Terka\AppData\Roaming\uTorrent
2015-03-16 11:52:12 ----D---- C:\Windows\SoftwareDistribution
2015-03-16 11:47:33 ----HD---- C:\ProgramData
2015-03-16 08:03:22 ----D---- C:\Windows\Panther
2015-03-16 08:03:16 ----D---- C:\Windows\Logs
2015-03-16 08:03:15 ----D---- C:\Windows\Debug
2015-03-16 08:03:14 ----D---- C:\Windows\Minidump
2015-03-16 07:50:45 ----D---- C:\Windows\Prefetch
2015-03-16 07:40:37 ----SHD---- C:\Windows\Installer
2015-03-16 07:40:37 ----D---- C:\Program Files\Common Files
2015-03-16 07:31:54 ----D---- C:\Windows\system32\Tasks
2015-03-15 20:21:25 ----D---- C:\Users\Terka\AppData\Roaming\vlc
2015-03-15 16:27:16 ----SHD---- C:\System Volume Information
2015-03-14 13:51:38 ----D---- C:\Windows\system32\migration
2015-03-14 13:51:37 ----D---- C:\Program Files\Internet Explorer
2015-03-14 13:49:50 ----D---- C:\Windows\winsxs
2015-03-14 13:49:47 ----D---- C:\Windows\system32\catroot
2015-03-14 13:48:43 ----SHD---- C:\Config.Msi
2015-03-14 13:48:43 ----D---- C:\ProgramData\Microsoft Help
2015-03-14 13:47:16 ----D---- C:\Windows\system32\catroot2
2015-03-14 13:41:43 ----D---- C:\Windows\system32\MRT
2015-03-14 13:15:33 ----A---- C:\Windows\system32\mrt.exe
2015-03-06 20:33:11 ----D---- C:\Windows\system32\drivers
2015-03-03 14:16:52 ----N---- C:\Windows\system32\MpSigStub.exe
2015-03-01 13:13:36 ----D---- C:\Program Files\Common Files\Steam
2015-02-26 21:06:00 ----HD---- C:\Windows\system32\GroupPolicy
2015-02-26 06:22:39 ----D---- C:\Windows\Tasks
2015-02-26 05:27:46 ----A---- C:\Windows\wauctla.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2008-04-22 312344]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-11-15 239224]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2010-07-12 45648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-10-28 717296]
R1 DMICall;Sony DMI Call service; C:\Windows\system32\DRIVERS\DMICall.sys [2008-11-25 10216]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2008-01-25 12672]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-11-15 95408]
R2 regi;regi; C:\Windows\system32\drivers\regi.sys [2007-04-17 11032]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2008-10-23 68608]
R2 risdptsk;risdptsk; C:\Windows\system32\DRIVERS\risdptsk.sys [2008-10-23 46592]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2008-01-25 8192]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2008-09-30 164400]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect; C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2008-04-24 17920]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-05-15 4304384]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2008-01-25 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2008-01-25 207360]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-01-06 2254880]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2009-05-28 4233728]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIV.sys [2009-03-10 153952]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 SFEP;Sony Firmware Extension Parser; C:\Windows\system32\DRIVERS\SFEP.sys [2008-11-19 9344]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-07-12 134272]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2008-01-25 659968]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2008-03-27 298496]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-02-10 84008]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2009-02-10 109096]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-02-10 29736]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-02-10 18344]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-01-21 200704]
S3 IObitUnlocker;IObitUnlocker; \??\C:\Users\Terka\IObit Unlocker\IObitUnlocker.sys [2011-03-09 26992]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 RegFltrX86;RegFltrX86; \??\C:\Users\Terka\AppData\Local\IndexKernelRecycle\RegFltrX86.sys []
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 RgFltX86;RgFltX86; \??\C:\Users\Terka\AppData\Local\FileFirmwareLog\RgFltX86.sys []
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM); C:\Windows\system32\DRIVERS\s1018bus.sys [2009-03-25 86824]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1018mdfl.sys [2009-03-25 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1018mdm.sys [2009-03-25 114728]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1018mgmt.sys [2009-03-25 106208]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1018nd5.sys [2009-03-25 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1018obex.sys [2009-03-25 104744]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1018unic.sys [2009-03-25 109864]
S3 s125bus;Sony Ericsson Device 125 driver (WDM); C:\Windows\system32\DRIVERS\s125bus.sys [2007-04-24 83336]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s125mdfl.sys [2007-04-24 15112]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s125mdm.sys [2007-04-24 108680]
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s125mgmt.sys [2007-04-24 100488]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s125obex.sys [2007-04-24 98696]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-06-07 131000]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S4 UIUSys;Conexant Setup API; C:\Windows\system32\DRIVERS\UIUSYS.SYS []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7; c:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-08 169312]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2009-05-14 729088]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-01-24 559656]
R2 ControlDatabaseWord;ControlDatabaseWord; C:\Windows\system32\ControlDatabaseWord\ControlDatabaseWord.exe [2014-10-13 68096]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2009-05-21 874768]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 interpretersharewareapi;interpretersharewareapi; C:\Windows\system32\interpretersharewareapi\interpretersharewareapi.exe [2015-01-16 83456]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2010-05-20 110736]
R2 kernelmysql_86;kernelmysql_86; C:\Windows\system32\kernelmysql_86\kernelmysql_86.exe [2015-01-16 83456]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-01-30 22184]
R2 NSUService;NSUService; C:\Program Files\Sony\Network Utility\NSUService.exe [2008-12-22 303104]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-10-19 66872]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2009-05-21 473360]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [2009-01-06 109088]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-10-09 3275136]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 syntaxsbeDrv.exe;syntaxsbeDrv.exe; C:\Users\Terka\AppData\Local\syntaxsbeDrv\syntaxsbeDrv.exe [2015-03-16 229888]
R2 Task Manager Pro;Task Manager Pro; C:\Windows\taskmgr.exe [2015-02-26 48128]
R2 uCamMonitor;CamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960]
R2 VAIO Event Service;VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [2009-01-19 203624]
R2 VAIO Power Management;VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2008-12-19 415592]
R2 VCFw;VAIO Content Folder Watcher; C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2009-03-05 5189992]
R2 VzCdbSvc;VAIO Entertainment Database Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [2009-03-05 192512]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2008-01-25 386560]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-01-30 284472]
R3 Vcsw;VAIO Entertainment UPnP Client Adapter; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [2009-03-05 313264]
R3 VUAgent;VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [2014-02-28 1228336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-06 267440]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-10-25 651720]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-10-25 137200]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [2009-04-01 114688]
S3 SOHCImp;VAIO Media plus Content Importer; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2012-03-06 122008]
S3 SOHDBSvr;VAIO Media plus Database Manager; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [2012-03-06 72856]
S3 SOHDms;VAIO Media plus Digital Media Server; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDms.exe [2012-03-06 392344]
S3 SOHDs;VAIO Media plus Device Searcher; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDs.exe [2012-03-06 76952]
S3 SOHPlMgr;VAIO Media plus Playlist Manager; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [2012-03-06 93336]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2015-02-19 835776]
S3 VAIO Entertainment TV Device Arbitration Service;VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [2009-03-05 69632]
S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2009-09-16 480624]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface; C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2009-09-08 83312]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-09-11 770168]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logů. Problém s reklamama

#2 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Sedivec111
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 16 Bře 2015 12:09

Re: Prosím o kontrolu logů. Problém s reklamama

#3 Příspěvek od Sedivec111 »

Zasílám výsledek. :)



Zoek.exe v5.0.0.0 Updated 05-March-2015
Tool run by Terka on po 16.03.2015 at 16:19:52,91.
Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\Terka\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

16.3.2015 16:21:33 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\Program Files\MSXML 4.0 deleted successfully
C:\Program Files\trend micro deleted successfully
C:\Users\Terka\AppData\Roaming\Media Player Classic deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3927468761-2713022208-1274307167-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully
HKEY_USERS\S-1-5-21-3927468761-2713022208-1274307167-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11d4-9B18-009027A5CD4F} deleted successfully
HKEY_USERS\S-1-5-21-3927468761-2713022208-1274307167-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11d4-9B18-009027A5CD4F} deleted successfully
HKEY_USERS\S-1-5-21-3927468761-2713022208-1274307167-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\AutorunsDisabled\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{AA58ED58-01DD-4d91-8333-CF10577473F7} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\syntaxsbeDrv.exe deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\syntaxsbeDrv.exe deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ControlDatabaseWord deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ControlDatabaseWord deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\interpretersharewareapi deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\interpretersharewareapi deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kernelmysql_86 deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\kernelmysql_86 deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RegFltrX86 deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RegFltrX86 deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RgFltX86 deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RgFltX86 deleted successfully

==== Deleting Files \ Folders ======================

C:\Program Files\trend micro not found
C:\Users\Terka\AppData\Local\CGIThumbnailUtility deleted
C:\Windows\System32\apibackupBckp deleted
C:\Windows\System32\indexits64 deleted
C:\Windows\System32\minimalmswsockRec deleted
C:\Windows\System32\ProcessSoftwareWinsock deleted
C:\Users\Terka\AppData\Roaming\WB.CFG deleted
C:\Users\Terka\AppData\Roaming\coreavc.ini deleted
C:\PROGRA~2\hpeB08.dll deleted
C:\PROGRA~2\Avg_Update_0215tb deleted
C:\PROGRA~2\Avg_Update_0814tb deleted
C:\PROGRA~2\Avg_Update_1114tb deleted
C:\PROGRA~2\Avg_Update_1214tb deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG SafeGuard toolbar deleted
C:\Windows\wininit.ini deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Windows\system32\GroupPolicy\Machine deleted
C:\Windows\system32\GroupPolicy\User deleted
C:\Windows\system32\GroupPolicy\gpt.ini deleted
"C:\Users\Terka\AppData\Local\syntaxsbeDrv\msdrmcredssp_86.exe" deleted
"C:\Users\Terka\AppData\Local\syntaxsbeDrv\msvcp100.dll" deleted
"C:\Users\Terka\AppData\Local\syntaxsbeDrv\msvcr100.dll" not deleted
"C:\Users\Terka\AppData\Local\syntaxsbeDrv\qjson0.dll" deleted
"C:\Users\Terka\AppData\Local\syntaxsbeDrv\QtCore4.dll" deleted
"C:\Users\Terka\AppData\Local\syntaxsbeDrv\QtNetwork4.dll" deleted
"C:\Users\Terka\AppData\Local\syntaxsbeDrv\syntaxsbeDrv.exe" deleted
"C:\Windows\System32\ControlDatabaseWord\ControlDatabaseWord.exe" deleted
"C:\Windows\System32\ControlDatabaseWord\msvcp100.dll" deleted
"C:\Windows\System32\ControlDatabaseWord\msvcr100.dll" not deleted
"C:\Windows\System32\ControlDatabaseWord\QtCore4.dll" deleted
"C:\Windows\System32\ControlDatabaseWord\QtNetwork4.dll" deleted
"C:\Windows\System32\interpretersharewareapi\interpretersharewareapi.exe" deleted
"C:\Windows\System32\interpretersharewareapi\msvcp100.dll" deleted
"C:\Windows\System32\interpretersharewareapi\msvcr100.dll" not deleted
"C:\Windows\System32\interpretersharewareapi\QtCore4.dll" deleted
"C:\Windows\System32\interpretersharewareapi\QtNetwork4.dll" deleted
"C:\Windows\System32\kernelmysql_86\kernelmysql_86.exe" deleted
"C:\Windows\System32\kernelmysql_86\msvcp100.dll" deleted
"C:\Windows\System32\kernelmysql_86\msvcr100.dll" not deleted
"C:\Windows\System32\kernelmysql_86\QtCore4.dll" deleted
"C:\Windows\System32\kernelmysql_86\QtNetwork4.dll" deleted
"C:\Program Files\eDealPop\eDealPop.exe" deleted
"C:\Program Files\eDealPop\msvcr100.dll" deleted
"C:\Users\Terka\AppData\Local\syntaxsbeDrv" not deleted
"C:\Windows\System32\ControlDatabaseWord" not deleted
"C:\Windows\System32\interpretersharewareapi" not deleted
"C:\Windows\System32\kernelmysql_86" not deleted
"C:\Program Files\eDealPop" deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [28.10.2009 07:20]

==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx[09.10.2013 09:59]

AdBlock - Terka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://mysearch.avg.com?cid={56A48B53- ... 2014-02-07 15:12:31&v=18.3.0.885&pid=safeguard&sg=0&sap=hp"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com/ig/redirectdomain ... &bmod=SNYT"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://www.google.com/search/?q=%s"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{64140D20-4D85-4435-89A8-9870DF8C974A} Google Url="http://www.google.co.uk/search?hl=en&q= ... rms}&meta="
{67A2568C-7A0A-4EED-AECC-B5405DE63B64} Google Url="http://www.google.com/search?sourceid=i ... YT_csCZ350"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... urceid=ie7"
{80c554b9-c7f8-4a21-9471-06d606da78a2} Bing Url="http://www.bing.com/search?q={searchTer ... DF&pc=MSSE"

==== Reset Google Chrome ======================

C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Reset IE Proxy ======================

Value(s) before fix:
"ProxyServer"="http=127.0.0.1:10578"
"ProxyOverride"="<local>;*origin.com;*ea.com;*akamaihd.net"
"ProxyEnable"=dword:00000001

Value(s) after fix:
"ProxyEnable"=dword:00000000

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\eDeals_is1 deleted successfully

==== Empty IE Cache ======================

C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Terka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=97 folders=19 58739280 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Terka\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Terka\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Terka\AppData\Local\syntaxsbeDrv\msvcr100.dll" not found
"C:\Windows\System32\ControlDatabaseWord\msvcr100.dll" not found
"C:\Windows\System32\interpretersharewareapi\msvcr100.dll" not found
"C:\Windows\System32\kernelmysql_86\msvcr100.dll" not found
"C:\Users\Terka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Users\Terka\AppData\Local\syntaxsbeDrv" not found
"C:\Windows\System32\ControlDatabaseWord" not found
"C:\Windows\System32\interpretersharewareapi" not found
"C:\Windows\System32\kernelmysql_86" not found

==== EOF on po 16.03.2015 at 16:39:09,54 ======================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logů. Problém s reklamama

#4 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Sedivec111
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 16 Bře 2015 12:09

Re: Prosím o kontrolu logů. Problém s reklamama

#5 Příspěvek od Sedivec111 »

Zasílám log

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by Terka (administrator) on TERKA-PC on 16-03-2015 21:49:08
Running from C:\Users\Terka\Desktop
Loaded Profiles: Terka (Available profiles: Terka)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Sony Corporation) C:\Program Files\Sony\ISB Utility\ISBMgr.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Sony Corporation) C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
(Sony Corporation) C:\Program Files\Sony\Network Utility\NSUService.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Rocket Division Software) C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
() C:\Windows\taskmgr.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ArcSoft, Inc.) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6703648 2009-01-06] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [122880 2008-09-30] (Alps Electric Co., Ltd.)
HKLM\...\Run: [ISBMgr.exe] => C:\Program Files\Sony\ISB Utility\ISBMgr.exe [317288 2008-12-18] (Sony Corporation)
HKLM\...\Run: [MarketingTools] => C:\Program Files\Sony\Marketing Tools\MarketingTools.exe [26112 2009-10-25] (Sony Corporation)
HKLM\...\Run: [AML] => C:\Program Files\Sony\VAIO Launcher\AML.exe [1101824 2009-03-09] (Sony)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [978520 2015-01-30] (Microsoft Corporation)
HKLM\...\Run: [eDealPop] => "C:\Program Files\eDealPop\eDealPop.exe"
Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll (Sony Corporation)
HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\...\Run: [Google Update] => C:\Users\Terka\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-12] (Google Inc.)
HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\...\MountPoints2: {560894f4-c3a5-11de-ba24-001dbab8e64b} - I:\AutoRun.exe TMM50PRO TMM50
HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [10240 2006-11-02] (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
SearchScopes: HKLM -> {64140D20-4D85-4435-89A8-9870DF8C974A} URL = http://www.google.co.uk/search?hl=en&q= ... rms}&meta=
SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... lz=1I7SNYT
SearchScopes: HKLM -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3927468761-2713022208-1274307167-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3927468761-2713022208-1274307167-1000 -> {64140D20-4D85-4435-89A8-9870DF8C974A} URL = http://www.google.co.uk/search?hl=en&q= ... rms}&meta=
SearchScopes: HKU\S-1-5-21-3927468761-2713022208-1274307167-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... YT_csCZ350
SearchScopes: HKU\S-1-5-21-3927468761-2713022208-1274307167-1000 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-01] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10] (Microsoft Corporation)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-01] (Oracle Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2008-10-28] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-06] ()
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-01] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3927468761-2713022208-1274307167-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Terka\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-08] (Google Inc.)
FF Plugin HKU\S-1-5-21-3927468761-2713022208-1274307167-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Terka\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-08] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppluginrichmediaplayer.dll [2013-03-12] ()
FF Extension: Pirrit Suggestor - C:\Users\Terka\AppData\Roaming\Mozilla\Firefox\profiles\extensions\suggestor@suggestor.pirrit.com.xpi [2014-03-15]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-10-25]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.cz/
CHR StartupUrls: Default -> "hxxp://www.google.cz/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-16]
CHR Extension: (Google Docs) - C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-16]
CHR Extension: (Google Drive) - C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-16]
CHR Extension: (YouTube) - C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-07-12]
CHR Extension: (Google Search) - C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-07-12]
CHR Extension: (Google Sheets) - C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-16]
CHR Extension: (AdBlock) - C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-03-29]
CHR Extension: (No Name) - C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbnkijekempmdlleaimfelifcejbkmcd [2015-03-16]
CHR Extension: (Google Wallet) - C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR Extension: (Gmail) - C:\Users\Terka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-07-12]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
StartMenuInternet: Google Chrome - C:\Users\Terka\AppData\Local\Google\Chrome\Application\chrome.exe

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AdobeActiveFileMonitor7.0; c:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [169312 2008-12-08] (Adobe Systems Incorporated)
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2009-10-25] (Macrovision Europe Ltd.) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation)
R2 NSUService; C:\Program Files\Sony\Network Utility\NSUService.exe [303104 2008-12-22] (Sony Corporation) [File not signed]
S3 PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [114688 2009-04-01] (Sony Corporation) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [109088 2009-01-06] (Realtek Semiconductor)
R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S3 SOHDBSvr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [72856 2012-03-06] (Sony Corporation)
S3 SOHPlMgr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [93336 2012-03-06] (Sony Corporation)
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [275968 2007-05-28] (Rocket Division Software) [File not signed]
R2 Task Manager Pro; C:\Windows\taskmgr.exe [48128 2015-02-26] () [File not signed]
R2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-03-05] (Sony Corporation) [File not signed]
R2 VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [203624 2009-01-19] (Sony Corporation)
R2 VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [415592 2008-12-19] (Sony Corporation)
S3 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [480624 2009-09-16] (Sony Corporation)
R3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-03-05] (Sony Corporation)
R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1228336 2014-02-28] (Sony Corporation)
R2 VzCdbSvc; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-03-05] (Sony Corporation) [File not signed]
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-24] (ArcSoft, Inc.)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
S3 IObitUnlocker; C:\Users\Terka\IObit Unlocker\IObitUnlocker.sys [26992 2011-03-09] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [153952 2009-03-10] (Realtek Semiconductor Corp.)
S3 s1018obex; C:\Windows\System32\DRIVERS\s1018obex.sys [104744 2009-03-25] (MCCI Corporation)
S3 s125bus; C:\Windows\System32\DRIVERS\s125bus.sys [83336 2007-04-24] (MCCI Corporation)
S3 s125mdfl; C:\Windows\System32\DRIVERS\s125mdfl.sys [15112 2007-04-24] (MCCI Corporation)
S3 s125mdm; C:\Windows\System32\DRIVERS\s125mdm.sys [108680 2007-04-24] (MCCI Corporation)
S3 s125mgmt; C:\Windows\System32\DRIVERS\s125mgmt.sys [100488 2007-04-24] (MCCI Corporation)
S3 s125obex; C:\Windows\System32\DRIVERS\s125obex.sys [98696 2007-04-24] (MCCI Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2009-10-28] () [File not signed]
U3 a4c8jswn; C:\Windows\system32\Drivers\a4c8jswn.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero size file/folder)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S4 UIUSys; system32\DRIVERS\UIUSYS.SYS [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-16 21:38 - 2015-03-16 21:48 - 00044126 _____ () C:\Users\Terka\Desktop\Addition.txt
2015-03-16 21:36 - 2015-03-16 21:49 - 00019779 _____ () C:\Users\Terka\Desktop\FRST.txt
2015-03-16 21:36 - 2015-03-16 21:49 - 00000000 ____D () C:\FRST
2015-03-16 21:35 - 2015-03-16 21:32 - 01135104 _____ (Farbar) C:\Users\Terka\Desktop\FRST.exe
2015-03-16 21:34 - 2015-03-16 21:34 - 00042309 _____ () C:\ProgramData\24188e0da34438d7.dat
2015-03-16 16:40 - 2015-03-16 16:40 - 00013042 _____ () C:\Users\Terka\Documents\zoek-results.txt
2015-03-16 16:38 - 2015-03-16 16:38 - 00337920 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-16 16:38 - 2015-03-16 16:38 - 00001568 _____ () C:\Windows\PFRO.log
2015-03-16 16:36 - 2015-03-16 16:19 - 00024064 _____ () C:\Windows\zoek-delete.exe
2015-03-16 16:21 - 2015-03-16 16:39 - 00013042 _____ () C:\zoek-results.log
2015-03-16 16:19 - 2015-03-16 16:34 - 00000000 ____D () C:\zoek_backup
2015-03-16 16:19 - 2015-03-16 16:18 - 01305600 _____ () C:\Users\Terka\Desktop\zoek.exe
2015-03-16 13:50 - 2015-03-16 13:50 - 00086240 _____ () C:\Users\Terka\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-16 12:07 - 2015-03-16 12:07 - 00000000 ____D () C:\rsit
2015-03-16 12:06 - 2015-03-16 11:57 - 01107968 _____ () C:\Users\Terka\Desktop\RSIT.exe
2015-03-16 07:44 - 2015-03-16 07:50 - 02750378 _____ ( ) C:\Program Files\distribution-installer.exe
2015-03-16 07:44 - 2015-03-16 07:50 - 02664983 _____ (w ) C:\Program Files\ExtensionsInstallerAsUpdate.exe
2015-03-16 07:44 - 2015-02-26 10:48 - 01032603 _____ (wauctla ) C:\Program Files\wauctla-setup.exe
2015-03-16 07:37 - 2015-03-16 07:44 - 00000000 ____D () C:\AdwCleaner
2015-03-16 07:37 - 2015-03-16 07:37 - 02171392 _____ () C:\Users\Terka\Downloads\adwcleaner_4.112.exe
2015-03-16 07:37 - 2015-03-16 07:37 - 02171392 _____ () C:\Users\Terka\Desktop\adwcleaner_4.112.exe
2015-03-16 07:31 - 2015-03-16 07:31 - 00000804 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-03-16 07:31 - 2015-03-16 07:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-03-16 07:30 - 2015-03-16 07:31 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-16 07:26 - 2015-03-16 07:28 - 05325696 _____ (Piriform Ltd) C:\Users\Terka\Downloads\ccsetup503.exe
2015-03-15 19:00 - 2015-03-15 19:01 - 203973976 _____ () C:\Users\Terka\Downloads\House.of.Cards.2013.S02E09.BDRip.x264-DEMAND.CZsub.mkv
2015-03-14 13:49 - 2015-01-29 02:35 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-14 13:46 - 2015-01-29 02:35 - 00975360 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-14 13:41 - 2015-02-26 01:18 - 02064384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-14 13:14 - 2015-02-20 03:03 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-14 13:14 - 2015-02-20 01:28 - 00296960 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-14 13:11 - 2015-02-26 03:01 - 03604408 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-03-14 13:11 - 2015-02-26 03:01 - 03552184 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-14 13:11 - 2015-01-21 03:02 - 00807936 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-14 13:11 - 2015-01-09 03:04 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-14 13:11 - 2015-01-09 01:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-14 13:09 - 2015-03-06 05:01 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-14 13:08 - 2014-10-13 02:12 - 02264064 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-03-14 13:07 - 2015-02-18 03:02 - 11587584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 11:47 - 2015-02-21 18:37 - 12375040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 11:47 - 2015-02-21 18:34 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-03-11 11:47 - 2015-02-21 18:29 - 09747968 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 11:47 - 2015-02-21 18:28 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 11:47 - 2015-02-21 18:22 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 11:47 - 2015-02-21 18:21 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 11:47 - 2015-02-21 18:21 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 11:47 - 2015-02-21 18:20 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-03-11 11:47 - 2015-02-21 18:20 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-11 11:47 - 2015-02-21 18:19 - 01803264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 11:47 - 2015-02-21 18:19 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-03-11 11:47 - 2015-02-21 18:19 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 11:47 - 2015-02-21 18:19 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 11:47 - 2015-02-21 18:19 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-11 11:47 - 2015-02-21 18:18 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-11 11:47 - 2015-02-21 18:18 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-11 11:47 - 2015-02-21 18:18 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 11:47 - 2015-02-21 18:18 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 11:47 - 2015-02-21 18:18 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-03-11 11:47 - 2015-02-21 18:18 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-03-11 11:47 - 2015-02-21 18:18 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-03-11 11:47 - 2015-02-21 18:17 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-01 19:44 - 2015-03-01 19:44 - 00000879 _____ () C:\Windows\InstallUtil.InstallLog
2015-03-01 19:44 - 2015-03-01 19:44 - 00000349 _____ () C:\Windows\taskmgr.InstallLog
2015-03-01 19:44 - 2015-02-26 05:25 - 00048128 _____ () C:\Windows\taskmgr.exe
2015-03-01 19:44 - 2015-01-19 20:26 - 00000314 _____ () C:\Windows\taskmgr.exe.config
2015-03-01 19:43 - 2015-03-01 19:44 - 01032603 _____ (wauctla ) C:\Windows\wauctla-setup.exe
2015-03-01 12:58 - 2015-03-01 13:03 - 00021543 _____ () C:\Users\Terka\Desktop\Četba.odt
2015-02-27 10:35 - 2015-02-27 10:35 - 00000000 ____D () C:\Users\Terka\AppData\Local\Steam
2015-02-26 21:05 - 2015-03-16 07:51 - 00000000 ____D () C:\Users\Terka\AppData\Local\Helper
2015-02-26 21:05 - 2015-02-26 21:05 - 00000000 ____D () C:\Users\Terka\AppData\Local\HelperApp
2015-02-17 16:04 - 2015-02-17 16:04 - 01202848 _____ (Microsoft Corporation) C:\Windows\system32\FM20.DLL

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-16 21:36 - 2009-10-25 17:51 - 01782704 _____ () C:\Windows\WindowsUpdate.log
2015-03-16 21:33 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-16 21:33 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-16 21:33 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-16 19:47 - 2009-03-27 17:38 - 00000012 _____ () C:\Windows\bthservsdp.dat
2015-03-16 19:47 - 2006-11-02 14:01 - 00032536 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-16 19:02 - 2012-07-12 08:58 - 00000962 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3927468761-2713022208-1274307167-1000UA.job
2015-03-16 18:50 - 2012-05-12 16:56 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-16 18:00 - 2015-02-01 08:35 - 00000000 ____D () C:\Program Files\Steam
2015-03-16 16:34 - 2006-11-02 12:18 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-03-16 12:53 - 2009-10-25 11:27 - 00000000 ____D () C:\Users\Terka\AppData\Local\Google
2015-03-16 12:11 - 2006-11-02 11:33 - 01532794 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-16 11:52 - 2010-09-13 15:10 - 00000000 ____D () C:\Users\Terka\AppData\Roaming\uTorrent
2015-03-16 08:03 - 2013-05-23 11:35 - 00000000 ____D () C:\Windows\Minidump
2015-03-16 08:03 - 2009-03-27 01:45 - 00000000 ____D () C:\Windows\Panther
2015-03-15 20:21 - 2014-10-29 18:34 - 00000000 ____D () C:\Users\Terka\AppData\Roaming\vlc
2015-03-15 18:48 - 2014-05-31 20:47 - 00000000 ____D () C:\Users\Terka\AppData\Local\2ce7f065b222ac1d1e9fc695ece9e528
2015-03-15 11:02 - 2012-07-12 08:58 - 00000910 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3927468761-2713022208-1274307167-1000Core.job
2015-03-14 18:04 - 2012-07-12 09:04 - 00002042 _____ () C:\Users\Terka\Desktop\Google Chrome.lnk
2015-03-14 13:48 - 2009-10-25 18:28 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-14 13:41 - 2013-08-15 10:11 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-14 13:15 - 2006-11-02 11:24 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-03-03 14:16 - 2009-11-04 17:54 - 00246920 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-03-01 19:44 - 2015-02-06 20:42 - 00001056 _____ () C:\Windows\wauctla.InstallLog
2015-03-01 13:13 - 2015-02-01 08:35 - 00000000 ____D () C:\Program Files\Common Files\Steam
2015-02-26 05:27 - 2015-02-06 20:42 - 01044480 _____ () C:\Windows\wauctla.exe

==================== Files in the root of some directories =======

2015-03-16 07:44 - 2015-03-16 07:50 - 2750378 _____ ( ) C:\Program Files\distribution-installer.exe
2015-03-16 07:44 - 2015-03-16 07:50 - 2664983 _____ (w ) C:\Program Files\ExtensionsInstallerAsUpdate.exe
2015-03-16 07:44 - 2015-02-26 10:48 - 1032603 _____ (wauctla ) C:\Program Files\wauctla-setup.exe
2010-10-19 15:13 - 2010-10-19 15:13 - 0022328 _____ () C:\Users\Terka\AppData\Roaming\PnkBstrK.sys
2010-07-21 18:28 - 2012-03-19 21:21 - 0000680 _____ () C:\Users\Terka\AppData\Local\d3d9caps.dat
2009-10-29 13:03 - 2015-02-02 13:52 - 0055808 _____ () C:\Users\Terka\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-16 21:34 - 2015-03-16 21:34 - 0042309 _____ () C:\ProgramData\24188e0da34438d7.dat
2010-03-12 18:07 - 2010-03-12 18:07 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2014-10-05 13:32 - 2014-10-05 13:32 - 0000952 ___SH () C:\ProgramData\KGyGaAvL.sys

Files to move or delete:
====================
C:\ProgramData\24188e0da34438d7.dat


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-16 21:48

==================== End Of Log ============================
Přílohy
Addition.zip
(11.87 KiB) Staženo 69 x

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logů. Problém s reklamama

#6 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    HKLM\...\Run: [] => [X]
    HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\...\Run: [Google Update] => C:\Users\Terka\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-12] (Google Inc.)
    HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
    HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\...\MountPoints2: {560894f4-c3a5-11de-ba24-001dbab8e64b} - I:\AutoRun.exe TMM50PRO TMM50
    HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [10240 2006-11-02] (Microsoft Corporation)
    BootExecute: autocheck autochk * sdnclean.exe
    
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
    
    FF Extension: Pirrit Suggestor - C:\Users\Terka\AppData\Roaming\Mozilla\Firefox\profiles\extensions\suggestor@suggestor.pirrit.com.xpi [2014-03-15]
    
    CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
    
    U3 a4c8jswn; C:\Windows\system32\Drivers\a4c8jswn.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero size file/folder)
    S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
    S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
    S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
    S4 UIUSys; system32\DRIVERS\UIUSYS.SYS [X]
    
    2015-03-16 21:38 - 2015-03-16 21:48 - 00044126 _____ () C:\Users\Terka\Desktop\Addition.txt
    2015-03-16 21:36 - 2015-03-16 21:49 - 00019779 _____ () C:\Users\Terka\Desktop\FRST.txt
    2015-03-16 21:34 - 2015-03-16 21:34 - 00042309 _____ () C:\ProgramData\24188e0da34438d7.dat
    2015-03-16 16:40 - 2015-03-16 16:40 - 00013042 _____ () C:\Users\Terka\Documents\zoek-results.txt
    2015-03-16 16:38 - 2015-03-16 16:38 - 00001568 _____ () C:\Windows\PFRO.log
    2015-03-16 16:36 - 2015-03-16 16:19 - 00024064 _____ () C:\Windows\zoek-delete.exe
    2015-03-16 16:21 - 2015-03-16 16:39 - 00013042 _____ () C:\zoek-results.log
    2015-03-16 16:19 - 2015-03-16 16:34 - 00000000 ____D () C:\zoek_backup
    2015-03-16 16:19 - 2015-03-16 16:18 - 01305600 _____ () C:\Users\Terka\Desktop\zoek.exe
    2015-03-16 12:07 - 2015-03-16 12:07 - 00000000 ____D () C:\rsit
    2015-03-16 12:06 - 2015-03-16 11:57 - 01107968 _____ () C:\Users\Terka\Desktop\RSIT.exe
    2015-03-16 07:44 - 2015-03-16 07:50 - 02750378 _____ ( ) C:\Program Files\distribution-installer.exe
    2015-03-16 07:44 - 2015-03-16 07:50 - 02664983 _____ (w ) C:\Program Files\ExtensionsInstallerAsUpdate.exe
    2015-03-16 07:44 - 2015-02-26 10:48 - 01032603 _____ (wauctla ) C:\Program Files\wauctla-setup.exe
    2015-03-16 07:37 - 2015-03-16 07:44 - 00000000 ____D () C:\AdwCleaner
    2015-03-16 07:37 - 2015-03-16 07:37 - 02171392 _____ () C:\Users\Terka\Downloads\adwcleaner_4.112.exe
    2015-03-16 07:37 - 2015-03-16 07:37 - 02171392 _____ () C:\Users\Terka\Desktop\adwcleaner_4.112.exe
    2015-03-16 07:26 - 2015-03-16 07:28 - 05325696 _____ (Piriform Ltd) C:\Users\Terka\Downloads\ccsetup503.exe
    2015-03-01 19:43 - 2015-03-01 19:44 - 01032603 _____ (wauctla ) C:\Windows\wauctla-setup.exe
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Sedivec111
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 16 Bře 2015 12:09

Re: Prosím o kontrolu logů. Problém s reklamama

#7 Příspěvek od Sedivec111 »

Výsledek :)

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-03-2015
Ran by Terka at 2015-03-17 17:40:27 Run:1
Running from C:\Users\Terka\Desktop
Loaded Profiles: Terka (Available profiles: Terka)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKLM\...\Run: [] => [X]
HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\...\Run: [Google Update] => C:\Users\Terka\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-12] (Google Inc.)
HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\...\MountPoints2: {560894f4-c3a5-11de-ba24-001dbab8e64b} - I:\AutoRun.exe TMM50PRO TMM50
HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [10240 2006-11-02] (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean.exe

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)

FF Extension: Pirrit Suggestor - C:\Users\Terka\AppData\Roaming\Mozilla\Firefox\profiles\extensions\suggestor@suggestor.pirrit.com.xpi [2014-03-15]

CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]

U3 a4c8jswn; C:\Windows\system32\Drivers\a4c8jswn.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero size file/folder)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S4 UIUSys; system32\DRIVERS\UIUSYS.SYS [X]

2015-03-16 21:38 - 2015-03-16 21:48 - 00044126 _____ () C:\Users\Terka\Desktop\Addition.txt
2015-03-16 21:36 - 2015-03-16 21:49 - 00019779 _____ () C:\Users\Terka\Desktop\FRST.txt
2015-03-16 21:34 - 2015-03-16 21:34 - 00042309 _____ () C:\ProgramData\24188e0da34438d7.dat
2015-03-16 16:40 - 2015-03-16 16:40 - 00013042 _____ () C:\Users\Terka\Documents\zoek-results.txt
2015-03-16 16:38 - 2015-03-16 16:38 - 00001568 _____ () C:\Windows\PFRO.log
2015-03-16 16:36 - 2015-03-16 16:19 - 00024064 _____ () C:\Windows\zoek-delete.exe
2015-03-16 16:21 - 2015-03-16 16:39 - 00013042 _____ () C:\zoek-results.log
2015-03-16 16:19 - 2015-03-16 16:34 - 00000000 ____D () C:\zoek_backup
2015-03-16 16:19 - 2015-03-16 16:18 - 01305600 _____ () C:\Users\Terka\Desktop\zoek.exe
2015-03-16 12:07 - 2015-03-16 12:07 - 00000000 ____D () C:\rsit
2015-03-16 12:06 - 2015-03-16 11:57 - 01107968 _____ () C:\Users\Terka\Desktop\RSIT.exe
2015-03-16 07:44 - 2015-03-16 07:50 - 02750378 _____ ( ) C:\Program Files\distribution-installer.exe
2015-03-16 07:44 - 2015-03-16 07:50 - 02664983 _____ (w ) C:\Program Files\ExtensionsInstallerAsUpdate.exe
2015-03-16 07:44 - 2015-02-26 10:48 - 01032603 _____ (wauctla ) C:\Program Files\wauctla-setup.exe
2015-03-16 07:37 - 2015-03-16 07:44 - 00000000 ____D () C:\AdwCleaner
2015-03-16 07:37 - 2015-03-16 07:37 - 02171392 _____ () C:\Users\Terka\Downloads\adwcleaner_4.112.exe
2015-03-16 07:37 - 2015-03-16 07:37 - 02171392 _____ () C:\Users\Terka\Desktop\adwcleaner_4.112.exe
2015-03-16 07:26 - 2015-03-16 07:28 - 05325696 _____ (Piriform Ltd) C:\Users\Terka\Downloads\ccsetup503.exe
2015-03-01 19:43 - 2015-03-01 19:44 - 01032603 _____ (wauctla ) C:\Windows\wauctla-setup.exe

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value deleted successfully.
HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WMPNSCFG => value deleted successfully.
"HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{560894f4-c3a5-11de-ba24-001dbab8e64b}" => Key deleted successfully.
HKCR\CLSID\{560894f4-c3a5-11de-ba24-001dbab8e64b} => Key not found.
HKU\S-1-5-21-3927468761-2713022208-1274307167-1000\Control Panel\Desktop\\SCRNSAVE.EXE => Value was restored successfully.
HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}" => Key deleted successfully.
"HKCR\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}" => Key deleted successfully.
"HKCR\PROTOCOLS\Handler\skype-ie-addon-data" => Key deleted successfully.
"HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => Key deleted successfully.
C:\Users\Terka\AppData\Roaming\Mozilla\Firefox\profiles\extensions\suggestor@suggestor.pirrit.com.xpi => Moved successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl" => Key deleted successfully.
C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx => Moved successfully.
a4c8jswn => Service not found.
IpInIp => Service deleted successfully.
NwlnkFlt => Service deleted successfully.
NwlnkFwd => Service deleted successfully.
UIUSys => Service deleted successfully.
C:\Users\Terka\Desktop\Addition.txt => Moved successfully.
C:\Users\Terka\Desktop\FRST.txt => Moved successfully.
"C:\ProgramData\24188e0da34438d7.dat" => File/Directory not found.
C:\Users\Terka\Documents\zoek-results.txt => Moved successfully.
C:\Windows\PFRO.log => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Terka\Desktop\zoek.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Users\Terka\Desktop\RSIT.exe => Moved successfully.
C:\Program Files\distribution-installer.exe => Moved successfully.
C:\Program Files\ExtensionsInstallerAsUpdate.exe => Moved successfully.
C:\Program Files\wauctla-setup.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Terka\Downloads\adwcleaner_4.112.exe => Moved successfully.
C:\Users\Terka\Desktop\adwcleaner_4.112.exe => Moved successfully.
C:\Users\Terka\Downloads\ccsetup503.exe => Moved successfully.
C:\Windows\wauctla-setup.exe => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 457 MB temporary data.


The system needed a reboot.

==== End of Fixlog 17:42:13 ====

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logů. Problém s reklamama

#8 Příspěvek od vyosek »

Supr, jak se chova PC??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Sedivec111
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 16 Bře 2015 12:09

Re: Prosím o kontrolu logů. Problém s reklamama

#9 Příspěvek od Sedivec111 »

Vpadá v pohodě.

Nemáš ještě nějaký tipy? Například co si myslíš, že je tam zbytečný, nebo změnu antiviru a podobně?

Jinak Donate na účet odesláno.

dobrá práce :thumbsup:

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logů. Problém s reklamama

#10 Příspěvek od vyosek »

:arrow: Zbytecnosti jsme odstranili, AV myslim netreba menit, MSE je pro bezneho uzivatele dostacujici - maximalne vymenit za Avast, ale neni bezpodminecne nutne

:arrow: Za podporu fora jmenem celeho tymu dekuji :worship:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět