
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Mail.ru v Mozille a MPC safe navigation v MS Edge
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Mail.ru v Mozille a MPC safe navigation v MS Edge
Zdravim,
moc nevim, jak se tyto dva nesvary dostaly do meho pc. Zkousel jsem je odstranit jak podle internetu, tak AVG, Spyboot, Malwarebytes...ale nic nepomohlo.
Prikladam log z FRST v priloze, jelikoz se nevleze do prispevku. Budu vdecny za kazdou pomoc. Dekuju moc:-)
moc nevim, jak se tyto dva nesvary dostaly do meho pc. Zkousel jsem je odstranit jak podle internetu, tak AVG, Spyboot, Malwarebytes...ale nic nepomohlo.
Prikladam log z FRST v priloze, jelikoz se nevleze do prispevku. Budu vdecny za kazdou pomoc. Dekuju moc:-)
- Přílohy
-
- Log + Addition.rar
- (76.69 KiB) Staženo 67 x
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Mail.ru v Mozille a MPC safe navigation v MS Edge
Zdravím!
Spusťte tuto utilitu:
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Mail.ru v Mozille a MPC safe navigation v MS Edge
Hezkou sobotu,
Moc dekuji za pomoc, prikladam log:
# AdwCleaner v6.000 - *Logfile created 13/08/2016 *at 09:21:59
# *Updated on 12/08/2016 by ToolsLib
# *Database : 2016-08-12.4 [*Server]
# *Operating System : Windows 10 Home (X64)
# *Username : Tomas - TOM
# *Running from : C:\Users\Tomas\Desktop\adwcleaner_6.000.exe
# *Mode: Clean
# *Support : https://toolslib.net/forum
***** [ *Services ] *****
[-] *Service deleted: vToolbarUpdater40.3.2
[-] *Service deleted: WtuSystemSupport
***** [ *Folders ] *****
[-] *Folder deleted: C:\Users\Tomas\AppData\Local\Mail.Ru
[-] *Folder deleted: C:\Users\Tomas\AppData\Local\PackageAware
[-] *Folder deleted: C:\Users\Tomas\AppData\Local\pokki
[-] *Folder deleted: C:\Users\Tomas\AppData\Local\avg web tuneup
[-] *Folder deleted: C:\Users\Tomas\AppData\Roaming\MailProducts
[-] *Folder deleted: C:\Program Files\avg web tuneup
[-] *Folder deleted: C:\Program Files\Common Files\AVG Secure Search
[-] *Folder deleted: C:\ProgramData\AVG Security Toolbar
[-] *Folder deleted: C:\ProgramData\Mail.Ru
[-] *Folder deleted: C:\ProgramData\pokki
[-] *Folder deleted: C:\ProgramData\avg web tuneup
[-] *Folder deleted: C:\Program Files (x86)\avg web tuneup
[-] *Folder deleted: C:\Program Files (x86)\Common Files\AVG Secure Search
[-] *Folder deleted: C:\Users\Default User\AppData\Local\Pokki
[#] *Folder deleted on reboot: C:\Users\Default\AppData\Local\Pokki
[-] *Folder deleted: C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\9m90ucow.default\extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}
[-] *Folder deleted: C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\9m90ucow.default\extensions\search@mail.ru
[-] *Folder deleted: C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\9m90ucow.default\extensions\homepage@mail.ru
***** [ *Files ] *****
[-] *File deleted: C:\Users\Tomas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Goodgame Empire.lnk
[-] *File deleted: C:\Users\Tomas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Goodgame Empire.lnk
[-] *File deleted: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk
[-] *File deleted: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
[-] *File deleted: C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\9m90ucow.default\extensions\Avg@toolbar.xpi
[-] *File deleted: C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\9m90ucow.default\searchplugins\avg-secure-search.xml
***** [ DLL ] *****
***** [ WMI ] *****
***** [ *Shortcuts ] *****
***** [ *Scheduled Tasks ] *****
[-] *Task deleted: ACC
[-] *Task deleted: Software Update Application
***** [ *Registry ] *****
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Classes\pokki
[#] *Key deleted on reboot: HKCU\Software\Classes\pokki
[-] *Key deleted: HKLM\SOFTWARE\Classes\dream.capture
[-] *Key deleted: HKLM\SOFTWARE\Classes\Prod.cap
[-] *Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd
[-] *Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd.1
[-] *Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi
[-] *Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi.1
[-] *Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
[-] *Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
[-] *Key deleted: HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj
[-] *Key deleted: HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj.1
[-] *Key deleted: [x64] HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] *Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
[-] *Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}
[-] *Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] *Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}
[-] *Key deleted: HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
[-] *Key deleted: HKLM\SOFTWARE\Classes\Interface\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}
[-] *Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
[-] *Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
[-] *Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] *Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099}
[-] *Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\OCS
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Pokki
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Mail.Ru
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\AppDataLow\Software\Mail.Ru
[#] *Key deleted on reboot: HKCU\Software\OCS
[#] *Key deleted on reboot: HKCU\Software\Pokki
[#] *Key deleted on reboot: HKCU\Software\Mail.Ru
[#] *Key deleted on reboot: HKCU\Software\AppDataLow\Software\Mail.Ru
[-] *Key deleted: HKLM\SOFTWARE\AVG Tuneup
[-] *Data restored: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] *Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
[-] *Data restored: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[#] *Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[#] *Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
[-] *Data restored: HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[-] *Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\mpc.am
[-] *Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\search.mpc.am
[-] *Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\mpc.am
[-] *Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\search.mpc.am
[-] *Key deleted: HKCU\Software\Classes\AllFileSystemObjects\shell\pokki
[-] *Key deleted: HKCU\Software\Classes\Directory\shell\pokki
[-] *Key deleted: HKCU\Software\Classes\Drive\shell\pokki
[-] *Key deleted: HKCU\Software\Classes\lnkfile\shell\pokki
[-] *Key deleted: HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
[-] *Key deleted: HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
***** [ *Browsers ] *****
[-] *Firefox preferences cleaned: "browser.search.defaultenginename" - "Поиск@Mail.Ru"
[-] *Firefox preferences cleaned: "browser.search.selectedEngine" - "Поиск@Mail.Ru"
[-] *Firefox preferences cleaned: "browser.startup.homepage" - "hxxps://mail.ru/cnt/11956636?fr=ffhp1.0.2&gp=811009"
[-] [google] [Search Provider] *Deleted: google
*************************
:: *"Tracing" keys deleted
:: *Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [8680 *Bytes] - [13/08/2016 09:21:59]
C:\AdwCleaner\AdwCleaner[S0].txt - [8616 *Bytes] - [13/08/2016 09:17:43]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [8828 *Bytes] ##########
Moc dekuji za pomoc, prikladam log:
# AdwCleaner v6.000 - *Logfile created 13/08/2016 *at 09:21:59
# *Updated on 12/08/2016 by ToolsLib
# *Database : 2016-08-12.4 [*Server]
# *Operating System : Windows 10 Home (X64)
# *Username : Tomas - TOM
# *Running from : C:\Users\Tomas\Desktop\adwcleaner_6.000.exe
# *Mode: Clean
# *Support : https://toolslib.net/forum
***** [ *Services ] *****
[-] *Service deleted: vToolbarUpdater40.3.2
[-] *Service deleted: WtuSystemSupport
***** [ *Folders ] *****
[-] *Folder deleted: C:\Users\Tomas\AppData\Local\Mail.Ru
[-] *Folder deleted: C:\Users\Tomas\AppData\Local\PackageAware
[-] *Folder deleted: C:\Users\Tomas\AppData\Local\pokki
[-] *Folder deleted: C:\Users\Tomas\AppData\Local\avg web tuneup
[-] *Folder deleted: C:\Users\Tomas\AppData\Roaming\MailProducts
[-] *Folder deleted: C:\Program Files\avg web tuneup
[-] *Folder deleted: C:\Program Files\Common Files\AVG Secure Search
[-] *Folder deleted: C:\ProgramData\AVG Security Toolbar
[-] *Folder deleted: C:\ProgramData\Mail.Ru
[-] *Folder deleted: C:\ProgramData\pokki
[-] *Folder deleted: C:\ProgramData\avg web tuneup
[-] *Folder deleted: C:\Program Files (x86)\avg web tuneup
[-] *Folder deleted: C:\Program Files (x86)\Common Files\AVG Secure Search
[-] *Folder deleted: C:\Users\Default User\AppData\Local\Pokki
[#] *Folder deleted on reboot: C:\Users\Default\AppData\Local\Pokki
[-] *Folder deleted: C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\9m90ucow.default\extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}
[-] *Folder deleted: C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\9m90ucow.default\extensions\search@mail.ru
[-] *Folder deleted: C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\9m90ucow.default\extensions\homepage@mail.ru
***** [ *Files ] *****
[-] *File deleted: C:\Users\Tomas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Goodgame Empire.lnk
[-] *File deleted: C:\Users\Tomas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Goodgame Empire.lnk
[-] *File deleted: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk
[-] *File deleted: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
[-] *File deleted: C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\9m90ucow.default\extensions\Avg@toolbar.xpi
[-] *File deleted: C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\9m90ucow.default\searchplugins\avg-secure-search.xml
***** [ DLL ] *****
***** [ WMI ] *****
***** [ *Shortcuts ] *****
***** [ *Scheduled Tasks ] *****
[-] *Task deleted: ACC
[-] *Task deleted: Software Update Application
***** [ *Registry ] *****
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Classes\pokki
[#] *Key deleted on reboot: HKCU\Software\Classes\pokki
[-] *Key deleted: HKLM\SOFTWARE\Classes\dream.capture
[-] *Key deleted: HKLM\SOFTWARE\Classes\Prod.cap
[-] *Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd
[-] *Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd.1
[-] *Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi
[-] *Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi.1
[-] *Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
[-] *Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
[-] *Key deleted: HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj
[-] *Key deleted: HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj.1
[-] *Key deleted: [x64] HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] *Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
[-] *Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}
[-] *Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] *Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}
[-] *Key deleted: HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
[-] *Key deleted: HKLM\SOFTWARE\Classes\Interface\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}
[-] *Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
[-] *Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
[-] *Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] *Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099}
[-] *Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\OCS
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Pokki
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Mail.Ru
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\AppDataLow\Software\Mail.Ru
[#] *Key deleted on reboot: HKCU\Software\OCS
[#] *Key deleted on reboot: HKCU\Software\Pokki
[#] *Key deleted on reboot: HKCU\Software\Mail.Ru
[#] *Key deleted on reboot: HKCU\Software\AppDataLow\Software\Mail.Ru
[-] *Key deleted: HKLM\SOFTWARE\AVG Tuneup
[-] *Data restored: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] *Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] *Key deleted: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
[-] *Data restored: HKU\S-1-5-21-854127422-758981130-2822688003-1001\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[#] *Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[#] *Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
[-] *Data restored: HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[-] *Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\mpc.am
[-] *Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\search.mpc.am
[-] *Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\mpc.am
[-] *Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\search.mpc.am
[-] *Key deleted: HKCU\Software\Classes\AllFileSystemObjects\shell\pokki
[-] *Key deleted: HKCU\Software\Classes\Directory\shell\pokki
[-] *Key deleted: HKCU\Software\Classes\Drive\shell\pokki
[-] *Key deleted: HKCU\Software\Classes\lnkfile\shell\pokki
[-] *Key deleted: HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
[-] *Key deleted: HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
***** [ *Browsers ] *****
[-] *Firefox preferences cleaned: "browser.search.defaultenginename" - "Поиск@Mail.Ru"
[-] *Firefox preferences cleaned: "browser.search.selectedEngine" - "Поиск@Mail.Ru"
[-] *Firefox preferences cleaned: "browser.startup.homepage" - "hxxps://mail.ru/cnt/11956636?fr=ffhp1.0.2&gp=811009"
[-] [google] [Search Provider] *Deleted: google
*************************
:: *"Tracing" keys deleted
:: *Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [8680 *Bytes] - [13/08/2016 09:21:59]
C:\AdwCleaner\AdwCleaner[S0].txt - [8616 *Bytes] - [13/08/2016 09:17:43]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [8828 *Bytes] ##########
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Mail.ru v Mozille a MPC safe navigation v MS Edge
Dejte nový log FRST.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Mail.ru v Mozille a MPC safe navigation v MS Edge
Zdravim,
Log je v priloze. Diky
Log je v priloze. Diky
- Přílohy
-
- Log + Addition 2.rar
- (76.41 KiB) Staženo 68 x
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Mail.ru v Mozille a MPC safe navigation v MS Edge
Otevřte poznámkový blok a zkopírujte do něj:
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.Start
HKU\S-1-5-21-854127422-758981130-2822688003-1001\...\MountPoints2: {a03cf539-8a54-11e5-8d6c-bbf6e58533e3} - "F:\setup.exe"
GroupPolicy: Restriction - Chrome <======= ATTENTION
SearchScopes: HKU\S-1-5-21-854127422-758981130-2822688003-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-854127422-758981130-2822688003-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
FF SelectedSearchEngine: Поиск@Mail.Ru
FF Homepage: hxxps://mail.ru/cnt/11956636?fr=ffhp1.0.2&gp=811009
FF Keyword.URL: hxxp://go.mail.ru/distib/ep/?product_id=%7B189B4C8C-4458-4D4B-8591-EC0EF4F8D103%7D&gp=811010
FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\msc\npMcSnFFPl.dll [No File]
FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll [No File]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor => not found
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\Tomas\AppData\Local\Вoйти в Интeрнет
C:\Users\Tomas\AppData\Local\Поиcк в Интeрнете
C:\WINDOWS\System32\Tasks\{CE8B4BEC-65DE-476C-8A94-CB4E7A1B37C9}
C:\Users\Tomas\AppData\Local\Temp
Task: {3914D91E-BA94-41A3-8709-F1D0B623B648} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {92E40279-C251-4264-8141-C2F07DA5189A} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {9B438DA0-3F63-42EA-B936-51DA1C4D1EA9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {B140B42B-D7D1-4265-9B05-24F05EDC7F6B} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {C4486066-1DBA-4C4E-B0FD-4C2170010F35} - \WPD\SqmUpload_S-1-5-21-854127422-758981130-2822688003-1001 -> No File <==== ATTENTION
Task: {EF54C8FE-AA21-4DB2-90FF-C01B0B351ECF} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Mail.ru v Mozille a MPC safe navigation v MS Edge
Zdravim, log:
Fix result of Farbar Recovery Scan Tool (x64) Version: 11-08-2016 01
Ran by Tomas (2016-08-13 21:12:17) Run:1
Running from C:\Users\Tomas\Desktop
Loaded Profiles: Tomas (Available Profiles: Tomas)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
HKU\S-1-5-21-854127422-758981130-2822688003-1001\...\MountPoints2: {a03cf539-8a54-11e5-8d6c-bbf6e58533e3} - "F:\setup.exe"
GroupPolicy: Restriction - Chrome <======= ATTENTION
SearchScopes: HKU\S-1-5-21-854127422-758981130-2822688003-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-854127422-758981130-2822688003-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
FF SelectedSearchEngine: ?????@Mail.Ru
FF Homepage: hxxps://mail.ru/cnt/11956636?fr=ffhp1.0.2&gp=811009
FF Keyword.URL: hxxp://go.mail.ru/distib/ep/?product_id ... &gp=811010
FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\msc\npMcSnFFPl.dll [No File]
FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll [No File]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor => not found
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\Tomas\AppData\Local\?o??? ? ???e????
C:\Users\Tomas\AppData\Local\???c? ? ???e?????
C:\WINDOWS\System32\Tasks\{CE8B4BEC-65DE-476C-8A94-CB4E7A1B37C9}
C:\Users\Tomas\AppData\Local\Temp
Task: {3914D91E-BA94-41A3-8709-F1D0B623B648} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {92E40279-C251-4264-8141-C2F07DA5189A} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {9B438DA0-3F63-42EA-B936-51DA1C4D1EA9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {B140B42B-D7D1-4265-9B05-24F05EDC7F6B} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {C4486066-1DBA-4C4E-B0FD-4C2170010F35} - \WPD\SqmUpload_S-1-5-21-854127422-758981130-2822688003-1001 -> No File <==== ATTENTION
Task: {EF54C8FE-AA21-4DB2-90FF-C01B0B351ECF} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
*****************
"HKU\S-1-5-21-854127422-758981130-2822688003-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a03cf539-8a54-11e5-8d6c-bbf6e58533e3}" => key removed successfully
HKCR\CLSID\{a03cf539-8a54-11e5-8d6c-bbf6e58533e3} => key not found.
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKU\S-1-5-21-854127422-758981130-2822688003-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-854127422-758981130-2822688003-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
Firefox SelectedSearchEngine removed successfully
Firefox "homepage" removed successfully
Firefox "Keyword.URL" removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@mcafee.com/MSC,version=10" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@mcafee.com/SAFFPlugin" => key removed successfully
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92} => value removed successfully
HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\msktbird@mcafee.com => value removed successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"C:\Users\Tomas\AppData\Local\?o??? ? ???e????" => not found.
"C:\Users\Tomas\AppData\Local\???c? ? ???e?????" => not found.
C:\WINDOWS\System32\Tasks\{CE8B4BEC-65DE-476C-8A94-CB4E7A1B37C9} => moved successfully
"C:\Users\Tomas\AppData\Local\Temp" folder move:
Could not move "C:\Users\Tomas\AppData\Local\Temp" => Scheduled to move on reboot.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3914D91E-BA94-41A3-8709-F1D0B623B648}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3914D91E-BA94-41A3-8709-F1D0B623B648}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{92E40279-C251-4264-8141-C2F07DA5189A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{92E40279-C251-4264-8141-C2F07DA5189A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9B438DA0-3F63-42EA-B936-51DA1C4D1EA9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B438DA0-3F63-42EA-B936-51DA1C4D1EA9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B140B42B-D7D1-4265-9B05-24F05EDC7F6B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B140B42B-D7D1-4265-9B05-24F05EDC7F6B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C4486066-1DBA-4C4E-B0FD-4C2170010F35}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4486066-1DBA-4C4E-B0FD-4C2170010F35}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-854127422-758981130-2822688003-1001" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EF54C8FE-AA21-4DB2-90FF-C01B0B351ECF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EF54C8FE-AA21-4DB2-90FF-C01B0B351ECF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2016-08-13 21:14:43)
C:\Users\Tomas\AppData\Local\Temp => moved successfully
==== End of Fixlog 21:14:44 ====
Fix result of Farbar Recovery Scan Tool (x64) Version: 11-08-2016 01
Ran by Tomas (2016-08-13 21:12:17) Run:1
Running from C:\Users\Tomas\Desktop
Loaded Profiles: Tomas (Available Profiles: Tomas)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
HKU\S-1-5-21-854127422-758981130-2822688003-1001\...\MountPoints2: {a03cf539-8a54-11e5-8d6c-bbf6e58533e3} - "F:\setup.exe"
GroupPolicy: Restriction - Chrome <======= ATTENTION
SearchScopes: HKU\S-1-5-21-854127422-758981130-2822688003-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-854127422-758981130-2822688003-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
FF SelectedSearchEngine: ?????@Mail.Ru
FF Homepage: hxxps://mail.ru/cnt/11956636?fr=ffhp1.0.2&gp=811009
FF Keyword.URL: hxxp://go.mail.ru/distib/ep/?product_id ... &gp=811010
FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\msc\npMcSnFFPl.dll [No File]
FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll [No File]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor => not found
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\Tomas\AppData\Local\?o??? ? ???e????
C:\Users\Tomas\AppData\Local\???c? ? ???e?????
C:\WINDOWS\System32\Tasks\{CE8B4BEC-65DE-476C-8A94-CB4E7A1B37C9}
C:\Users\Tomas\AppData\Local\Temp
Task: {3914D91E-BA94-41A3-8709-F1D0B623B648} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {92E40279-C251-4264-8141-C2F07DA5189A} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {9B438DA0-3F63-42EA-B936-51DA1C4D1EA9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {B140B42B-D7D1-4265-9B05-24F05EDC7F6B} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {C4486066-1DBA-4C4E-B0FD-4C2170010F35} - \WPD\SqmUpload_S-1-5-21-854127422-758981130-2822688003-1001 -> No File <==== ATTENTION
Task: {EF54C8FE-AA21-4DB2-90FF-C01B0B351ECF} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
*****************
"HKU\S-1-5-21-854127422-758981130-2822688003-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a03cf539-8a54-11e5-8d6c-bbf6e58533e3}" => key removed successfully
HKCR\CLSID\{a03cf539-8a54-11e5-8d6c-bbf6e58533e3} => key not found.
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKU\S-1-5-21-854127422-758981130-2822688003-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-854127422-758981130-2822688003-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
Firefox SelectedSearchEngine removed successfully
Firefox "homepage" removed successfully
Firefox "Keyword.URL" removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@mcafee.com/MSC,version=10" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@mcafee.com/SAFFPlugin" => key removed successfully
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92} => value removed successfully
HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\msktbird@mcafee.com => value removed successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"C:\Users\Tomas\AppData\Local\?o??? ? ???e????" => not found.
"C:\Users\Tomas\AppData\Local\???c? ? ???e?????" => not found.
C:\WINDOWS\System32\Tasks\{CE8B4BEC-65DE-476C-8A94-CB4E7A1B37C9} => moved successfully
"C:\Users\Tomas\AppData\Local\Temp" folder move:
Could not move "C:\Users\Tomas\AppData\Local\Temp" => Scheduled to move on reboot.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3914D91E-BA94-41A3-8709-F1D0B623B648}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3914D91E-BA94-41A3-8709-F1D0B623B648}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{92E40279-C251-4264-8141-C2F07DA5189A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{92E40279-C251-4264-8141-C2F07DA5189A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9B438DA0-3F63-42EA-B936-51DA1C4D1EA9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B438DA0-3F63-42EA-B936-51DA1C4D1EA9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B140B42B-D7D1-4265-9B05-24F05EDC7F6B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B140B42B-D7D1-4265-9B05-24F05EDC7F6B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C4486066-1DBA-4C4E-B0FD-4C2170010F35}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4486066-1DBA-4C4E-B0FD-4C2170010F35}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-854127422-758981130-2822688003-1001" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EF54C8FE-AA21-4DB2-90FF-C01B0B351ECF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EF54C8FE-AA21-4DB2-90FF-C01B0B351ECF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2016-08-13 21:14:43)
C:\Users\Tomas\AppData\Local\Temp => moved successfully
==== End of Fixlog 21:14:44 ====
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Mail.ru v Mozille a MPC safe navigation v MS Edge
Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Mail.ru v Mozille a MPC safe navigation v MS Edge
Zdravim, je to v poradku. moc dekuji za pomoc:-) Poslal jsem na ucet nejakou korunu. Hezky zbytek vikendu.
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Mail.ru v Mozille a MPC safe navigation v MS Edge
Hezký zbytek i vám a nemáte zač. Za příspěvek děkujeme! 
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Přispějete na provoz fóra?