Stránka 2 z 3

Re: default-search.net jako homepage

Napsal: 14 črc 2014 22:21
od Kenny123
aha, jojo máte pravdu, a já si říkal že se to mělo restartovat a ono nic, ok tedy zde:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:13-07-2014 01
Ran by Radim at 2014-07-14 23:13:58 Run:1
Running from C:\Users\Radim\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-2847674021-541428230-2807636112-1007\...\MountPoints2: {a2b76294-1c0d-11df-9c30-00241dd74c45} - D:\start.exe

SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - URL http://search.certified-toolbar.com?si= ... 04065E0&q={searchTerms}
SearchScopes: HKLM - SuggestionsURL_JSON http://api.widdit.com/suggestions/?form ... 1&command={searchTerms}
SearchScopes: HKLM - TopResultURLFallback http://search.certified-toolbar.com?si= ... 04065E0&q={searchTerms}
SearchScopes: HKLM - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}

S2 Update DoughGo; "C:\Program Files\DoughGo\updateDoughGo.exe" [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S1 iSafeKrnlKit; \??\C:\Program Files\iSafe\iSafeKrnlKit.sys [X]
S1 iSafeKrnlR3; \??\C:\Program Files\iSafe\iSafeKrnlR3.sys [X]
S1 {735c7dda-e3b7-44f2-8521-a39cc0d289b2}Gw; system32\drivers\{735c7dda-e3b7-44f2-8521-a39cc0d289b2}Gw.sys [X]

2014-07-13 23:26 - 2014-07-13 23:27 - 00010205 _____ () C:\Users\Radim\Desktop\FRST.txt
2014-07-13 23:15 - 2014-07-13 23:15 - 00000000 _____ () C:\Users\Radim\Desktop\FRSTLauncher_exe.fr27l6g.partial
2014-07-13 23:01 - 2014-07-13 23:01 - 00000000 _____ () C:\Users\Radim\Desktop\FRSTLauncher_exe.sz34zyg.partial
2014-07-13 22:58 - 2014-07-13 22:58 - 00000000 _____ () C:\Users\Radim\Desktop\FRSTLauncher.exe.ta63azi.partial
2014-07-13 22:20 - 2014-07-13 22:03 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-07-13 22:05 - 2014-07-13 22:21 - 00023685 _____ () C:\zoek-results.log
2014-07-13 22:03 - 2014-07-13 22:16 - 00000000 ____D () C:\zoek_backup
2014-07-13 22:02 - 2014-07-13 22:02 - 01285120 _____ () C:\Users\Radim\Desktop\zoek.exe
2014-07-13 21:44 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-07-13 21:43 - 2014-07-13 21:45 - 00000000 ____D () C:\AdwCleaner
2014-07-13 21:42 - 2014-07-13 21:42 - 01348263 _____ () C:\Users\Radim\Desktop\adwcleaner_3.215.exe
2014-07-13 21:41 - 2014-07-13 21:41 - 00066371 _____ () C:\Users\Radim\Desktop\JRT2.txt
2014-07-13 21:34 - 2014-07-13 21:34 - 00066371 _____ () C:\Users\Radim\Desktop\JRT.txt
2014-07-13 21:29 - 2014-07-13 21:29 - 00000000 ____D () C:\Windows\ERUNT
2014-07-13 21:27 - 2014-07-13 21:28 - 01016261 _____ (Thisisu) C:\Users\Radim\Desktop\JRT.exe
2014-07-13 20:13 - 2014-07-13 20:15 - 00000000 ____D () C:\rsit
2014-07-13 20:10 - 2014-07-13 22:20 - 00001750 _____ () C:\Windows\PFRO.log
2014-07-13 20:02 - 2014-07-13 20:03 - 01107968 _____ () C:\Users\Radim\Desktop\RSIT.exe
2014-07-13 20:01 - 2014-07-13 20:01 - 00461038 _____ () C:\Users\Radim\Desktop\RSIT.exe.4hoeo13.partial
2014-07-03 23:47 - 2014-07-03 23:48 - 04814144 _____ (Piriform Ltd) C:\Users\Radim\Downloads\ccsetup415pro (2).exe
2014-07-03 23:42 - 2014-07-03 23:43 - 04814144 _____ (Piriform Ltd) C:\Users\Radim\Downloads\ccsetup415pro (1).exe
2014-07-03 23:42 - 2014-07-03 23:42 - 04814144 _____ (Piriform Ltd) C:\Users\Radim\Downloads\ccsetup415pro.exe

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

Hosts:
Reboot:
End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => value deleted successfully.
'HKU\S-1-5-21-2847674021-541428230-2807636112-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a2b76294-1c0d-11df-9c30-00241dd74c45}' => Key deleted successfully.
'HKCR\CLSID\{a2b76294-1c0d-11df-9c30-00241dd74c45}'=> Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL http://search.certified-toolbar.com?si= ... => Value not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON http://api.widdit.com/suggestions/?form ... => Value not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\TopResultURLFallback http://search.certified-toolbar.com?si= ... => Value not found.
'HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}' => Key deleted successfully.
'HKCR\CLSID\{0191A6B0-1154-4C22-9182-23A95BBE92D9}'=> Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}' => Key deleted successfully.
'HKCR\CLSID\{0191A6B0-1154-4C22-9182-23A95BBE92D9}'=> Key not found.
'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}' => Key deleted successfully.
'HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}'=> Key not found.
Update DoughGo => Service not found.
esgiguard => Service deleted successfully.
gdrv => Service deleted successfully.
iSafeKrnlKit => Service deleted successfully.
iSafeKrnlR3 => Service deleted successfully.
{735c7dda-e3b7-44f2-8521-a39cc0d289b2}Gw => Service deleted successfully.
C:\Users\Radim\Desktop\FRST.txt => Moved successfully.
C:\Users\Radim\Desktop\FRSTLauncher_exe.fr27l6g.partial => Moved successfully.
C:\Users\Radim\Desktop\FRSTLauncher_exe.sz34zyg.partial => Moved successfully.
C:\Users\Radim\Desktop\FRSTLauncher.exe.ta63azi.partial => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Radim\Desktop\zoek.exe => Moved successfully.
C:\Windows\system32\sqlite3.dll => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Radim\Desktop\adwcleaner_3.215.exe => Moved successfully.
C:\Users\Radim\Desktop\JRT2.txt => Moved successfully.
C:\Users\Radim\Desktop\JRT.txt => Moved successfully.
C:\Windows\ERUNT => Moved successfully.
C:\Users\Radim\Desktop\JRT.exe => Moved successfully.
C:\rsit => Moved successfully.
"C:\Windows\PFRO.log" => File/Directory not found.
C:\Users\Radim\Desktop\RSIT.exe => Moved successfully.
C:\Users\Radim\Desktop\RSIT.exe.4hoeo13.partial => Moved successfully.
C:\Users\Radim\Downloads\ccsetup415pro (2).exe => Moved successfully.
C:\Users\Radim\Downloads\ccsetup415pro (1).exe => Moved successfully.
C:\Users\Radim\Downloads\ccsetup415pro.exe => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.


The system needed a reboot.

==== End of Fixlog ====

Re: default-search.net jako homepage

Napsal: 15 črc 2014 05:24
od vyosek
Jak se chova PC???

Re: default-search.net jako homepage

Napsal: 15 črc 2014 17:32
od Kenny123
Ten default search.net jako nechtěná homepage už není, drží normálně Seznam :thumbsup: ( už po začátku našeho působení :wub: ) Spuštění PC je normální. Největší problém je Internet, bez varování během zlomku vteřiny aplikace zavře natvrdo všechny okna prohlížeče! (exprorer) Tak 2x do hodiny určitě :shock: Naštěstí když se klikne že neočekávaná relace to zavřela, tak obnovit jde a člověk může pokračovat. (dřív to nebylo, na nějaké nové stránky nechodím). Nějak déle najíždění oblíbené položky. :?: Jinak ale hlavně na první pohled už intenzivně nepracuje (chrochtání hdd + kontrolka) v době, když nemá resp se otevírá se obyčejná www stránka. V době default search pracoval fakt moooooc usilovně. V době našeho působení se mi zdá že jsem přišel o VLC player, ale byl freeware, tak to kdyžtak někde stáhnu.

Jinak, teď to asi s tím nesouvisí, ale tak už cca 2-3 měsíce se jak by "ucpává" . Že se víc zanáší ty mezipaměti nebo jak to popsat. Např dřív jsem z jednoho USB disku na druhý USB disk zkopíroval 50GB (pár filmů) bez mrknutí oka na jeden zátah. Dneska se to sekne. Tak je to třeba dělat po 5 max 10GB. A pak je problém aby se zobrazili všechny ikony ve složce, když jich je tam třeba 20 a jsou jako miniatury. Ostatní jsou bílé a trvá než (pokud vůbec) najedou. Vždycky "poluxuju" CCleanerem a hlavně TFC (klidně Gb pomaže) a je to OK, ale jen dočasně. Dřív se to tak neucpávalo a nebylo "poluxovat" třeba tak často a najely všechny všechny složky či velká plejáda miniatur obrázků hned. Tak kdyby šlo nějak omezit ten prostor mezipaměti nebo jak to říct, byla by to super :all_coholic:

ps: budem prosím ComboFixovat? silné kalibry co to požerou z gruntu mně lákají :D
ps2: mám aktuální CCleaner Free? v4.15.4725 ještě nikdy se mi to (aspoň si to myslím) nepovedlo aktualizovat, zde bude problém spíš mezi klávesnicí a židlí :o

Re: default-search.net jako homepage

Napsal: 15 črc 2014 21:41
od vyosek
:arrow: Stahnete Malwarebytes Anti-Rootkit http://www.bleepingcomputer.com/downloa ... i-rootkit/
  • Ulozte nejlepe na Plochu a rozbalte
  • Spustte kliknutim na mbar
  • Nyni postupne kliknete na Next a Update
  • Po dokonceni update (aktualizace) databaze kliknete opet na Next
  • Nechte zaskrtnute vsechny tri moznosti a klinete na Scan cimz spustite prohledavani PC
  • Po dokonceni skenu (cca 5 minutek) zkontrolujte, zda-li je u vsech nalezu (samozrejme pokud budou) zatrzitko
  • Tez zkontrolujte, jetsli je zatrzitko u Create Restore point
  • Nyni kliknete na CleanUp cimz nalezenou infekci odstranime
  • PC bude restartovan
  • Slozka mbar by mela obsahovat log (a zrejme se i sam otevre) mbar-log-rok-mesic-den (hodina-minuta-sekunda).txt, ten mi sem dejte

Re: default-search.net jako homepage

Napsal: 16 črc 2014 01:29
od Kenny123
Našlo to jeden v oblíbených. Jinak všechno šlo jak jste psal, pohoda. Akorát se to nerestartovalo... Log ze složky mbar zde:

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1012

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x86

Account is Administrative

Internet Explorer version: 11.0.9600.17207

Java version: 1.6.0_20

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.999000 GHz
Memory total: 2145902592, free: 1081823232

Downloaded database version: v2014.07.15.15
Downloaded database version: v2014.07.14.01
Initializing...
======================
------------ Kernel report ------------
07/16/2014 01:21:07
------------ Loaded modules -----------
\SystemRoot\system32\ntkrnlpa.exe
\SystemRoot\system32\halmacpi.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\system32\drivers\pciide.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\system32\DRIVERS\Lbd.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\System32\Drivers\aswVmm.sys
\SystemRoot\System32\Drivers\aswRvrt.sys
\SystemRoot\system32\drivers\cdrom.sys
\SystemRoot\system32\drivers\aswSnx.sys
\SystemRoot\system32\drivers\aswSP.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\aswRdr2.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\atikmdag.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\Rt86win7.sys
\SystemRoot\system32\DRIVERS\serial.sys
\SystemRoot\system32\DRIVERS\serenum.sys
\SystemRoot\system32\DRIVERS\parport.sys
\SystemRoot\system32\drivers\i8042prt.sys
\SystemRoot\system32\drivers\mouclass.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\drivers\kbdclass.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\RTKVHDA.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\drivers\hidusb.sys
\SystemRoot\system32\drivers\HIDCLASS.SYS
\SystemRoot\system32\drivers\HIDPARSE.SYS
\SystemRoot\system32\drivers\kbdhid.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\aswMonFlt.sys
\SystemRoot\system32\drivers\aswStm.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\parvdm.sys
\SystemRoot\system32\drivers\aswHwid.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\imm32.dll
\Windows\System32\ws2_32.dll
\Windows\System32\urlmon.dll
\Windows\System32\kernel32.dll
\Windows\System32\shlwapi.dll
\Windows\System32\psapi.dll
\Windows\System32\msvcrt.dll
\Windows\System32\difxapi.dll
\Windows\System32\Wldap32.dll
\Windows\System32\ole32.dll
\Windows\System32\advapi32.dll
\Windows\System32\msctf.dll
\Windows\System32\sechost.dll
\Windows\System32\lpk.dll
\Windows\System32\usp10.dll
\Windows\System32\clbcatq.dll
\Windows\System32\iertutil.dll
\Windows\System32\comdlg32.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\imagehlp.dll
\Windows\System32\nsi.dll
\Windows\System32\normaliz.dll
\Windows\System32\gdi32.dll
\Windows\System32\setupapi.dll
\Windows\System32\oleaut32.dll
\Windows\System32\wininet.dll
\Windows\System32\user32.dll
\Windows\System32\shell32.dll
\Windows\System32\comctl32.dll
\Windows\System32\wintrust.dll
\Windows\System32\userenv.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\KernelBase.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\crypt32.dll
\Windows\System32\devobj.dll
\Windows\System32\msasn1.dll
\Windows\System32\profapi.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk4\DR4
Upper Device Object: 0xffffffff86811ac8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\0000006b\
Lower Device Object: 0xffffffff86814698
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk3\DR3
Upper Device Object: 0xffffffff86811030
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\0000006a\
Lower Device Object: 0xffffffff855e1030
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk2\DR2
Upper Device Object: 0xffffffff86813ac8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000069\
Lower Device Object: 0xffffffff855e13b8
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR1
Upper Device Object: 0xffffffff86813030
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000068\
Lower Device Object: 0xffffffff86812cb8
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff85a587a0
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP3T0L0-3\
Lower Device Object: 0xffffffff85986030
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff85a587a0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff85a583d8, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff85a587a0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff8597e918, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xffffffff85986030, DeviceName: \Device\Ide\IdeDeviceP3T0L0-3\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: B07B7292

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 579584
Partition file system is NTFS
Partition is bootable

Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 581632 Numsec = 311996416

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 160041885696 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-2047-312561808-312581808)...
Done!
Physical Sector Size: 0
Drive: 1, DevicePointer: 0xffffffff86813030, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff86814378, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff86813030, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86812cb8, DeviceName: \Device\00000068\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 2, DevicePointer: 0xffffffff86813ac8, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff868124a8, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff86813ac8, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff855e13b8, DeviceName: \Device\00000069\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 3, DevicePointer: 0xffffffff86811030, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff86814d10, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff86811030, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff855e1030, DeviceName: \Device\0000006a\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 4, DevicePointer: 0xffffffff86811ac8, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff86812998, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff86811ac8, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86814698, DeviceName: \Device\0000006b\, DriverName: \Driver\USBSTOR\
------------ End ----------
Infected: C:\Users\Radim\Favorites\Free Porn Hot Hardcore Sex Pics and Video - xxxporn.com.url --> [Rogue.Link]
Scan finished
Creating System Restore point...
Cleaning up...
Removal successful. No system shutdown is required.
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1012

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x86

Account is Administrative

Internet Explorer version: 11.0.9600.17207

Java version: 1.6.0_20

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.999000 GHz
Memory total: 2145902592, free: 1079341056

=======================================


---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1012

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x86

Account is Administrative

Internet Explorer version: 11.0.9600.17207

Java version: 1.6.0_20

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.999000 GHz
Memory total: 2145902592, free: 1060655104

Downloaded database version: v2014.07.15.15
Downloaded database version: v2014.07.14.01
=======================================
Initializing...
------------ Kernel report ------------
07/16/2014 02:18:31
------------ Loaded modules -----------
\SystemRoot\system32\ntkrnlpa.exe
\SystemRoot\system32\halmacpi.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\system32\drivers\pciide.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\system32\DRIVERS\Lbd.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\System32\Drivers\aswVmm.sys
\SystemRoot\System32\Drivers\aswRvrt.sys
\SystemRoot\system32\drivers\cdrom.sys
\SystemRoot\system32\drivers\aswSnx.sys
\SystemRoot\system32\drivers\aswSP.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\aswRdr2.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\atikmdag.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\Rt86win7.sys
\SystemRoot\system32\DRIVERS\serial.sys
\SystemRoot\system32\DRIVERS\serenum.sys
\SystemRoot\system32\DRIVERS\parport.sys
\SystemRoot\system32\drivers\i8042prt.sys
\SystemRoot\system32\drivers\mouclass.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\drivers\kbdclass.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\RTKVHDA.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\drivers\hidusb.sys
\SystemRoot\system32\drivers\HIDCLASS.SYS
\SystemRoot\system32\drivers\HIDPARSE.SYS
\SystemRoot\system32\drivers\kbdhid.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\aswMonFlt.sys
\SystemRoot\system32\drivers\aswStm.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\parvdm.sys
\SystemRoot\system32\drivers\aswHwid.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\imm32.dll
\Windows\System32\ws2_32.dll
\Windows\System32\urlmon.dll
\Windows\System32\kernel32.dll
\Windows\System32\shlwapi.dll
\Windows\System32\psapi.dll
\Windows\System32\msvcrt.dll
\Windows\System32\difxapi.dll
\Windows\System32\Wldap32.dll
\Windows\System32\ole32.dll
\Windows\System32\advapi32.dll
\Windows\System32\msctf.dll
\Windows\System32\sechost.dll
\Windows\System32\lpk.dll
\Windows\System32\usp10.dll
\Windows\System32\clbcatq.dll
\Windows\System32\iertutil.dll
\Windows\System32\comdlg32.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\imagehlp.dll
\Windows\System32\nsi.dll
\Windows\System32\normaliz.dll
\Windows\System32\gdi32.dll
\Windows\System32\setupapi.dll
\Windows\System32\oleaut32.dll
\Windows\System32\wininet.dll
\Windows\System32\user32.dll
\Windows\System32\shell32.dll
\Windows\System32\comctl32.dll
\Windows\System32\wintrust.dll
\Windows\System32\userenv.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\KernelBase.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\crypt32.dll
\Windows\System32\devobj.dll
\Windows\System32\msasn1.dll
\Windows\System32\profapi.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk4\DR4
Upper Device Object: 0xffffffff86811ac8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\0000006b\
Lower Device Object: 0xffffffff86814698
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk3\DR3
Upper Device Object: 0xffffffff86811030
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\0000006a\
Lower Device Object: 0xffffffff855e1030
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk2\DR2
Upper Device Object: 0xffffffff86813ac8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000069\
Lower Device Object: 0xffffffff855e13b8
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR1
Upper Device Object: 0xffffffff86813030
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000068\
Lower Device Object: 0xffffffff86812cb8
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff85a587a0
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP3T0L0-3\
Lower Device Object: 0xffffffff85986030
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff85a587a0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff85a583d8, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff85a587a0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff8597e918, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xffffffff85986030, DeviceName: \Device\Ide\IdeDeviceP3T0L0-3\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: B07B7292

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 579584
Partition file system is NTFS
Partition is bootable

Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 581632 Numsec = 311996416

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 160041885696 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-2047-312561808-312581808)...
Done!
Physical Sector Size: 0
Drive: 1, DevicePointer: 0xffffffff86813030, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff86814378, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff86813030, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86812cb8, DeviceName: \Device\00000068\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 2, DevicePointer: 0xffffffff86813ac8, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff868124a8, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff86813ac8, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff855e13b8, DeviceName: \Device\00000069\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 3, DevicePointer: 0xffffffff86811030, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff86814d10, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff86811030, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff855e1030, DeviceName: \Device\0000006a\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 4, DevicePointer: 0xffffffff86811ac8, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff86812998, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff86811ac8, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86814698, DeviceName: \Device\0000006b\, DriverName: \Driver\USBSTOR\
------------ End ----------

Re: default-search.net jako homepage

Napsal: 17 črc 2014 17:26
od vyosek
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: default-search.net jako homepage

Napsal: 19 črc 2014 17:46
od Kenny123
ComboFix 14-07-17.03 - Radim 19.07.2014 18:22:27.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2046.1063 [GMT 2:00]
Spuštěný z: c:\users\Radim\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1F911D9424.sys
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-19 do 2014-07-19 )))))))))))))))))))))))))))))))
.
.
2014-07-19 16:31 . 2014-07-19 16:31 -------- d-----w- c:\users\Radim\AppData\Local\temp
2014-07-19 16:31 . 2014-07-19 16:31 -------- d-----w- c:\users\Pavla\AppData\Local\temp
2014-07-18 10:39 . 2014-07-02 03:11 8217224 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{052536D6-29B3-4FC9-9617-F0245908F292}\mpengine.dll
2014-07-15 23:21 . 2014-07-15 23:21 -------- d-----w- c:\programdata\Malwarebytes
2014-07-15 23:21 . 2014-07-16 21:01 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-07-15 23:21 . 2014-07-16 20:32 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-07-15 23:19 . 2014-07-16 20:32 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-07-13 21:07 . 2014-07-14 21:14 -------- d-----w- C:\FRST
2014-07-13 18:07 . 2014-07-13 18:07 43152 ----a-w- c:\windows\avastSS.scr
2014-07-13 00:42 . 2014-06-06 09:44 509440 ----a-w- c:\windows\system32\qedit.dll
2014-07-13 00:40 . 2014-05-30 07:52 247808 ----a-w- c:\windows\system32\schannel.dll
2014-07-13 00:40 . 2014-05-30 07:52 550912 ----a-w- c:\windows\system32\kerberos.dll
2014-07-13 00:40 . 2014-05-30 07:52 259584 ----a-w- c:\windows\system32\msv1_0.dll
2014-07-13 00:40 . 2014-05-30 07:52 172032 ----a-w- c:\windows\system32\wdigest.dll
2014-07-13 00:40 . 2014-05-30 07:52 220160 ----a-w- c:\windows\system32\ncrypt.dll
2014-07-13 00:40 . 2014-05-30 07:52 65536 ----a-w- c:\windows\system32\TSpkg.dll
2014-07-13 00:40 . 2014-05-30 07:52 17408 ----a-w- c:\windows\system32\credssp.dll
2014-07-13 00:39 . 2014-05-30 06:36 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2014-07-13 00:39 . 2014-06-30 01:40 404480 ----a-w- c:\windows\system32\aepdu.dll
2014-07-13 00:39 . 2014-06-30 01:36 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-07-13 00:39 . 2014-06-05 14:26 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-07-12 22:45 . 2014-06-27 09:54 40064 ----a-w- c:\windows\system32\drivers\iSafeKrnlBoot.sys
2014-07-12 08:42 . 2014-07-13 00:25 -------- d-----w- c:\program files\DoughGo
2014-07-11 22:40 . 2014-07-11 22:40 -------- d-----w- c:\program files\Enigma Software Group
2014-07-11 22:38 . 2014-07-11 22:38 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-06-28 05:11 . 2014-06-28 05:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2014-06-28 05:11 . 2014-06-28 05:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2014-06-28 05:11 . 2014-06-28 05:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2014-06-28 05:11 . 2014-06-28 05:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2014-06-28 05:11 . 2014-06-28 05:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2014-06-28 05:10 . 2014-07-13 01:32 -------- d-----w- c:\program files\QuickTime
2014-06-28 05:10 . 2014-06-28 05:10 -------- d-----w- c:\programdata\Apple Computer
2014-06-22 13:11 . 2014-06-22 13:12 -------- d-----w- c:\users\Radim\AppData\Local\Casino.com
2014-06-21 13:44 . 2014-06-21 13:45 -------- d-----w- c:\users\Radim\AppData\Local\Windows Live Writer
2014-06-21 13:44 . 2014-06-21 13:44 -------- d-----w- c:\users\Radim\AppData\Roaming\Windows Live Writer
2014-06-20 21:47 . 2014-06-20 21:47 -------- d-----w- c:\users\Radim\AppData\Local\ElevatedDiagnostics
2014-06-20 21:29 . 2014-07-13 18:07 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-13 18:08 . 2014-02-01 16:19 414520 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-07-13 18:07 . 2014-03-25 07:54 71944 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-07-13 18:07 . 2014-02-01 16:19 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-07-13 18:07 . 2014-02-01 16:19 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-13 18:07 . 2014-02-01 16:19 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-13 18:07 . 2014-02-01 16:19 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-13 18:07 . 2014-02-01 16:19 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-13 18:07 . 2014-02-01 16:19 276432 ----a-w- c:\windows\system32\aswBoot.exe
2014-07-09 09:24 . 2012-05-26 17:19 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-09 09:24 . 2011-06-24 19:12 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-06-06 10:47 . 2014-06-06 10:47 4558848 ----a-w- c:\windows\system32\GPhotos.scr
2014-05-08 09:06 . 2014-06-11 20:49 2742784 ----a-w- c:\windows\system32\rdpcorets.dll
2014-05-08 09:06 . 2014-06-11 20:49 13824 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-04-25 02:06 . 2014-06-12 08:36 626688 ----a-w- c:\windows\system32\usp10.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-13 18:07 578240 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-01-20 6711840]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-13 4086432]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-07-13 71944]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-06-18 108032]
R3 iSafeKrnlBoot;iSafeKrnl Boot Driver;c:\windows\system32\DRIVERS\iSafeKrnlBoot.sys [2014-06-27 40064]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-06-18 64288]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-07-13 414520]
S2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [2010-07-22 814344]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-13 15:18 1091912 ----a-w- c:\program files\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://www.google.com
mStart Page = www.seznam.cz
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 217.196.209.2 8.8.8.8
FF - ProfilePath - c:\users\Radim\AppData\Roaming\Mozilla\Firefox\Profiles\twue63jj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
@DACL=(02 0000)
@="Bing"
"DisplayName"="@ieframe.dll,-12512"
"URL"="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-07-19 18:34:11
ComboFix-quarantined-files.txt 2014-07-19 16:34
.
Před spuštěním: Volných bajtů: 58 250 952 704
Po spuštění: Volných bajtů: 57 913 655 296
.
- - End Of File - - 4BF0848F862F984C5796E16755B7C0C4
A36C5E4F47E84449FF07ED3517B43A31

Re: default-search.net jako homepage

Napsal: 19 črc 2014 20:08
od vyosek
:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Folder::
    c:\program files\Enigma Software Group
    
    Driver::
    Lbd
    
    File::
    c:\windows\system32\DRIVERS\Lbd.sys
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: default-search.net jako homepage

Napsal: 19 črc 2014 21:44
od Kenny123
Uděláno dle instrukcí , jen jsem si tentokrát zapoměl vypnout avast, tak mě to ze začátku vyzvalo ať jej vypnu, a pak to pokračovalo. Všecko na první pohled +- OK, akorát v prohlížeči, když zadám do řádku adresy "www.google.com" tak stránka nechce najet, dělá jak by nic. To stejné přihlašování do emailu na seznamu, facebook taky nenajede. Nevím proč, předtím to šlo normálně. Že internet občas zhavaruje a nečekaně zavře všechny relace zůstalo.

ComboFix 14-07-17.03 - Radim 19.07.2014 22:22:33.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2046.1174 [GMT 2:00]
Spuštěný z: c:\users\Radim\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Radim\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\DRIVERS\Lbd.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Enigma Software Group
c:\program files\Enigma Software Group\SpyHunter\cos.dat
c:\program files\Enigma Software Group\SpyHunter\gas.dat
c:\program files\Enigma Software Group\SpyHunter\gil.dat
c:\program files\Enigma Software Group\SpyHunter\INSTALL.LOG
c:\program files\Enigma Software Group\SpyHunter\key.dat
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140712_004058.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140712_100024.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140712_104959.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140713_003629.log
c:\program files\Enigma Software Group\SpyHunter\Rollback\arch_130496339240210000.xml
c:\program files\Enigma Software Group\SpyHunter\Rollback\arch_1f80c15acc3c04ffad4efb17274200bf_130496339237430000.esg
c:\program files\Enigma Software Group\SpyHunter\safeol.dat
c:\program files\Enigma Software Group\SpyHunter\scanlog.log
c:\program files\Enigma Software Group\SpyHunter\supportlog.txt
c:\program files\Enigma Software Group\SpyHunter\unkcache.dat
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_LBD
-------\Service_Lbd
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-19 do 2014-07-19 )))))))))))))))))))))))))))))))
.
.
2014-07-19 20:31 . 2014-07-19 20:35 -------- d-----w- c:\users\Radim\AppData\Local\temp
2014-07-19 20:31 . 2014-07-19 20:31 -------- d-----w- c:\users\Pavla\AppData\Local\temp
2014-07-19 20:31 . 2014-07-19 20:31 -------- d-----w- c:\users\Jana\AppData\Local\temp
2014-07-19 20:31 . 2014-07-19 20:31 -------- d-----w- c:\users\Hanka\AppData\Local\temp
2014-07-19 20:31 . 2014-07-19 20:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-07-19 20:16 . 2014-07-19 20:16 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{052536D6-29B3-4FC9-9617-F0245908F292}\offreg.dll
2014-07-18 10:39 . 2014-07-02 03:11 8217224 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{052536D6-29B3-4FC9-9617-F0245908F292}\mpengine.dll
2014-07-15 23:21 . 2014-07-15 23:21 -------- d-----w- c:\programdata\Malwarebytes
2014-07-15 23:21 . 2014-07-16 21:01 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-07-15 23:21 . 2014-07-16 20:32 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-07-15 23:19 . 2014-07-16 20:32 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-07-13 21:07 . 2014-07-14 21:14 -------- d-----w- C:\FRST
2014-07-13 18:07 . 2014-07-13 18:07 43152 ----a-w- c:\windows\avastSS.scr
2014-07-13 00:42 . 2014-06-06 09:44 509440 ----a-w- c:\windows\system32\qedit.dll
2014-07-13 00:40 . 2014-05-30 07:52 247808 ----a-w- c:\windows\system32\schannel.dll
2014-07-13 00:40 . 2014-05-30 07:52 550912 ----a-w- c:\windows\system32\kerberos.dll
2014-07-13 00:40 . 2014-05-30 07:52 259584 ----a-w- c:\windows\system32\msv1_0.dll
2014-07-13 00:40 . 2014-05-30 07:52 172032 ----a-w- c:\windows\system32\wdigest.dll
2014-07-13 00:40 . 2014-05-30 07:52 220160 ----a-w- c:\windows\system32\ncrypt.dll
2014-07-13 00:40 . 2014-05-30 07:52 65536 ----a-w- c:\windows\system32\TSpkg.dll
2014-07-13 00:40 . 2014-05-30 07:52 17408 ----a-w- c:\windows\system32\credssp.dll
2014-07-13 00:39 . 2014-05-30 06:36 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2014-07-13 00:39 . 2014-06-30 01:40 404480 ----a-w- c:\windows\system32\aepdu.dll
2014-07-13 00:39 . 2014-06-30 01:36 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-07-13 00:39 . 2014-06-05 14:26 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-07-12 22:45 . 2014-06-27 09:54 40064 ----a-w- c:\windows\system32\drivers\iSafeKrnlBoot.sys
2014-07-12 08:42 . 2014-07-13 00:25 -------- d-----w- c:\program files\DoughGo
2014-07-11 22:38 . 2014-07-11 22:38 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-06-28 05:11 . 2014-06-28 05:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2014-06-28 05:11 . 2014-06-28 05:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2014-06-28 05:11 . 2014-06-28 05:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2014-06-28 05:11 . 2014-06-28 05:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2014-06-28 05:11 . 2014-06-28 05:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2014-06-28 05:10 . 2014-07-13 01:32 -------- d-----w- c:\program files\QuickTime
2014-06-28 05:10 . 2014-06-28 05:10 -------- d-----w- c:\programdata\Apple Computer
2014-06-22 13:11 . 2014-06-22 13:12 -------- d-----w- c:\users\Radim\AppData\Local\Casino.com
2014-06-21 13:44 . 2014-06-21 13:45 -------- d-----w- c:\users\Radim\AppData\Local\Windows Live Writer
2014-06-21 13:44 . 2014-06-21 13:44 -------- d-----w- c:\users\Radim\AppData\Roaming\Windows Live Writer
2014-06-20 21:47 . 2014-06-20 21:47 -------- d-----w- c:\users\Radim\AppData\Local\ElevatedDiagnostics
2014-06-20 21:29 . 2014-07-13 18:07 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-13 18:08 . 2014-02-01 16:19 414520 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-07-13 18:07 . 2014-03-25 07:54 71944 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-07-13 18:07 . 2014-02-01 16:19 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-07-13 18:07 . 2014-02-01 16:19 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-13 18:07 . 2014-02-01 16:19 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-13 18:07 . 2014-02-01 16:19 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-13 18:07 . 2014-02-01 16:19 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-13 18:07 . 2014-02-01 16:19 276432 ----a-w- c:\windows\system32\aswBoot.exe
2014-07-09 09:24 . 2012-05-26 17:19 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-09 09:24 . 2011-06-24 19:12 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-06-06 10:47 . 2014-06-06 10:47 4558848 ----a-w- c:\windows\system32\GPhotos.scr
2014-05-08 09:06 . 2014-06-11 20:49 2742784 ----a-w- c:\windows\system32\rdpcorets.dll
2014-05-08 09:06 . 2014-06-11 20:49 13824 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-04-25 02:06 . 2014-06-12 08:36 626688 ----a-w- c:\windows\system32\usp10.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-13 18:07 578240 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-01-20 6711840]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-13 4086432]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-06-18 108032]
R3 iSafeKrnlBoot;iSafeKrnl Boot Driver;c:\windows\system32\DRIVERS\iSafeKrnlBoot.sys [2014-06-27 40064]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-07-13 414520]
S2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [2010-07-22 814344]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-07-13 71944]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-13 15:18 1091912 ----a-w- c:\program files\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://www.google.com
mStart Page = http://www.seznam.cz
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 217.196.209.2 8.8.8.8
FF - ProfilePath - c:\users\Radim\AppData\Roaming\Mozilla\Firefox\Profiles\twue63jj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\windows\system32\conhost.exe
.
**************************************************************************
.
Celkový čas: 2014-07-19 22:40:12 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-07-19 20:40
ComboFix2.txt 2014-07-19 16:34
.
Před spuštěním: Volných bajtů: 57 988 132 864
Po spuštění: Volných bajtů: 57 699 586 048
.
- - End Of File - - 08D520B8C21FEBCDD1DFF7E210916962
A36C5E4F47E84449FF07ED3517B43A31

Re: default-search.net jako homepage

Napsal: 20 črc 2014 08:02
od vyosek
Problem je ve vsech prohlizecich??

Re: default-search.net jako homepage

Napsal: 20 črc 2014 11:45
od Kenny123
V ostatních jede vše normálně. Jen v Internet Explorer, bohužel je nejpoužívanější. Na začátku našeho sezení to přitom nebylo, podezřívám ten ComboFix, časově by to tak odpovídalo.

Re: default-search.net jako homepage

Napsal: 20 črc 2014 12:44
od vyosek
Spustte tedy CF jeste jednou, bez skriptu, on se sam pokousi IE opravit

Re: default-search.net jako homepage

Napsal: 20 črc 2014 13:45
od Kenny123
hmm google ani přihlášení do emailu na seznamu pořád nejde :x log zde:

ComboFix 14-07-19.01 - Radim 20.07.2014 14:19:42.3.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2046.1110 [GMT 2:00]
Spuštěný z: c:\users\Radim\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-20 do 2014-07-20 )))))))))))))))))))))))))))))))
.
.
2014-07-20 12:30 . 2014-07-20 12:30 -------- d-----w- c:\users\Pavla\AppData\Local\temp
2014-07-20 12:30 . 2014-07-20 12:30 -------- d-----w- c:\users\Jana\AppData\Local\temp
2014-07-20 12:30 . 2014-07-20 12:30 -------- d-----w- c:\users\Hanka\AppData\Local\temp
2014-07-20 12:30 . 2014-07-20 12:30 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-07-20 11:30 . 2014-07-20 11:30 -------- d-----w- c:\users\Radim\AppData\Roaming\iSafe
2014-07-18 10:39 . 2014-07-02 03:11 8217224 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{052536D6-29B3-4FC9-9617-F0245908F292}\mpengine.dll
2014-07-15 23:21 . 2014-07-15 23:21 -------- d-----w- c:\programdata\Malwarebytes
2014-07-15 23:21 . 2014-07-16 21:01 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-07-15 23:21 . 2014-07-16 20:32 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-07-15 23:19 . 2014-07-16 20:32 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-07-13 21:07 . 2014-07-14 21:14 -------- d-----w- C:\FRST
2014-07-13 18:07 . 2014-07-13 18:07 43152 ----a-w- c:\windows\avastSS.scr
2014-07-13 00:42 . 2014-06-06 09:44 509440 ----a-w- c:\windows\system32\qedit.dll
2014-07-13 00:40 . 2014-05-30 07:52 247808 ----a-w- c:\windows\system32\schannel.dll
2014-07-13 00:40 . 2014-05-30 07:52 550912 ----a-w- c:\windows\system32\kerberos.dll
2014-07-13 00:40 . 2014-05-30 07:52 259584 ----a-w- c:\windows\system32\msv1_0.dll
2014-07-13 00:40 . 2014-05-30 07:52 172032 ----a-w- c:\windows\system32\wdigest.dll
2014-07-13 00:40 . 2014-05-30 07:52 220160 ----a-w- c:\windows\system32\ncrypt.dll
2014-07-13 00:40 . 2014-05-30 07:52 65536 ----a-w- c:\windows\system32\TSpkg.dll
2014-07-13 00:40 . 2014-05-30 07:52 17408 ----a-w- c:\windows\system32\credssp.dll
2014-07-13 00:39 . 2014-05-30 06:36 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2014-07-13 00:39 . 2014-06-30 01:40 404480 ----a-w- c:\windows\system32\aepdu.dll
2014-07-13 00:39 . 2014-06-30 01:36 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-07-13 00:39 . 2014-06-05 14:26 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-07-12 22:45 . 2014-06-27 09:54 40064 ----a-w- c:\windows\system32\drivers\iSafeKrnlBoot.sys
2014-07-12 08:42 . 2014-07-13 00:25 -------- d-----w- c:\program files\DoughGo
2014-07-11 22:38 . 2014-07-11 22:38 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-06-28 05:11 . 2014-06-28 05:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2014-06-28 05:11 . 2014-06-28 05:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2014-06-28 05:11 . 2014-06-28 05:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2014-06-28 05:11 . 2014-06-28 05:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2014-06-28 05:11 . 2014-06-28 05:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2014-06-28 05:10 . 2014-07-13 01:32 -------- d-----w- c:\program files\QuickTime
2014-06-28 05:10 . 2014-06-28 05:10 -------- d-----w- c:\programdata\Apple Computer
2014-06-22 13:11 . 2014-06-22 13:12 -------- d-----w- c:\users\Radim\AppData\Local\Casino.com
2014-06-21 13:44 . 2014-06-21 13:45 -------- d-----w- c:\users\Radim\AppData\Local\Windows Live Writer
2014-06-21 13:44 . 2014-06-21 13:44 -------- d-----w- c:\users\Radim\AppData\Roaming\Windows Live Writer
2014-06-20 21:47 . 2014-06-20 21:47 -------- d-----w- c:\users\Radim\AppData\Local\ElevatedDiagnostics
2014-06-20 21:29 . 2014-07-13 18:07 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-13 18:08 . 2014-02-01 16:19 414520 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-07-13 18:07 . 2014-03-25 07:54 71944 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-07-13 18:07 . 2014-02-01 16:19 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-07-13 18:07 . 2014-02-01 16:19 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-13 18:07 . 2014-02-01 16:19 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-13 18:07 . 2014-02-01 16:19 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-13 18:07 . 2014-02-01 16:19 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-13 18:07 . 2014-02-01 16:19 276432 ----a-w- c:\windows\system32\aswBoot.exe
2014-07-09 09:24 . 2012-05-26 17:19 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-09 09:24 . 2011-06-24 19:12 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-06-06 10:47 . 2014-06-06 10:47 4558848 ----a-w- c:\windows\system32\GPhotos.scr
2014-05-08 09:06 . 2014-06-11 20:49 2742784 ----a-w- c:\windows\system32\rdpcorets.dll
2014-05-08 09:06 . 2014-06-11 20:49 13824 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-04-25 02:06 . 2014-06-12 08:36 626688 ----a-w- c:\windows\system32\usp10.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-13 18:07 578240 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-06-27 12:20 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-01-20 6711840]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-13 4086432]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-07-13 71944]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-06-18 108032]
R3 iSafeKrnlBoot;iSafeKrnl Boot Driver;c:\windows\system32\DRIVERS\iSafeKrnlBoot.sys [2014-06-27 40064]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-07-13 414520]
S2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [2010-07-22 814344]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-07-20 10:16 1104200 ----a-w- c:\program files\Google\Chrome\Application\36.0.1985.125\Installer\chrmstp.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://www.google.com
mStart Page = www.seznam.cz
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 217.196.209.2 8.8.8.8
FF - ProfilePath - c:\users\Radim\AppData\Roaming\Mozilla\Firefox\Profiles\twue63jj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
.
.
Celkový čas: 2014-07-20 14:32:42
ComboFix-quarantined-files.txt 2014-07-20 12:32
ComboFix2.txt 2014-07-19 20:40
ComboFix3.txt 2014-07-19 16:34
.
Před spuštěním: Volných bajtů: 58 760 306 688
Po spuštění: Volných bajtů: 58 209 845 248
.
- - End Of File - - D5806C657804508C7308530BB12B6292
A36C5E4F47E84449FF07ED3517B43A31

Re: default-search.net jako homepage

Napsal: 22 črc 2014 04:19
od vyosek

Re: default-search.net jako homepage

Napsal: 24 črc 2014 00:01
od Kenny123
teď to běhá hezky :wub: (kromě toho že pořád u všeho prohlížeč nabízí zda si má pamatovat heslo, grr) ...tak asi můžeme pomalu uklízet a chýlit se do cílové roviny :)