Stránka 2 z 2

Re: prosím o kjontrolu, chrome se mi podezřele seká

Napsal: 18 led 2015 23:23
od flanker
Zde je FIXLOG

PS: co jsem nyní spustil chrome, přihlásil se na viry.cz+otevřel moje témata, s každýou operací vyskočila jedna stránka :), viz:
Obrázek

Obrázek
Obrázek
Obrázek


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-01-2015 01
Ran by FlanK3rPC at 2015-01-18 23:12:14 Run:2
Running from C:\Users\FlanK3rPC\Desktop
Loaded Profiles: FlanK3rPC (Available profiles: FlanK3rPC)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]

ProxyEnable: [S-1-5-21-303234811-3137648231-2145477389-1000] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-303234811-3137648231-2145477389-1000] => localhost:21320
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-303234811-3137648231-2145477389-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

FF Plugin HKU\S-1-5-21-303234811-3137648231-2145477389-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\FlanK3rPC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File
R3 ALSysIO; \??\C:\Users\FLANK3~1\AppData\Local\Temp\ALSysIO64.sys [X]

2015-01-02 17:47 - 2015-01-13 15:27 - 00000000 ____D () C:\Users\FlanK3rPC\AppData\Roaming\IHlpr
2015-01-10 16:25 - 2015-01-10 16:25 - 00870817 _____ () C:\Users\FlanK3rPC\AppData\Roaming\defin.rar
Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SDTray => value deleted successfully.
"HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon" => Key deleted successfully.
HKU\S-1-5-21-303234811-3137648231-2145477389-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKU\S-1-5-21-303234811-3137648231-2145477389-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-21-303234811-3137648231-2145477389-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-303234811-3137648231-2145477389-1000\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin" => Key deleted successfully.
C:\Users\FlanK3rPC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll not found.
ALSysIO => Service stopped successfully.
ALSysIO => Service deleted successfully.
C:\Users\FlanK3rPC\AppData\Roaming\IHlpr => Moved successfully.
C:\Users\FlanK3rPC\AppData\Roaming\defin.rar => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1 GB temporary data.


The system needed a reboot.

==== End of Fixlog 23:12:20 ====

Re: prosím o kjontrolu, chrome se mi podezřele seká

Napsal: 18 led 2015 23:29
od altrok
:arrow: Postupujte dle navodu kolegy
Rudy píše:Chrome zazálohujte pomocí Chromebackup: http://www.stahuj.centrum.cz/internet_a ... me-backup/ Pak chrome odinstalujte vč. jeho profilu. Znovu nainstalujte a zpět ze zálohy nakopírujte pouze záložky, příp. hesla.