Márty84 píše:Vsak nikdo nerekl, ze uz jsme skoncili

Nejde to udelat najednou, musime postupne

Dejte logy podle tohoto navodu
http://forum.viry.cz/viewtopic.php?f=13&t=133100 - vypnete na chvili antivir, je mozne, ze to bude blokovat jako skodnou, ale pouzivame to porad, jedna se o falesny poplach

(Kdyby nesel Launcher stahnout, dejte logy jen ze samotneho FRST, tedy bez pouziti Launcheru)
Prvni log a dodatek v příloze.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-09-2016
Ran by Zuzka (administrator) on ZUZKA-PC (28-09-2016 14:58:36)
Running from C:\Users\Zuzka\Downloads
Loaded Profiles: Zuzka (Available Profiles: Zuzka)
Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() C:\Windows\System32\AsusService.exe
() C:\ExpressGateUtil\VAWinService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\ExpressGateUtil\VAWinAgent.exe
(ASUSTeK Computer Inc.) C:\Program Files\Asus\HotkeyService\HotKeyMon.exe
(ASUSTeK Computer Inc.) C:\Program Files\Asus\HotkeyService\HotkeyService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ASUSTeK Computer Inc.) C:\Program Files\Asus\SHE\SuperHybridEngine.exe
(ASUS) C:\Program Files\Asus\CapsHook\CapsHook.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(AsusTek Computer Inc.) C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [HotkeyMon] => C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe [101288 2011-03-04] (ASUSTeK Computer Inc.)
HKLM\...\Run: [HotkeyService] => C:\Program Files\ASUS\HotkeyService\HotkeyService.exe [1252272 2011-03-04] (ASUSTeK Computer Inc.)
HKLM\...\Run: [SuperHybridEngine] => C:\Program Files\ASUS\SHE\SuperHybridEngine.exe [412600 2010-11-15] (ASUSTeK Computer Inc.)
HKLM\...\Run: [LiveUpdate] => C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [1095080 2011-03-11] (AsusTek Computer Inc.)
HKLM\...\Run: [CapsHook] => C:\Program Files\ASUS\CapsHook\CapsHook.exe [445344 2010-11-15] (ASUS)
HKLM\...\Run: [VAWinAgent] => C:\ExpressGateUtil\VAWinAgent.exe [45448 2011-03-24] ()
HKLM\...\Run: [ASUSPRP] => C:\Program Files\ASUS\APRP\APRP.EXE [2018032 2011-04-30] (ASUSTek Computer Inc.)
HKU\S-1-5-21-2978567687-4275224139-954450255-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {CC5FC992-B0AA-47CD-9DC2-83445083CBB8} => C:\Program Files\Asus\ASUS WebStorage\3.0.108.222\AsusWSShellExt.dll [2010-09-02] ()
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {618A47A2-528B-4D9A-AFC8-97D3233511E2} => C:\Program Files\Asus\ASUS WebStorage\3.0.108.222\AsusWSShellExt.dll [2010-09-02] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2014-05-18]
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files\Asus\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{62BAAC46-1B79-4899-B04F-E09E7C8D9B57}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2978567687-4275224139-954450255-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2978567687-4275224139-954450255-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2978567687-4275224139-954450255-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
HKU\S-1-5-21-2978567687-4275224139-954450255-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://eeepc.asus.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-2978567687-4275224139-954450255-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-2978567687-4275224139-954450255-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://
www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2978567687-4275224139-954450255-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&for ... -SearchBox
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Zuzka\AppData\Roaming\Mozilla\Firefox\Profiles\a74kucnk.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [No File]
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [No File]
FF Extension: (No Name) - C:\Program Files\AVAST Software\Avast\WebRep\FF [not found]
Chrome:
=======
CHR Profile: C:\Users\Zuzka\AppData\Local\Google\Chrome\User Data\Default [2016-09-28]
CHR Extension: (Prezentace Google) - C:\Users\Zuzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-09-27]
CHR Extension: (Dokumenty Google) - C:\Users\Zuzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-09-27]
CHR Extension: (Disk Google) - C:\Users\Zuzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-27]
CHR Extension: (YouTube) - C:\Users\Zuzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-27]
CHR Extension: (Tabulky Google) - C:\Users\Zuzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-09-27]
CHR Extension: (Dokumenty Google offline) - C:\Users\Zuzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-27]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Zuzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-09-27]
CHR Extension: (Gmail) - C:\Users\Zuzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-27]
CHR Extension: (Chrome Media Router) - C:\Users\Zuzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-27]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AsusService; C:\windows\system32\AsusService.exe [224680 2011-03-04] ()
R2 VideAceWindowsService; C:\ExpressGateUtil\VAWinService.exe [91464 2011-01-13] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\windows\System32\drivers\AsIO.sys [11456 2010-06-28] ()
R1 AsUpIO; C:\windows\System32\drivers\AsUpIO.sys [11832 2010-08-03] ()
R3 ETD; C:\windows\System32\DRIVERS\ETD.sys [109960 2010-04-13] (ELAN Microelectronic Corp.)
R2 giveio; C:\windows\system32\giveio.sys [5248 1996-04-03] () [File not signed]
R3 kbfiltr; C:\windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
R2 speedfan; C:\windows\system32\speedfan.sys [24184 2012-12-29] (Almico Software)
S3 wsvd; C:\windows\System32\DRIVERS\wsvd.sys [81704 2009-07-22] (CyberLink)
U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 btwavdt; \SystemRoot\system32\drivers\btwavdt.sys [X]
S3 btwrchid; \SystemRoot\system32\drivers\btwrchid.sys [X]
S3 catchme; \??\C:\Users\Zuzka\AppData\Local\Temp\catchme.sys [X]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-09-28 14:58 - 2016-09-28 14:59 - 00010995 _____ C:\Users\Zuzka\Downloads\FRST.txt
2016-09-28 14:57 - 2016-09-28 14:57 - 00112640 _____ (forum.viry.cz) C:\Users\Zuzka\Desktop\FRSTLauncher.exe
2016-09-28 14:53 - 2016-09-28 14:58 - 00000000 ____D C:\FRST
2016-09-28 14:53 - 2016-09-28 14:53 - 01754624 _____ (Farbar) C:\Users\Zuzka\Downloads\FRST.exe
2016-09-28 14:51 - 2016-09-28 14:52 - 02404352 _____ (Farbar) C:\Users\Zuzka\Downloads\FRST64 (1).exe
2016-09-28 14:51 - 2016-09-28 14:51 - 02404352 _____ (Farbar) C:\Users\Zuzka\Downloads\FRST64.exe
2016-09-28 14:16 - 2016-09-28 14:17 - 00420976 _____ C:\windows\system32\FNTCACHE.DAT
2016-09-27 11:44 - 2016-09-27 11:05 - 00024064 _____ C:\windows\zoek-delete.exe
2016-09-27 11:05 - 2016-09-27 11:39 - 00000000 ____D C:\zoek_backup
2016-09-27 08:33 - 2016-09-27 08:33 - 00000682 _____ C:\Users\Zuzka\Desktop\SpeedFan.lnk
2016-09-27 08:31 - 2016-09-27 08:33 - 00000045 _____ C:\windows\system32\initdebug.nfo
2016-09-26 23:57 - 2016-09-26 23:58 - 00000000 ____D C:\Users\Zuzka\Desktop\Nová složka
2016-09-26 21:41 - 2016-09-26 21:41 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-09-26 18:26 - 2016-09-26 18:26 - 00000000 ____D C:\Users\Zuzka\AppData\Roaming\Netscape
2016-09-26 18:26 - 2016-09-26 18:26 - 00000000 ____D C:\Users\Zuzka\AppData\Local\Netscape
2016-09-22 22:59 - 2016-09-22 22:59 - 00000000 ____D C:\rsit
2016-09-22 22:59 - 2016-09-22 22:59 - 00000000 ____D C:\Program Files\trend micro
2016-09-21 21:28 - 2016-09-21 21:28 - 00005616 _____ C:\ComboFix.txt
2016-09-21 21:04 - 2011-06-26 08:45 - 00256000 _____ C:\windows\PEV.exe
2016-09-21 21:04 - 2010-11-07 19:20 - 00208896 _____ C:\windows\MBR.exe
2016-09-21 21:04 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2016-09-21 21:04 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2016-09-21 21:04 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2016-09-21 21:04 - 2000-08-31 02:00 - 00098816 _____ C:\windows\sed.exe
2016-09-21 21:04 - 2000-08-31 02:00 - 00080412 _____ C:\windows\grep.exe
2016-09-21 21:04 - 2000-08-31 02:00 - 00068096 _____ C:\windows\zip.exe
2016-09-21 20:56 - 2016-09-26 18:44 - 00000000 ____D C:\Qoobox
2016-09-21 20:53 - 2016-09-21 21:25 - 00000000 ____D C:\windows\erdnt
2016-09-21 19:33 - 2016-09-21 19:33 - 00000965 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-09-21 19:07 - 2016-09-21 19:07 - 00000000 ____D C:\found.000
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-09-28 14:24 - 2009-07-14 06:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-09-28 14:24 - 2009-07-14 06:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-09-28 14:17 - 2015-07-20 18:54 - 00000936 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-09-28 14:17 - 2009-07-14 06:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-09-28 14:17 - 2009-07-14 04:37 - 00000000 ____D C:\windows\inf
2016-09-26 22:56 - 2014-05-18 15:42 - 00000000 ____D C:\Users\Zuzka\AppData\Local\Windows Live
2016-09-26 18:26 - 2014-05-18 15:42 - 00000000 ____D C:\Users\Zuzka\AppData\Local\VirtualStore
2016-09-26 18:25 - 2014-05-18 15:42 - 00000000 ____D C:\Users\Zuzka
2016-09-22 22:37 - 2015-07-20 18:53 - 00000000 ____D C:\Users\Zuzka\AppData\Local\Google
2016-09-22 06:47 - 2015-07-20 18:54 - 00002141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-09-22 06:47 - 2015-07-20 18:54 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-09-21 21:23 - 2009-07-14 04:04 - 00000215 _____ C:\windows\system.ini
2016-09-21 19:33 - 2015-07-20 22:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-09-21 19:33 - 2015-07-20 22:27 - 00000000 ____D C:\Program Files\CCleaner
2016-09-21 19:00 - 2015-07-20 18:54 - 00000940 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
==================== Files in the root of some directories =======
2011-04-30 03:17 - 2010-03-03 00:59 - 0131984 _____ () C:\ProgramData\FullRemove.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-23 16:49
==================== End of FRST.txt ============================