Stránka 1 z 2

Awardhotspoty :(

Napsal: 13 úno 2014 14:38
od miros1
Zdravím Vás, a žádám o pomoc a odstranění zelených podtržených slov či půlslov, kdy po kliknutí na podtržené místo se zobrazí buď např.publi8media.com nebo awardhotspot... Stalo se mi to včera zničehonic.. Od té doby mi vyskakují okénka (adcash.com) a mám dost textu v prohlížeči podtrhlý zeleně. Proto, pokud máte čas, bych prosil o radu krok za krokem jak se toho zbavit. Děkuji.

Míra

Re: Awardhotspoty :(

Napsal: 13 úno 2014 15:29
od vyosek
Zdravim :)

:arrow: Stahnete Shortcut Cleaner http://www.bleepingcomputer.com/downloa ... t-cleaner/
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Spustte tradicne dvouklikem
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v miste spusteni jako sc-cleaner.txt, ten sem vlozte
:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte

Re: Awardhotspoty :(

Napsal: 13 úno 2014 16:15
od miros1
1)
Shortcut Cleaner 1.2.8 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
http://www.bleepingcomputer.com/downloa ... t-cleaner/

Windows Version: Microsoft Windows XP Service Pack 3
Program started at: 02/13/2014 03:32:15 PM.

Scanning for registry hijacks:

* No issues found in the Registry.

Searching for Hijacked Shortcuts:

Searching C:\Documents and Settings\Mirek\Nabídka Start\

Searching C:\Documents and Settings\All Users\Nabídka Start\

Searching C:\Documents and Settings\Mirek\Data aplikací\Microsoft\Internet Explorer\Quick Launch\

Searching C:\Documents and Settings\All Users\Plocha\

Searching C:\Documents and Settings\Mirek\Plocha


0 bad shortcuts found.

Program finished at: 02/13/2014 03:32:18 PM
Execution time: 0 hours(s), 0 minute(s), and 3 seconds(s)

2)Junkware

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.1 (02.04.2014:1)
OS: Microsoft Windows XP x86
Ran by Mirek on čt 13.02.2014 at 15:33:54,20
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{99c91fc5-db5b-4aa0-bb70-5d89c5a4df96}



~~~ Files

Successfully deleted: [File] C:\WINDOWS\Tasks\amiupdxp.job



~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\Mirek\Data aplikací\opencandy"
Successfully deleted: [Folder] "C:\Documents and Settings\Mirek\Data aplikací\swvupdater"



~~~ FireFox

Successfully deleted the following from C:\Documents and Settings\Mirek\Data aplikací\mozilla\firefox\profiles\0f9cek7x.default-1386354203562\prefs.js

user_pref("extensions.RO8UCXM6sZE.url", "hxxp://getsync.info/sync2/?q=hfZ9ofV9CShEAen0rHC6tMqLDe49CNU0n8OMCMlNhd9FrHwGrjkEpdkGrjrMBzqUojwHrjsFpdwErTs8rih7hfs0pihPBMn0qjaFrdC6p





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on čt 13.02.2014 at 15:50:47,06
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


3) Adw
# AdwCleaner v3.018 - Report created 13/02/2014 at 16:12:05
# Updated 28/01/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Mirek - MIRA
# Running from : C:\Documents and Settings\Mirek\Dokumenty\Stažené soubory\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\Alawar Stargaze
Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
Folder Deleted : C:\Documents and Settings\Mirek\Local Settings\Data aplikací\AlawarWrapper
Folder Deleted : C:\Documents and Settings\Mirek\Data aplikací\Alawar Stargaze

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [Backup.old.Start Page]
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper

Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted :

HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App

Management\ARPCache\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}

***** [ Browsers ] *****

-\\ Internet Explorer v7.0.6000.21364


-\\ Mozilla Firefox v26.0 (cs)

[ File : C:\Documents and Settings\Mirek\Data

aplikací\Mozilla\Firefox\Profiles\0f9cek7x.default-1386354203562\prefs.js ]


-\\ Google Chrome v

[ File : C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Google\Chrome\User

Data\Default\preferences ]


*************************

AdwCleaner[R1].txt - [1743 octets] - [13/02/2014 15:52:10]
AdwCleaner[S1].txt - [1688 octets] - [13/02/2014 16:12:05]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1748 octets] ##########

Re: Awardhotspoty :(

Napsal: 13 úno 2014 16:17
od vyosek
:arrow: Fajn, jdeme dale :James008:

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    process;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: Awardhotspoty :(

Napsal: 13 úno 2014 17:10
od miros1
zoek:
Zoek.exe v5.0.0.0 Updated 10-February-2014
Tool run by Mirek on čt 13.02.2014 at 16:23:59,46.
Systém Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Documents and Settings\Mirek\Dokumenty\Stažené soubory\zoek.exe [Scan all users] [Quick Scan] [Auto Clean]

==== System Restore Info ======================

13.2.2014 16:27:16 Zoek.exe System Restore Point Created Succesfully.

==== Suspicious Entries Found ======================

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
"139:TCP"="139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002"

==== Empty Folders Check ======================

C:\Program Files\Alcohol Soft deleted successfully
C:\Program Files\Winamp deleted successfully
C:\Documents and Settings\Mirek\Nabídka Start\Programy\Ultimate Turbine Sound - 737NG v2 deleted successfully
C:\Documents and Settings\All Users\Data aplikací\AWEM deleted successfully
C:\Documents and Settings\All Users\Data aplikací\BigFishCache deleted successfully
C:\Documents and Settings\All Users\Data aplikací\Panda Security deleted successfully
C:\Documents and Settings\All Users\Data aplikací\Real deleted successfully
C:\Documents and Settings\Default User\Data aplikací\Real deleted successfully
C:\Documents and Settings\LocalService\Data aplikací\Apple Computer deleted successfully
C:\Documents and Settings\Mirek\Data aplikací\Canon Easy-WebPrint EX deleted successfully
C:\Documents and Settings\Mirek\Data aplikací\Easy MP3 Recorder deleted successfully
C:\Documents and Settings\Mirek\Data aplikací\WiiSports101in1 deleted successfully
C:\Documents and Settings\Mirek\Data aplikací\WinRAR deleted successfully
C:\Documents and Settings\Default User\Local Settings\Data aplikací\Real deleted successfully
C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Avg2013 deleted successfully
C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Axialis deleted successfully
C:\Documents and Settings\Mirek\Local Settings\Data aplikací\PowerChallenge deleted successfully
C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Real deleted successfully
C:\Documents and Settings\Mirek\Local Settings\Data aplikací\STARGAZE_IMAGE_CACHE deleted successfully
C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Unity deleted successfully
C:\Documents and Settings\Mirek\Local Settings\Data aplikací\WMTools Downloaded Files deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E5E2654-AD2D-48BF-AC2D-D17F00898D06} deleted successfully
HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E5E2654-AD2D-48BF-AC2D-D17F00898D06} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{99079A25-328F-4BD4-BE04-00955ACAA0A7} deleted successfully
HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{9D717F81-9148-4F12-8568-69135F087DB0} deleted successfully
HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully
HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95} deleted successfully
HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{8E5E2654-AD2D-48BF-AC2D-D17F00898D06} deleted successfully
HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{18DBB6CE-3148-4FEC-B481-103CB3290427} deleted successfully
HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{4723AAA8-B2F9-4CC1-9E60-190976DB1FA4} deleted successfully
HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{8271B5D6-76D3-4ABF-AEB3-1721161C76BC} deleted successfully
HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{1824FF90-C98E-48A6-838F-E3B6572B0C77} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully

==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Documents and Settings\Mirek\AppData\LocalLow\{0351B388-9EDC-46D1-3B92-12387FD6006B} deleted
C:\Documents and Settings\Mirek\AppData\LocalLow\{5167B7D9-AAA2-9633-2F27-DED6877B5A9B} deleted
C:\Documents and Settings\Mirek\AppData\LocalLow\{67DA5E8E-95DA-6CE6-9DB7-5D694C12637E} deleted
C:\Documents and Settings\Mirek\AppData\LocalLow\{AB2CF468-D14C-DA46-517F-05249A4DFA63} deleted
C:\Documents and Settings\Mirek\Local Settings\Data aplikací\genienext deleted
C:\Documents and Settings\Mirek\daemonprocess.txt deleted
C:\Documents and Settings\Mirek\.android deleted
C:\Program Files\Mobogenie deleted
C:\Program Files\MediaPlayerV1 deleted
C:\Program Files\Surftastic deleted
C:\Documents and Settings\Mirek\Data aplikací\newnext.me deleted
C:\Documents and Settings\Mirek\Data aplikací\Alawar deleted
C:\Documents and Settings\Mirek\Data aplikací\Alawar Entertainment deleted
C:\Documents and Settings\Mirek\Data aplikací\AlawarEntertainment deleted
C:\Documents and Settings\Mirek\Data aplikací\eCyber deleted
C:\Documents and Settings\All Users\Data aplikací\svcdotnet.txt deleted
C:\Documents and Settings\All Users\Data aplikací\InstallMate deleted
C:\Documents and Settings\Mirek\Local Settings\Data aplikací\speeddial.crx deleted
C:\Documents and Settings\Mirek\Local Settings\Data aplikací\CRE deleted
C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Mobogenie deleted
C:\Documents and Settings\Mirek\Local Settings\Data aplikací\cache deleted
C:\WINDOWS\Reimage.ini deleted
C:\WINDOWS\wininit.ini deleted
"C:\Documents and Settings\All Users\Data aplikací\12889c35e138d404\{4820778D-AB0D-6D18-C316-52A6A0E1D507}" deleted
"C:\Documents and Settings\All Users\Data aplikací\12889c35e138d404\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}" deleted
"C:\Documents and Settings\All Users\Data aplikací\12889c35e138d404\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}.old" deleted
"C:\Documents and Settings\All Users\Data aplikací\12889c35e138d404\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}" deleted
"C:\Documents and Settings\All Users\Data aplikací\12889c35e138d404\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}.old" deleted
"C:\Documents and Settings\All Users\Data aplikací\12889c35e138d404" deleted

==== Files Recently Created / Modified ======================

====== C:\WINDOWS ====
====== C:\DOCUME~1\Mirek\LOCALS~1\Temp ====
2014-02-13 14:33:43 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Documents and Settings\Mirek\Local Settings\Temp\jrt\erunt\ERUNT.EXE
2014-02-11 07:26:24 D7F41D63C4B528C1F259C19304CCBC73 966017 ----a-w- C:\Documents and Settings\Mirek\Local Settings\Temp\Setup2.exe
====== Java Cache =====
2014-01-29 12:43:12 571BC38AD8317B78F5469D59CA2B908D 37 ----a-w- C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Sun\Java\Deployment\cache\6.0\1\5bcb8a01-6.0.lap
2014-01-29 12:37:12 CD9A0E5EC5F270092C8884B040C24121 37 ----a-w- C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Sun\Java\Deployment\cache\6.0\17\dc3ca91-6.0.lap
2014-01-29 12:35:58 5FA93F67CA7D34FCFB72169F8A5F37C5 37 ----a-w- C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Sun\Java\Deployment\cache\6.0\20\24357614-6.0.lap
2014-01-29 12:43:39 37FE80B807914F23FCBAC3ED0532FDB8 37 ----a-w- C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Sun\Java\Deployment\cache\6.0\32\63cb2ba0-6.0.lap
2014-01-29 12:34:15 8D31375AFB6F3BD606E6A3605970694A 119301 ----a-w- C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Sun\Java\Deployment\cache\6.0\49\50d3f671-7032be2e
2014-01-29 12:34:14 FC9ABF692AEFF01E8BBE4E0DD8919CE9 37 ----a-w- C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Sun\Java\Deployment\cache\6.0\51\46b98eb3-6.0.lap
2014-01-29 12:43:12 4D9DBC0C8FFF0A5C865894924C99D6D2 60928 ----a-w- C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Sun\Java\Deployment\cache\6.0\56\47636478-1f9c0a93
2014-01-29 12:35:58 4D9DBC0C8FFF0A5C865894924C99D6D2 60928 ----a-w- C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Sun\Java\Deployment\cache\6.0\62\284c507e-401e3c46
2014-01-30 07:28:34 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Sun\Java\Deployment\SystemCache\6.0\32\6c34baa0-6d74dbeb
====== C:\WINDOWS\system32 =====
====== C:\WINDOWS\system32\drivers =====
2014-01-23 14:04:45 1F730FDDC8E4602ECFD8D143F970CF82 13120 ----a-w- C:\WINDOWS\System32\drivers\StarOpen.sys
2014-01-23 11:51:24 CBEAEA2729985BFB260641AB424E0166 320120 ----a-w- C:\WINDOWS\System32\drivers\sptd.sys
====== C:\WINDOWS\Tasks ======
====== C:\WINDOWS\Temp ======
======= C:\Program Files =====
2014-01-29 12:32:23 -------- d-----w- C:\Program Files\Common Files\Java
2014-01-23 14:04:44 -------- d-----w- C:\Program Files\CDBurnerXP
2014-01-23 13:54:43 -------- d-----w- C:\Program Files\MSXML 4.0
2014-01-22 14:39:23 -------- d-----w- C:\Program Files\AVG
======= C: =====
2014-02-13 14:32:15 9F43DB1E80E4EE5DCDA5340F650042E6 1876 ----a-w- C:\sc-cleaner.txt
====== C:\Documents and Settings\Mirek\Data aplikací ======
2014-02-13 15:45:05 -------- d-----w- C:\Documents and Settings\Mirek\Data aplikací\WinRAR
2014-02-02 20:24:22 -------- d-----w- C:\Documents and Settings\Mirek\Data aplikací\SUPERAntiSpyware.com
2014-01-29 12:39:26 -------- d-----w- C:\Documents and Settings\Mirek\Data aplikací\PowerChallenge
2014-01-16 16:40:37 -------- d-----w- C:\Documents and Settings\Mirek\Data aplikací\DominiGames
====== C:\Documents and Settings\Mirek ======
2014-02-10 14:18:26 -------- d--h--r- C:\Documents and Settings\Mirek\Recent

====== C: exe-files ==
2014-02-13 14:51:55 54DB2B8C60F04C5ADE6D711D47EABA75 1166132 ----a-w- C:\Documents and Settings\Mirek\Dokumenty\Stažené soubory\adwcleaner.exe
2014-02-13 14:33:43 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\erunt\ERUNT.EXE
2014-02-13 14:33:39 56DBC01BF6DFBA60A863DE308FB58334 1037530 ----a-w- C:\Documents and Settings\Mirek\Dokumenty\plocha stará\JRT.exe
2014-02-13 14:32:05 F9849017067613E3384F952C54575325 406264 ----a-w- C:\Documents and Settings\Mirek\Dokumenty\plocha stará\sc-cleaner.exe
2014-02-11 07:26:24 D7F41D63C4B528C1F259C19304CCBC73 966017 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\Setup2.exe
=== C: other files ==
2014-02-13 14:33:43 DFB8D08F2FD68D58239045B366D68CE2 10261 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\JRT.bat
2014-02-13 14:33:43 CC6C23C02BE66014AD87F2678BBB3A1D 8117 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\modules.bat
2014-02-13 14:33:43 C4A5476A9D54B400F1623A2EE7DDA5C5 13955 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\chrome.bat
2014-02-13 14:33:43 B964B792D3692699CD7D4FDB63EE470E 1239 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\FWPolicy.bat
2014-02-13 14:33:43 B45931E5313CB14CAA0F2BC3DA30E6FC 29648 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\ask.bat
2014-02-13 14:33:43 AE697BC275F5B52FB9E1164F14FB18F8 151936 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\firefox.bat
2014-02-13 14:33:43 8C7709AE609C5235976C4567E810D4B8 154424 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\misc.bat
2014-02-13 14:33:43 868D0E22DC055BA214D7EC71600F2CFA 16063 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\get.bat
2014-02-13 14:33:43 80D02380F1AC33E459324B088392A1EC 732 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\ev_clear.bat
2014-02-13 14:33:43 75C9C20DD9839BF287B43B0E179822DC 31414 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\iexplore.bat
2014-02-13 14:33:43 7178963AEE641F3E47E1CE22416F8A3A 9295 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\runvalues.bat
2014-02-13 14:33:43 654E9FE74B930A454EE5BDE165794B65 85 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\delorphans.bat
2014-02-13 14:33:43 58605DA3492FB918D3D40B1FB88046AE 39471 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\prelim.bat
2014-02-13 14:33:43 372EA6F783198102CF5779072EE78C79 24751 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\searchlnk.bat
2014-02-13 14:33:43 1FBF882AA934A741530741FC134872A3 1243 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\TDL4.bat
2014-02-13 14:33:43 14D6EE8B672684E2232FB430D8C4A928 18668 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\medfos.bat
2014-02-13 14:33:43 0768E560CCD86C18F35FAD29DCEA7B80 1820 ----a-w- C:\Documents and Settings\Mirek\Local Settings\temp\jrt\delfolders.bat

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe"
"NextLive"="C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\Mirek\Data aplikací\newnext.me\nengine.dll,EntryPoint -m l"
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup"
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"mobilegeni daemon"="C:\Program Files\Mobogenie\DaemonProcess.exe"
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe"
"NextLive"="C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\Mirek\Data aplikací\newnext.me\nengine.dll,EntryPoint -m l"
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"

==== Startup Registry Disabled ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AdobeARM"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CanonMyPrinter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BJMyPrt"
"hkey"="HKLM"
"command"="C:\\Program Files\\Canon\\MyPrinter\\BJMyPrt.exe /logon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CanonSolutionMenu]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CNSLMAIN"
"hkey"="HKLM"
"command"="C:\\Program Files\\Canon\\SolutionMenu\\CNSLMAIN.exe /logon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ctfmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NvMediaCenter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvMcTray"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\pdfFactory Dispatcher v3]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="fppdis3a"
"hkey"="HKLM"
"command"="\"C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\fppdis3a.exe\" /source=HKLM"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RTHDCPL]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RTHDCPL"
"hkey"="HKLM"
"command"="RTHDCPL.EXE"


==== Task Scheduler Jobs ======================

C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a------ C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [05.02.2014 16:31]

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"ext@MediaPlayerV1alpha8194.net"="C:\Program Files\MediaPlayerV1\MediaPlayerV1alpha8194\ff" []

==== Firefox Extensions ======================

ProfilePath: C:\Documents and Settings\Mirek\Data aplikací\Mozilla\Firefox\Profiles\0f9cek7x.default-1386354203562
- Undetermined - C:\Program Files\MediaPlayerV1\MediaPlayerV1alpha8194\ff
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Documents and Settings\Mirek\Data aplikací\Mozilla\Firefox\Profiles\0f9cek7x.default-1386354203562
FD6ACD9D85177259D442A0C4AC15F7B8 - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll - Shockwave Flash
A9191AE22A8F1287B5E2DF33E3A57253 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U51
9B10927CFD0F7AD39E40C0E34005B1AD - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.510.13
5B4DA1113F240C3F06FFF9D52761528B - C:\Program Files\Google\Picasa3\npPicasa3.dll - Picasa
AC987EE8037531807C5D7E6217A23501 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
EB41064BC07017F5694CF16B4DEF6B10 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
EEEB86077BB4682B3FCFEDA5AED3E396 - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.7.4
BADFB0DCCD9B7E9F2F6EB7954D24EED1 - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.7.4
1153F58FACBC9731AF6CDF313F76DF29 - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.7.4
9E4F520270BF7301CC24E8FA67791C22 - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.7.4
E50A1DB5DE70D656287511297B42F9F2 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.7.4
8E9A08E2092B3E1ADFF3C46BC1A5124B - C:\WINDOWS\system32\TVUAx\npTVUAx.dll - TVU Web Player for FireFox
0843C70733E8CA876475123A6601630D - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL - CANON iMAGE GATEWAY Album Plugin Utility
AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
8A5657AF7B9944D1ACA509FB1EF2A12A - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll - RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)
3D84A7E0CD7A1FC93EAB9F2D50E5BD9C - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll - RealPlayer Version Plugin
7E54D1EC87CE306CB1A26CE59AFE6E37 - C:\Program Files\Windows Media Player\npdrmv2.dll - Microsoft® DRM
D33D39A318AEA70691CED7530E2D9DF9 - C:\Program Files\Windows Media Player\npdsplay.dll - Windows Media Player Plug-in Dynamic Link Library
CFBC726A1712BD8DC9914EA06DBCE20B - C:\Program Files\Windows Media Player\npwmsdrm.dll - Microsoft® DRM


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[]

Docs - Mirek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://www.google.com/search?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{CCBDD7BB-8A0D-41C3-BD8C-53102FC40FF7} Google Url="http://www.google.com/search?q={searchT ... 1I7SKPT_cs"

==== Deleting CLSID Registry Keys ======================

HKEY_CLASSES_ROOT\CLSID\{77809411-9e16-439d-8168-db4b35af68d6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77809411-9e16-439d-8168-db4b35af68d6} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{77809411-9e16-439d-8168-db4b35af68d6} deleted successfully
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\ext@MediaPlayerV1alpha8194.net deleted successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{62592BCE-C06A-B55D-F78A-D73137836BF1} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9A5B721A-11BA-9C38-03F2-BEF62226E626} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{EC6A6049-39A4-E48E-451B-DBC959585304} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F22C3801-0E34-BB20-E381-39348DCC93A2} deleted successfully
HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\ExtensionInstallForcelist deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki deleted successfully

==== Empty IE Cache ======================

C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Documents and Settings\Mirek\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Mozilla\Firefox\Profiles\0f9cek7x.default-1386354203562\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=405 folders=110 39012014 bytes)

==== Empty Temp Folders ======================

C:\Documents and Settings\Default User\Local Settings\Temp emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temp emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\Temp emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp emptied successfully
C:\Documents and Settings\Mirek\Local Settings\Temp will be emptied at reboot
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\Mirek\LOCALS~1\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\RECYCLER successfully emptied

==== Deleting Files / Folders ======================

"C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Documents and Settings\Mirek\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found

==== EOF on čt 13.02.2014 at 17:09:49,14 ======================

Re: Awardhotspoty :(

Napsal: 15 úno 2014 08:16
od vyosek

Re: Awardhotspoty :(

Napsal: 16 úno 2014 21:44
od miros1
Dobrý den... Čtu to až nyní. Awardhotspoty již zmizely... Nicméně mám dva problémy ještě. Po spuštění počítače se mi ukáže tabulka s bílým křížkem v červeném kolečku, že chybí nějaký rundll (nyní si nepamatuji přesně text) a další - kupoval jsem si klávesnici a i když už s ní 14 dní pracuji, při každém spuštění mi naskočí tabulka požadující nainstalování nového hardwaru, musím to pořád stornovat. Děkuji případně za radu. P.S.: Když už ty zelené reklamy nemám, mám dělat ten FRST Launcher z vašeho posledního příspěvku?? M

Re: Awardhotspoty :(

Napsal: 17 úno 2014 15:21
od vyosek
:arrow: Ano, log z FRST dejte - tim vyresime snad zminovanou tabulku

Re: Awardhotspoty :(

Napsal: 18 úno 2014 14:09
od miros1
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-02-2014
Ran by Mirek (administrator) on MIRA on 18-02-2014 14:07:06
Running from C:\Documents and Settings\Mirek\Plocha
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 7
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\launcher_service.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(forum.viry.cz) C:\Documents and Settings\Mirek\Plocha\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [13877248 2009-08-17] (NVIDIA Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-861567501-842925246-682003330-1003\...\Run: [NextLive] - C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Mirek\Data aplikací\newnext.me\nengine.dll",EntryPoint -m l
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = ru.redirect.wrapper.services.alawar.ru/startpage.php?lang=cs&wspv=3.0&locale=cs&pid=10202
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0017-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
Tcpip\..\Interfaces\{912994FC-195C-4101-A02D-A9B71DB1CF9B}: [NameServer]10.1.0.56,10.1.0.20
Tcpip\..\Interfaces\{D003D105-377B-4264-9B0C-C75902A995F2}: [NameServer]10.1.0.56,10.1.0.20

FireFox:
========
FF ProfilePath: C:\Documents and Settings\Mirek\Data aplikací\Mozilla\Firefox\Profiles\0f9cek7x.default-1386354203562
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer - C:\WINDOWS\system32\TVUAx\npTVUAx.dll (TVU networks)
FF Plugin: @real.com/nppl3260;version=6.0.11.2852 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nppl3260;version=6.0.12.46 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.1662 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.46 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @powerchallenge.com/PowerLoader - C:\Documents and Settings\Mirek\Data aplikací\PowerChallenge\nppowerloader.dll (Power Challenge Sweden AB)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Adblock Plus - C:\Documents and Settings\Mirek\Data aplikací\Mozilla\Firefox\Profiles\0f9cek7x.default-1386354203562\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-11]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.com/",
"ru.redirect.wrapper.services.alawar.ru/startpage.php?lang=cs&wspv=3.0&locale=cs&pid=10202"
CHR Extension: (Docs) - C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-14]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

========================== Services (Whitelisted) =================

R2 CLPSLauncher; C:\Program Files\Common Files\COMODO\launcher_service.exe [70352 2013-11-28] (Comodo Security Solutions, Inc.)
R2 GeekBuddyRSP; C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2013-11-28] (Comodo Security Solutions, Inc.)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-01-29] (Oracle Corporation)
R2 NWCWorkstation; C:\WINDOWS\System32\nwwks.dll [65536 2008-04-14] (Microsoft Corporation)
S2 cmdAgent; "C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe" [X]
S3 cmdvirth; "C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe" [X]
S2 Update Surftastic; "C:\Program Files\Surftastic\updateSurftastic.exe" [X]

==================== Drivers (Whitelisted) ====================

S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R1 CFRMD; C:\WINDOWS\System32\DRIVERS\CFRMD.sys [36112 2013-05-07] (Windows (R) Win 7 DDK provider)
R1 cmderd; C:\WINDOWS\System32\DRIVERS\cmderd.sys [18528 2013-06-18] (COMODO)
R1 cmdGuard; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [587352 2013-07-08] (COMODO)
R1 cmdHlp; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [32816 2013-06-18] (COMODO)
R1 HMD; C:\WINDOWS\System32\DRIVERS\hmd.sys [14272 2013-10-07] ()
R0 Inspect; C:\WINDOWS\System32\DRIVERS\inspect.sys [99520 2013-06-18] (COMODO)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
R0 nvatabus; C:\WINDOWS\system32\Drivers\nvatabus.sys [100736 2008-07-30] (NVIDIA Corporation)
R2 NwlnkIpx; C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-14] (Microsoft Corporation)
R2 NwlnkNb; C:\WINDOWS\System32\DRIVERS\nwlnknb.sys [63232 2001-10-25] (Microsoft Corporation)
R2 NwlnkSpx; C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys [55936 2001-10-25] (Microsoft Corporation)
R3 NWRDR; C:\WINDOWS\System32\DRIVERS\nwrdr.sys [163584 2008-04-14] (Microsoft Corporation)
R3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [320120 2014-01-23] (Duplex Secure Ltd.)
R2 StarOpen; C:\WINDOWS\system32\Drivers\StarOpen.sys [13120 2013-08-25] ()
S3 ZD1211BU(TP-LINK); C:\WINDOWS\System32\DRIVERS\zd1211Bu.sys [500736 2007-06-25] (Atheros Technology Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-18 14:07 - 2014-02-18 14:07 - 00010000 _____ () C:\Documents and Settings\Mirek\Plocha\FRST.txt
2014-02-18 14:05 - 2014-02-18 14:07 - 00000000 ____D () C:\FRST
2014-02-18 14:05 - 2014-02-18 14:05 - 01141248 _____ (Farbar) C:\Documents and Settings\Mirek\Plocha\FRST.exe
2014-02-18 14:05 - 2014-02-18 14:05 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Mirek\Plocha\FRSTLauncher.exe
2014-02-18 12:46 - 2014-02-18 12:46 - 00008349 _____ () C:\Documents and Settings\Mirek\Plocha\friends.txt
2014-02-16 13:26 - 2014-02-16 13:26 - 00004096 _____ () C:\WINDOWS\d3dx.dat
2014-02-16 13:26 - 2014-02-16 13:26 - 00000000 ____D () C:\Documents and Settings\Mirek\Data aplikací\IteraLabs
2014-02-16 13:22 - 2014-02-16 13:25 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
2014-02-16 13:22 - 2014-02-16 13:22 - 00000000 ____D () C:\Documents and Settings\Mirek\Local Settings\Data aplikací\AlawarWrapper
2014-02-15 21:05 - 2014-02-18 12:56 - 00001612 _____ () C:\WINDOWS\wmsetup.log
2014-02-15 19:57 - 2014-02-15 19:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-15 09:40 - 2014-02-18 12:28 - 00060491 _____ () C:\WINDOWS\setupapi.log
2014-02-14 12:44 - 2014-02-14 12:44 - 00000000 ____D () C:\Documents and Settings\Mirek\Data aplikací\Fenomen Games
2014-02-13 17:08 - 2014-02-13 16:23 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-02-13 16:45 - 2014-02-13 16:45 - 00000000 ____D () C:\Documents and Settings\Mirek\Data aplikací\WinRAR
2014-02-13 16:26 - 2014-02-13 17:09 - 00026603 _____ () C:\zoek-results.log
2014-02-13 16:23 - 2014-02-13 16:51 - 00000000 ____D () C:\zoek_backup
2014-02-13 15:52 - 2014-02-13 16:14 - 00000000 ____D () C:\AdwCleaner
2014-02-13 15:51 - 2014-02-13 15:51 - 00002246 _____ () C:\Documents and Settings\Mirek\Plocha\JRT.txt
2014-02-13 15:35 - 2014-02-13 15:35 - 00000939 _____ () C:\Documents and Settings\Mirek\Plocha\Scan.txt
2014-02-13 15:32 - 2014-02-13 15:32 - 00001876 _____ () C:\sc-cleaner.txt
2014-02-11 08:26 - 2014-02-11 08:26 - 00000620 __RSH () C:\Documents and Settings\All Users\ntuser.pol
2014-02-11 08:26 - 2014-02-11 08:26 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy
2014-01-29 13:39 - 2014-01-29 13:39 - 00000000 ____D () C:\Documents and Settings\Mirek\Data aplikací\PowerChallenge
2014-01-29 13:32 - 2014-01-29 13:32 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-01-29 13:32 - 2014-01-29 13:32 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Java
2014-01-29 13:32 - 2014-01-29 13:31 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-01-29 13:32 - 2014-01-29 13:31 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-01-29 13:32 - 2014-01-29 13:31 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-01-29 13:32 - 2014-01-29 13:31 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-01-29 13:32 - 2014-01-29 13:31 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-01-29 13:31 - 2014-01-29 13:31 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Sun
2014-01-26 15:02 - 2014-01-26 15:03 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Norton
2014-01-25 23:43 - 2014-01-26 00:35 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
2014-01-25 23:43 - 2014-01-25 23:55 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2014-01-25 23:43 - 2014-01-25 23:43 - 00065536 _____ () C:\WINDOWS\system32\config\SpybotSD.evt
2014-01-23 15:04 - 2014-01-23 15:04 - 00001569 _____ () C:\Documents and Settings\All Users\Nabídka Start\Programy\CDBurnerXP.lnk
2014-01-23 15:04 - 2014-01-23 15:04 - 00000000 ____D () C:\Program Files\CDBurnerXP
2014-01-23 15:04 - 2013-08-25 10:30 - 00013120 _____ () C:\WINDOWS\system32\Drivers\StarOpen.sys
2014-01-23 14:54 - 2014-01-23 14:54 - 00000000 ____D () C:\Program Files\MSXML 4.0
2014-01-23 14:54 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2014-01-23 14:53 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2014-01-23 14:53 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2014-01-23 14:52 - 2014-01-23 14:52 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB942288-v3$
2014-01-23 14:17 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2014-01-23 14:16 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2014-01-23 13:06 - 2014-01-23 13:49 - 00000124 _____ () C:\Documents and Settings\Mirek\Dokumenty\ax_files.xml
2014-01-23 12:51 - 2014-01-23 12:51 - 00320120 _____ (Duplex Secure Ltd.) C:\WINDOWS\system32\Drivers\sptd.sys
2014-01-22 15:39 - 2014-01-22 15:39 - 00000000 ____D () C:\Program Files\AVG

==================== One Month Modified Files and Folders =======

2014-02-18 14:07 - 2014-02-18 14:07 - 00010000 _____ () C:\Documents and Settings\Mirek\Plocha\FRST.txt
2014-02-18 14:07 - 2014-02-18 14:05 - 00000000 ____D () C:\FRST
2014-02-18 14:07 - 2010-04-09 20:56 - 00000000 ____D () C:\Documents and Settings\Mirek\Plocha
2014-02-18 14:06 - 2010-04-09 20:56 - 00000000 ___HD () C:\Documents and Settings\Mirek\Local Settings\Data aplikací
2014-02-18 14:05 - 2014-02-18 14:05 - 01141248 _____ (Farbar) C:\Documents and Settings\Mirek\Plocha\FRST.exe
2014-02-18 14:05 - 2014-02-18 14:05 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Mirek\Plocha\FRSTLauncher.exe
2014-02-18 14:03 - 2001-10-25 17:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-02-18 13:31 - 2013-12-18 14:37 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-02-18 12:57 - 2010-04-09 20:40 - 01080432 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-18 12:56 - 2014-02-15 21:05 - 00001612 _____ () C:\WINDOWS\wmsetup.log
2014-02-18 12:46 - 2014-02-18 12:46 - 00008349 _____ () C:\Documents and Settings\Mirek\Plocha\friends.txt
2014-02-18 12:38 - 2010-04-09 22:15 - 00000000 ___RD () C:\Documents and Settings\Mirek\Dokumenty\plocha stará
2014-02-18 12:28 - 2014-02-15 09:40 - 00060491 _____ () C:\WINDOWS\setupapi.log
2014-02-18 12:27 - 2010-04-09 22:23 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-02-18 12:27 - 2010-04-09 22:23 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-02-18 12:27 - 2010-04-09 20:55 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-18 12:27 - 2009-08-17 02:03 - 00249324 _____ () C:\WINDOWS\system32\NvApps.xml
2014-02-18 01:55 - 2010-04-09 20:55 - 00032638 _____ () C:\WINDOWS\SchedLgU.Txt
2014-02-18 01:54 - 2010-04-09 20:56 - 00000178 ___SH () C:\Documents and Settings\Mirek\ntuser.ini
2014-02-18 01:07 - 2012-04-27 11:31 - 00000000 ___RD () C:\Documents and Settings\Mirek\Plocha\propaganda
2014-02-17 21:27 - 2010-04-09 21:19 - 00000000 ___RD () C:\Documents and Settings\Mirek\Dokumenty\Obrázky
2014-02-17 20:30 - 2013-12-08 09:21 - 00216465 _____ () C:\WINDOWS\system32\Drivers\sfi.dat
2014-02-17 18:35 - 2010-04-09 22:16 - 00000000 ___RD () C:\Documents and Settings\Mirek\Plocha\mp3
2014-02-16 23:28 - 2013-12-04 17:47 - 00000000 ____D () C:\Documents and Settings\Mirek\Dokumenty\Stažené soubory
2014-02-16 17:51 - 2013-12-13 12:30 - 00000000 ____D () C:\Program Files\Hry.cz
2014-02-16 17:51 - 2013-12-13 12:30 - 00000000 ____D () C:\Documents and Settings\Mirek\Nabídka Start\Programy\Hry.cz
2014-02-16 13:26 - 2014-02-16 13:26 - 00004096 _____ () C:\WINDOWS\d3dx.dat
2014-02-16 13:26 - 2014-02-16 13:26 - 00000000 ____D () C:\Documents and Settings\Mirek\Data aplikací\IteraLabs
2014-02-16 13:26 - 2010-04-09 20:56 - 00000000 __RHD () C:\Documents and Settings\Mirek\Data aplikací
2014-02-16 13:25 - 2014-02-16 13:22 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
2014-02-16 13:25 - 2010-04-09 22:22 - 00000000 ___RD () C:\Documents and Settings\All Users\Dokumenty
2014-02-16 13:22 - 2014-02-16 13:22 - 00000000 ____D () C:\Documents and Settings\Mirek\Local Settings\Data aplikací\AlawarWrapper
2014-02-16 13:22 - 2010-04-09 22:21 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-02-16 12:51 - 2010-04-09 22:22 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-02-16 12:51 - 2010-04-09 22:22 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-02-16 12:46 - 2012-11-04 21:17 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-15 21:58 - 2010-04-11 10:41 - 03828236 ___SH () C:\Documents and Settings\Mirek\Plocha\Thumbs.db
2014-02-15 19:57 - 2014-02-15 19:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-15 19:42 - 2013-12-09 19:27 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-02-15 19:42 - 2010-04-09 22:22 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start
2014-02-14 17:08 - 2010-04-09 20:56 - 00000000 ____D () C:\Documents and Settings\Mirek
2014-02-14 12:44 - 2014-02-14 12:44 - 00000000 ____D () C:\Documents and Settings\Mirek\Data aplikací\Fenomen Games
2014-02-13 20:02 - 2012-01-27 02:01 - 00000000 ____D () C:\Documents and Settings\Mirek\Plocha\učení
2014-02-13 17:09 - 2014-02-13 16:26 - 00026603 _____ () C:\zoek-results.log
2014-02-13 16:51 - 2014-02-13 16:23 - 00000000 ____D () C:\zoek_backup
2014-02-13 16:45 - 2014-02-13 16:45 - 00000000 ____D () C:\Documents and Settings\Mirek\Data aplikací\WinRAR
2014-02-13 16:32 - 2010-04-09 22:22 - 00000000 ___HD () C:\Documents and Settings\Default User\Local Settings\Data aplikací
2014-02-13 16:32 - 2010-04-09 22:21 - 00000000 __RHD () C:\Documents and Settings\Default User\Data aplikací
2014-02-13 16:32 - 2010-04-09 20:56 - 00000000 ___RD () C:\Documents and Settings\Mirek\Nabídka Start\Programy
2014-02-13 16:32 - 2010-04-09 20:55 - 00000000 ____D () C:\Documents and Settings\LocalService\Data aplikací
2014-02-13 16:27 - 2010-06-18 13:00 - 00089088 _____ () C:\Documents and Settings\Mirek\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-13 16:23 - 2014-02-13 17:08 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-02-13 16:14 - 2014-02-13 15:52 - 00000000 ____D () C:\AdwCleaner
2014-02-13 15:51 - 2014-02-13 15:51 - 00002246 _____ () C:\Documents and Settings\Mirek\Plocha\JRT.txt
2014-02-13 15:50 - 2010-07-19 14:40 - 00000000 ____D () C:\Program Files\Czech Soccer Manager 2002 FE
2014-02-13 15:35 - 2014-02-13 15:35 - 00000939 _____ () C:\Documents and Settings\Mirek\Plocha\Scan.txt
2014-02-13 15:32 - 2014-02-13 15:32 - 00001876 _____ () C:\sc-cleaner.txt
2014-02-13 15:30 - 2014-01-08 15:01 - 00002963 _____ () C:\Documents and Settings\Mirek\Plocha\Text.txt
2014-02-11 08:26 - 2014-02-11 08:26 - 00000620 __RSH () C:\Documents and Settings\All Users\ntuser.pol
2014-02-11 08:26 - 2014-02-11 08:26 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy
2014-02-11 08:26 - 2013-02-09 21:26 - 00000664 _____ () C:\WINDOWS\system32\d3d9caps.dat
2014-02-09 22:28 - 2010-04-09 20:56 - 00000000 ___HD () C:\Documents and Settings\Mirek\Okolní síť
2014-02-09 00:56 - 2010-04-09 20:56 - 00000000 ___RD () C:\Documents and Settings\Mirek\Dokumenty
2014-02-05 16:31 - 2012-05-25 22:17 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-02-05 16:31 - 2012-05-25 22:17 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-02-01 20:07 - 2013-01-05 18:03 - 00002421 _____ () C:\Documents and Settings\All Users\Plocha\FS Repaint v2.lnk
2014-01-29 18:27 - 2013-08-04 16:27 - 00000000 ____D () C:\Documents and Settings\Mirek\Data aplikací\MagicIndie
2014-01-29 16:14 - 2010-07-19 14:33 - 00000000 ____D () C:\Documents and Settings\Mirek\Plocha\Manažer
2014-01-29 13:39 - 2014-01-29 13:39 - 00000000 ____D () C:\Documents and Settings\Mirek\Data aplikací\PowerChallenge
2014-01-29 13:32 - 2014-01-29 13:32 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-01-29 13:32 - 2014-01-29 13:32 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\Java
2014-01-29 13:31 - 2014-01-29 13:32 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-01-29 13:31 - 2014-01-29 13:32 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-01-29 13:31 - 2014-01-29 13:32 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-01-29 13:31 - 2014-01-29 13:32 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-01-29 13:31 - 2014-01-29 13:32 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-01-29 13:31 - 2014-01-29 13:31 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Sun
2014-01-26 15:03 - 2014-01-26 15:02 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Norton
2014-01-26 14:55 - 2013-06-24 19:01 - 00000000 ___RD () C:\Documents and Settings\Mirek\Plocha\FOTKY
2014-01-26 00:35 - 2014-01-25 23:43 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
2014-01-25 23:55 - 2014-01-25 23:43 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2014-01-25 23:43 - 2014-01-25 23:43 - 00065536 _____ () C:\WINDOWS\system32\config\SpybotSD.evt
2014-01-23 15:04 - 2014-01-23 15:04 - 00001569 _____ () C:\Documents and Settings\All Users\Nabídka Start\Programy\CDBurnerXP.lnk
2014-01-23 15:04 - 2014-01-23 15:04 - 00000000 ____D () C:\Program Files\CDBurnerXP
2014-01-23 14:55 - 2010-04-15 14:11 - 00000000 ____D () C:\Documents and Settings\Mirek\Local Settings\Data aplikací\Adobe
2014-01-23 14:54 - 2014-01-23 14:54 - 00000000 ____D () C:\Program Files\MSXML 4.0
2014-01-23 14:54 - 2010-04-09 20:40 - 00000000 ____D () C:\WINDOWS\system32\DirectX
2014-01-23 14:53 - 2010-04-09 22:16 - 00000000 ____D () C:\WINDOWS\system32\mui
2014-01-23 14:52 - 2014-01-23 14:52 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB942288-v3$
2014-01-23 13:49 - 2014-01-23 13:06 - 00000124 _____ () C:\Documents and Settings\Mirek\Dokumenty\ax_files.xml
2014-01-23 12:51 - 2014-01-23 12:51 - 00320120 _____ (Duplex Secure Ltd.) C:\WINDOWS\system32\Drivers\sptd.sys
2014-01-22 17:05 - 2013-12-10 18:46 - 00000000 ____D () C:\Documents and Settings\Mirek\Local Settings\Data aplikací\ESET
2014-01-22 16:17 - 2010-04-18 17:02 - 00000000 ____D () C:\WINDOWS\Minidump
2014-01-22 15:39 - 2014-01-22 15:39 - 00000000 ____D () C:\Program Files\AVG
2014-01-19 11:59 - 2013-12-18 13:02 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\AVAST Software

Some content of TEMP:
====================
C:\Documents and Settings\Mirek\Local Settings\Temp\BrowserInfo.exe


==================== Bamital & volsnap Check =================

C:\WINDOWS\explorer.exe
[2008-07-30 09:10] - [2008-07-30 09:10] - 1589760 ____A (Microsoft Corporation) dd7e25e20aebd672dae7e1d911c2d824

C:\WINDOWS\system32\winlogon.exe
[2008-07-30 09:17] - [2008-07-30 09:17] - 0557056 ____A (Microsoft Corporation) 12a799ad9415ae9c8abcc5f75e9cf034

C:\WINDOWS\system32\svchost.exe
[2008-04-14 09:52] - [2008-04-14 09:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93

C:\WINDOWS\system32\services.exe
[2008-04-14 09:52] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7

C:\WINDOWS\system32\User32.dll
[2008-07-30 09:16] - [2008-07-30 09:16] - 0578560 ____A (Microsoft Corporation) ccb32d10c69a89822e9134c0c4894be1

C:\WINDOWS\system32\userinit.exe
[2008-04-14 09:52] - [2008-04-14 09:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239

C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys
[2008-04-14 08:42] - [2008-04-14 08:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: COMODO Antivirus (Disabled - Up to date) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall (Disabled) {043803A3-4F86-4ef6-AFC5-F6E02A79969B}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Documents and Settings\Mirek\Plocha" je 6689 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu
C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfFactory Dispatcher v3
"C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" /source=HKLM [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL
Reim ECHO je vypnut.


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Winamp\\winamp.exe"="C:\\Program Files\\Winamp\\winamp.exe:*:Enabled:Winamp"


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:Torrent"
"C:\\WINDOWS\\system32\\msiexec.exe"="C:\\WINDOWS\\system32\\msiexec.exe:*:Enabled:UpdateManagerSetup"
"C:\\Program Files\\Opera\\opera.exe"="C:\\Program Files\\Opera\\opera.exe:*:Enabled:Opera Internet Browser"
"C:\\Program Files\\AVG\\AVG2013\\avgmfapx.exe"="C:\\Program Files\\AVG\\AVG2013\\avgmfapx.exe:*:Enabled:Instaltor AVG"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
"139:TCP"="139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002"


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000


==================== End Of Log ==============================

Re: Awardhotspoty :(

Napsal: 25 úno 2014 13:29
od vyosek
:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
    HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe
    HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKU\S-1-5-21-861567501-842925246-682003330-1003\...\Run: [NextLive] - C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Mirek\Data aplikací\newnext.me\nengine.dll",EntryPoint -m l
    GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = ru.redirect.wrapper.services.alawar.ru/startpage.php?lang=cs&wspv=3.0&locale=cs&pid=10202
    SearchScopes: HKLM - DefaultScope value is missing.
    
    CHR RestoreOnStartup: "hxxp://www.google.com/",
    "ru.redirect.wrapper.services.alawar.ru/startpage.php?lang=cs&wspv=3.0&locale=cs&pid=10202"
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    
    S2 Update Surftastic; "C:\Program Files\Surftastic\updateSurftastic.exe" [X]
    C:\Program Files\Surftastic
    
    2014-02-18 14:05 - 2014-02-18 14:05 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Mirek\Plocha\FRSTLauncher.exe
    2014-02-13 17:08 - 2014-02-13 16:23 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
    2014-02-13 16:26 - 2014-02-13 17:09 - 00026603 _____ () C:\zoek-results.log
    2014-02-13 16:23 - 2014-02-13 16:51 - 00000000 ____D () C:\zoek_backup
    2014-02-13 15:52 - 2014-02-13 16:14 - 00000000 ____D () C:\AdwCleaner
    2014-02-13 15:51 - 2014-02-13 15:51 - 00002246 _____ () C:\Documents and Settings\Mirek\Plocha\JRT.txt
    2014-02-13 15:35 - 2014-02-13 15:35 - 00000939 _____ () C:\Documents and Settings\Mirek\Plocha\Scan.txt
    2014-02-13 15:32 - 2014-02-13 15:32 - 00001876 _____ () C:\sc-cleaner.txt
    
    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfFactory Dispatcher v3" /f
    
    Hosts:
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt

Re: Awardhotspoty :(

Napsal: 26 úno 2014 09:39
od miros1
Dobrý den, nevím přesně jak myslíte :"Presunte vytvoreny fixlist vedle FRST" .. Jinak děkuji za trpělivost, byl jsem teď pracovně zaneprázdněn, doufám, že to dneska dokončím(e) :-)

Re: Awardhotspoty :(

Napsal: 26 úno 2014 10:36
od cernohous13
To znamená na plochu C:\Documents and Settings\Mirek\Plocha :wink:

Re: Awardhotspoty :(

Napsal: 26 úno 2014 16:42
od miros1
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-02-2014 01
Ran by Mirek at 2014-02-26 16:30:41 Run:1
Running from C:\Documents and Settings\Mirek\Plocha
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-861567501-842925246-682003330-1003\...\Run: [NextLive] - C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Mirek\Data aplikací\newnext.me\nengine.dll",EntryPoint -m l
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = ru.redirect.wrapper.services.alawar.ru/startpage.php?lang=cs&wspv=3.0&locale=cs&pid=10202
SearchScopes: HKLM - DefaultScope value is missing.

CHR RestoreOnStartup: "hxxp://www.google.com/",
"ru.redirect.wrapper.services.alawar.ru/startpage.php?lang=cs&wspv=3.0&locale=cs&pid=10202"
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

S2 Update Surftastic; "C:\Program Files\Surftastic\updateSurftastic.exe" [X]
C:\Program Files\Surftastic

2014-02-18 14:05 - 2014-02-18 14:05 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Mirek\Plocha\FRSTLauncher.exe
2014-02-13 17:08 - 2014-02-13 16:23 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-02-13 16:26 - 2014-02-13 17:09 - 00026603 _____ () C:\zoek-results.log
2014-02-13 16:23 - 2014-02-13 16:51 - 00000000 ____D () C:\zoek_backup
2014-02-13 15:52 - 2014-02-13 16:14 - 00000000 ____D () C:\AdwCleaner
2014-02-13 15:51 - 2014-02-13 15:51 - 00002246 _____ () C:\Documents and Settings\Mirek\Plocha\JRT.txt
2014-02-13 15:35 - 2014-02-13 15:35 - 00000939 _____ () C:\Documents and Settings\Mirek\Plocha\Scan.txt
2014-02-13 15:32 - 2014-02-13 15:32 - 00001876 _____ () C:\sc-cleaner.txt

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfFactory Dispatcher v3" /f

Hosts:

End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKU\S-1-5-21-861567501-842925246-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully.
C:\WINDOWS\system32\GroupPolicy\Machine => Moved successfully.
C:\WINDOWS\system32\GroupPolicy\GPT.ini => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
CHR RestoreOnStartup: "hxxp://www.google.com/", ==> The Chrome "Settings" can be used to fix the entry.
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
Update Surftastic => Service deleted successfully.
"C:\Program Files\Surftastic" => File/Directory not found.
"C:\Documents and Settings\Mirek\Plocha\FRSTLauncher.exe" => File/Directory not found.
C:\WINDOWS\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Documents and Settings\Mirek\Plocha\JRT.txt => Moved successfully.
C:\Documents and Settings\Mirek\Plocha\Scan.txt => Moved successfully.
C:\sc-cleaner.txt => Moved successfully.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.

========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f =========


Operace byla dokončena úspěšně.


========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfFactory Dispatcher v3" /f =========


Operace byla dokončena úspěšně.


========= End of Reg: =========

C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.


The system needs a manual reboot.

==== End of Fixlog ====

Re: Awardhotspoty :(

Napsal: 26 úno 2014 19:21
od vyosek
:arrow: Diky kolegovi za vstup :thumbsup:

:arrow: Jak se chova nas pacient?? Stale si podtrhuje co se mu zachce a vyskakuji okynka??

Re: Awardhotspoty :(

Napsal: 27 úno 2014 15:38
od miros1
Zdravím vás a děkuji. Zdá se být v pořádku. Zelené podtržení plus okna už nějaký den ne, nyní zmizela i varovná tabulka s tím rundllem :-) Ještě jeden malý dotaz. mám nainstalovanou klávesnici, ale po každém spuštění musím 3x stornovat průvodce novým hardwarem :( Není to virus, ale přesto nevím co s tím. Jinak ještě jednou díky :) M