Stránka 1 z 3

Zloděj hesel?

Napsal: 24 črc 2014 08:21
od mapete
Prosím o pomoc při kontrole PC. Nedávno mi chodily zpět e-maily z účtů na seznam.cz s "nedoručenou poštou", kterou jsem však nikdy neodesílal, Gmail mi před několika hodinami oznámil pokus o napadení účtu. Najdete nějakou havěť?

Logfile of random's system information tool 1.06 (written by random/random)
Run by Owner at 2014-07-24 09:19:00
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 10 GB (25%) free of 40 GB
Total RAM: 3326 MB (71% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-18Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-18UA.job
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-07-11 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-14 457712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-07-11 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
10

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2013-01-31 15517472]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2013-01-31 1982312]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-14 4086432]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2009-11-26 5129128]
"Služba Acronis Scheduler2"=C:\Program Files\Common Files\Acronis\Plán2\schedhlp.exe [2009-11-26 361976]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2012-06-06 20065936]
"Lexmark 2200 Series"=C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe [2004-02-13 57344]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Privatefirewall"=C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe [2013-12-17 3048480]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-07-11 256896]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoKMS]
C:\WINDOWS\AutoKMS.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NextLive]
C:\Documents and Settings\Owner\Data aplikací\newnext.me\nengine.dll,EntryPoint -m l []

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

C:\Documents and Settings\Owner\Nabídka Start\Programy\Po spuštění
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PFNet]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\WINDOWS\KMSEmulator.exe"="C:\WINDOWS\KMSEmulator.exe:*:Enabled:KMSEmulator"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Disabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Disabled:Microsoft Office OneNote"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Disabled:Microsoft Office Outlook"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"C:\Program Files\SendMails\sa\spamassassin.exe"="C:\Program Files\SendMails\sa\spamassassin.exe:*:Enabled:SpamAssassin for Win32"
"C:\Program Files\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe"="C:\Program Files\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe:*:Enabled:Update Engine"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2014-07-24 08:27:36 ----D---- C:\rsit
2014-07-24 08:27:36 ----D---- C:\Program Files\trend micro
2014-07-18 10:53:47 ----D---- C:\Program Files\Common Files\Java
2014-07-18 10:53:41 ----A---- C:\WINDOWS\system32\javaws.exe
2014-07-18 10:53:36 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-07-18 10:53:36 ----A---- C:\WINDOWS\system32\javaw.exe
2014-07-18 10:53:36 ----A---- C:\WINDOWS\system32\java.exe
2014-07-14 12:10:18 ----A---- C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-07-14 11:02:23 ----D---- C:\WINDOWS\jumpshot.com
2014-07-08 08:48:39 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2014-07-08 08:48:33 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2014-07-08 08:35:00 ----A---- C:\WINDOWS\system32\WdfCoInstaller01009.dll
2014-07-08 08:34:30 ----D---- C:\Program Files\Sony Mobile
2014-07-08 08:34:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony Mobile
2014-07-04 15:46:00 ----D---- C:\Documents and Settings\Owner\Data aplikací\MyPhoneExplorer
2014-07-04 15:45:44 ----D---- C:\Program Files\MyPhoneExplorer
2014-07-04 15:44:51 ----D---- C:\Documents and Settings\Owner\Data aplikací\Settings Manager
2014-07-04 14:44:53 ----D---- C:\Program Files\Sony
2014-07-04 14:44:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony
2014-07-04 14:42:24 ----D---- C:\Documents and Settings\All Users\Data aplikací\BVRP Software
2014-07-04 14:41:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony Ericsson

======List of files/folders modified in the last 1 months======

2014-07-24 09:17:25 ----D---- C:\WINDOWS\Prefetch
2014-07-24 08:27:36 ----D---- C:\Program Files
2014-07-24 07:48:25 ----D---- C:\Documents and Settings\Owner\Data aplikací\vlc
2014-07-24 07:08:33 ----D---- C:\WINDOWS\system32\CatRoot2
2014-07-24 05:29:36 ----D---- C:\WINDOWS\Temp
2014-07-23 17:49:25 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-07-23 05:39:43 ----D---- C:\WINDOWS\system32
2014-07-23 05:39:43 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-07-22 08:28:03 ----D---- C:\Documents and Settings\All Users\Data aplikací\YTD Video Downloader
2014-07-21 06:44:25 ----D---- C:\Program Files\rajce
2014-07-21 06:42:41 ----D---- C:\Program Files\Mozilla Firefox
2014-07-19 12:20:31 ----D---- C:\WINDOWS
2014-07-18 10:53:47 ----SHD---- C:\WINDOWS\Installer
2014-07-18 10:53:47 ----D---- C:\Program Files\Common Files
2014-07-18 10:53:35 ----D---- C:\Program Files\Java
2014-07-18 04:51:13 ----HD---- C:\WINDOWS\inf
2014-07-18 04:51:09 ----D---- C:\WINDOWS\system32\drivers
2014-07-14 12:10:52 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-07-14 11:00:00 ----D---- C:\Program Files\YTD
2014-07-14 10:59:27 ----SD---- C:\WINDOWS\Tasks
2014-07-14 10:59:15 ----A---- C:\WINDOWS\system32\aswBoot.exe
2014-07-11 07:59:31 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2014-07-09 05:47:01 ----D---- C:\WINDOWS\system32\MRT
2014-07-09 05:45:53 ----D---- C:\WINDOWS\Debug
2014-07-09 05:45:46 ----A---- C:\WINDOWS\system32\MRT.exe
2014-07-08 08:35:00 ----DC---- C:\WINDOWS\system32\DRVSTORE
2014-07-07 05:47:23 ----HD---- C:\Program Files\InstallShield Installation Information
2014-07-04 16:45:26 ----A---- C:\WINDOWS\win.ini
2014-06-25 19:01:17 ----D---- C:\Program Files\CCleaner

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 {16d667ee-6782-4b21-81df-8ded8ebc3868}Gt;{16d667ee-6782-4b21-81df-8ded8ebc3868}Gt; C:\WINDOWS\system32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gt.sys [2014-07-01 55224]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2014-07-14 55112]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-07-14 779536]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-07-14 414520]
R1 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2014-07-14 57800]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2013-12-28 218688]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-07-14 24184]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-07-14 67824]
R2 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2013-08-25 13120]
R3 afcdp;afcdp; C:\WINDOWS\system32\DRIVERS\afcdp.sys [2013-12-18 160288]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2012-06-19 6141584]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2013-01-31 12648960]
R3 pwipf6;Privacyware Filter Driver; C:\WINDOWS\system32\DRIVERS\pwipf6.sys [2012-05-25 135272]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2011-12-08 327400]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2009-03-18 30336]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S2 MLPTDR_Q;MLPTDR_Q; \??\C:\WINDOWS\system32\MLPTDR_Q.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 aswTap;avast! SecureLine TAP Adapter v3; C:\WINDOWS\system32\DRIVERS\aswTap.sys [2014-07-14 35144]
S3 ggflt;SOMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2014-07-08 13528]
S3 ggsomc;SOMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsomc.sys [2014-07-08 26328]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files\Common Files\Acronis\Plán2\schedul2.exe [2009-11-26 661008]
R2 afcdpsrv;Acronis Nonstop Backup service; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [2013-12-18 2480048]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-07-14 50344]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2014-07-11 182696]
R2 LexBceS;LexBce Server; C:\WINDOWS\system32\LEXBCES.EXE [2004-01-14 311296]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2013-01-31 156448]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-01-31 1259296]
R2 PFNet;Privacyware network service; C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe [2013-12-17 374600]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-19 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-14 262320]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-19 116648]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2014-01-06 136120]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-05-12 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Zloděj hesel?

Napsal: 24 črc 2014 08:27
od cernohous13
Vítám tě u nás Obrázek

Nejprve zkusíme roboty :wink:
:arrow: Stáhni Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Ulož jej na plochu a spusť - zobrazí se licenční podminky -> start libovolnou klávesou.
Bude vytvořena záloha a proběhne skenování.
Vyskočí log (nebo je uložen zde c:\JRT jako JRT.txt) - zkopíruj jej sem

:arrow: Stáhni AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Ulož nejlépe na plochu -> ukonči všechny programy -> spusť AdwCleaner -> klikni na Scan po dokončení na Clean
bude provedena oprava, restartuje se - (případně restartuj) a vypadne log C:\AdwCleaner\AdwCleaner[S?].txt , jeho obsah vložíš sem

:arrow: pravděpodobně budeš nucen vypnout na tu chvíli antivir - je to čisté, prověřeno
vyosek píše: :arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • :arrow: Po spuštění do okna vlozte skript nize

    Kód: Vybrat vše

    srinfo;
    autoclean;
    emptyclsid;
    iedefaults;
    process;
    hijackthis;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Log bude zde C:\zoek-results.log

Re: Zloděj hesel?

Napsal: 24 črc 2014 09:15
od mapete
Je-li to správně, vkládám tři logy.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Microsoft Windows XP x86
Ran by Owner on źt 24.07.2014 at 9:34:49,75
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\Owner\Data aplikacˇ\newnext.me"
Successfully deleted: [Folder] "C:\Documents and Settings\Owner\Data aplikacˇ\opencandy"
Successfully deleted: [Folder] "C:\Documents and Settings\Owner\Data aplikacˇ\thinstall"
Successfully deleted: [Folder] "C:\Program Files\mobogenie"
Successfully deleted: [Folder] "C:\Program Files\mypc backup"
Successfully deleted: [Folder] "C:\Program Files\ytd"





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 24.07.2014 at 9:40:33,81
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


# AdwCleaner v3.216 - Report created 24/07/2014 at 09:49:01
# Updated 17/07/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Owner - MAREK
# Running from : D:\Dokumenty\Downloads\adwcleaner_3.216.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files\GreenTree Applications
Folder Deleted : C:\Documents and Settings\Owner\Local Settings\Data aplikací\genienext
Folder Deleted : C:\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie
Folder Deleted : C:\Documents and Settings\Owner\Data aplikací\Settings Manager
File Deleted : C:\Documents and Settings\Owner\daemonprocess.txt
File Deleted : C:\Documents and Settings\Owner\Data aplikací\Mozilla\Firefox\Profiles\o80dgahh.default\searchplugins\default-search.xml
File Deleted : C:\Program Files\Mozilla Firefox\browser\searchplugins\default-search.xml

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\MyPC Backup
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F06672-0E95-41A9-80CB-DEE386AF99AD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F06672-0E95-41A9-80CB-DEE386AF99AD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Key Deleted : HKCU\Software\Linkey
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v29.0.1 (cs)

[ File : C:\Documents and Settings\Owner\Data aplikací\Mozilla\Firefox\Profiles\o80dgahh.default\prefs.js ]

Line Deleted : user_pref("browser.search.defaultenginename", "default-search.net");
Line Deleted : user_pref("browser.search.order.1", "default-search.net");
Line Deleted : user_pref("browser.search.selectedEngine", "default-search.net");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://www.default-search.net?sid=498&aid=0&it ... 98&src=hmp");
Line Deleted : user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=498&a ... &src=ds&p=");

-\\ Google Chrome v35.0.1916.153

[ File : C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [6363 octets] - [24/07/2014 09:47:54]
AdwCleaner[S0].txt - [5784 octets] - [24/07/2014 09:49:01]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5844 octets] ##########



Zoek.exe v5.0.0.0 Updated 22-07-2014
Tool run by Owner on źt 24.07.2014 at 10:05:08,94.
Microsoft Windows XP Home Edition 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: D:\Dokumenty\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

24.7.2014 10:05:40 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-436374069-1364589140-682003330-1003\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Running Processes ======================

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Plán2\schedhlp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Acronis\Plán2\schedul2.exe
C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Google\Update\1.3.24.15\GoogleCrashHandler.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wscntfy.exe
D:\Dokumenty\Downloads\zoek.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc

==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Documents and Settings\Owner\.android deleted
C:\Program Files\ComPlus Applications deleted
C:\Program Files\Common Files\DVDVideoSoft\bin deleted
C:\DOCUME~1\ALLUSE~1\DATAAP~1\Package Cache deleted
C:\WINDOWS\System32\SET1F8.tmp deleted
C:\WINDOWS\System32\SET1FA.tmp deleted
C:\WINDOWS\System32\SET1FD.tmp deleted
C:\WINDOWS\System32\SET201.tmp deleted
C:\WINDOWS\System32\SET202.tmp deleted
C:\WINDOWS\System32\SET209.tmp deleted
C:\WINDOWS\System32\SET20B.tmp deleted
C:\WINDOWS\System32\SET251.tmp deleted
"C:\WINDOWS\Installer\14ab42e.msi" deleted

======== System Restore Points ========

RP186: 19.6.2014 14:35:23 - Kontrolní bod systému
RP187: 23.6.2014 7:54:47 - Kontrolní bod systému
RP188: 24.6.2014 9:46:52 - Kontrolní bod systému
RP189: 25.6.2014 10:40:43 - Kontrolní bod systému
RP190: 26.6.2014 11:08:02 - Kontrolní bod systému
RP191: 27.6.2014 11:14:14 - Kontrolní bod systému
RP192: 30.6.2014 11:35:01 - Kontrolní bod systému
RP193: 1.7.2014 12:08:32 - Kontrolní bod systému
RP194: 2.7.2014 14:19:29 - Kontrolní bod systému
RP195: 3.7.2014 14:41:55 - Kontrolní bod systému
RP196: 4.7.2014 14:45:17 - Sony PC Companion
RP197: 4.7.2014 14:49:15 - Sony PC Companion
RP198: 7.7.2014 14:15:36 - Kontrolní bod systému
RP199: 8.7.2014 8:34:58 - Installed Sony Mobile Drivers
RP200: 8.7.2014 8:48:38 - Installed Windows XP Wdf01009.
RP201: 9.7.2014 5:45:39 - Software Distribution Service 3.0
RP202: 10.7.2014 7:02:14 - Kontrolní bod systému
RP203: 11.7.2014 8:27:50 - Kontrolní bod systému
RP204: 14.7.2014 10:58:49 - avast! antivirus system restore point
RP205: 15.7.2014 14:22:19 - Kontrolní bod systému
RP206: 16.7.2014 18:37:16 - Kontrolní bod systému
RP207: 18.7.2014 10:49:02 - Installed Java 7 Update 65
RP208: 21.7.2014 7:51:54 - Kontrolní bod systému
RP209: 22.7.2014 9:01:48 - Kontrolní bod systému
RP210: 23.7.2014 12:52:54 - Kontrolní bod systému
RP211: 24.7.2014 10:05:40 - zoek.exe restore point

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [21.12.2013 07:35]

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[14.07.2014 10:59]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search"

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F60730A4A66673047777F5728467D401 deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoKMS deleted successfully

==== HijackThis Entries ======================

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [Služba Acronis Scheduler2] "C:\Program Files\Common Files\Acronis\Plán2\schedhlp.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Privatefirewall] C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-436374069-1364589140-682003330-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs:
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Plán2\schedul2.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Privacyware network service (PFNet) - Privacyware/PWI, Inc. - C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe

==== Empty IE Cache ======================

C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\Owner\Local Settings\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\UpdatusUser\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=107 folders=27 16136915 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\Owner\LOCALS~1\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\RECYCLER successfully emptied

==== Deleting Files / Folders ======================

"C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found

==== EOF on źt 24.07.2014 at 10:12:20,60 ======================

Re: Zloděj hesel?

Napsal: 24 črc 2014 10:36
od cernohous13
Je to správně - částečně nám ulevily :wink:

:arrow: zde Stáhni a nainstaluj MBAM zde http://www.bleepingcomputer.com/downloa ... re/dl/241/ verzi 1.75
Při aktualizaci ti jako první nabídne instalaci nové verze - dáš Storno
Spustit -> na 3.záložce "Aktualizace" -> Kontrola aktualizací (možná bude provedeno automaticky)
následně na 1.záložce "Kontrolor" -> Úplná kontrola -> Prohledat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení a program nezavírej

Re: Zloděj hesel?

Napsal: 24 črc 2014 12:36
od mapete
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2014.07.24.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Owner :: MAREK [administrátor]

Ochrana: Povolena

24.7.2014 12:25:25
MBAM-log-2014-07-24 (13-34-19).txt

Typ: Kompletní kontrola (C:\|D:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 450583
Uplynulý čas: 52 minut, 15 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 2
HKLM\SYSTEM\CurrentControlSet\Services\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gt (PUP.Optional.Sanbreel.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\SmdmF (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 45
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\File System\011\t\00\00000000 (PUP.Optional.InstalleRex) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\File System\011\t\00\00000001 (PUP.Optional.Excellent4App) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\File System\013\t\00\00000000 (PUP.Optional.Somoto.A) -> Nebyla provedena žádná instrukce.
C:\Program Files\YTDSetup.exe (PUP.Optional.Spigot.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053102.exe (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053127.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053110.exe (PUP.Optional.Linkey.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053111.exe (PUP.Optional.Linkey.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053113.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053114.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053115.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053116.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053117.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053118.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053119.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053120.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053121.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053122.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053123.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053124.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053125.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053126.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053128.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053129.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053130.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053131.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053132.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053133.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053134.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053135.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053136.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053137.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053138.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053139.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP198\A0053140.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP200\A0053429.dll (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP200\A0053430.exe (PUP.Optional.SettingsManager.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP210\A0055234.exe (Trojan.Agent) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{04EC439E-A15E-4142-8336-76E982F2AA57}\RP210\A0055235.exe (Trojan.Agent) -> Nebyla provedena žádná instrukce.
D:\Dokumenty\Mapy\Keygen 1.5.0.65.exe (RiskWare.Tool.CK) -> Nebyla provedena žádná instrukce.
D:\Dokumenty\Mapy\Keygen 1.5.0.65.rar (RiskWare.Tool.CK) -> Nebyla provedena žádná instrukce.
D:\Dokumenty\Mapy\Mapy - programy\Keygen 1.5.0.65-KOPIE.exe (RiskWare.Tool.CK) -> Nebyla provedena žádná instrukce.
D:\Dokumenty\Mapy\Mapy - programy\Keygen 1.5.0.65.exe (RiskWare.Tool.CK) -> Nebyla provedena žádná instrukce.
D:\ZÁLOHY\ZÁLOHA OFFICE NOVÝ\Portable-Office-2003-CZ\Microsoft Office Word 2003.exe (Worm.VB) -> Nebyla provedena žádná instrukce.
C:\WINDOWS\system32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gt.sys (PUP.Optional.Sanbreel.A) -> Nebyla provedena žádná instrukce.

(konec)

Re: Zloděj hesel?

Napsal: 24 črc 2014 13:25
od cernohous13
Ty mapy na D:\ bych ti tam nechal - ostatní označit a odstranit
pak odinstaluj http://downloads.malwarebytes.org/file/mbam_clean

restart a nový RSIT

Re: Zloděj hesel?

Napsal: 24 črc 2014 13:54
od mapete
Logfile of random's system information tool 1.06 (written by random/random)
Run by Owner at 2014-07-24 14:52:47
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 10 GB (25%) free of 40 GB
Total RAM: 3326 MB (80% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-18Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-18UA.job
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-07-11 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-14 457712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-07-11 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
10

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2013-01-31 15517472]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2013-01-31 1982312]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-14 4086432]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2009-11-26 5129128]
"Služba Acronis Scheduler2"=C:\Program Files\Common Files\Acronis\Plán2\schedhlp.exe [2009-11-26 361976]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2012-06-06 20065936]
"Lexmark 2200 Series"=C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe [2004-02-13 57344]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Privatefirewall"=C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe [2013-12-17 3048480]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-07-11 256896]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NextLive]
C:\Documents and Settings\Owner\Data aplikací\newnext.me\nengine.dll,EntryPoint -m l []

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

C:\Documents and Settings\Owner\Nabídka Start\Programy\Po spuštění
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PFNet]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\WINDOWS\KMSEmulator.exe"="C:\WINDOWS\KMSEmulator.exe:*:Enabled:KMSEmulator"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Disabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Disabled:Microsoft Office OneNote"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Disabled:Microsoft Office Outlook"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"C:\Program Files\SendMails\sa\spamassassin.exe"="C:\Program Files\SendMails\sa\spamassassin.exe:*:Enabled:SpamAssassin for Win32"
"C:\Program Files\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe"="C:\Program Files\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe:*:Enabled:Update Engine"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2014-07-24 10:10:56 ----A---- C:\WINDOWS\zoek-delete.exe
2014-07-24 10:10:55 ----D---- C:\WINDOWS\Temp
2014-07-24 10:04:45 ----D---- C:\zoek_backup
2014-07-24 09:48:20 ----A---- C:\WINDOWS\system32\sqlite3.dll
2014-07-24 09:47:42 ----D---- C:\AdwCleaner
2014-07-24 09:34:45 ----D---- C:\WINDOWS\ERUNT
2014-07-24 08:27:36 ----D---- C:\rsit
2014-07-24 08:27:36 ----D---- C:\Program Files\trend micro
2014-07-18 10:53:47 ----D---- C:\Program Files\Common Files\Java
2014-07-18 10:53:41 ----A---- C:\WINDOWS\system32\javaws.exe
2014-07-18 10:53:36 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-07-18 10:53:36 ----A---- C:\WINDOWS\system32\javaw.exe
2014-07-18 10:53:36 ----A---- C:\WINDOWS\system32\java.exe
2014-07-14 12:10:18 ----A---- C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-07-14 11:02:23 ----D---- C:\WINDOWS\jumpshot.com
2014-07-08 08:48:39 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2014-07-08 08:48:33 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2014-07-08 08:35:00 ----A---- C:\WINDOWS\system32\WdfCoInstaller01009.dll
2014-07-08 08:34:30 ----D---- C:\Program Files\Sony Mobile
2014-07-08 08:34:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony Mobile
2014-07-04 15:46:00 ----D---- C:\Documents and Settings\Owner\Data aplikací\MyPhoneExplorer
2014-07-04 15:45:44 ----D---- C:\Program Files\MyPhoneExplorer
2014-07-04 14:44:53 ----D---- C:\Program Files\Sony
2014-07-04 14:44:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony
2014-07-04 14:42:24 ----D---- C:\Documents and Settings\All Users\Data aplikací\BVRP Software
2014-07-04 14:41:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony Ericsson

======List of files/folders modified in the last 1 months======

2014-07-24 14:52:39 ----D---- C:\WINDOWS\Prefetch
2014-07-24 14:44:08 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-07-24 14:43:23 ----D---- C:\WINDOWS\system32\drivers
2014-07-24 14:42:37 ----D---- C:\WINDOWS\system32\CatRoot2
2014-07-24 14:40:50 ----D---- C:\Program Files
2014-07-24 14:38:39 ----D---- C:\WINDOWS\mui
2014-07-24 10:12:08 ----D---- C:\WINDOWS
2014-07-24 10:09:31 ----SHD---- C:\WINDOWS\Installer
2014-07-24 10:09:31 ----D---- C:\WINDOWS\system32
2014-07-24 10:09:30 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2014-07-24 09:23:05 ----D---- C:\Documents and Settings\Owner\Data aplikací\vlc
2014-07-23 05:39:43 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-07-22 08:28:03 ----D---- C:\Documents and Settings\All Users\Data aplikací\YTD Video Downloader
2014-07-21 06:44:25 ----D---- C:\Program Files\rajce
2014-07-21 06:42:41 ----D---- C:\Program Files\Mozilla Firefox
2014-07-18 10:53:47 ----D---- C:\Program Files\Common Files
2014-07-18 10:53:35 ----D---- C:\Program Files\Java
2014-07-18 04:51:13 ----HD---- C:\WINDOWS\inf
2014-07-14 12:10:52 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-07-14 10:59:27 ----SD---- C:\WINDOWS\Tasks
2014-07-14 10:59:15 ----A---- C:\WINDOWS\system32\aswBoot.exe
2014-07-11 07:59:31 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2014-07-09 05:47:01 ----D---- C:\WINDOWS\system32\MRT
2014-07-09 05:45:53 ----D---- C:\WINDOWS\Debug
2014-07-09 05:45:46 ----A---- C:\WINDOWS\system32\MRT.exe
2014-07-08 08:35:00 ----DC---- C:\WINDOWS\system32\DRVSTORE
2014-07-07 05:47:23 ----HD---- C:\Program Files\InstallShield Installation Information
2014-07-04 16:45:26 ----A---- C:\WINDOWS\win.ini
2014-06-25 19:01:17 ----D---- C:\Program Files\CCleaner

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 {16d667ee-6782-4b21-81df-8ded8ebc3868}Gt;{16d667ee-6782-4b21-81df-8ded8ebc3868}Gt; C:\WINDOWS\system32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gt.sys [2014-07-01 55224]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2014-07-14 55112]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-07-14 779536]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-07-14 414520]
R1 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2014-07-14 57800]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2013-12-28 218688]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-07-14 24184]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-07-14 67824]
R2 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2013-08-25 13120]
R3 afcdp;afcdp; C:\WINDOWS\system32\DRIVERS\afcdp.sys [2013-12-18 160288]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2012-06-19 6141584]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2013-01-31 12648960]
R3 pwipf6;Privacyware Filter Driver; C:\WINDOWS\system32\DRIVERS\pwipf6.sys [2012-05-25 135272]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2011-12-08 327400]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2009-03-18 30336]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S2 MLPTDR_Q;MLPTDR_Q; \??\C:\WINDOWS\system32\MLPTDR_Q.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 aswTap;avast! SecureLine TAP Adapter v3; C:\WINDOWS\system32\DRIVERS\aswTap.sys [2014-07-14 35144]
S3 ggflt;SOMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2014-07-08 13528]
S3 ggsomc;SOMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsomc.sys [2014-07-08 26328]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files\Common Files\Acronis\Plán2\schedul2.exe [2009-11-26 661008]
R2 afcdpsrv;Acronis Nonstop Backup service; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [2013-12-18 2480048]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-07-14 50344]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2014-07-11 182696]
R2 LexBceS;LexBce Server; C:\WINDOWS\system32\LEXBCES.EXE [2004-01-14 311296]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2013-01-31 156448]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-01-31 1259296]
R2 PFNet;Privacyware network service; C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe [2013-12-17 374600]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-19 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-14 262320]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-19 116648]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2014-01-06 136120]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-05-12 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Zloděj hesel?

Napsal: 24 črc 2014 15:15
od cernohous13
Stáhni OTM z jednoho odkazu a rozbal nejlépe na plochu.
http://oldtimer.geekstogo.com/OTM.exe
http://www.itxassociates.com/OT-Tools/OTM.exe

Spusť program „OTM.exe“
Do okna pod žlutou čáru vlož celý text zeleným písmem ze „Scriptu“

Klikni na červené „MoveIt!“

Při nabídce restartu „YES“
a log potom najdeš v C:\_OTM\MovedFiles\ - dej mi ho sem na kontrolu
Script OTM

Kód: Vybrat vše

:Commands
[resethosts]
[emptytemp]
[emptyflash]
[emptyjava]
[clearallrestorepoints]

:Files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp /s
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-18Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-18UA.job
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
C:\WINDOWS\zoek-delete.exe
C:\zoek_backup
C:\AdwCleaner

:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=-
"GrooveMonitor"=-
"SunJavaUpdateSched"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NextLive]

:Services
JavaQuickStarterService
nvUpdatusService
gupdate
gupdatem
gusvc

Re: Zloděj hesel?

Napsal: 24 črc 2014 16:03
od mapete
All processes killed
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 32913 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Owner
->Temp folder emptied: 728348 bytes
->Temporary Internet Files folder emptied: 189592 bytes
->FireFox cache emptied: 20861721 bytes
->Google Chrome cache emptied: 276411798 bytes
->Flash cache emptied: 599 bytes

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Uživatel

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 26796 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 623628631 bytes

Total Files Cleaned = 879,00 mb


[EMPTYFLASH]

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: Owner
->Flash cache emptied: 0 bytes

User: UpdatusUser

User: Uživatel

Total Flash Files Cleaned = 0,00 mb


[EMPTYJAVA]

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: Owner

User: UpdatusUser

User: Uživatel

Total Java Files Cleaned = 0,00 mb


Restore point Set: OTM Restore Point
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP172.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP193.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1A9.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1BC.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1CE.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP6A.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPCA.tmp folder moved successfully.
C:\WINDOWS\Installer\MSI16.tmp- folder moved successfully.
C:\WINDOWS\Installer\MSI19.tmp- folder moved successfully.
C:\WINDOWS\Installer\MSI1A.tmp- folder moved successfully.
C:\WINDOWS\Installer\MSI1B.tmp- folder moved successfully.
C:\WINDOWS\Installer\MSI1C.tmp- folder moved successfully.
C:\WINDOWS\Installer\MSI429.tmp- folder moved successfully.
C:\WINDOWS\Installer\MSI42C.tmp- folder moved successfully.
C:\WINDOWS\Installer\MSI42D.tmp- folder moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-18Core.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-18UA.job moved successfully.
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job moved successfully.
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job moved successfully.
C:\WINDOWS\zoek-delete.exe moved successfully.
C:\zoek_backup\C_Program Files_ComPlus Applications folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\zh-TW folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\zh-CN folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\vi-VN folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\tr-TR folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\sv-SE folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\sl-SI folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\sk-SK folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\ru-RU folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\pt-PT folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\pt-BR folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\pl-PL folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\nl-NL folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\ja-JP folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\it-IT folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\hu-HU folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\fr-FR folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\fi-FI folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\es-ES folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\el-GR folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\de-DE folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin\da-DK folder moved successfully.
C:\zoek_backup\C_Program Files_Common Files_DVDVideoSoft_bin folder moved successfully.
C:\zoek_backup\C_DOCUME~1_ALLUSE~1_DATAAP~1_Package Cache\E15AD80FC74277EF2048312E9A71AF56B2EBA622\redist folder moved successfully.
C:\zoek_backup\C_DOCUME~1_ALLUSE~1_DATAAP~1_Package Cache\E15AD80FC74277EF2048312E9A71AF56B2EBA622 folder moved successfully.
C:\zoek_backup\C_DOCUME~1_ALLUSE~1_DATAAP~1_Package Cache folder moved successfully.
C:\zoek_backup\C_Documents and Settings_Owner_.android folder moved successfully.
C:\zoek_backup folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\Mozilla Firefox\browser\searchplugins folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\Mozilla Firefox\browser folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\Mozilla Firefox folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\prop-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_output folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_filter\.svn\text-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_filter\.svn\prop-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_filter\.svn folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_filter folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\codec\.svn\text-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\codec\.svn\prop-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\codec\.svn folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\codec folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_output\.svn\text-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_output\.svn\prop-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_output\.svn folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_output folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\text-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\prop-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\text-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\prop-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_filter folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\access\.svn\text-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\access\.svn\prop-base folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\access\.svn folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins\access folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\plugins folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader\Lang folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications\YTD Video Downloader folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\GreenTree Applications folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\notice folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\download folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\connect folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\tab_switch folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\dialog folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\welcome folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\pb folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\moduletemp folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\vedio folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\ui folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\subject folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\message folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\image folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\driver folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\download folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\contact folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\app folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\interface folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_ folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_square folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_rounded folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_square folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_rounded folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\debug folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\iframe folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_ folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\skin folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\libraries folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\test folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples\views folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\bin folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks\templating folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\css folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\sqldrivers folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\phonon_backend folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\log folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\imageformats folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version\OldVersion folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Version folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie\Data folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací\Mobogenie folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings\Data aplikací folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Local Settings folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Data aplikací\Mozilla\Firefox\Profiles\o80dgahh.default\searchplugins folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Data aplikací\Mozilla\Firefox\Profiles\o80dgahh.default folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Data aplikací\Mozilla\Firefox\Profiles folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Data aplikací\Mozilla\Firefox folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Data aplikací\Mozilla folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner\Data aplikací folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Owner folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings folder moved successfully.
C:\AdwCleaner\Quarantine\C folder moved successfully.
C:\AdwCleaner\Quarantine folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings\Owner\Data aplikací\Mozilla\Firefox\Profiles\o80dgahh.default folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings\Owner\Data aplikací\Mozilla\Firefox\Profiles folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings\Owner\Data aplikací\Mozilla\Firefox folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings\Owner\Data aplikací\Mozilla folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings\Owner\Data aplikací folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings\Owner folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings folder moved successfully.
C:\AdwCleaner\Backup\C folder moved successfully.
C:\AdwCleaner\Backup folder moved successfully.
C:\AdwCleaner folder moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NextLive\ deleted successfully.
========== SERVICES/DRIVERS ==========
Service JavaQuickStarterService stopped successfully!
Service JavaQuickStarterService deleted successfully!
Service nvUpdatusService stopped successfully!
Service nvUpdatusService deleted successfully!
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
Service gusvc stopped successfully!
Service gusvc deleted successfully!

OTM by OldTimer - Version 3.1.21.0 log created on 07242014_164315

Files moved on Reboot...
File C:\Documents and Settings\Owner\Local Settings\Temp\JETB749.tmp not found!
File move failed. C:\WINDOWS\temp\_avast_\AvastLock.txt scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Re: Zloděj hesel?

Napsal: 24 črc 2014 16:24
od cernohous13
:arrow: Spusť opět OTM -> CleanUp! - odinstaluje a vyčistí po sobě.

:arrow: Mohu doporučit kontrolu a vyčištění Ccleanerem
Stáhni Ccleaner - http://www.filehippo.com/download_ccleaner
Při instalaci vyhodit fajfku u nabízených toolbarů
Můžeš nastavit potřebný jazyk
zavřít Internetový prohlížeč a
spustit "Čistič" > "Spustit Ccleaner" - odstraní nepotřebné
spustit "Registry" > "Hledej problémy" > "Opravit vybrané problémy"
souhlas se zálohou registrů - opakovat dokud nebudou registry čisté.
spustit "Nástroje" > "Start" - tady můžeš zkusit deaktivovat procesy, které při spuštění nepotřebuješ (pokud by ti potom něco nechodilo, stejným způsobem je povolíš)

Návod:http://jnp.zive.cz/Clanky/Prirucka-do-k ... fault.aspx
Ten si můžeš nechat i na budoucí občasné čištění.

:arrow: Po vyčištění by se hodila defragmentace
http://www.filehippo.com/download_defraggler

:???: napiš mi pak jaké jsou ještě problémy

Re: Zloděj hesel?

Napsal: 24 črc 2014 18:09
od mapete
1) OTM -> CleanUp! - spuštěno
2) Ccleaner používám pravidelně
3) defragmentace běží
4) další problémy neregistruji

Bylo tedy nalezeno něco špatného, nebo jsme provedli jen zběžné čištění?
Mohlo "TO" být (či stále je) i v Android telefonu, kde poštu stahuji?
Nestahuju z GooglePlay v podstatě nic, hry nehraju, a tak nějak všeobecně nepoužívám a nestahuji zbytečné programy na zkoušku ani do PC, ani do mobilu...

Re: Zloděj hesel?

Napsal: 25 črc 2014 03:57
od cernohous13
Bylo to skutečně jen odstranění balastu - nic nebezpečného jsem nezaznamenal

Na Android můžeš vyzkoušet http://androidportal.zoznam.sk/2014/02/ ... bezpecnost
vyber si (za mě Avast, Eset)

Re: Zloděj hesel?

Napsal: 25 črc 2014 04:14
od mapete
cernohous13 píše:Bylo to skutečně jen odstranění balastu - nic nebezpečného jsem nezaznamenal
To mě moc neuspokojuje, raději bych byl, kdyby se něco našlo a následně odstranilo...
OK děkuji, posílám bankovním převodem děkovačku.

Re: Zloděj hesel?

Napsal: 25 črc 2014 04:35
od cernohous13
Pro klid duše můžeš ještě nasadit Kasperskyho
Pro důkladnou kontrolu systému můžeš použít
návod-http://i275.photobucket.com/albums/jj28 ... S/KAS9.gif
link-http://www.kaspersky.com/kos/eng/partne ... bscan.html
podle návodu vytvoř log a dej ho sem.
Za podporu fóra děkujeme :thumbsup:

Re: Zloděj hesel?

Napsal: 25 črc 2014 06:04
od mapete
ON-LINE scan se mi nepodařilo spustit, nabízí se pouze instalace, tedy pokud jsem něco nepřehlédnul. Výsledek níže.
AVAST na mobilu používám, nikdy nic nehlásil.

Computer protection (1)
Information about anti-virus software and firewalls installed on the computer.
Kaspersky Lab recommends
Firewall is disabled.

Malware (2)
Information about malware detected on the computer.
Kaspersky Lab recommends
Trojan.Win32.AntiFW.b
data0005
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\File System\011\t\00\00000001/
Trojan.Win32.AntiFW.b
data0005
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\User Data\Default\File System\011\t\00\00000000/

Vulnerabilities (4)
Information about applications and operating system components in which vulnerabilities have been detected.
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Garmin GPS Plugin\npGarmin.dll
C:\Program Files\Picasa2\Picasa2.exe
C:\Program Files\WinRAR\WinRAR.exe

Other issues (10)
Information about vulnerabilities associated with the settings of installed applications and the operating system.
"Autorun from hard drives is allowed"
"Autorun from network drives is enabled"
"CD/DVD autorun is enabled"
"Removable media autorun is enabled"
"Microsoft Internet Explorer - disable caching data received via protected channel"
"Microsoft Internet Explorer: disable sending error reports"
"Microsoft Internet Explorer: clear the list of trusted domains"
"Microsoft Internet Explorer: clear list of pop-up blocker exceptions"
"Microsoft Internet Explorer: enable cache autocleanup on browser closing"
"Microsoft Internet Explorer: start page reset"