nežádoucí reklama v prohlížečích logzRsit

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
digitaaalek
1. Stupeň Varování
Příspěvky: 36
Registrován: 26 Led 2009 11:20

nežádoucí reklama v prohlížečích logzRsit

#1 Příspěvek od digitaaalek »

V prohlížečích mi skáče spoustu reklam, na čištění jsem použil Antispyware a Cleaner. Díky

Logfile of random's system information tool 1.10 (written by random/random)
Run by acer at 2015-01-20 18:20:33
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 90 GB (39%) free of 228 GB
Total RAM: 3997 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:20:42, on 20.1.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Launch Manager\LManager.EXE
C:\Program Files (x86)\Inbox Toolbar\Inbox.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\acer\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\acer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source= ... 1377277308
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source= ... 1377277308
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source= ... 1377277308
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [InboxToolbar] "C:\Program Files (x86)\Inbox Toolbar\Inbox.exe" /STARTUP
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\Program Files (x86)\Inbox Toolbar\Inbox64.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O20 - AppInit_DLLs: c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: YAC Service (iSafeService) - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Network HTTP Support Service (NetHttpService) - Unknown owner - C:\Windows\SysWOW64\nethtsrv.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Network Support Service Updater (ServiceUpdater) - Unknown owner - C:\Windows\SysWOW64\netupdsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: ujopqrpsggkjpn - LIMITED - c:\windows\SysWOW64\ztpfzeq.exe
O23 - Service: Updater Service - Acer Group - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WinZiper service (winzipersvc) - Taiwan Shui Mu Chih Ching Technology Limited. - C:\Program Files (x86)\WinZipper\winzipersvc.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11790 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Acer Registration - Data Sending task.job - C:\Program Files (x86)\Acer\Registration\GREG.exe /DS
C:\Windows\tasks\AmiUpdXp.job - C:\Users\acer\AppData\Local\13337\Updater.exe
C:\Windows\tasks\PC SpeedUp Service Deactivator.job - C:\Program Files (x86)\Zrychleni Pocitace\PCSUSD.exe /dev0 /idle

=========Mozilla firefox=========

ProfilePath - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\aw0f2o6c.default

"xz123@ya456.com"=C:\Program Files (x86)\BetterSurf\ff
"12x3q@3244516.com"=C:\Program Files (x86)\Better-Surf\ff
"ext@bettersurfplus.com"=C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff
"ext@WebexpEnhancedV1alpha5490.net"=C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha5490\ff
"ext@VideoPlayerV3beta4064.net"=C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta4064\ff
"ext@MediaPlayerV1alpha1812.net"=C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha1812\ff
"ext@MediaViewerV1alpha1774.net"=C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1774\ff
"ext@MediaViewV1alpha917.net"=C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha917\ff
"ext@MediaViewV1alpha2893.net"=C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha2893\ff
"ext@MediaWatchV1home4088.net"=C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home4088\ff
"ext@MediaBuzzV1mode2096.net"=C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode2096\ff
"ext@RichMediaViewV1release7300.net"=C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release7300\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14 1709152]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-28 35696]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-02-18 283160]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2009-09-24 825864]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"InboxToolbar"=C:\Program Files (x86)\Inbox Toolbar\Inbox.exe [2014-11-11 1430936]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2014-12-15 7780120]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer VCM.lnk - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
Bluetooth.lnk - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-01-20 18:20:34 ----D---- C:\Program Files (x86)\trend micro
2015-01-20 18:20:33 ----D---- C:\rsit
2015-01-20 18:11:11 ----A---- C:\awh99FD.tmp
2015-01-20 18:10:32 ----D---- C:\Users\acer\AppData\Roaming\Mozilla
2015-01-20 18:10:06 ----D---- C:\ProgramData\Mozilla
2015-01-20 18:10:03 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-20 18:09:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-01-20 17:43:42 ----A---- C:\awhF0E3.tmp
2015-01-20 17:01:39 ----D---- C:\SUPERDelete
2015-01-20 17:00:25 ----D---- C:\Users\acer\AppData\Roaming\SUPERAntiSpyware.com
2015-01-20 17:00:05 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2015-01-20 16:50:02 ----D---- C:\Program Files (x86)\Elex-tech
2015-01-20 16:50:01 ----D---- C:\Users\acer\AppData\Roaming\Elex-tech
2015-01-17 15:30:07 ----A---- C:\awh68C0.tmp
2015-01-14 16:30:52 ----A---- C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 16:30:52 ----A---- C:\Windows\SysWOW64\ncsi.dll
2015-01-14 16:30:43 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 16:30:41 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 16:30:35 ----A---- C:\Windows\SysWOW64\srclient.dll
2015-01-14 16:09:19 ----A---- C:\awh91EB.tmp
2015-01-01 02:37:12 ----A---- C:\awhC622.tmp
2014-12-31 22:39:42 ----A---- C:\Windows\SysWOW64\nethtsrv.exe
2014-12-31 22:39:40 ----A---- C:\Windows\SysWOW64\netupdsrv.exe
2014-12-31 22:39:30 ----A---- C:\Windows\SysWOW64\installd.exe
2014-12-31 22:39:12 ----A---- C:\Windows\SysWOW64\hfnapi.dll
2014-12-31 22:39:04 ----A---- C:\Windows\SysWOW64\hfpapi.dll

======List of files/folders modified in the last 1 month======

2015-01-20 18:20:39 ----AD---- C:\ProgramData\TEMP
2015-01-20 18:20:34 ----RD---- C:\Program Files (x86)
2015-01-20 18:15:47 ----D---- C:\Windows\Temp
2015-01-20 18:13:00 ----D---- C:\Windows\System32
2015-01-20 18:13:00 ----D---- C:\Windows\inf
2015-01-20 18:10:06 ----HD---- C:\ProgramData
2015-01-20 18:08:46 ----D---- C:\Program Files (x86)\WinZipper
2015-01-20 18:05:54 ----D---- C:\Windows\SysWOW64
2015-01-20 18:05:38 ----D---- C:\Windows
2015-01-20 17:59:07 ----D---- C:\Windows\Tasks
2015-01-20 17:59:06 ----SHD---- C:\Windows\Installer
2015-01-20 17:59:06 ----SHD---- C:\Config.Msi
2015-01-20 17:58:54 ----D---- C:\Program Files (x86)\Google
2015-01-20 17:50:47 ----D---- C:\Windows\Panther
2015-01-20 17:50:46 ----D---- C:\Windows\Logs
2015-01-20 17:50:45 ----D---- C:\Windows\Minidump
2015-01-20 17:50:45 ----D---- C:\Windows\debug
2015-01-20 17:43:44 ----D---- C:\Users\acer\AppData\Roaming\Seznam.cz
2015-01-20 17:39:24 ----D---- C:\Windows\Prefetch
2015-01-20 17:22:42 ----D---- C:\Program Files (x86)\PokerStars
2015-01-20 17:00:05 ----RD---- C:\Program Files
2015-01-20 16:16:00 ----SHD---- C:\System Volume Information
2015-01-20 16:04:55 ----D---- C:\Users\acer\AppData\Roaming\WinZipper
2015-01-18 04:45:20 ----D---- C:\Users\acer\AppData\Roaming\vlc
2015-01-17 15:25:02 ----D---- C:\Windows\winsxs
2015-01-03 22:44:37 ----SD---- C:\Users\acer\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys []
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 iSafeKrnl;YAC Mini-Filter Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [2015-01-19 249000]
R1 iSafeKrnlKit;YAC Kit Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [2015-01-19 99496]
R1 iSafeKrnlMon;YAC Monitor Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [2015-01-19 42152]
R1 iSafeKrnlR3;YAC Ring3 Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [2015-01-19 93352]
R1 iSafeNetFilter;YAC NDIS Driver; C:\Windows\system32\DRIVERS\iSafeNetFilter.sys []
R1 nethfdrv;nethfdrv; \??\C:\Windows\system32\drivers\nethfdrv.sys []
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys []
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys []
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys []
R3 DKbFltr;Dritek Keyboard Filter Driver (64-bit); C:\Windows\SysWOW64\Drivers\DKbFltr.sys [2009-03-26 25608]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys []
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys []
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys []
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys []
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys []
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys []
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys []
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys []
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys []
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys []
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys []
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys []
S3 E1G60;Intel(R) PRO/1000 NDIS 6 Adapter Driver; C:\Windows\system32\DRIVERS\E1G6032E.sys []
S3 iSafeKrnlBoot;YAC Boot Driver; C:\Windows\system32\DRIVERS\iSafeKrnlBoot.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys []
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys []
S3 RtsUIR;Realtek IR Driver; C:\Windows\system32\DRIVERS\Rts516xIR.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys []
S3 USBCCID;Realtek Smartcard Reader Driver; C:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2014-07-23 172344]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-17 864032]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-07-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-07-14 1767520]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-02-26 841248]
R2 GREGService;GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 23584]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-02-18 13336]
R2 iSafeService;YAC Service; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [2015-01-19 120128]
R2 IviRegMgr;IviRegMgr; C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 23784]
R2 NetHttpService;Network HTTP Support Service; C:\Windows\SysWOW64\nethtsrv.exe [2014-12-31 314368]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 RS_Service;Raw Socket Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [2010-01-30 260640]
R2 ServiceUpdater;Network Support Service Updater; C:\Windows\SysWOW64\netupdsrv.exe [2014-12-31 335872]
R2 ujopqrpsggkjpn;ujopqrpsggkjpn; c:\windows\SysWOW64\ztpfzeq.exe [2014-05-15 76800]
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-01-29 243232]
R2 winzipersvc;WinZiper service; C:\Program Files (x86)\WinZipper\winzipersvc.exe [2015-01-12 424624]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 368624]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe /V []
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-01-09 114800]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []

-----------------EOF-----------------

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: nežádoucí reklama v prohlížečích logzRsit

#2 Příspěvek od altrok »

Zdravim :bye:

:arrow: Odinstalujte :arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).

:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan, pote na Clean
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
:arrow: Ulozte na plochu zoek.exe http://hijackthis.nl/smeenk/zoek.htm
  • spustte jako spravce
  • do velkeho okna zkopirujte script uvedeny nize
  • kliknete na Run script
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\zoek-results.log) - vlozte mi jej do pristi odpovedi

    Kód: Vybrat vše

    autoclean;
    emptyclsid;
    emptyalltemp;
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

digitaaalek
1. Stupeň Varování
Příspěvky: 36
Registrován: 26 Led 2009 11:20

Re: nežádoucí reklama v prohlížečích logzRsit

#3 Příspěvek od digitaaalek »

# AdwCleaner v4.108 - Report created 20/01/2015 at 19:12:31
# Updated 17/01/2015 by Xplode
# Database : 2015-01-18.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : acer - ACER-PC
# Running from : C:\Users\acer\Downloads\adwcleaner_4.108.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : nethfdrv
Service Deleted : NethxxpService
Service Deleted : ServiceUpdater
Service Deleted : winzipersvc
[#] Service Deleted : iSafeKrnlMon

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\eSafe
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inbox Toolbar
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zrychleni Pocitace
Folder Deleted : C:\Program Files (x86)\Desk 365
Folder Deleted : C:\Program Files (x86)\Inbox Toolbar
Folder Deleted : C:\Program Files (x86)\Uniblue
Folder Deleted : C:\Program Files (x86)\WinZipper
Folder Deleted : C:\Program Files\PCDApp
Folder Deleted : C:\Users\acer\AppData\Local\Conduit
Folder Deleted : C:\Users\acer\AppData\Local\Microsoft\Silverlight\OutOfBrowser\Speedchecker.PCSpeedUp
Folder Deleted : C:\Users\acer\AppData\Local\NativeMessaging
Folder Deleted : C:\Users\acer\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\acer\AppData\Local\TBHostSupport
Folder Deleted : C:\Users\acer\AppData\Local\WhiteListing
Folder Deleted : C:\Users\acer\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\acer\AppData\LocalLow\Inbox Toolbar
Folder Deleted : C:\Users\acer\AppData\Roaming\eIntaller
Folder Deleted : C:\Users\acer\AppData\Roaming\eUpdate
Folder Deleted : C:\Users\acer\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\acer\AppData\Roaming\Uniblue
Folder Deleted : C:\Users\acer\AppData\Roaming\WinZipper
File Deleted : C:\END
File Deleted : C:\Windows\SysWOW64\hfpapi.dll
File Deleted : C:\Windows\SysWOW64\installd.exe
File Deleted : C:\Windows\SysWOW64\nethtsrv.exe
File Deleted : C:\Windows\SysWOW64\netupdsrv.exe
File Deleted : C:\Windows\System32\drivers\nethfdrv.sys
File Deleted : C:\Windows\System32\log\iSafeKrnlCall.log

***** [ Scheduled Tasks ] *****

Task Deleted : AmiUpdXp
Task Deleted : BrowserProtect
Task Deleted : Desk 365 RunAsStdUser
Task Deleted : PC SpeedUp Service Deactivator

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\acer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk

***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [12x3q@3244516.com]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [ext@bettersurfplus.com]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [xz123@ya456.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dedmngkbaffkenlfdcbganndoghblmap
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\poheodfamflhhhdcmjfeggbgigeefaco
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mmifolfpllfdhilecpdpmemhelmanajl
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKLM\SOFTWARE\Classes\inbox.appserver
Key Deleted : HKLM\SOFTWARE\Classes\inbox.ibx404
Key Deleted : HKLM\SOFTWARE\Classes\Inbox.JSServer
Key Deleted : HKLM\SOFTWARE\Classes\Inbox.Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\inbox
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [InboxToolbar]
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Key Deleted : HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZipper
Key Deleted : HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZipper
Key Deleted : HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\WinZipper
Key Deleted : HKCU\Software\5a48a8ce63de845
Key Deleted : HKLM\SOFTWARE\5a48a8ce63de845
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A2773ED4-83BD-488A-A186-73590706C916}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{042DA63B-0933-403D-9395-B49307691690}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{37540F19-DD4C-478B-B2DF-C19281BCAF27}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{612AD33D-9824-4E87-8396-92374E91C4BB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0AFD55C8-ADF8-4A33-A6E1-DEDB7A36AEB4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{28C3737A-32D1-492D-B76B-8D75EBBFB887}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CE057E0D-2D7E-4DFF-A890-07BA69B8C762}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{615E8AA1-6BB8-4A3D-A1CC-373194DB612C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CBEF8724-D080-4737-88DA-111EEC6651AA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99E29823-2F67-41C3-8AA5-6425097A771F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{612AD33D-9824-4E87-8396-92374E91C4BB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{042DA63B-0933-403D-9395-B49307691690}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{37540F19-DD4C-478B-B2DF-C19281BCAF27}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{28C3737A-32D1-492D-B76B-8D75EBBFB887}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{CE057E0D-2D7E-4DFF-A890-07BA69B8C762}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{612AD33D-9824-4E87-8396-92374E91C4BB}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\BABSOLUTION
Key Deleted : HKCU\Software\BabylonToolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\filescout
Key Deleted : HKCU\Software\Inbox Toolbar
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\Speedchecker Limited
Key Deleted : HKCU\Software\V9
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\BetterSurf
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\delta-homesSoftware
Key Deleted : HKLM\SOFTWARE\Desksvc
Key Deleted : HKLM\SOFTWARE\eSafeSecControl
Key Deleted : HKLM\SOFTWARE\hdcode
Key Deleted : HKLM\SOFTWARE\Inbox Toolbar
Key Deleted : HKLM\SOFTWARE\MediaBuzzV1
Key Deleted : HKLM\SOFTWARE\MediaPlayerV1
Key Deleted : HKLM\SOFTWARE\MediaViewerV1
Key Deleted : HKLM\SOFTWARE\MediaViewV1
Key Deleted : HKLM\SOFTWARE\MediaWatchV1
Key Deleted : HKLM\SOFTWARE\qvo6Software
Key Deleted : HKLM\SOFTWARE\Speedchecker Limited
Key Deleted : HKLM\SOFTWARE\Uniblue
Key Deleted : HKLM\SOFTWARE\V9
Key Deleted : HKLM\SOFTWARE\winzipersvc
Key Deleted : HKLM\SOFTWARE\Webexp Enhanced
Key Deleted : HKLM\SOFTWARE\WebexpEnhancedV1
Key Deleted : HKLM\SOFTWARE\Video Player
Key Deleted : HKLM\SOFTWARE\VideoPlayerV3
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{612AD33D-9824-4E87-8396-92374E91C4BB}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\inethnfd
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winzipper
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
Key Deleted : [x64] HKLM\SOFTWARE\Speedchecker Limited
Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\v9.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.v9.com

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17496

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [bProtectTabs]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v35.0 (x86 cs)


-\\ Google Chrome v


*************************

AdwCleaner[R0].txt - [11457 octets] - [20/01/2015 19:10:18]
AdwCleaner[S0].txt - [10591 octets] - [20/01/2015 19:12:31]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10652 octets] ##########

digitaaalek
1. Stupeň Varování
Příspěvky: 36
Registrován: 26 Led 2009 11:20

Re: nežádoucí reklama v prohlížečích logzRsit

#4 Příspěvek od digitaaalek »

Report ze Zoek.

Zoek.exe v5.0.0.0 Updated 18-01-2015
Tool run by acer on Łt 20.01.2015 at 19:17:05,48.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\acer\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

20.1.2015 19:19:18 Zoek.exe System Restore Point Created Succesfully.

==== Empty Folders Check ======================

C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\Webteh deleted successfully
C:\Program Files\Google deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3265205095-3385449152-526931692-1000\Software\Microsoft\Internet Explorer\SearchScopes\{23BE0251-B97E-49F8-996F-23D679C17A0C} deleted successfully
HKEY_USERS\S-1-5-21-3265205095-3385449152-526931692-1000\Software\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-3265205095-3385449152-526931692-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@WebexpEnhancedV1alpha5490.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@VideoPlayerV3beta4064.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaPlayerV1alpha1812.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewerV1alpha1774.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewV1alpha917.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewV1alpha2893.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaWatchV1home4088.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaBuzzV1mode2096.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@RichMediaViewV1release7300.net deleted successfully

==== Deleting Services ======================


==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"bProtectTabs"=-

==== Deleting Files \ Folders ======================

C:\Users\acer\AppData\Local\13337 deleted
C:\Users\acer\AppData\Local\8066 deleted
C:\PROGRA~2\COMMON~1\Config\uninstinethnfd.exe deleted
C:\PROGRA~2\COMMON~1\Config deleted
C:\extensions.sqlite deleted
C:\extensions.ini deleted
C:\awh275D.tmp deleted
C:\awh3449.tmp deleted
C:\awh38CB.tmp deleted
C:\awh601A.tmp deleted
C:\awh661C.tmp deleted
C:\awh67F5.tmp deleted
C:\awh68C0.tmp deleted
C:\awh82E5.tmp deleted
C:\awh91EB.tmp deleted
C:\awh9CAB.tmp deleted
C:\awhA0CA.tmp deleted
C:\awhB651.tmp deleted
C:\awhC622.tmp deleted
C:\awhDB70.tmp deleted
C:\awhF0E3.tmp deleted
C:\awhF574.tmp deleted
C:\awhFEF5.tmp deleted
C:\PROGRA~3\OberonGameConsole deleted
C:\Users\acer\AppData\Local\CRE deleted
C:\Users\acer\AppData\Local\TB deleted
C:\Users\acer\Downloads\SoftonicDownloader_for_vlc-media-player.exe deleted
C:\Users\acer\AppData\LocalLow\TB deleted
C:\Windows\wininit.ini deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Windows\Syswow64\hfnapi.dll deleted
C:\Windows\SysWow64\searchplugins deleted
C:\Windows\SysWow64\Extensions deleted

==== Firefox Extensions ======================

ProfilePath: C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\aw0f2o6c.default
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================


==== Fake Chromium Profiles Check ======================

Fake profile C:\Users\acer\AppData\Local\Google\Chrome deleted

==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
akbcmaomjhhafokpncokoeiogmebgkdj - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha917\ch\MediaViewV1alpha917.crx[]
aliffhcbidgpolagjekcopjgppifkafc - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha5490\ch\WebexpEnhancedV1alpha5490.crx[]
chapminjiikhmllppbgcdnjpjdifjeki - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1774\ch\MediaViewerV1alpha1774.crx[]
edfohacdfdemjkeejihknkmjkabndgkg - C:\Users\acer\AppData\Local\CRE\edfohacdfdemjkeejihknkmjkabndgkg.crx[]
egmapnpgphhohceanbccpjnhnhgejcje - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home4088\ch\MediaWatchV1home4088.crx[]
jfljcadpfihbmckhmbjpnjoaajbjfool - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode2096\ch\MediaBuzzV1mode2096.crx[]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[14.07.2014 17:22]
pifnolekclbcondppkcggkjpofnnfcio - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha2893\ch\MediaViewV1alpha2893.crx[]
pmaaimndnbeofgjpgaapiibegfjoimeh - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta4064\ch\VideoPlayerV3beta4064.crx[]

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
edfohacdfdemjkeejihknkmjkabndgkg - C:\Users\acer\AppData\Local\CRE\edfohacdfdemjkeejihknkmjkabndgkg.crx[]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://seznam.cz/"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://seznam.cz/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{31D0D945-F79A-440F-BA05-1471542E0D77} Firmy.cz Url="http://www.firmy.cz/?q={searchTerms}&so ... arch_16194"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... urceid=ie7"
{78470451-3989-43DA-9C26-C916A946716B} Slovnˇk EN/CZ Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_16194"
{A4A54847-ED97-4D0E-B788-89E1E7EA5682} Google Url="http://www.google.com/search?sourceid=i ... AW_csCZ530"
{B1D9ACE2-20E6-4137-9326-758E24D6C47D} Slovnˇk CZ/EN Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_16194"
{BB99FA24-FB9A-4F91-AC88-4343447E5370} Mapy.cz Url="http://www.mapy.cz/?query={searchTerms} ... arch_16194"
{D183EFCE-6B3E-4A95-BED1-9454AD249114} Encyklopedie Seznam Url="http://encyklopedie.seznam.cz/search?q= ... arch_16194"
{D8E4AC46-522C-435C-AD18-4090746DF317} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_16194"
{EA888914-9408-4D69-B976-60EC047E059C} Novinky.cz Url="http://www.novinky.cz/hledej?w={searchT ... arch_16194"
{EFFBCCD4-F11C-4FE0-91E0-D42DE5EE175D} Zbo§ˇ.cz Url="http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194"

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\akbcmaomjhhafokpncokoeiogmebgkdj deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\aliffhcbidgpolagjekcopjgppifkafc deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\chapminjiikhmllppbgcdnjpjdifjeki deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\edfohacdfdemjkeejihknkmjkabndgkg deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\egmapnpgphhohceanbccpjnhnhgejcje deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jfljcadpfihbmckhmbjpnjoaajbjfool deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pifnolekclbcondppkcggkjpofnnfcio deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pmaaimndnbeofgjpgaapiibegfjoimeh deleted successfully
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\edfohacdfdemjkeejihknkmjkabndgkg deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\acer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\acer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\acer\AppData\Local\Mozilla\Firefox\Profiles\aw0f2o6c.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

No Chrome Cache found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=341 folders=21 16318931 bytes)

==== Empty Temp Folders ======================

C:\Users\acer\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\acer\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on Łt 20.01.2015 at 19:39:13,90 ======================

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: nežádoucí reklama v prohlížečích logzRsit

#5 Příspěvek od altrok »

:arrow: Dejte novy log FRST.txt, prilozte i Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

digitaaalek
1. Stupeň Varování
Příspěvky: 36
Registrován: 26 Led 2009 11:20

Re: nežádoucí reklama v prohlížečích logzRsit

#6 Příspěvek od digitaaalek »

FRST
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-01-2015
Ran by acer (administrator) on ACER-PC on 20-01-2015 20:02:30
Running from C:\Users\acer\Downloads
Loaded Profiles: acer (Available profiles: acer)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
() C:\Windows\PLFSetI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.EXE
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(PokerStars) C:\Program Files (x86)\PokerStars\PokerStars.exe
() C:\Program Files (x86)\PokerStars\gameutil1.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [818720 2010-02-26] (Acer Incorporated)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [503864 2009-07-20] (Conexant Systems, Inc.)
HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [206072 2009-12-14] ()
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1814312 2009-08-14] (Synaptics Incorporated)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [825864 2009-09-24] (Dritek System Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3265205095-3385449152-526931692-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7780120 2014-12-15] (SUPERAntiSpyware)
HKU\S-1-5-21-3265205095-3385449152-526931692-1000\...\MountPoints2: {5173c07c-1bce-11e3-b501-60eb692dc10c} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-07-17] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk -> C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKU\S-1-5-21-3265205095-3385449152-526931692-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {31D0D945-F79A-440F-BA05-1471542E0D77} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {78470451-3989-43DA-9C26-C916A946716B} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {A4A54847-ED97-4D0E-B788-89E1E7EA5682} URL = http://www.google.com/search?sourceid=i ... AW_csCZ530
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {B1D9ACE2-20E6-4137-9326-758E24D6C47D} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {BB99FA24-FB9A-4F91-AC88-4343447E5370} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {D183EFCE-6B3E-4A95-BED1-9454AD249114} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {D8E4AC46-522C-435C-AD18-4090746DF317} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {EA888914-9408-4D69-B976-60EC047E059C} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {EFFBCCD4-F11C-4FE0-91E0-D42DE5EE175D} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Pomocník pro přihlášení ke službě Windows Live -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\aw0f2o6c.default
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: Adblock Plus - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\aw0f2o6c.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-20]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
R2 ujopqrpsggkjpn; c:\windows\SysWOW64\ztpfzeq.exe [76800 2014-05-15] (LIMITED) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-20 20:02 - 2015-01-20 20:03 - 00012278 _____ () C:\Users\acer\Downloads\FRST.txt
2015-01-20 20:01 - 2015-01-20 20:02 - 00000000 ____D () C:\FRST
2015-01-20 20:00 - 2015-01-20 20:01 - 02126848 _____ (Farbar) C:\Users\acer\Downloads\FRST64.exe
2015-01-20 19:59 - 2015-01-20 19:59 - 01118208 _____ (Farbar) C:\Users\acer\Downloads\FRST.exe
2015-01-20 19:37 - 2015-01-20 19:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
2015-01-20 19:18 - 2015-01-20 19:39 - 00012605 _____ () C:\zoek-results.log
2015-01-20 19:17 - 2015-01-20 19:33 - 00000000 ____D () C:\zoek_backup
2015-01-20 19:13 - 2015-01-20 19:38 - 00000868 _____ () C:\Windows\PFRO.log
2015-01-20 19:11 - 2015-01-20 19:11 - 01295360 _____ () C:\Users\acer\Downloads\zoek.exe
2015-01-20 19:09 - 2015-01-20 19:12 - 00000000 ____D () C:\AdwCleaner
2015-01-20 19:09 - 2015-01-20 19:09 - 02186752 _____ () C:\Users\acer\Downloads\adwcleaner_4.108.exe
2015-01-20 18:20 - 2015-01-20 18:20 - 00000000 ____D () C:\rsit
2015-01-20 18:20 - 2015-01-20 18:20 - 00000000 ____D () C:\Program Files (x86)\trend micro
2015-01-20 18:19 - 2015-01-20 18:19 - 01107968 _____ () C:\Users\acer\Downloads\RSIT.exe
2015-01-20 18:10 - 2015-01-20 18:10 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-20 18:10 - 2015-01-20 18:10 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-20 18:10 - 2015-01-20 18:10 - 00000000 ____D () C:\Users\acer\AppData\Roaming\Mozilla
2015-01-20 18:10 - 2015-01-20 18:10 - 00000000 ____D () C:\Users\acer\AppData\Local\Mozilla
2015-01-20 18:10 - 2015-01-20 18:10 - 00000000 ____D () C:\ProgramData\Mozilla
2015-01-20 18:10 - 2015-01-20 18:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-20 18:09 - 2015-01-20 18:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-20 18:07 - 2015-01-20 18:08 - 00243512 _____ () C:\Users\acer\Downloads\Firefox Setup Stub 35.0.exe
2015-01-20 18:05 - 2015-01-20 19:38 - 00000168 _____ () C:\Windows\setupact.log
2015-01-20 18:05 - 2015-01-20 18:05 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-20 18:00 - 2015-01-20 18:01 - 00211974 _____ () C:\Users\acer\Documents\zaloha registrucc_20150120_180029.reg
2015-01-20 17:01 - 2015-01-20 17:01 - 00000000 ____D () C:\SUPERDelete
2015-01-20 17:00 - 2015-01-20 19:39 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-01-20 17:00 - 2015-01-20 17:00 - 00001812 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-01-20 17:00 - 2015-01-20 17:00 - 00000000 ____D () C:\Users\acer\AppData\Roaming\SUPERAntiSpyware.com
2015-01-20 17:00 - 2015-01-20 17:00 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2015-01-20 17:00 - 2015-01-20 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-01-20 16:51 - 2015-01-20 16:51 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-01-20 16:51 - 2015-01-20 16:51 - 00000826 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-01-20 16:51 - 2015-01-20 16:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-01-20 16:51 - 2015-01-20 16:51 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-20 16:50 - 2015-01-20 19:12 - 00000000 ____D () C:\Windows\system32\log
2015-01-20 16:49 - 2015-01-20 16:50 - 20851832 _____ (SUPERAntiSpyware) C:\Users\acer\Downloads\SUPERAntiSpyware.exe
2015-01-20 16:48 - 2015-01-20 16:49 - 05317104 _____ (Piriform Ltd) C:\Users\acer\Downloads\ccsetup501.exe
2015-01-20 16:18 - 2015-01-20 16:18 - 07032714 _____ () C:\Users\acer\Downloads\Nice_mammaries_of_summer.wmv
2015-01-20 16:18 - 2015-01-20 16:18 - 07032714 _____ () C:\Users\acer\Downloads\Nice_mammaries_of_summer (1).wmv
2015-01-14 16:30 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 16:30 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 16:30 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 16:30 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 16:30 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 16:30 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 16:30 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 16:30 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 16:30 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 16:30 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 16:30 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 16:30 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 16:30 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 16:30 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 16:30 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-13 21:59 - 2015-01-13 21:59 - 00183090 _____ () C:\Users\acer\Downloads\00743174-12-2014-EVP.zip
2015-01-12 16:15 - 2015-01-12 16:15 - 00019968 _____ () C:\Users\acer\Downloads\Přihláška OVA Leden 2.xls
2015-01-12 16:14 - 2015-01-12 16:14 - 00019456 _____ () C:\Users\acer\Downloads\Přihláška OVA Leden.xls
2015-01-10 21:21 - 2015-01-10 21:21 - 03144704 _____ () C:\Users\acer\Downloads\marias3.1.0.0_CZ.msi
2015-01-07 22:30 - 2015-01-08 01:07 - 1467115520 _____ () C:\Users\acer\Downloads\Nikomu-to-nerikej-2006-cz.avi
2015-01-02 05:14 - 2015-01-01 17:32 - 1473453766 ____N () C:\Users\acer\Desktop\interstellar-2014-cam-x264-aac-cz-v-obraze.avi
2015-01-01 16:01 - 2014-12-21 21:45 - 728684544 ____N () C:\Users\acer\Desktop\jak-vycvicit-draka-2010-cz-peapryk.avi
2015-01-01 14:02 - 2015-01-01 15:04 - 1118085120 _____ () C:\Users\acer\Downloads\Jak-vycvičit-draka-2-CZ.avi

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-20 20:03 - 2013-04-10 22:15 - 00000000 ____D () C:\ProgramData\TEMP
2015-01-20 20:00 - 2013-05-04 09:09 - 00000384 _____ () C:\Windows\Tasks\Acer Registration - Data Sending task.job
2015-01-20 19:46 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-20 19:46 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-20 19:45 - 2013-03-27 23:49 - 00622660 _____ () C:\Windows\system32\perfh005.dat
2015-01-20 19:45 - 2013-03-27 23:49 - 00118810 _____ () C:\Windows\system32\perfc005.dat
2015-01-20 19:45 - 2013-03-27 14:56 - 01122288 _____ () C:\Windows\WindowsUpdate.log
2015-01-20 19:45 - 2009-07-14 06:13 - 01445734 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-20 19:44 - 2013-06-16 08:34 - 00000000 ____D () C:\Users\acer\AppData\Local\PokerStars
2015-01-20 19:39 - 2014-10-26 16:23 - 00000434 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-01-20 19:39 - 2014-01-31 16:25 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-01-20 19:38 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-20 19:35 - 2013-04-02 18:46 - 00000000 ____D () C:\Users\acer\AppData\Local\Google
2015-01-20 19:33 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-01-20 19:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2015-01-20 19:03 - 2013-04-02 22:16 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-20 17:58 - 2011-08-17 11:47 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-20 17:50 - 2013-07-14 17:30 - 00000000 ____D () C:\Windows\Minidump
2015-01-20 17:50 - 2007-07-12 02:49 - 00000000 ____D () C:\Windows\Panther
2015-01-20 17:43 - 2013-05-31 23:06 - 00000000 ____D () C:\Users\acer\AppData\Roaming\Seznam.cz
2015-01-20 17:22 - 2013-06-16 08:33 - 00000000 ____D () C:\Program Files (x86)\PokerStars
2015-01-18 04:45 - 2014-08-25 11:18 - 00000000 ____D () C:\Users\acer\AppData\Roaming\vlc
2015-01-03 22:44 - 2014-02-17 15:49 - 00000000 ____D () C:\Users\acer\Desktop\tank
2015-01-03 22:44 - 2014-02-15 15:12 - 00000000 ____D () C:\Users\acer\AppData\Local\Microsoft Help
2014-12-31 12:14 - 2013-07-06 20:16 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

==================== Files in the root of some directories =======
2011-08-17 11:33 - 2010-01-27 15:40 - 0131472 _____ () C:\ProgramData\FullRemove.exe
2013-09-03 20:52 - 2014-04-02 15:49 - 0000952 ___SH () C:\ProgramData\KGyGaAvL.sys

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-15 18:00

==================== End Of Log ============================

digitaaalek
1. Stupeň Varování
Příspěvky: 36
Registrován: 26 Led 2009 11:20

Re: nežádoucí reklama v prohlížečích logzRsit

#7 Příspěvek od digitaaalek »

adition.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-01-2015
Ran by acer at 2015-01-20 20:03:54
Running from C:\Users\acer\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acer Crystal Eye Webcam (HKLM-x32\...\{7760D94E-B1B5-40A0-9AA0-ABF942108755}) (Version: 5.2.11.1 - Suyin Optronics Corp)
Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 4.05.3007 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3011 - Acer Incorporated)
Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3003 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.11.1209 - Acer Incorporated)
Acer VCM (HKLM-x32\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3002 - Acer Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.45.2 - Adobe Systems Incorporated)
Adobe Reader 9.1 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.1.0 - Adobe Systems Incorporated)
Asistent pro přihlášení ke službě Windows Live (HKLM-x32\...\{3E62B27C-342F-4B44-9331-CA4BC59A586F}) (Version: 5.000.818.5 - Microsoft Corporation)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.17 - Atheros Communications Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.98.9.0 - Conexant)
Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media)
eSobi v2 (HKLM-x32\...\InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}) (Version: 2.0.4.000274 - esobi Inc.)
eSobi v2 (x32 Version: 2.0.4.000274 - esobi Inc.) Hidden
Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media)
Granny In Paradise (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110551697}) (Version: - Oberon Media)
Chicken Invaders 2 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}) (Version: - Oberon Media)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3003 - Acer Incorporated)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.2202 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
InterVideo WinDVD 8 (HKLM-x32\...\InstallShield_{5FEBF468-5AC2-4C66-AD80-DF85C085AA73}) (Version: 8.5.10.75 - InterVideo Inc.)
InterVideo WinDVD 8 (x32 Version: 8.5.10.75 - InterVideo Inc.) Hidden
Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\...\LManager) (Version: 3.0.04 - Acer Inc.)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 35.0 (x86 cs) (HKLM-x32\...\Mozilla Firefox 35.0 (x86 cs)) (Version: 35.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nástroj pro odesílání služby Windows Live (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
NTI Backup Now 5 (HKLM-x32\...\InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}) (Version: 5.1.2.628 - NewTech Infosystems)
NTI Backup Now Standard (x32 Version: 5.1.2.628 - NewTech Infosystems) Hidden
NTI Media Maker 8 (HKLM-x32\...\InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}) (Version: 8.0.12.6630 - NewTech Infosystems)
NTI Media Maker 8 (x32 Version: 8.0.12.6630 - NewTech Infosystems) Hidden
PokerStars (HKLM-x32\...\PokerStars) (Version: - PokerStars)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7100.30094 - Realtek Semiconductor Corp.)
Seznam Software (HKU\S-1-5-21-3265205095-3385449152-526931692-1000\...\SeznamInstall) (Version: - Seznam.cz)
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Software Bluetooth WIDCOMM (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.0.9700 - Broadcom)
Spin & Win (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}) (Version: - Oberon Media)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1168 - SUPERAntiSpyware.com)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.0.3 - Synaptics Incorporated)
The KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 3.9.0.127 - PandoraTV)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.01.3002 - Acer Incorporated)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{068B46A0-8858-4CEB-80BC-A4AE787A05FC}) (Version: 14.0.8089.726 - Microsoft Corporation)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points =========================

02-01-2015 13:41:13 Windows Update
05-01-2015 16:39:33 Windows Zálohování
06-01-2015 05:57:27 Windows Update
10-01-2015 19:28:10 Windows Update
10-01-2015 21:23:26 Installed Mariáš 3.1
13-01-2015 16:44:42 Windows Zálohování
14-01-2015 20:41:05 Windows Update
15-01-2015 16:24:06 Windows Update
18-01-2015 20:34:40 Windows Update
20-01-2015 16:15:32 Windows Zálohování
20-01-2015 19:01:45 Removed Skype Click to Call
20-01-2015 19:18:28 zoek.exe restore point

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0755206E-2304-45DD-94B9-A927D1AE024F} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION
Task: {173E6FE9-9AB0-427A-BB61-0315465F5462} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION
Task: {28F404BE-B70F-4068-8AEE-2F4494D79330} - System32\Tasks\{57EA3313-BD39-4453-9961-DE99C32C1E15} => pcalua.exe -a C:\Users\acer\Downloads\Touchpad_Synaptics_v14.0.0.3_W7x86\Setup.exe -d C:\Users\acer\Downloads\Touchpad_Synaptics_v14.0.0.3_W7x86
Task: {7A25C705-43BC-4971-B804-359D223DDD05} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd)
Task: {C0C2874F-B1CB-451B-A1DB-58D17BE553B2} - System32\Tasks\Acer Registration - Data Sending task => C:\Program Files (x86)\Acer\Registration\GREG.exe [2010-04-28] (Acer Incorporated)
Task: C:\Windows\Tasks\Acer Registration - Data Sending task.job => C:\Program Files (x86)\Acer\Registration\GREG.exe

==================== Loaded Modules (whitelisted) =============

2013-03-27 15:28 - 2009-12-14 10:06 - 00206072 _____ () C:\Windows\PLFSetI.exe
2009-07-17 17:20 - 2009-07-17 17:20 - 00173344 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2015-01-20 17:22 - 2015-01-20 17:16 - 02213656 _____ () C:\Program Files (x86)\PokerStars\gameutil1.exe
2015-01-20 18:09 - 2015-01-09 10:05 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-10-17 06:14 - 2014-10-17 06:14 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\17c296575fad30d021e6370dc70cf800\IsdiInterop.ni.dll
2013-03-27 15:00 - 2011-02-18 08:16 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:8927A071
AlternateDataStreams: C:\ProgramData\TEMP:93EB7685

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: cz.seznam.software.autoupdate => "C:\Users\acer\AppData\Roaming\Seznam.cz\szninstall.exe" -c
MSCONFIG\startupreg: cz.seznam.software.szndesktop => "C:\Users\acer\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
MSCONFIG\startupreg: seznam-listicka-distribuce => "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate

========================= Accounts: ==========================

acer (S-1-5-21-3265205095-3385449152-526931692-1000 - Administrator - Enabled) => C:\Users\acer
Administrator (S-1-5-21-3265205095-3385449152-526931692-500 - Administrator - Disabled)
Guest (S-1-5-21-3265205095-3385449152-526931692-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3265205095-3385449152-526931692-1002 - Limited - Enabled)

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/20/2015 07:03:06 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: acer-PC)
Description: Aplikaci nebo službu Skype Click to Call PNR Service nelze restartovat.

Error: (01/20/2015 07:03:06 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: acer-PC)
Description: Aplikaci nebo službu Skype Click to Call Updater nelze restartovat.

Error: (01/20/2015 07:02:53 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: acer-PC)
Description: Aplikaci nebo službu Internet Explorer nelze ukončit.

Error: (01/20/2015 05:54:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CCleaner64.exe, verze: 5.1.0.5075, časové razítko: 0x54877062
Název chybujícího modulu: CCleaner64.exe, verze: 5.1.0.5075, časové razítko: 0x54877062
Kód výjimky: 0x40000015
Posun chyby: 0x0000000000101b5d
ID chybujícího procesu: 0x109c
Čas spuštění chybující aplikace: 0xCCleaner64.exe0
Cesta k chybující aplikaci: CCleaner64.exe1
Cesta k chybujícímu modulu: CCleaner64.exe2
ID zprávy: CCleaner64.exe3

Error: (01/20/2015 05:51:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CCleaner64.exe, verze: 5.1.0.5075, časové razítko: 0x54877062
Název chybujícího modulu: CCleaner64.exe, verze: 5.1.0.5075, časové razítko: 0x54877062
Kód výjimky: 0x40000015
Posun chyby: 0x0000000000101b5d
ID chybujícího procesu: 0x1394
Čas spuštění chybující aplikace: 0xCCleaner64.exe0
Cesta k chybující aplikaci: CCleaner64.exe1
Cesta k chybujícímu modulu: CCleaner64.exe2
ID zprávy: CCleaner64.exe3

Error: (01/20/2015 04:46:33 PM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Zálohování nebylo úspěšné. Chyba: V programu Windows Zálohování došlo k chybě při pokusu o čtení ze stínové kopie jednoho ze zálohovaných svazků. Zkontrolujte protokoly událostí a vyhledejte související chyby. (0x81000037).

Error: (01/18/2015 06:12:46 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Generování kontextu aktivace pro WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1 se nezdařilo. Chyba v souboru manifestu nebo zásady WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2 na řádku WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Identita komponenty nalezená v manifestu nesouhlasí s identitou požadované komponenty.
Odkaz je WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definice je WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (01/18/2015 06:11:33 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: Generování kontextu aktivace pro assemblyIdentity1 se nezdařilo. Chyba v souboru manifestu nebo zásady assemblyIdentity2 na řádku assemblyIdentity3.
Hodnota MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR atributu version v prvku assemblyIdentity je neplatná.

Error: (01/17/2015 03:53:28 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Generování kontextu aktivace pro WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1 se nezdařilo. Chyba v souboru manifestu nebo zásady WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2 na řádku WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Identita komponenty nalezená v manifestu nesouhlasí s identitou požadované komponenty.
Odkaz je WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definice je WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (01/17/2015 03:52:04 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: Generování kontextu aktivace pro assemblyIdentity1 se nezdařilo. Chyba v souboru manifestu nebo zásady assemblyIdentity2 na řádku assemblyIdentity3.
Hodnota MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR atributu version v prvku assemblyIdentity je neplatná.


System errors:
=============
Error: (01/20/2015 07:39:09 PM) (Source: ipnathlp) (EventID: 30013) (User: )
Description: 192.168.0.100192.168.137.0255.255.255.0

Error: (01/20/2015 07:39:09 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description:

Error: (01/20/2015 07:33:36 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (01/20/2015 07:33:36 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (01/20/2015 07:33:35 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (01/20/2015 07:33:35 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (01/20/2015 07:33:34 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (01/20/2015 07:14:28 PM) (Source: ipnathlp) (EventID: 30013) (User: )
Description: 192.168.0.100192.168.137.0255.255.255.0

Error: (01/20/2015 07:14:28 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description:

Error: (01/20/2015 07:13:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Windows Search neuspěla při spuštění v důsledku následující chyby:
%%3


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Processor: Celeron(R) Dual-Core CPU T3500 @ 2.10GHz
Percentage of memory in use: 39%
Total physical RAM: 3996.93 MB
Available physical RAM: 2403.17 MB
Total Pagefile: 8292.04 MB
Available Pagefile: 6569.18 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:223.01 GB) (Free:87.77 GB) NTFS
Drive d: (DATA) (Fixed) (Total:223.12 GB) (Free:38.12 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 533B68A1)
Partition 1: (Not Active) - (Size=19.5 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=223 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=223.1 GB) - (Type=07 NTFS)

==================== End Of Log ============================

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: nežádoucí reklama v prohlížečích logzRsit

#8 Příspěvek od altrok »

:arrow: Aktualizutje Adobe Flash Player na http://get.adobe.com/cz/flashplayer/ - pred stazenim nezapomente vyhodit zatrzitko u adwaru v podobe McAfee Security Scanu

:arrow: Na virustotal.com otesujte C:\ProgramData\FullRemove.exe - vysledek analyzy (link) vlozte do dalsi odpovedi.

  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu na Vas vyskoci fixlog (pripadne bude ulozen na Plose), jehoz obsah mi vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CloseProcesses:
    HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [825864 2009-09-24] (Dritek System Inc.)
    HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
    HKLM\...\Policies\Explorer: [NoControlPanel] 0
    HKU\S-1-5-21-3265205095-3385449152-526931692-1000\...\MountPoints2: {5173c07c-1bce-11e3-b501-60eb692dc10c} - F:\HTC_Sync_Manager_PC.exe
    
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    FF Plugin: @microsoft.com/GENUINE -> disabled No File
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
    FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
    
    R2 ujopqrpsggkjpn; c:\windows\SysWOW64\ztpfzeq.exe [76800 2014-05-15] (LIMITED) [File not signed]
    S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
    S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
    
    2015-01-20 20:02 - 2015-01-20 20:03 - 00012278 _____ () C:\Users\acer\Downloads\FRST.txt
    2015-01-20 19:59 - 2015-01-20 19:59 - 01118208 _____ (Farbar) C:\Users\acer\Downloads\FRST.exe
    2015-01-20 19:37 - 2015-01-20 19:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
    2015-01-20 19:18 - 2015-01-20 19:39 - 00012605 _____ () C:\zoek-results.log
    2015-01-20 19:17 - 2015-01-20 19:33 - 00000000 ____D () C:\zoek_backup
    2015-01-20 19:13 - 2015-01-20 19:38 - 00000868 _____ () C:\Windows\PFRO.log
    2015-01-20 19:11 - 2015-01-20 19:11 - 01295360 _____ () C:\Users\acer\Downloads\zoek.exe
    2015-01-20 19:09 - 2015-01-20 19:12 - 00000000 ____D () C:\AdwCleaner
    2015-01-20 19:09 - 2015-01-20 19:09 - 02186752 _____ () C:\Users\acer\Downloads\adwcleaner_4.108.exe
    2015-01-20 18:20 - 2015-01-20 18:20 - 00000000 ____D () C:\rsit
    2015-01-20 18:20 - 2015-01-20 18:20 - 00000000 ____D () C:\Program Files (x86)\trend micro
    2015-01-20 18:19 - 2015-01-20 18:19 - 01107968 _____ () C:\Users\acer\Downloads\RSIT.exe
    2015-01-20 16:48 - 2015-01-20 16:49 - 05317104 _____ (Piriform Ltd) C:\Users\acer\Downloads\ccsetup501.exe
    
    Task: {0755206E-2304-45DD-94B9-A927D1AE024F} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION
    Task: {173E6FE9-9AB0-427A-BB61-0315465F5462} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION
    AlternateDataStreams: C:\ProgramData\TEMP:8927A071
    AlternateDataStreams: C:\ProgramData\TEMP:93EB7685
    Hosts:
    EmptyTemp:
    End
    
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.


digitaaalek
1. Stupeň Varování
Příspěvky: 36
Registrován: 26 Led 2009 11:20

Re: nežádoucí reklama v prohlížečích logzRsit

#10 Příspěvek od digitaaalek »

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-01-2015
Ran by acer (administrator) on ACER-PC on 20-01-2015 20:50:55
Running from C:\Users\acer\Downloads
Loaded Profiles: acer (Available profiles: acer)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
() C:\Windows\PLFSetI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.EXE
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(PokerStars) C:\Program Files (x86)\PokerStars\PokerStars.exe
() C:\Program Files (x86)\PokerStars\gameutil1.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [818720 2010-02-26] (Acer Incorporated)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [503864 2009-07-20] (Conexant Systems, Inc.)
HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [206072 2009-12-14] ()
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1814312 2009-08-14] (Synaptics Incorporated)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [825864 2009-09-24] (Dritek System Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3265205095-3385449152-526931692-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7780120 2014-12-15] (SUPERAntiSpyware)
HKU\S-1-5-21-3265205095-3385449152-526931692-1000\...\MountPoints2: {5173c07c-1bce-11e3-b501-60eb692dc10c} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-07-17] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk -> C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKU\S-1-5-21-3265205095-3385449152-526931692-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {31D0D945-F79A-440F-BA05-1471542E0D77} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {78470451-3989-43DA-9C26-C916A946716B} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {A4A54847-ED97-4D0E-B788-89E1E7EA5682} URL = http://www.google.com/search?sourceid=i ... AW_csCZ530
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {B1D9ACE2-20E6-4137-9326-758E24D6C47D} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {BB99FA24-FB9A-4F91-AC88-4343447E5370} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {D183EFCE-6B3E-4A95-BED1-9454AD249114} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {D8E4AC46-522C-435C-AD18-4090746DF317} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {EA888914-9408-4D69-B976-60EC047E059C} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKU\S-1-5-21-3265205095-3385449152-526931692-1000 -> {EFFBCCD4-F11C-4FE0-91E0-D42DE5EE175D} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Pomocník pro přihlášení ke službě Windows Live -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\aw0f2o6c.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: Adblock Plus - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\aw0f2o6c.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-20]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
R2 ujopqrpsggkjpn; c:\windows\SysWOW64\ztpfzeq.exe [76800 2014-05-15] (LIMITED) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-20 20:48 - 2015-01-20 20:48 - 00003084 _____ () C:\Users\acer\Desktop\fixlist.txt
2015-01-20 20:41 - 2015-01-20 20:41 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-20 20:41 - 2015-01-20 20:41 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-20 20:41 - 2015-01-20 20:41 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-20 20:41 - 2015-01-20 20:41 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-20 20:41 - 2015-01-20 20:41 - 00000000 ____D () C:\Windows\system32\Macromed
2015-01-20 20:03 - 2015-01-20 20:04 - 00020163 _____ () C:\Users\acer\Downloads\Addition.txt
2015-01-20 20:02 - 2015-01-20 20:50 - 00012480 _____ () C:\Users\acer\Downloads\FRST.txt
2015-01-20 20:01 - 2015-01-20 20:50 - 00000000 ____D () C:\FRST
2015-01-20 20:00 - 2015-01-20 20:01 - 02126848 _____ (Farbar) C:\Users\acer\Downloads\FRST64.exe
2015-01-20 19:59 - 2015-01-20 19:59 - 01118208 _____ (Farbar) C:\Users\acer\Downloads\FRST.exe
2015-01-20 19:37 - 2015-01-20 19:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
2015-01-20 19:18 - 2015-01-20 19:39 - 00012605 _____ () C:\zoek-results.log
2015-01-20 19:17 - 2015-01-20 19:33 - 00000000 ____D () C:\zoek_backup
2015-01-20 19:13 - 2015-01-20 19:38 - 00000868 _____ () C:\Windows\PFRO.log
2015-01-20 19:11 - 2015-01-20 19:11 - 01295360 _____ () C:\Users\acer\Downloads\zoek.exe
2015-01-20 19:09 - 2015-01-20 19:12 - 00000000 ____D () C:\AdwCleaner
2015-01-20 19:09 - 2015-01-20 19:09 - 02186752 _____ () C:\Users\acer\Downloads\adwcleaner_4.108.exe
2015-01-20 18:20 - 2015-01-20 18:20 - 00000000 ____D () C:\rsit
2015-01-20 18:20 - 2015-01-20 18:20 - 00000000 ____D () C:\Program Files (x86)\trend micro
2015-01-20 18:19 - 2015-01-20 18:19 - 01107968 _____ () C:\Users\acer\Downloads\RSIT.exe
2015-01-20 18:10 - 2015-01-20 18:10 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-20 18:10 - 2015-01-20 18:10 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-20 18:10 - 2015-01-20 18:10 - 00000000 ____D () C:\Users\acer\AppData\Roaming\Mozilla
2015-01-20 18:10 - 2015-01-20 18:10 - 00000000 ____D () C:\Users\acer\AppData\Local\Mozilla
2015-01-20 18:10 - 2015-01-20 18:10 - 00000000 ____D () C:\ProgramData\Mozilla
2015-01-20 18:10 - 2015-01-20 18:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-20 18:09 - 2015-01-20 18:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-20 18:07 - 2015-01-20 18:08 - 00243512 _____ () C:\Users\acer\Downloads\Firefox Setup Stub 35.0.exe
2015-01-20 18:05 - 2015-01-20 19:38 - 00000168 _____ () C:\Windows\setupact.log
2015-01-20 18:05 - 2015-01-20 18:05 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-20 18:00 - 2015-01-20 18:01 - 00211974 _____ () C:\Users\acer\Documents\zaloha registrucc_20150120_180029.reg
2015-01-20 17:01 - 2015-01-20 17:01 - 00000000 ____D () C:\SUPERDelete
2015-01-20 17:00 - 2015-01-20 19:39 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-01-20 17:00 - 2015-01-20 17:00 - 00001812 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-01-20 17:00 - 2015-01-20 17:00 - 00000000 ____D () C:\Users\acer\AppData\Roaming\SUPERAntiSpyware.com
2015-01-20 17:00 - 2015-01-20 17:00 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2015-01-20 17:00 - 2015-01-20 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-01-20 16:51 - 2015-01-20 16:51 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-01-20 16:51 - 2015-01-20 16:51 - 00000826 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-01-20 16:51 - 2015-01-20 16:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-01-20 16:51 - 2015-01-20 16:51 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-20 16:50 - 2015-01-20 19:12 - 00000000 ____D () C:\Windows\system32\log
2015-01-20 16:49 - 2015-01-20 16:50 - 20851832 _____ (SUPERAntiSpyware) C:\Users\acer\Downloads\SUPERAntiSpyware.exe
2015-01-20 16:48 - 2015-01-20 16:49 - 05317104 _____ (Piriform Ltd) C:\Users\acer\Downloads\ccsetup501.exe
2015-01-20 16:18 - 2015-01-20 16:18 - 07032714 _____ () C:\Users\acer\Downloads\Nice_mammaries_of_summer.wmv
2015-01-20 16:18 - 2015-01-20 16:18 - 07032714 _____ () C:\Users\acer\Downloads\Nice_mammaries_of_summer (1).wmv
2015-01-14 16:30 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 16:30 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 16:30 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 16:30 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 16:30 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 16:30 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 16:30 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 16:30 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 16:30 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 16:30 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 16:30 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 16:30 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 16:30 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 16:30 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 16:30 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-13 21:59 - 2015-01-13 21:59 - 00183090 _____ () C:\Users\acer\Downloads\00743174-12-2014-EVP.zip
2015-01-12 16:15 - 2015-01-12 16:15 - 00019968 _____ () C:\Users\acer\Downloads\Přihláška OVA Leden 2.xls
2015-01-12 16:14 - 2015-01-12 16:14 - 00019456 _____ () C:\Users\acer\Downloads\Přihláška OVA Leden.xls
2015-01-10 21:21 - 2015-01-10 21:21 - 03144704 _____ () C:\Users\acer\Downloads\marias3.1.0.0_CZ.msi
2015-01-07 22:30 - 2015-01-08 01:07 - 1467115520 _____ () C:\Users\acer\Downloads\Nikomu-to-nerikej-2006-cz.avi
2015-01-02 05:14 - 2015-01-01 17:32 - 1473453766 ____N () C:\Users\acer\Desktop\interstellar-2014-cam-x264-aac-cz-v-obraze.avi
2015-01-01 16:01 - 2014-12-21 21:45 - 728684544 ____N () C:\Users\acer\Desktop\jak-vycvicit-draka-2010-cz-peapryk.avi
2015-01-01 14:02 - 2015-01-01 15:04 - 1118085120 _____ () C:\Users\acer\Downloads\Jak-vycvičit-draka-2-CZ.avi

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-20 20:51 - 2013-04-10 22:15 - 00000000 ____D () C:\ProgramData\TEMP
2015-01-20 20:44 - 2013-04-21 10:37 - 00000000 ____D () C:\Users\acer\AppData\Local\Adobe
2015-01-20 20:30 - 2013-05-04 09:09 - 00000384 _____ () C:\Windows\Tasks\Acer Registration - Data Sending task.job
2015-01-20 19:46 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-20 19:46 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-20 19:45 - 2013-03-27 23:49 - 00622660 _____ () C:\Windows\system32\perfh005.dat
2015-01-20 19:45 - 2013-03-27 23:49 - 00118810 _____ () C:\Windows\system32\perfc005.dat
2015-01-20 19:45 - 2013-03-27 14:56 - 01122288 _____ () C:\Windows\WindowsUpdate.log
2015-01-20 19:45 - 2009-07-14 06:13 - 01445734 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-20 19:44 - 2013-06-16 08:34 - 00000000 ____D () C:\Users\acer\AppData\Local\PokerStars
2015-01-20 19:39 - 2014-10-26 16:23 - 00000434 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-01-20 19:39 - 2014-01-31 16:25 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-01-20 19:38 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-20 19:35 - 2013-04-02 18:46 - 00000000 ____D () C:\Users\acer\AppData\Local\Google
2015-01-20 19:33 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-01-20 19:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2015-01-20 19:03 - 2013-04-02 22:16 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-20 17:58 - 2011-08-17 11:47 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-20 17:50 - 2013-07-14 17:30 - 00000000 ____D () C:\Windows\Minidump
2015-01-20 17:50 - 2007-07-12 02:49 - 00000000 ____D () C:\Windows\Panther
2015-01-20 17:43 - 2013-05-31 23:06 - 00000000 ____D () C:\Users\acer\AppData\Roaming\Seznam.cz
2015-01-20 17:22 - 2013-06-16 08:33 - 00000000 ____D () C:\Program Files (x86)\PokerStars
2015-01-18 04:45 - 2014-08-25 11:18 - 00000000 ____D () C:\Users\acer\AppData\Roaming\vlc
2015-01-03 22:44 - 2014-02-17 15:49 - 00000000 ____D () C:\Users\acer\Desktop\tank
2015-01-03 22:44 - 2014-02-15 15:12 - 00000000 ____D () C:\Users\acer\AppData\Local\Microsoft Help
2014-12-31 12:14 - 2013-07-06 20:16 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

==================== Files in the root of some directories =======
2011-08-17 11:33 - 2010-01-27 15:40 - 0131472 _____ () C:\ProgramData\FullRemove.exe
2013-09-03 20:52 - 2014-04-02 15:49 - 0000952 ___SH () C:\ProgramData\KGyGaAvL.sys

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-15 18:00

==================== End Of Log ============================

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: nežádoucí reklama v prohlížečích logzRsit

#11 Příspěvek od altrok »

fixlist jste sice vytvoril, ale po spusteni FRST jste klikl na Scan... mel jste kliknout na Fix... prectete si znovu navod vyse a postupujte podle nej
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

digitaaalek
1. Stupeň Varování
Příspěvky: 36
Registrován: 26 Led 2009 11:20

Re: nežádoucí reklama v prohlížečích logzRsit

#12 Příspěvek od digitaaalek »

Když jsem dal FIX napíše to : No fixlist.txt found. The fixlist.txt should be in the same folder/directory the tool is located

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: nežádoucí reklama v prohlížečích logzRsit

#13 Příspěvek od altrok »

nectete navody... jsou psane pro vas.. ne pro nas
FRST64.exe mate v Running from C:\Users\acer\Downloads
nikoliv na plose jak se pise v navodu
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

digitaaalek
1. Stupeň Varování
Příspěvky: 36
Registrován: 26 Led 2009 11:20

Re: nežádoucí reklama v prohlížečích logzRsit

#14 Příspěvek od digitaaalek »

Nezpouštěl jsem to z plochy nýbrž z C:.......

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: nežádoucí reklama v prohlížečích logzRsit

#15 Příspěvek od altrok »

to nemeni nic na tom, ze nectete navody

FRST64.exe i fixlist.txt musi byt ve stejne slozce... drzte se navodu
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Zamčeno