Vyskakující reklamní stránky v prohlížečích
Napsal: 13 říj 2015 18:11
Zdravím,
prosím o kontrolu logu. V prohlížečích IE a Mozilla prakticky na každé kliknutí vyskakují reklamní stránky v samostatných oknech, v Google Chrome se problém vyskytuje taky, ale méně. Počítač byl bez antiviru, nyní nainstalován Avast Free, který našel desítky infikovaných souborů, ale problémy úplně nevyřešil.
Předem díky
---------------------
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:12-10-2015
Ran by Lenovo (administrator) on NOTEBOOK (13-10-2015 18:50:09)
Running from C:\Users\Lenovo\Desktop
Loaded Profiles: Lenovo (Available Profiles: Lenovo)
Platform: Windows 8.1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332STI.EXE
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-15] (Conexant Systems, Inc.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17079376 2013-12-08] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191568 2013-12-08] (Lenovo(beijing) Limited)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-01-18] (IvoSoft)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-27] (Synaptics Incorporated)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332STI.EXE [548864 2012-03-21] (Vimicro)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-26] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-19] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-10-09] (AVAST Software)
HKU\S-1-5-21-3922014775-476238916-793784252-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8461224 2015-09-16] (Piriform Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-10-09] (AVAST Software)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-01-18] (IvoSoft)
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-01-18] (IvoSoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-12-08]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{67A7CA02-B3D0-4807-B88F-970D79A082D5}: [NameServer] 199.203.131.145,82.163.143.167
Tcpip\..\Interfaces\{67A7CA02-B3D0-4807-B88F-970D79A082D5}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.gboxapp.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.gboxapp.com/
HKU\S-1-5-21-3922014775-476238916-793784252-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
HKU\S-1-5-21-3922014775-476238916-793784252-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
HKU\S-1-5-21-3922014775-476238916-793784252-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
HKU\S-1-5-21-3922014775-476238916-793784252-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-3922014775-476238916-793784252-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKLM-x32 -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.goodforsearch.info/?l=1&q={searchTerms}&pid=2921&r=2015/05/10&hid=11507217868994325399&lg=EN&cc=CZ&unqvl=86
SearchScopes: HKLM-x32 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.goodforsearch.info/?l=1&q={searchTerms}&pid=2921&r=2015/05/10&hid=11507217868994325399&lg=EN&cc=CZ&unqvl=86
SearchScopes: HKU\S-1-5-21-3922014775-476238916-793784252-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-3922014775-476238916-793784252-1001 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.goodforsearch.info/?l=1&q={searchTerms}&pid=2921&r=2015/05/10&hid=11507217868994325399&lg=EN&cc=CZ&unqvl=86
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-01-18] (IvoSoft)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-10-09] (AVAST Software)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-01-18] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-01-18] (IvoSoft)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-10-09] (AVAST Software)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-01-18] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-01-18] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-01-18] (IvoSoft)
FireFox:
========
FF ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\v12oof3e.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-21] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-21] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-07-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-07-05] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-11-11] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\v12oof3e.default\searchplugins\WebSearch.xml [2015-05-15]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-10-09]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://websearch.goodforsearch.info/?pid=2921&r=2015/05/10&hid=11507217868994325399&lg=EN&cc=CZ&unqvl=86"
CHR Profile: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-09]
CHR Extension: (Disk Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-09]
CHR Extension: (YouTube) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-09]
CHR Extension: (Vyhledávání Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-09]
CHR Extension: (Avast Online Security) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-10-09]
CHR Extension: (AirDroid Notifier) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\imlonnilcaednlloaadgddbjfliioklh [2015-05-10]
CHR Extension: (Peněženka Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-09]
CHR Extension: (Gmail) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-09]
CHR Extension: (UniDeals) - C:\ProgramData\mkphlfdeiohblcdejiboaepapckblfkb\ []
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-10-09]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-10-09] (AVAST Software)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-09-04] (Broadcom Corporation.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [959256 2012-11-16] (Broadcom Corporation.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319376 2014-10-01] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S3 TrustedInstaller; %SystemRoot%\servicing\TrustedInstaller.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-10-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-10-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-10-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-10-09] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1049880 2015-10-09] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [448968 2015-10-09] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-10-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-10-09] (AVAST Software)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-09-04] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-09-24] (Microsoft Corporation)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-27] (Synaptics Incorporated)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44024 2015-02-04] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [264000 2015-02-04] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-13 18:50 - 2015-10-13 18:50 - 00016748 _____ C:\Users\Lenovo\Desktop\FRST.txt
2015-10-13 18:49 - 2015-10-13 18:50 - 00000000 ____D C:\FRST
2015-10-13 18:47 - 2015-10-13 18:47 - 00112640 _____ (forum.viry.cz) C:\Users\Lenovo\Desktop\FRSTLauncher.exe
2015-10-13 18:45 - 2015-10-13 18:45 - 02196480 _____ (Farbar) C:\Users\Lenovo\Desktop\FRST64.exe
2015-10-13 18:22 - 2015-10-13 18:22 - 00000000 ____D C:\Users\Lenovo\AppData\Local\TeamViewer
2015-10-13 18:20 - 2015-10-13 18:20 - 00001066 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-10-13 18:20 - 2015-10-13 18:20 - 00001054 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-10-13 18:20 - 2015-10-13 18:20 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-10-13 18:19 - 2015-10-13 18:19 - 08206600 _____ (TeamViewer GmbH) C:\Users\Lenovo\Downloads\TeamViewer_Setup_cs (1).exe
2015-10-09 14:37 - 2015-10-09 14:37 - 08206600 _____ (TeamViewer GmbH) C:\Users\Lenovo\Downloads\TeamViewer_Setup_cs.exe
2015-10-09 14:31 - 2015-10-09 14:32 - 00000231 _____ C:\WINDOWS\setupact.log
2015-10-09 14:31 - 2015-10-09 14:31 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-10-09 14:19 - 2015-10-09 14:19 - 00490568 _____ () C:\Users\Lenovo\Downloads\LSBsetup.exe
2015-10-09 11:02 - 2015-10-09 11:02 - 00005564 _____ C:\Users\Lenovo\Documents\cc_20151009_110232.reg
2015-10-09 11:01 - 2015-10-09 11:01 - 00094842 _____ C:\Users\Lenovo\Documents\cc_20151009_110123.reg
2015-10-09 10:57 - 2015-10-09 10:57 - 00002792 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2015-10-09 10:57 - 2015-10-09 10:57 - 00000845 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-10-09 10:57 - 2015-10-09 10:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-10-09 10:57 - 2015-10-09 10:57 - 00000000 ____D C:\Program Files\CCleaner
2015-10-09 10:55 - 2015-10-09 10:55 - 06677440 _____ (Piriform Ltd) C:\Users\Lenovo\Downloads\ccsetup510.exe
2015-10-09 09:41 - 2015-10-09 09:41 - 05693008 _____ (AVAST Software) C:\Users\Lenovo\Downloads\avast_free_antivirus_setup_online (1).exe
2015-10-09 08:31 - 2015-10-09 08:31 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\AVAST Software
2015-10-09 08:30 - 2015-10-09 10:48 - 00004182 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-10-09 08:30 - 2015-10-09 08:30 - 00001949 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-10-09 08:30 - 2015-10-09 08:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-10-09 08:29 - 2015-10-09 08:29 - 01049880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00448968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-10-09 08:29 - 2015-10-09 08:29 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00153744 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-10-09 08:29 - 2015-10-09 08:29 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-10-09 08:25 - 2015-10-09 08:25 - 00000000 ____D C:\Program Files\AVAST Software
2015-10-09 08:19 - 2015-10-09 08:19 - 05693008 _____ (AVAST Software) C:\Users\Lenovo\Downloads\avast_free_antivirus_setup_online.exe
2015-09-21 15:51 - 2015-10-09 08:43 - 00000000 ____D C:\Program Files (x86)\DNS Unlocker
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-13 18:49 - 2014-12-20 08:41 - 01918996 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-13 18:44 - 2014-04-09 14:02 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\ClassicShell
2015-10-13 18:33 - 2014-12-21 07:45 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3922014775-476238916-793784252-1001
2015-10-13 18:28 - 2014-04-09 12:49 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-10-13 18:27 - 2014-12-26 18:18 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-10-13 18:16 - 2015-02-11 19:03 - 00003974 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{9FCC1BAB-1732-4CE9-8121-E7E95D0CE7E8}
2015-10-13 18:15 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-12 06:05 - 2014-09-24 18:23 - 01745984 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-12 06:05 - 2014-09-24 17:39 - 00739924 _____ C:\WINDOWS\system32\perfh005.dat
2015-10-12 06:05 - 2014-09-24 17:39 - 00151610 _____ C:\WINDOWS\system32\perfc005.dat
2015-10-11 22:00 - 2014-12-04 15:58 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-09 14:32 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-09 10:58 - 2014-12-20 08:11 - 00000000 ___DC C:\WINDOWS\Panther
2015-10-09 10:58 - 2014-09-08 12:26 - 00000000 ____D C:\Users\Lenovo\AppData\Local\CrashDumps
2015-10-09 10:45 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-10-09 10:41 - 2014-04-09 12:54 - 00001146 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-10-09 10:41 - 2014-04-09 12:54 - 00001146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-10-09 09:38 - 2014-04-09 13:55 - 00000000 ____D C:\ProgramData\Norton
2015-10-09 08:48 - 2015-06-07 12:03 - 00000000 ____D C:\Program Files (x86)\Share with Facebook Twitter Google Email
2015-10-09 08:48 - 2015-05-10 10:11 - 00000000 ____D C:\Program Files (x86)\UniDeals
2015-10-09 08:44 - 2015-06-07 12:03 - 00000000 ____D C:\Program Files (x86)\HHAppy2Savee
2015-10-09 08:44 - 2015-06-07 12:03 - 00000000 ____D C:\Program Files (x86)\Happy2Savee
2015-10-09 08:44 - 2015-06-07 12:03 - 00000000 ____D C:\Program Files (x86)\Happy2Saave
2015-10-09 08:43 - 2015-06-13 21:39 - 00000000 ____D C:\Program Files (x86)\Fun2SaavE
2015-10-09 08:43 - 2015-05-18 21:27 - 00000000 ____D C:\Program Files (x86)\DuIgiSavER
2015-10-09 08:43 - 2015-05-18 21:27 - 00000000 ____D C:\Program Files (x86)\DowwnSavE
2015-10-09 08:42 - 2015-05-18 21:28 - 00000000 ____D C:\Program Files (x86)\Best of 3d Football Soccer Games 2013
2015-10-09 08:42 - 2015-05-18 21:27 - 00000000 ____D C:\Program Files (x86)\BitSaaveR
2015-10-09 08:42 - 2015-05-10 10:12 - 00000000 ____D C:\Program Files (x86)\bestadblocker
2015-10-09 08:42 - 2015-05-10 10:12 - 00000000 ____D C:\Program Files (x86)\AirDroid Notifier
2015-10-09 08:33 - 2015-05-10 10:13 - 00000000 ____D C:\Program Files (x86)\AppendEngine
2015-10-09 08:33 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2015-10-09 08:33 - 2012-07-26 10:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-10-09 08:32 - 2015-07-31 12:25 - 00000000 ____D C:\WINDOWS\System32\Tasks\Remediation
2015-10-09 06:06 - 2015-07-05 21:37 - 00000020 _____ C:\Users\Lenovo\AppData\Roaming\appdataFr2.bin
2015-10-08 18:16 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-21 20:01 - 2014-12-04 15:58 - 00003802 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-09-21 20:00 - 2015-07-14 21:00 - 18819272 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2015-09-21 15:51 - 2015-05-10 10:11 - 00000000 ____D C:\ProgramData\14887237305190576793
2015-09-14 21:37 - 2014-12-20 08:25 - 00000000 ____D C:\Users\Lenovo
2015-09-13 09:36 - 2014-04-09 11:53 - 00001129 _____ C:\Users\Lenovo\Desktop\Cyberlink Power2Go.lnk
==================== Files in the root of some directories =======
2015-05-17 12:41 - 2015-05-17 12:41 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2015-07-05 21:37 - 2015-10-09 06:06 - 0000020 _____ () C:\Users\Lenovo\AppData\Roaming\appdataFr2.bin
2015-06-17 22:07 - 2015-07-08 10:51 - 0000024 _____ () C:\Users\Lenovo\AppData\Roaming\appdataFr25.bin
2013-12-08 12:57 - 2013-12-08 12:57 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-10-09 11:07
==================== End of FRST.txt ============================
prosím o kontrolu logu. V prohlížečích IE a Mozilla prakticky na každé kliknutí vyskakují reklamní stránky v samostatných oknech, v Google Chrome se problém vyskytuje taky, ale méně. Počítač byl bez antiviru, nyní nainstalován Avast Free, který našel desítky infikovaných souborů, ale problémy úplně nevyřešil.
Předem díky
---------------------
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:12-10-2015
Ran by Lenovo (administrator) on NOTEBOOK (13-10-2015 18:50:09)
Running from C:\Users\Lenovo\Desktop
Loaded Profiles: Lenovo (Available Profiles: Lenovo)
Platform: Windows 8.1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332STI.EXE
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-15] (Conexant Systems, Inc.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17079376 2013-12-08] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191568 2013-12-08] (Lenovo(beijing) Limited)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-01-18] (IvoSoft)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-27] (Synaptics Incorporated)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332STI.EXE [548864 2012-03-21] (Vimicro)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-26] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-19] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-10-09] (AVAST Software)
HKU\S-1-5-21-3922014775-476238916-793784252-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8461224 2015-09-16] (Piriform Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-10-09] (AVAST Software)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-01-18] (IvoSoft)
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-01-18] (IvoSoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-12-08]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{67A7CA02-B3D0-4807-B88F-970D79A082D5}: [NameServer] 199.203.131.145,82.163.143.167
Tcpip\..\Interfaces\{67A7CA02-B3D0-4807-B88F-970D79A082D5}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.gboxapp.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.gboxapp.com/
HKU\S-1-5-21-3922014775-476238916-793784252-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
HKU\S-1-5-21-3922014775-476238916-793784252-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
HKU\S-1-5-21-3922014775-476238916-793784252-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
HKU\S-1-5-21-3922014775-476238916-793784252-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-3922014775-476238916-793784252-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKLM-x32 -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.goodforsearch.info/?l=1&q={searchTerms}&pid=2921&r=2015/05/10&hid=11507217868994325399&lg=EN&cc=CZ&unqvl=86
SearchScopes: HKLM-x32 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.goodforsearch.info/?l=1&q={searchTerms}&pid=2921&r=2015/05/10&hid=11507217868994325399&lg=EN&cc=CZ&unqvl=86
SearchScopes: HKU\S-1-5-21-3922014775-476238916-793784252-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-3922014775-476238916-793784252-1001 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.goodforsearch.info/?l=1&q={searchTerms}&pid=2921&r=2015/05/10&hid=11507217868994325399&lg=EN&cc=CZ&unqvl=86
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-01-18] (IvoSoft)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-10-09] (AVAST Software)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-01-18] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-01-18] (IvoSoft)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-10-09] (AVAST Software)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-01-18] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-01-18] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-01-18] (IvoSoft)
FireFox:
========
FF ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\v12oof3e.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-21] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-21] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-07-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-07-05] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-11-11] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\v12oof3e.default\searchplugins\WebSearch.xml [2015-05-15]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-10-09]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://websearch.goodforsearch.info/?pid=2921&r=2015/05/10&hid=11507217868994325399&lg=EN&cc=CZ&unqvl=86"
CHR Profile: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-09]
CHR Extension: (Disk Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-09]
CHR Extension: (YouTube) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-09]
CHR Extension: (Vyhledávání Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-09]
CHR Extension: (Avast Online Security) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-10-09]
CHR Extension: (AirDroid Notifier) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\imlonnilcaednlloaadgddbjfliioklh [2015-05-10]
CHR Extension: (Peněženka Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-09]
CHR Extension: (Gmail) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-09]
CHR Extension: (UniDeals) - C:\ProgramData\mkphlfdeiohblcdejiboaepapckblfkb\ []
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-10-09]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-10-09] (AVAST Software)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-09-04] (Broadcom Corporation.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [959256 2012-11-16] (Broadcom Corporation.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319376 2014-10-01] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S3 TrustedInstaller; %SystemRoot%\servicing\TrustedInstaller.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-10-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-10-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-10-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-10-09] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1049880 2015-10-09] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [448968 2015-10-09] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-10-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-10-09] (AVAST Software)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-09-04] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-09-24] (Microsoft Corporation)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-27] (Synaptics Incorporated)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44024 2015-02-04] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [264000 2015-02-04] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-13 18:50 - 2015-10-13 18:50 - 00016748 _____ C:\Users\Lenovo\Desktop\FRST.txt
2015-10-13 18:49 - 2015-10-13 18:50 - 00000000 ____D C:\FRST
2015-10-13 18:47 - 2015-10-13 18:47 - 00112640 _____ (forum.viry.cz) C:\Users\Lenovo\Desktop\FRSTLauncher.exe
2015-10-13 18:45 - 2015-10-13 18:45 - 02196480 _____ (Farbar) C:\Users\Lenovo\Desktop\FRST64.exe
2015-10-13 18:22 - 2015-10-13 18:22 - 00000000 ____D C:\Users\Lenovo\AppData\Local\TeamViewer
2015-10-13 18:20 - 2015-10-13 18:20 - 00001066 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-10-13 18:20 - 2015-10-13 18:20 - 00001054 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-10-13 18:20 - 2015-10-13 18:20 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-10-13 18:19 - 2015-10-13 18:19 - 08206600 _____ (TeamViewer GmbH) C:\Users\Lenovo\Downloads\TeamViewer_Setup_cs (1).exe
2015-10-09 14:37 - 2015-10-09 14:37 - 08206600 _____ (TeamViewer GmbH) C:\Users\Lenovo\Downloads\TeamViewer_Setup_cs.exe
2015-10-09 14:31 - 2015-10-09 14:32 - 00000231 _____ C:\WINDOWS\setupact.log
2015-10-09 14:31 - 2015-10-09 14:31 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-10-09 14:19 - 2015-10-09 14:19 - 00490568 _____ () C:\Users\Lenovo\Downloads\LSBsetup.exe
2015-10-09 11:02 - 2015-10-09 11:02 - 00005564 _____ C:\Users\Lenovo\Documents\cc_20151009_110232.reg
2015-10-09 11:01 - 2015-10-09 11:01 - 00094842 _____ C:\Users\Lenovo\Documents\cc_20151009_110123.reg
2015-10-09 10:57 - 2015-10-09 10:57 - 00002792 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2015-10-09 10:57 - 2015-10-09 10:57 - 00000845 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-10-09 10:57 - 2015-10-09 10:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-10-09 10:57 - 2015-10-09 10:57 - 00000000 ____D C:\Program Files\CCleaner
2015-10-09 10:55 - 2015-10-09 10:55 - 06677440 _____ (Piriform Ltd) C:\Users\Lenovo\Downloads\ccsetup510.exe
2015-10-09 09:41 - 2015-10-09 09:41 - 05693008 _____ (AVAST Software) C:\Users\Lenovo\Downloads\avast_free_antivirus_setup_online (1).exe
2015-10-09 08:31 - 2015-10-09 08:31 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\AVAST Software
2015-10-09 08:30 - 2015-10-09 10:48 - 00004182 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-10-09 08:30 - 2015-10-09 08:30 - 00001949 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-10-09 08:30 - 2015-10-09 08:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-10-09 08:29 - 2015-10-09 08:29 - 01049880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00448968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-10-09 08:29 - 2015-10-09 08:29 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00153744 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-10-09 08:29 - 2015-10-09 08:29 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-10-09 08:29 - 2015-10-09 08:29 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-10-09 08:25 - 2015-10-09 08:25 - 00000000 ____D C:\Program Files\AVAST Software
2015-10-09 08:19 - 2015-10-09 08:19 - 05693008 _____ (AVAST Software) C:\Users\Lenovo\Downloads\avast_free_antivirus_setup_online.exe
2015-09-21 15:51 - 2015-10-09 08:43 - 00000000 ____D C:\Program Files (x86)\DNS Unlocker
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-13 18:49 - 2014-12-20 08:41 - 01918996 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-13 18:44 - 2014-04-09 14:02 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\ClassicShell
2015-10-13 18:33 - 2014-12-21 07:45 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3922014775-476238916-793784252-1001
2015-10-13 18:28 - 2014-04-09 12:49 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-10-13 18:27 - 2014-12-26 18:18 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-10-13 18:16 - 2015-02-11 19:03 - 00003974 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{9FCC1BAB-1732-4CE9-8121-E7E95D0CE7E8}
2015-10-13 18:15 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-12 06:05 - 2014-09-24 18:23 - 01745984 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-12 06:05 - 2014-09-24 17:39 - 00739924 _____ C:\WINDOWS\system32\perfh005.dat
2015-10-12 06:05 - 2014-09-24 17:39 - 00151610 _____ C:\WINDOWS\system32\perfc005.dat
2015-10-11 22:00 - 2014-12-04 15:58 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-09 14:32 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-09 10:58 - 2014-12-20 08:11 - 00000000 ___DC C:\WINDOWS\Panther
2015-10-09 10:58 - 2014-09-08 12:26 - 00000000 ____D C:\Users\Lenovo\AppData\Local\CrashDumps
2015-10-09 10:45 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-10-09 10:41 - 2014-04-09 12:54 - 00001146 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-10-09 10:41 - 2014-04-09 12:54 - 00001146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-10-09 09:38 - 2014-04-09 13:55 - 00000000 ____D C:\ProgramData\Norton
2015-10-09 08:48 - 2015-06-07 12:03 - 00000000 ____D C:\Program Files (x86)\Share with Facebook Twitter Google Email
2015-10-09 08:48 - 2015-05-10 10:11 - 00000000 ____D C:\Program Files (x86)\UniDeals
2015-10-09 08:44 - 2015-06-07 12:03 - 00000000 ____D C:\Program Files (x86)\HHAppy2Savee
2015-10-09 08:44 - 2015-06-07 12:03 - 00000000 ____D C:\Program Files (x86)\Happy2Savee
2015-10-09 08:44 - 2015-06-07 12:03 - 00000000 ____D C:\Program Files (x86)\Happy2Saave
2015-10-09 08:43 - 2015-06-13 21:39 - 00000000 ____D C:\Program Files (x86)\Fun2SaavE
2015-10-09 08:43 - 2015-05-18 21:27 - 00000000 ____D C:\Program Files (x86)\DuIgiSavER
2015-10-09 08:43 - 2015-05-18 21:27 - 00000000 ____D C:\Program Files (x86)\DowwnSavE
2015-10-09 08:42 - 2015-05-18 21:28 - 00000000 ____D C:\Program Files (x86)\Best of 3d Football Soccer Games 2013
2015-10-09 08:42 - 2015-05-18 21:27 - 00000000 ____D C:\Program Files (x86)\BitSaaveR
2015-10-09 08:42 - 2015-05-10 10:12 - 00000000 ____D C:\Program Files (x86)\bestadblocker
2015-10-09 08:42 - 2015-05-10 10:12 - 00000000 ____D C:\Program Files (x86)\AirDroid Notifier
2015-10-09 08:33 - 2015-05-10 10:13 - 00000000 ____D C:\Program Files (x86)\AppendEngine
2015-10-09 08:33 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2015-10-09 08:33 - 2012-07-26 10:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-10-09 08:32 - 2015-07-31 12:25 - 00000000 ____D C:\WINDOWS\System32\Tasks\Remediation
2015-10-09 06:06 - 2015-07-05 21:37 - 00000020 _____ C:\Users\Lenovo\AppData\Roaming\appdataFr2.bin
2015-10-08 18:16 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-21 20:01 - 2014-12-04 15:58 - 00003802 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-09-21 20:00 - 2015-07-14 21:00 - 18819272 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2015-09-21 15:51 - 2015-05-10 10:11 - 00000000 ____D C:\ProgramData\14887237305190576793
2015-09-14 21:37 - 2014-12-20 08:25 - 00000000 ____D C:\Users\Lenovo
2015-09-13 09:36 - 2014-04-09 11:53 - 00001129 _____ C:\Users\Lenovo\Desktop\Cyberlink Power2Go.lnk
==================== Files in the root of some directories =======
2015-05-17 12:41 - 2015-05-17 12:41 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2015-07-05 21:37 - 2015-10-09 06:06 - 0000020 _____ () C:\Users\Lenovo\AppData\Roaming\appdataFr2.bin
2015-06-17 22:07 - 2015-07-08 10:51 - 0000024 _____ () C:\Users\Lenovo\AppData\Roaming\appdataFr25.bin
2013-12-08 12:57 - 2013-12-08 12:57 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-10-09 11:07
==================== End of FRST.txt ============================