Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Mozzila sama otvara stranky

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
stelinka
Návštěvník
Návštěvník
Příspěvky: 125
Registrován: 06 dub 2013 10:27

Mozzila sama otvara stranky

#1 Příspěvek od stelinka »

Zdravim. Prosim o kontrolu. Notebook je strasne spomaleny a mozzila otvara okna a stranky. Dakujem
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:27-01-2016
Ran by Viera (administrator) on MAREK (13-01-2016 04:01:05)
Running from C:\Users\Viera\Desktop
Loaded Profiles: Viera (Available Profiles: Viera)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: Slovenčina (Slovensko)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Silicon Integrated Systems Corporation) C:\Program Files\SiS VGA Utilities\SiSTray.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
() C:\Users\Viera\Desktop\RSIT.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(forum.viry.cz) C:\Users\Viera\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SiSTray] => C:\Program Files\SiS VGA Utilities\SiSTray.exe [552960 2007-08-24] (Silicon Integrated Systems Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4706304 2007-11-14] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-10-11] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-27] (AVAST Software)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\RunOnce: [20150107] => C:\Program Files\AVAST Software\Avast\setup\emupdate\ab5813f6-1294-4179-a4ed-345d1ea7948e.exe [168336 2016-01-13] (AVAST Software)
HKU\S-1-5-21-3725892672-3043224248-1115301474-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\ORION2~1.SCR [624640 2009-12-25] (Jan Kolarik & Ondrej Vaverka)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-12-27] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.20 192.168.3.105
Tcpip\..\Interfaces\{18FB10D8-7CBA-495F-8EC3-29F668821AEF}: [DhcpNameServer] 192.168.1.20
Tcpip\..\Interfaces\{60B2ED20-0EA6-4B35-A274-97736D01BFC0}: [DhcpNameServer] 192.168.1.20 192.168.3.105
Tcpip\..\Interfaces\{625966F6-3047-4617-B1D0-6A525E57F219}: [DhcpNameServer] 192.168.1.20 192.168.3.105
Tcpip\..\Interfaces\{BD0824E6-3FE8-4C1A-A625-16381E8CA554}: [DhcpNameServer] 208.67.220.220 208.67.222.222

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3725892672-3043224248-1115301474-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://fr.msn.com/
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3725892672-3043224248-1115301474-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3725892672-3043224248-1115301474-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.sk/
HKU\S-1-5-21-3725892672-3043224248-1115301474-1000\Software\Microsoft\Internet Explorer\Main,Default_search_url = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope value is missing
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-09-26] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-27] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-09-26] (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2010-04-06] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default
FF DefaultSearchUrl:
FF Homepage: hxxps://www.google.sk/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_267.dll [2016-01-06] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-09-26] (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @parallelgraphics.com/Cortona -> C:\Program Files\Common Files\ParallelGraphics\Cortona\npCortona.dll [2009-06-01] (ParallelGraphics)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-27] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-27] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3725892672-3043224248-1115301474-1000: @facebook.com/FBPlugin,version=1.0.3 -> C:\Users\Viera\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll [2010-02-26] ( )
FF Plugin HKU\S-1-5-21-3725892672-3043224248-1115301474-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Viera\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF user.js: detected! => C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\user.js [2015-12-28]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npCortona.dll [2009-06-01] (ParallelGraphics)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npImagine.dll [2003-06-19] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npkimi.dll [2007-12-17] ( )
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppluginrichmediaplayer.dll [2013-03-12] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-01-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-01-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-01-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-01-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-01-18] (Apple Inc.)
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-07-29] [not signed]
FF Extension: Discover Treasure - C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\Extensions\{a44facf7-e93c-4cf2-a8c4-c884f14bb3b0}.xpi [2015-12-27] [not signed]
FF Extension: Gamers Unite! Snag Bar - C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\Extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}.xpi [2015-06-25] [not signed]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2015-12-27] [not signed]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-12-27] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-03-30] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-28]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-23]
CHR Extension: (Disk Google) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-15]
CHR Extension: (YouTube) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-15]
CHR Extension: (Hľadať v Google) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-15]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-28]
CHR Extension: (Avast Online Security) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-06-05]
CHR Extension: (Peňaženka Google) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-26]
CHR Extension: (GoPhoto.it) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk [2014-04-26] [UpdateUrl: hxxp://cdn.gophoto.it/Extensions/gophotoit/chrome/update.xml] <==== ATTENTION
CHR Extension: (Gmail) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-14]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-27]
CHR HKLM\...\Chrome\Extension: [pfmopbbadnfoelckkcmjjeaaegjpjjbk] - C:\Program Files\Gophoto.it\gophotoit16.crx [2013-08-08]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-27] (AVAST Software)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-12-27] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [81168 2015-12-27] (AVAST Software)
R1 AswRdr; C:\Windows\system32\drivers\aswRdr.sys [55200 2015-12-27] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-12-27] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [812208 2016-01-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449384 2016-01-13] (AVAST Software)
R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [165104 2015-12-27] (AVAST Software)
S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [58016 2015-12-27] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209432 2015-12-27] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-08-31] (Disc Soft Ltd)
S3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2013-04-06] (Malwarebytes Corporation)
R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [350720 2010-03-31] (Realtek Semiconductor Corporation )
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-01-13 04:01 - 2016-01-13 04:01 - 00014641 _____ C:\Users\Viera\Desktop\FRST.txt
2016-01-13 04:00 - 2016-01-13 04:01 - 00000000 ____D C:\FRST
2016-01-13 03:59 - 2016-01-13 03:59 - 01721856 _____ (Farbar) C:\Users\Viera\Desktop\FRST.exe
2016-01-13 03:56 - 2016-01-13 03:56 - 00112640 _____ (forum.viry.cz) C:\Users\Viera\Desktop\FRSTLauncher.exe
2016-01-13 03:49 - 2016-01-13 03:49 - 01107968 _____ C:\Users\Viera\Desktop\RSIT.exe
2016-01-13 03:49 - 2016-01-13 03:49 - 00000000 ____D C:\rsit
2016-01-13 03:43 - 2016-01-13 03:43 - 172483424 _____ C:\Users\Viera\Desktop\23456VS.ZIP.part
2016-01-13 03:43 - 2016-01-13 03:43 - 00000000 _____ C:\Users\Viera\Desktop\23456VS.ZIP
2015-12-28 22:11 - 2015-12-28 22:12 - 00000000 ____D C:\Users\Viera\AppData\Roaming\Room Arranger
2015-12-28 22:11 - 2015-12-28 22:11 - 00000837 _____ C:\Users\Public\Desktop\Room Arranger.lnk
2015-12-28 22:11 - 2015-12-28 22:11 - 00000000 ____D C:\ProgramData\Room Arranger
2015-12-28 22:10 - 2015-12-28 22:11 - 00000000 ____D C:\Users\Viera\Documents\Room Arranger
2015-12-28 22:10 - 2015-12-28 22:11 - 00000000 ____D C:\Program Files\Room Arranger
2015-12-28 22:04 - 2015-12-28 22:04 - 00000430 _____ C:\Windows\PFRO.log
2015-12-28 21:57 - 2015-12-28 21:57 - 00000504 _____ C:\Users\Viera\Desktop\cc_20151228_215725.reg
2015-12-28 21:56 - 2015-12-28 21:56 - 00039652 _____ C:\Users\Viera\Desktop\cc_20151228_215635.reg
2015-12-28 18:02 - 2015-12-28 18:02 - 00000000 ____D C:\Users\Viera\AppData\Roaming\SimpleFiles
2015-12-28 17:36 - 2015-12-28 17:57 - 00011892 _____ C:\Users\Viera\Desktop\dom1.rap
2015-12-27 22:20 - 2015-12-27 22:20 - 00109173 _____ C:\Users\Viera\Desktop\plan1.jpg
2015-12-27 21:05 - 2015-12-27 21:15 - 00004392 _____ C:\Users\Viera\Desktop\dom.rap
2015-12-27 20:27 - 2016-01-11 06:05 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-12-27 19:24 - 2015-12-27 19:23 - 00165104 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStmXP.sys
2015-12-27 19:23 - 2015-12-27 19:23 - 00322760 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-12-27 19:23 - 2015-12-27 19:23 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-12-27 19:14 - 2015-12-27 19:14 - 00000000 ____D C:\Users\Viera\AppData\LocalLow\Oracle
2015-12-27 17:55 - 2016-01-13 03:37 - 2010300416 ___SH C:\hiberfil.sys
2015-12-27 17:53 - 2016-01-11 07:28 - 00000012 _____ C:\Windows\bthservsdp.dat

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-01-13 03:49 - 2010-02-22 23:22 - 00000000 ____D C:\Program Files\trend micro
2016-01-13 03:48 - 2006-11-02 13:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-13 03:48 - 2006-11-02 13:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-13 03:45 - 2013-04-06 16:20 - 00812208 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2016-01-13 03:45 - 2013-04-06 16:20 - 00449384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2016-01-13 03:44 - 2008-01-21 06:30 - 00703388 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-13 03:44 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\inf
2016-01-13 03:38 - 2014-01-14 18:58 - 00000920 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-13 03:38 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-11 07:28 - 2006-11-02 14:01 - 00032552 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-01-11 07:20 - 2013-04-17 13:10 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-11 06:33 - 2014-01-14 18:58 - 00000924 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-06 19:20 - 2012-04-04 19:47 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-01-06 19:20 - 2011-05-17 17:25 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-12-28 22:11 - 2010-06-30 12:46 - 00000000 ____D C:\Users\Viera\AppData\Local\Room Arranger
2015-12-28 22:11 - 2009-12-20 14:46 - 00000000 ____D C:\Users\Viera\AppData\Roaming
2015-12-28 22:11 - 2006-11-02 12:18 - 00000000 __RHD C:\Users\Public\Desktop
2015-12-28 22:11 - 2006-11-02 12:18 - 00000000 ____D C:\ProgramData
2015-12-28 22:10 - 2009-12-20 14:46 - 00000000 ___RD C:\Users\Viera\Documents
2015-12-28 22:10 - 2006-11-02 12:18 - 00000000 ___RD C:\Program Files
2015-12-28 21:58 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\catroot
2015-12-28 21:55 - 2013-08-31 08:38 - 00000000 ____D C:\Users\Viera\AppData\Roaming\DAEMON Tools Lite
2015-12-28 21:54 - 2010-01-26 23:30 - 00000000 ____D C:\Windows\Minidump
2015-12-28 21:54 - 2009-12-20 14:43 - 00000000 ____D C:\Windows\Debug
2015-12-28 21:54 - 2009-12-20 14:33 - 00000000 ____D C:\Windows\Panther
2015-12-28 21:54 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Logs
2015-12-28 18:06 - 2006-11-02 12:18 - 00000000 ____D C:\Program Files\Common Files
2015-12-28 18:05 - 2009-12-20 14:46 - 00000000 ___RD C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
2015-12-28 18:05 - 2006-11-02 12:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs
2015-12-28 18:00 - 2014-01-14 19:01 - 00002345 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-28 18:00 - 2012-07-24 22:22 - 00001036 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-12-28 18:00 - 2012-04-26 19:47 - 00001938 _____ C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Mozilla Firefox (3).lnk
2015-12-28 18:00 - 2012-03-18 11:05 - 00001938 _____ C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Mozilla Firefox (2).lnk
2015-12-28 18:00 - 2011-05-17 17:25 - 00001048 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-12-28 18:00 - 2010-12-08 20:03 - 00001938 _____ C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Mozilla Firefox.lnk
2015-12-28 18:00 - 2009-12-20 14:46 - 00001139 _____ C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-12-28 17:30 - 2012-04-25 13:56 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-12-27 20:46 - 2010-03-03 19:32 - 00000000 ____D C:\Program Files\DVDVideoSoft
2015-12-27 20:46 - 2010-03-03 19:32 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2015-12-27 20:15 - 2009-12-25 15:08 - 00227840 _____ C:\Users\Viera\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-12-27 19:32 - 2009-12-20 15:06 - 00000000 __SHD C:\Windows\Installer
2015-12-27 19:27 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Tasks
2015-12-27 19:25 - 2013-04-06 16:20 - 00436360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1452653106687
2015-12-27 19:25 - 2013-04-06 16:20 - 00081168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2015-12-27 19:24 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\Tasks
2015-12-27 19:23 - 2014-05-05 19:47 - 00024016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-12-27 19:23 - 2013-04-06 16:20 - 00209432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-12-27 19:23 - 2013-04-06 16:20 - 00058016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2015-12-27 19:23 - 2013-04-06 16:20 - 00055200 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys
2015-12-27 19:23 - 2013-04-06 16:20 - 00049776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-12-27 19:22 - 2013-04-06 16:20 - 00794952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1452653106687
2015-12-27 19:21 - 2009-12-20 14:46 - 00000000 ___SD C:\Users\Viera\AppData\Roaming\Microsoft
2015-12-27 19:21 - 2009-12-20 14:35 - 00000000 __SHD C:\System Volume Information
2015-12-27 19:19 - 2014-05-11 17:11 - 00000000 ____D C:\Program Files\GameforgeLive
2015-12-27 19:19 - 2011-12-17 18:45 - 00000000 ____D C:\Users\Viera\AppData\Local\Unity
2015-12-27 19:17 - 2012-08-09 21:30 - 00002425 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2015-12-27 19:14 - 2009-12-20 14:46 - 00000000 ____D C:\Users\Viera\AppData\LocalLow
2015-12-27 19:13 - 2009-12-20 14:35 - 00000000 ____D C:\Windows\Prefetch
2015-12-27 17:56 - 2009-12-20 14:46 - 00002032 _____ C:\Users\Viera\AppData\Local\d3d9caps.dat
2015-12-27 17:53 - 2006-11-02 12:18 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories

==================== Files in the root of some directories =======

2009-12-23 19:52 - 2010-01-04 21:08 - 0880557 _____ () C:\Users\Viera\AppData\Roaming\farm.bmp
2009-12-23 19:35 - 2010-01-04 22:25 - 0011333 _____ () C:\Users\Viera\AppData\Roaming\settings.dat
2010-03-03 18:40 - 2010-03-03 18:40 - 0016960 ____T (Un4seen Developments) C:\Users\Viera\AppData\Roaming\Microsoft\1eaadjc.dll
2014-03-10 22:49 - 2014-03-10 22:50 - 158105199 _____ () C:\Users\Viera\AppData\Local\ACCCx2_4_1_351.zip.aamdownload
2014-03-10 22:49 - 2014-03-10 22:50 - 0001858 _____ () C:\Users\Viera\AppData\Local\ACCCx2_4_1_351.zip.aamdownload.aamd
2009-12-20 14:46 - 2015-12-27 17:56 - 0002032 _____ () C:\Users\Viera\AppData\Local\d3d9caps.dat
2009-12-25 15:08 - 2015-12-27 20:15 - 0227840 _____ () C:\Users\Viera\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-11-08 15:30 - 2011-11-08 15:30 - 0004096 ____H () C:\Users\Viera\AppData\Local\keyfile3.drm

Files to move or delete:
====================
C:\Users\Viera\revelation-natural-art.exe


Some files in TEMP:
====================
C:\Users\Viera\AppData\Local\temp\7i5nvHKrv2.exe
C:\Users\Viera\AppData\Local\temp\{DBEE007D-43F7-4333-98E8-87DAEA2036C4}.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Viera\Desktop" je 167 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files\Common Files\Java\Java Update\jusched.exe"


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================





Log z RSIT
Logfile of random's system information tool 1.10 (written by random/random)
Run by Viera at 2016-01-13 03:49:19
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 50 GB (53%) free of 95 GB
Total RAM: 1916 MB (30% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:49:34, on 13. 1. 2016
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16584)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\SiS VGA Utilities\SiSTray.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Viera\Desktop\RSIT.exe
C:\Program Files\trend micro\Viera.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://stoppblock.me/wpad.dat?0a04783a8 ... f103367806
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SiSTray] %ProgramFiles%\SiS VGA Utilities\SiSTray.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\RunOnce: [20150107] C:\Program Files\AVAST Software\Avast\setup\emupdate\ab5813f6-1294-4179-a4ed-345d1ea7948e.exe /check
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe

--
End of file - 4159 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default

prefs.js - "browser.search.useDBForOrder" - "false"
prefs.js - "browser.startup.homepage" - "https://www.google.sk/"
prefs.js - "extensions.enabledItems" - "{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.1, {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.3, {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.19"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.267 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_267.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.71.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@parallelgraphics.com/Cortona]
"Description"=Cortona VRML Plugin
"Path"=C:\Program Files\Common Files\ParallelGraphics\Cortona\npCortona.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
npCortona.xpt
nsIQTScriptablePlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
exeImagine.IMD
np-mswmp.dll
npCortona.dll
npImagine.dll
npkimi.dll
NPOFF12.DLL
nppdf32.dll
nppluginrichmediaplayer.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-09-26 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-27 664184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-09-26 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SiSTray"=C:\Program Files\SiS VGA Utilities\SiSTray.exe [2007-08-24 552960]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-11-14 4706304]
"Skytel"=C:\Windows\Skytel.exe [2007-10-11 1826816]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-12-27 7021880]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2013-05-01 421888]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"20150107"=C:\Program Files\AVAST Software\Avast\setup\emupdate\ab5813f6-1294-4179-a4ed-345d1ea7948e.exe [2016-01-13 168336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2013-08-01 3673696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-09-26 271744]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=0
"NoDriveTypeAutoRun"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=0
"NoDriveTypeAutoRun"=0
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.DIVX"=divx.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2016-01-13 03:49:19 ----D---- C:\rsit
2015-12-28 22:11:36 ----D---- C:\Users\Viera\AppData\Roaming\Room Arranger
2015-12-28 22:11:04 ----D---- C:\ProgramData\Room Arranger
2015-12-28 22:10:50 ----D---- C:\Program Files\Room Arranger
2015-12-28 18:02:00 ----D---- C:\Users\Viera\AppData\Roaming\SimpleFiles
2015-12-27 20:27:58 ----D---- C:\Program Files\Mozilla Firefox
2015-12-27 19:24:18 ----A---- C:\Windows\system32\drivers\aswStmXP.sys
2015-12-27 19:23:44 ----A---- C:\Windows\system32\aswBoot.exe
2015-12-27 19:23:01 ----A---- C:\Windows\avastSS.scr
2015-12-27 17:55:52 ----ASH---- C:\hiberfil.sys
2015-12-27 17:53:07 ----A---- C:\Windows\bthservsdp.dat

======List of files/folders modified in the last 1 month======

2016-01-13 03:49:22 ----D---- C:\Program Files\trend micro
2016-01-13 03:49:13 ----D---- C:\Windows\temp
2016-01-13 03:45:21 ----D---- C:\Windows\system32\drivers
2016-01-13 03:44:25 ----D---- C:\Windows\System32
2016-01-13 03:44:25 ----D---- C:\Windows\inf
2016-01-13 03:44:25 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-01-06 19:20:55 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2015-12-28 22:11:04 ----D---- C:\ProgramData
2015-12-28 22:10:50 ----RD---- C:\Program Files
2015-12-28 22:04:36 ----D---- C:\Windows
2015-12-28 21:58:31 ----D---- C:\Windows\system32\catroot
2015-12-28 21:55:05 ----D---- C:\Users\Viera\AppData\Roaming\DAEMON Tools Lite
2015-12-28 21:54:41 ----D---- C:\Windows\Panther
2015-12-28 21:54:40 ----D---- C:\Windows\Minidump
2015-12-28 21:54:40 ----D---- C:\Windows\Logs
2015-12-28 21:54:40 ----D---- C:\Windows\Debug
2015-12-28 18:06:25 ----D---- C:\Program Files\Common Files
2015-12-28 17:30:43 ----D---- C:\Program Files\Mozilla Maintenance Service
2015-12-27 20:46:27 ----D---- C:\Program Files\DVDVideoSoft
2015-12-27 20:46:26 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2015-12-27 19:32:14 ----SHD---- C:\Windows\Installer
2015-12-27 19:27:20 ----D---- C:\Windows\Tasks
2015-12-27 19:24:30 ----D---- C:\Windows\system32\Tasks
2015-12-27 19:21:31 ----SD---- C:\Users\Viera\AppData\Roaming\Microsoft
2015-12-27 19:21:00 ----SHD---- C:\System Volume Information
2015-12-27 19:19:07 ----D---- C:\Program Files\GameforgeLive
2015-12-27 19:13:00 ----D---- C:\Windows\Prefetch

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-12-27 49776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-12-27 209432]
R1 AswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2015-12-27 55200]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2016-01-13 812208]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2016-01-13 449384]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-08-31 243128]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-12-27 24016]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-12-27 81168]
R3 aswStmXP;Avast StreamFilter Driver; C:\Windows\system32\drivers\aswStmXP.sys [2015-12-27 165104]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-11-14 2016920]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8187B.sys [2010-03-31 350720]
R3 SiS6350;SiS6350; C:\Windows\system32\DRIVERS\SISGRKMD.sys [2007-08-24 452096]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSGB6.sys [2008-05-02 48128]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-07-12 134272]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S3 aswTdi;aswTdi; C:\Windows\system32\drivers\aswTdi.sys [2015-12-27 58016]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-10 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-10 236544]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys []
S3 KMWDFILTER;HIDUASDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys [2008-10-09 17408]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2013-04-06 40776]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-10 148992]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-09-24 81088]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-12-27 226440]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-06 269504]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-12-27 114800]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Mozzila sama otvara stranky

#2 Příspěvek od Márty84 »

Zdravim :)

:arrow: Stahnete crystal disk info http://sourceforge.jp/projects/crystald ... 5_0_0.zip/
Spustte jako spravce. Za chvili se zobrazi vysledek.
Kliknete nahore na napis Úpravy a pak na napis Kopírovat. To co se zkopiruje (ulozi se to do pameti) mi sem vlozte (ctrl + V)

:arrow: Stahnete AdwCleaner https://toolslib.net/downloads/finish/1/ a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Cleaning
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner[C?].txt ). Ten mi sem zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

stelinka
Návštěvník
Návštěvník
Příspěvky: 125
Registrován: 06 dub 2013 10:27

Re: Mozzila sama otvara stranky

#3 Příspěvek od stelinka »

----------------------------------------------------------------------------
CrystalDiskInfo 5.0.0 (C) 2008-2012 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows Vista Home Premium Edition SP2 [6.0 Build 6002] (x86)
Date : 2016/01/13 8:09:53

-- Controller Map ----------------------------------------------------------
+ SiS PCI IDE Controller [ATA]
+ IDE Channel (0)
- TSSTcorp CDDVDW TS-L632H ATA Device
+ Standard Dual Channel PCI IDE Controller [ATA]
+ IDE Channel (0)
- FUJITSU MHY2200BH ATA Device
- IDE Channel (1)
- Microsoft iSCSI Initiator [SCSI]

-- Disk List ---------------------------------------------------------------
(1) FUJITSU MHY2200BH : 200,0 GB [0/1/0, pd1]

----------------------------------------------------------------------------
(1) FUJITSU MHY2200BH
----------------------------------------------------------------------------
Model : FUJITSU MHY2200BH
Firmware : 0000000B
Serial Number : K406T8629JNY
Disk Size : 200,0 GB (8,4/137,4/200,0)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 390721968
Rotation Rate : Unknown
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 3f
Transfer Mode : SATA/150
Power On Hours : 14124 hours
Power On Count : 4285 count
Temparature : 51 C (123 F)
Health Status : Good
Features : S.M.A.R.T., APM, AAM, 48bit LBA, NCQ
APM Level : 4080h [ON]
AAM Level : FEFEh [ON]

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _46 00000003FE4B Read Error Rate
02 100 100 _30 000002B50000 Throughput Performance
03 100 100 _25 000000000001 Spin-Up Time
04 _99 _99 __0 0000000012F9 Start/Stop Count
05 100 100 _24 07D000000000 Reallocated Sectors Count
07 100 100 _47 000000000F1C Seek Error Rate
08 100 100 _19 000000000000 Seek Time Performance
09 _72 _72 __0 00000000372C Power-On Hours
0A 100 100 _20 000000000000 Spin Retry Count
0C 100 100 __0 0000000010BD Power Cycle Count
C0 100 100 __0 0000000000E0 Power-off Retract Count
C1 _97 _97 __0 00000000EF98 Load/Unload Cycle Count
C2 100 100 __0 003C000D0033 Temperature
C3 100 100 __0 000000000034 Hardware ECC recovered
C4 100 100 __0 00001B700000 Reallocation Event Count
C5 100 100 __0 000000000000 Current Pending Sector Count
C6 100 100 __0 000000000000 Uncorrectable Sector Count
C7 200 253 __0 000000000000 UltraDMA CRC Error Count
C8 100 100 _60 000000003AEF Write Error Rate
CB 100 100 __0 0364039C051D Run Out Cancel
F0 200 200 __0 000000000000 Head Flying Hours

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 045A 3FFF C837 0010 0000 003F 003F 0000 0000 0000
010: 2020 2020 2020 2020 4B34 5438 5438 3632 394A 4E59
020: 0003 4000 0000 3030 3030 3042 3042 4655 4A49 5453
030: 5520 4D48 5932 3230 3042 2020 2020 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4000 0200 0200 0007 3FFF 003F 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 0702 0702 0000 004C 0040
080: 01F8 0042 346B 7F09 6163 BF09 BF09 6163 203F 0064
090: 0000 4080 FFFE 0000 FEFE 0000 0000 0000 0000 0000
100: F1B0 1749 0000 0000 0000 4000 4000 0000 5000 00E0
110: 4230 2295 0000 0000 0000 0000 0000 0000 0000 401D
120: 401C 0000 0000 0000 0000 0000 0000 0000 0009 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0000 0000 03D5 0000 0000 0000 4004 4000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 003D 003D 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
220: 0000 0000 100F 0021 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 D2A5

stelinka
Návštěvník
Návštěvník
Příspěvky: 125
Registrován: 06 dub 2013 10:27

Re: Mozzila sama otvara stranky

#4 Příspěvek od stelinka »

# AdwCleaner v5.031 - Logfile created 13/01/2016 at 09:04:37
# Updated 25/01/2016 by Xplode
# Database : 2016-01-25.3 [Server]
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (x86)
# Username : Viera - MAREK
# Running from : C:\Users\Viera\Desktop\adwcleaner_5.031.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files\Gophoto.it
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rich Media Player
[-] Folder Deleted : C:\Users\Viera\AppData\Local\Rich Media Player
[-] Folder Deleted : C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk
[-] Folder Deleted : C:\Users\Viera\AppData\Roaming\OpenCandy
[-] Folder Deleted : C:\Users\Viera\AppData\Roaming\SimpleFiles

***** [ Files ] *****

[-] File Deleted : C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\user.js

***** [ DLLs ] *****


***** [ Shortcuts ] *****

[-] Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk
[-] Shortcut Disinfected : C:\Users\Public\Desktop\Mozilla Firefox.lnk
[-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[-] Shortcut Disinfected : C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Mozilla Firefox (2).lnk
[-] Shortcut Disinfected : C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Mozilla Firefox (3).lnk
[-] Shortcut Disinfected : C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Mozilla Firefox.lnk
[-] Shortcut Disinfected : C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[-] Shortcut Disinfected : C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
[-] Shortcut Disinfected : C:\Users\Viera\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[-] Shortcut Disinfected : C:\Users\Viera\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[-] Shortcut Disinfected : C:\Users\Viera\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk

***** [ Scheduled tasks ] *****

[-] Task Deleted : Scheduled Update for Ask Toolbar

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{81CA8FCD-1420-4A07-B47D-B30F3DDA79E1}
[-] Key Deleted : HKCU\Software\1ClickDownload
[-] Key Deleted : HKCU\Software\SimpleFiles
[-] Key Deleted : HKLM\SOFTWARE\SimpleFiles
[-] Key Deleted : HKU\.DEFAULT\Software\AVG Secure Search
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9

***** [ Web browsers ] *****

[-] [C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : pfmopbbadnfoelckkcmjjeaaegjpjjbk

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [3860 bytes] ##########

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Mozzila sama otvara stranky

#5 Příspěvek od Márty84 »

:arrow: Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu (cili Vlastni sken vsech disku) http://forum.viry.cz/viewtopic.php?f=29&t=144868 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

stelinka
Návštěvník
Návštěvník
Příspěvky: 125
Registrován: 06 dub 2013 10:27

Re: Mozzila sama otvara stranky

#6 Příspěvek od stelinka »

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 13. 1. 2016
Čas skenování: 10:53:29
Protokol:
Správce: Ano

Verze: 2.2.0.1024
Databáze malwaru: v2016.01.30.02
Databáze rootkitů: v2016.01.20.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows Vista Service Pack 2
CPU: x86
Souborový systém: NTFS
Uživatel: Viera

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 464847
Uplynulý čas: 5 hod, 25 min, 59 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 1
PUP.Optional.ASK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Scheduled Update for Ask Toolbar, , [3298d56ad3c6e45283a7c57f39cb0cf4],

Hodnoty registru: 1
Hijack.AutoConfigURL, HKU\S-1-5-21-3725892672-3043224248-1115301474-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|AutoConfigUrl, http://stoppblock.me/wpad.dat?0a04783a8 ... f103367806, , [26a457e8752476c048110bd633cf51af]

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 2
PUP.Optional.ConduitTB.Gen, C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\CT2438727, , [e3e747f8bedb5adc617f78657b87be42],
PUP.Optional.ConduitTB.Gen, C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\CT2438727\MyStuffComponents, , [e3e747f8bedb5adc617f78657b87be42],

Soubory: 17
PUP.Optional.Yontoo, C:\Users\Viera\AppData\Local\temp\7i5nvHKrv2.exe, , [3b8f330c2e6b102604fbc49442bf51af],
PUP.Optional.BundleInstaller, C:\Users\Viera\AppData\Local\temp\asVXrqf8xR.tmp, , [f4d6d86735649e98328315b8af52a858],
PUP.Optional.Yontoo, C:\Users\Viera\AppData\Local\temp\{DBEE007D-43F7-4333-98E8-87DAEA2036C4}.dll, , [616969d643569f97e9160256b15054ac],
Trojan.Agent.ED, C:\Users\Viera\Downloads\Farmville.zip, , [75554cf32b6ef3437e1a1aca54ac52ae],
PUP.Optional.BitCoinMiner, C:\Windows\System32\acumncfislxd.exe, , [616981be2574ef47265d56dce31fb44c],
Trojan.BitCoinMiner, C:\Windows\System32\dcgmncfislxd.exe, , [1caea19ec9d03cfa663fa58d927057a9],
Trojan.Agent.BCM, C:\Windows\System32\lcpmncfislxd.exe, , [8d3d3c0302975ed8622ad5d9eb159b65],
PUP.Optional.SweetIM, C:\Windows\Installer\c98a90.msi, , [6a6083bc65343cfaf36e4a989f65fb05],
PUP.Optional.CrossRider, C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage, , [cdfd63dc5445f541b5fedd685ba9ae52],
PUP.Optional.CrossRider, C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal, , [705aab94a8f151e5783bfb4a966e4db3],
PUP.Optional.Yontoo, C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\extensions\{a44facf7-e93c-4cf2-a8c4-c884f14bb3b0}.xpi, , [fbcf63dc01981b1b5934f255a95bdd23],
PUP.Optional.ConduitTB.Gen, C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\CT2438727\LanguagePack.xml, , [e3e747f8bedb5adc617f78657b87be42],
PUP.Optional.ConduitTB.Gen, C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\CT2438727\LocalSettings.txt, , [e3e747f8bedb5adc617f78657b87be42],
PUP.Optional.ConduitTB.Gen, C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\CT2438727\searchInNewTabData.xml, , [e3e747f8bedb5adc617f78657b87be42],
PUP.Optional.ConduitTB.Gen, C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\CT2438727\ThirdPartyComponents.xml, , [e3e747f8bedb5adc617f78657b87be42],
PUP.Optional.ConduitTB.Gen, C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\CT2438727\UserAdditionalComponents.xml, , [e3e747f8bedb5adc617f78657b87be42],
PUP.Optional.ConduitTB.Gen, C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\CT2438727\MyStuffComponents\list.json, , [e3e747f8bedb5adc617f78657b87be42],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Mozzila sama otvara stranky

#7 Příspěvek od Márty84 »

Vsechny nalezy nechte odstranit. Po odstraneni a restartu pc test s MBAM zopakujte, at vime, jestli se to nevraci. Napiste vysledek testu a podle nej zvolim dalsi postup.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

stelinka
Návštěvník
Návštěvník
Příspěvky: 125
Registrován: 06 dub 2013 10:27

Re: Mozzila sama otvara stranky

#8 Příspěvek od stelinka »

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 14. 1. 2016
Čas skenování: 3:27:38
Protokol:
Správce: Ano

Verze: 2.2.0.1024
Databáze malwaru: v2016.01.30.06
Databáze rootkitů: v2016.01.20.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows Vista Service Pack 2
CPU: x86
Souborový systém: NTFS
Uživatel: Viera

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 464574
Uplynulý čas: 4 hod, 40 min, 1 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 0
(Nenalezeny žádné škodlivé položky)

Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 2
PUP.Optional.ConduitTB.Gen, C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\CT2438727, , [a727053a82175adca5b0617d30d246ba],
PUP.Optional.ConduitTB.Gen, C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\CT2438727\MyStuffComponents, , [a727053a82175adca5b0617d30d246ba],

Soubory: 2
PUP.Optional.CrossRider, C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage, , [804e84bbb4e5072f8f99172fdb290af6],
PUP.Optional.CrossRider, C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal, , [6a643e01c7d26ec880a870d69371bc44],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Mozzila sama otvara stranky

#9 Příspěvek od Márty84 »

:arrow: Nalezy nechte odstranit, pak muzete MBAM odinstalovat.


:arrow: Postupujte podle navodu kolegy
vyosek píše: :arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte

:arrow: Postupujte podle navodu kolegy
vyosek píše: :arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

stelinka
Návštěvník
Návštěvník
Příspěvky: 125
Registrován: 06 dub 2013 10:27

Re: Mozzila sama otvara stranky

#10 Příspěvek od stelinka »

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.2 (01.06.2016)
Operating System: Windows Vista (TM) Home Premium x86
Ran by Viera (Administrator) on çt 14. 01. 2016 at 14:49:07,10
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 5

Successfully deleted: C:\Users\Viera\AppData\Roaming\getrighttogo (Folder)
Successfully deleted: C:\Users\Viera\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DZ0LGO65 (Folder)
Successfully deleted: C:\Users\Viera\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SKD2Q48C (Folder)
Successfully deleted: C:\Users\Viera\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UTARFDES (Folder)
Successfully deleted: C:\Users\Viera\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WCEQDTEL (Folder)



Registry: 1

Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on çt 14. 01. 2016 at 15:01:30,70
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

stelinka
Návštěvník
Návštěvník
Příspěvky: 125
Registrován: 06 dub 2013 10:27

Re: Mozzila sama otvara stranky

#11 Příspěvek od stelinka »

Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Viera on çt 14. 01. 2016 at 15:05:20,10.
Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Viera\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

14. 1. 2016 15:08:46 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Oracle deleted successfully
C:\Users\Viera\AppData\Roaming\WinRAR deleted successfully
C:\Users\Viera\AppData\Local\Unity deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.sk/");
user_pref("browser.search.defaulturl", "");
user_pref("browser.search.defaultengine", "");
user_pref("browser.search.useDBForOrder", "false");

Added to C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\prefs.js:

ProfilePath: C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_201614.01._1750_.backup

==== Deleting Files \ Folders ======================

C:\Program Files\Blaze Media Pro deleted
C:\PROGRA~2\ICQ deleted
C:\PROGRA~2\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} deleted
C:\Users\Viera\Downloads\FreeYouTubeToMp3Converter.exe deleted
C:\Users\Viera\AppData\LocalLow\Unity deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted
C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\CT2438727 deleted
C:\Users\Viera\revelation-natural-art.exe deleted
"C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo.xml" deleted

==== Orphaned Tasks deleted from Registry ======================

avast Emergency Update deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [28. 12. 2015 17:30]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default
- Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
- Gamers Unite Snag Bar - %ProfilePath%\extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default
A107920551356DAEE665F0884F34D2D7 - C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_286.dll - Shockwave Flash
3D1497F3F1A344FFB733CE616BB9096D - C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll - Google Update
F169116C1BA501AB4D0D66D41FF496B5 - C:\Program Files\Adobe\Reader 10.0\Reader\browser\nppdf32.dll - Adobe Acrobat
FC5D7AF1FC3A63782E19B375E2312D1C - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
BBF0479C2D30519A2E746D12CAE54B43 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U71
1ED046D972B98E0ADEC4D4D61BF37695 - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.710.14
3CD19649B2C3023D65E67C056457A2BC - C:\Users\Viera\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin
EEEB86077BB4682B3FCFEDA5AED3E396 - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.7.4
BADFB0DCCD9B7E9F2F6EB7954D24EED1 - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.7.4
1153F58FACBC9731AF6CDF313F76DF29 - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.7.4
9E4F520270BF7301CC24E8FA67791C22 - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.7.4
E50A1DB5DE70D656287511297B42F9F2 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.7.4
0C0C5C207121C7A78414A8250E8E099A - C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll - Shockwave for Director / Shockwave for Director
1BE4D00995FDD31B5B65E5D1CF0C5FE9 - C:\Users\Viera\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll - Facebook Plugin
E07621823F4AF01589E53420B0E12C55 - C:\Program Files\Common Files\ParallelGraphics\Cortona\npCortona.dll - Cortona3D Viewer
AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation


==== Chromium Look ======================

Google Chrome Version: 43.0.2357.130

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[27. 12. 2015 19:22]

Avast Online Security - Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki

==== Chromium Fix ======================

C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage deleted successfully
C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.sk/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="${searchCLSID}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{searchCLSID}] not found

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.sk/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"=""
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
HKCU\SearchScopes\${searchCLSID} - http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
HKCU\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} - http://www.bing.com/search?q={searchTer ... ORM=IE8SRC

==== Reset Google Chrome ======================

C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{895722FE-25FE-4854-95AC-B0C42F9DBEDA} deleted successfully

==== Empty IE Cache ======================

C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Viera\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Viera\AppData\Local\Mozilla\Firefox\Profiles\j5a98b64.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=506 folders=235 245049559 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Users\Viera\AppData\Local\temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Viera\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Viera\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted

==== EOF on pi 15. 01. 2016 at 2:01:30,68 ======================

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Mozzila sama otvara stranky

#12 Příspěvek od Márty84 »

Dejte novy log z FRST
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

stelinka
Návštěvník
Návštěvník
Příspěvky: 125
Registrován: 06 dub 2013 10:27

Re: Mozzila sama otvara stranky

#13 Příspěvek od stelinka »

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:27-01-2016
Ran by Viera (administrator) on MAREK (02-02-2016 15:13:58)
Running from C:\Users\Viera\Desktop
Loaded Profiles: Viera (Available Profiles: Viera)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: Slovenčina (Slovensko)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Silicon Integrated Systems Corporation) C:\Program Files\SiS VGA Utilities\SiSTray.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\Viera\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SiSTray] => C:\Program Files\SiS VGA Utilities\SiSTray.exe [552960 2007-08-24] (Silicon Integrated Systems Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4706304 2007-11-14] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-10-11] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-27] (AVAST Software)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKU\S-1-5-21-3725892672-3043224248-1115301474-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\ORION2~1.SCR [624640 2009-12-25] (Jan Kolarik & Ondrej Vaverka)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-12-27] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.20 192.168.3.105
Tcpip\..\Interfaces\{18FB10D8-7CBA-495F-8EC3-29F668821AEF}: [DhcpNameServer] 192.168.1.20
Tcpip\..\Interfaces\{60B2ED20-0EA6-4B35-A274-97736D01BFC0}: [DhcpNameServer] 192.168.1.20 192.168.3.105
Tcpip\..\Interfaces\{625966F6-3047-4617-B1D0-6A525E57F219}: [DhcpNameServer] 192.168.1.20 192.168.3.105
Tcpip\..\Interfaces\{BD0824E6-3FE8-4C1A-A625-16381E8CA554}: [DhcpNameServer] 208.67.220.220 208.67.222.222

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3725892672-3043224248-1115301474-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://fr.msn.com/
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3725892672-3043224248-1115301474-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3725892672-3043224248-1115301474-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.sk/
HKU\S-1-5-21-3725892672-3043224248-1115301474-1000\Software\Microsoft\Internet Explorer\Main,Default_search_url = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-3725892672-3043224248-1115301474-1000 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3725892672-3043224248-1115301474-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-09-26] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-27] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-09-26] (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2010-04-06] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-13] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-09-26] (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @parallelgraphics.com/Cortona -> C:\Program Files\Common Files\ParallelGraphics\Cortona\npCortona.dll [2009-06-01] (ParallelGraphics)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-27] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-27] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3725892672-3043224248-1115301474-1000: @facebook.com/FBPlugin,version=1.0.3 -> C:\Users\Viera\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll [2010-02-26] ( )
FF Plugin HKU\S-1-5-21-3725892672-3043224248-1115301474-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Viera\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npCortona.dll [2009-06-01] (ParallelGraphics)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npImagine.dll [2003-06-19] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npkimi.dll [2007-12-17] ( )
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppluginrichmediaplayer.dll [2013-03-12] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-01-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-01-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-01-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-01-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-01-18] (Apple Inc.)
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-07-29] [not signed]
FF Extension: Gamers Unite! Snag Bar - C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\Extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}.xpi [2015-06-25] [not signed]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2016-02-01] [not signed]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2016-02-01] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-03-30] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-28]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found

Chrome:
=======
CHR Profile: C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentácie Google) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-02]
CHR Extension: (Dokumenty Google) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-02]
CHR Extension: (Disk Google) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-02]
CHR Extension: (YouTube) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-02]
CHR Extension: (Google Search) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-02]
CHR Extension: (Tabuľky Google) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-02]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-02]
CHR Extension: (Avast Online Security) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-02]
CHR Extension: (Gmail) - C:\Users\Viera\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-02]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-27]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-27] (AVAST Software)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-12-27] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [81168 2015-12-27] (AVAST Software)
R1 AswRdr; C:\Windows\system32\drivers\aswRdr.sys [55200 2015-12-27] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-12-27] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [812208 2016-01-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449384 2016-01-13] (AVAST Software)
R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [165104 2015-12-27] (AVAST Software)
S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [58016 2015-12-27] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209432 2015-12-27] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-08-31] (Disc Soft Ltd)
S3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider)
R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [350720 2010-03-31] (Realtek Semiconductor Corporation )
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-02 15:13 - 2016-02-02 15:14 - 00014264 _____ C:\Users\Viera\Desktop\FRST.txt
2016-02-02 15:13 - 2016-02-02 15:13 - 00112640 _____ (forum.viry.cz) C:\Users\Viera\Desktop\FRSTLauncher.exe
2016-02-02 15:03 - 2016-02-02 15:03 - 01721856 _____ (Farbar) C:\Users\Viera\Desktop\FRST.exe
2016-02-01 10:39 - 2016-02-01 10:40 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-01-14 18:08 - 2016-01-14 15:04 - 00024064 _____ C:\Windows\zoek-delete.exe
2016-01-14 15:05 - 2016-01-14 17:59 - 00000000 ____D C:\zoek_backup
2016-01-14 14:50 - 2016-01-14 14:50 - 01309184 _____ C:\Users\Viera\Desktop\zoek.exe
2016-01-14 14:48 - 2016-01-14 14:48 - 01609032 _____ (Malwarebytes) C:\Users\Viera\Desktop\JRT.exe
2016-01-13 13:56 - 2016-01-26 19:01 - 00000000 ____D C:\Users\Viera\Downloads\23456
2016-01-13 10:47 - 2016-01-13 10:49 - 22908888 _____ (Malwarebytes ) C:\Users\Viera\Downloads\mbam-setup-2.2.0.1024.exe
2016-01-13 09:14 - 2016-01-13 13:34 - 3321853283 _____ C:\Users\Viera\Downloads\23456VS.ZIP
2016-01-13 08:27 - 2016-01-13 09:04 - 00000000 ____D C:\AdwCleaner
2016-01-13 08:24 - 2016-01-13 08:25 - 01507840 _____ C:\Users\Viera\Desktop\adwcleaner_5.031.exe
2016-01-13 08:09 - 2016-01-13 08:09 - 00000000 ____D C:\Users\Viera\Desktop\Smart
2016-01-13 08:09 - 2012-05-27 20:28 - 00000000 ____D C:\Users\Viera\Desktop\CdiResource
2016-01-13 08:07 - 2016-01-13 08:08 - 00000000 ____D C:\Users\Viera\Desktop\CrystalDiskInfo5_0_0
2016-01-13 08:07 - 2012-06-15 14:08 - 01149912 _____ (Crystal Dew World) C:\Users\Viera\Desktop\DiskInfo.exe
2016-01-13 04:00 - 2016-02-02 15:13 - 00000000 ____D C:\FRST
2016-01-13 03:49 - 2016-01-13 03:49 - 01107968 _____ C:\Users\Viera\Desktop\RSIT.exe
2016-01-13 03:49 - 2016-01-13 03:49 - 00000000 ____D C:\rsit

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-02 15:00 - 2008-01-21 06:30 - 00703388 _____ C:\Windows\system32\PerfStringBackup.INI
2016-02-02 15:00 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\inf
2016-02-02 14:59 - 2012-04-25 13:56 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-02-02 14:53 - 2014-01-14 18:58 - 00000920 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-02 14:53 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-02 14:53 - 2006-11-02 13:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2016-02-02 14:53 - 2006-11-02 13:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2016-02-01 11:15 - 2015-12-27 17:53 - 00000012 _____ C:\Windows\bthservsdp.dat
2016-02-01 11:15 - 2006-11-02 14:01 - 00032552 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-02-01 10:32 - 2014-01-14 18:58 - 00000924 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-01 10:20 - 2013-04-17 13:10 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-14 17:51 - 2009-12-20 14:46 - 00000000 ____D C:\Users\Viera
2016-01-13 14:26 - 2009-12-25 15:08 - 00227840 _____ C:\Users\Viera\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-01-13 10:49 - 2013-04-06 12:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-01-13 09:04 - 2014-01-14 19:01 - 00001099 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-01-13 09:04 - 2014-01-14 19:01 - 00001087 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-01-13 09:04 - 2012-07-24 22:22 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-01-13 09:04 - 2012-04-26 19:47 - 00000870 _____ C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Mozilla Firefox (3).lnk
2016-01-13 09:04 - 2012-03-18 11:05 - 00000870 _____ C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Mozilla Firefox (2).lnk
2016-01-13 09:04 - 2011-05-17 17:25 - 00000858 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-01-13 09:04 - 2010-12-08 20:03 - 00000870 _____ C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Mozilla Firefox.lnk
2016-01-13 09:04 - 2009-12-20 14:46 - 00000979 _____ C:\Users\Viera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-01-13 05:20 - 2012-04-04 19:47 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-01-13 05:20 - 2011-05-17 17:25 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-01-13 03:49 - 2010-02-22 23:22 - 00000000 ____D C:\Program Files\trend micro
2016-01-13 03:45 - 2013-04-06 16:20 - 00812208 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2016-01-13 03:45 - 2013-04-06 16:20 - 00449384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys

==================== Files in the root of some directories =======

2009-12-23 19:52 - 2010-01-04 21:08 - 0880557 _____ () C:\Users\Viera\AppData\Roaming\farm.bmp
2009-12-23 19:35 - 2010-01-04 22:25 - 0011333 _____ () C:\Users\Viera\AppData\Roaming\settings.dat
2010-03-03 18:40 - 2010-03-03 18:40 - 0016960 ____T (Un4seen Developments) C:\Users\Viera\AppData\Roaming\Microsoft\1eaadjc.dll
2014-03-10 22:49 - 2014-03-10 22:50 - 158105199 _____ () C:\Users\Viera\AppData\Local\ACCCx2_4_1_351.zip.aamdownload
2014-03-10 22:49 - 2014-03-10 22:50 - 0001858 _____ () C:\Users\Viera\AppData\Local\ACCCx2_4_1_351.zip.aamdownload.aamd
2009-12-20 14:46 - 2015-12-27 17:56 - 0002032 _____ () C:\Users\Viera\AppData\Local\d3d9caps.dat
2009-12-25 15:08 - 2016-01-13 14:26 - 0227840 _____ () C:\Users\Viera\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-11-08 15:30 - 2011-11-08 15:30 - 0004096 ____H () C:\Users\Viera\AppData\Local\keyfile3.drm

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Viera\Desktop" je 9 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files\Common Files\Java\Java Update\jusched.exe"


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

stelinka
Návštěvník
Návštěvník
Příspěvky: 125
Registrován: 06 dub 2013 10:27

Re: Mozzila sama otvara stranky

#14 Příspěvek od stelinka »

Až teraz som si všimla ze sa nedajú nainštalovať aktualizácie. Len mi vypíše že neúspešné. :(

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Mozzila sama otvara stranky

#15 Příspěvek od Márty84 »

stelinka píše:Až teraz som si všimla ze sa nedajú nainštalovať aktualizácie. Len mi vypíše že neúspešné. :(
:???: Jak dlouho uz to nejde? Nejde zadna, nebo jen nektere?




:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

Start
CloseProcesses:
CreateRestorePoint:

HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3725892672-3043224248-1115301474-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://fr.msn.com/
SearchScopes: HKLM -> DefaultScope value is missing

FF Extension: Gamers Unite! Snag Bar - C:\Users\Viera\AppData\Roaming\Mozilla\Firefox\Profiles\j5a98b64.default\Extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}.xpi [2015-06-25] [not signed]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found

S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-09-24 81088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]

2016-01-14 18:08 - 2016-01-14 15:04 - 00024064 _____ C:\Windows\zoek-delete.exe
2016-01-14 15:05 - 2016-01-14 17:59 - 00000000 ____D C:\zoek_backup
2016-01-13 10:47 - 2016-01-13 10:49 - 22908888 _____ (Malwarebytes ) C:\Users\Viera\Downloads\mbam-setup-2.2.0.1024.exe
2016-01-13 10:49 - 2013-04-06 12:28 - 00000000 ____D C:\ProgramData\Malwarebytes

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched

Hosts:
EmptyTemp:
Reboot:
End
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev fixlist a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Spustte FRST jako spravce, kliknete na napis Fix a program vykona prikazy.
Po restartu pc by se mel objevit novy log - s nazvem fixlog, ten mi sem zase zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno