Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím kontrola logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Jim55
Návštěvník
Návštěvník
Příspěvky: 1
Registrován: 19 led 2017 18:54

Prosím kontrola logu

#1 Příspěvek od Jim55 »

Zdravím, mám spomalený pc a samovolně se mi instalují aplikace.



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:58:59, on 19.01.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)

FIREFOX: 48.0.2 (x86 cs)
Boot mode: Normal

Running processes:
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Lenka\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: 34.195.153.94 469ba60d9681f961064c-3cca6631dac1b4997db921c060b712f6.r30.cf2.rackcdn.com
O1 - Hosts: 34.195.153.94 a.bf-ad.net
O1 - Hosts: 34.195.153.94 a.visualrevenue.com
O1 - Hosts: 34.195.153.94 a1.vdna-assets.com
O1 - Hosts: 34.195.153.94 a248.e.akamai.net
O1 - Hosts: 34.195.153.94 aax.amazon-adsystem.com
O1 - Hosts: 34.195.153.94 ad.crwdcntrl.net
O1 - Hosts: 34.195.153.94 ad.mail.ru
O1 - Hosts: 34.195.153.94 ade.clmbtech.com
O1 - Hosts: 34.195.153.94 ads.adfox.ru
O1 - Hosts: 34.195.153.94 ads.pubmatic.com
O1 - Hosts: 34.195.153.94 apis.google.com
O1 - Hosts: 34.195.153.94 asset.pagefair.net
O1 - Hosts: 34.195.153.94 assets.adobedtm.com
O1 - Hosts: 34.195.153.94 assets.flocktory.com
O1 - Hosts: 34.195.153.94 autocontext.begun.ru
O1 - Hosts: 34.195.153.94 b.grvcdn.com
O1 - Hosts: 34.195.153.94 b.ns1p.net
O1 - Hosts: 34.195.153.94 b.scorecardresearch.com
O1 - Hosts: 34.195.153.94 b.wal.co
O1 - Hosts: 34.195.153.94 babator-stg-cdn.babator.com
O1 - Hosts: 34.195.153.94 beacon.krxd.net
O1 - Hosts: 34.195.153.94 beacon.walmart.com
O1 - Hosts: 34.195.153.94 c.amazon-adsystem.com
O1 - Hosts: 34.195.153.94 c.vepxl1.net
O1 - Hosts: 34.195.153.94 c2.taboola.com
O1 - Hosts: 34.195.153.94 cdn.3lift.com
O1 - Hosts: 34.195.153.94 cdn.admixer.net
O1 - Hosts: 34.195.153.94 cdn.brcdn.com
O1 - Hosts: 34.195.153.94 cdn.cxense.com
O1 - Hosts: 34.195.153.94 cdn.interactivemedia.ne
O1 - Hosts: 34.195.153.94 cdn.krxd.net
O1 - Hosts: 34.195.153.94 cdn.lenmit.com
O1 - Hosts: 34.195.153.94 cdn.livefyre.com
O1 - Hosts: 34.195.153.94 cdn.m-pathy.com
O1 - Hosts: 34.195.153.94 cdn.mathjax.org
O1 - Hosts: 34.195.153.94 cdn.mxpnl.com
O1 - Hosts: 34.195.153.94 cdn.onthe.io
O1 - Hosts: 34.195.153.94 cdn.optimizely.com
O1 - Hosts: 34.195.153.94 cdn.prom.st
O1 - Hosts: 34.195.153.94 cdn.pushwoosh.com
O1 - Hosts: 34.195.153.94 cdn.scarabresearch.com
O1 - Hosts: 34.195.153.94 cdn.taboola.com
O1 - Hosts: 34.195.153.94 cdn.taplytics.com
O1 - Hosts: 34.195.153.94 cdn.tt.omtrdc.net
O1 - Hosts: 34.195.153.94 cdn.unid.go.com
O1 - Hosts: 34.195.153.94 cdn1.graphiq.com
O1 - Hosts: 34.195.153.94 cdn3.optimizely.com
O1 - Hosts: 34.195.153.94 cdnjs.cloudflare.com
O1 - Hosts: 34.195.153.94 cdnssl.clicktale.net
O1 - Hosts: 34.195.153.94 comet.yahoo.com
O1 - Hosts: 34.195.153.94 consent.truste.com
O1 - Hosts: 34.195.153.94 content.adriver.ru
O1 - Hosts: 34.195.153.94 contextual.media.net
O1 - Hosts: 34.195.153.94 cstatic.weborama.fr
O1 - Hosts: 34.195.153.94 d134l0cdryxgwa.cloudfront.net
O1 - Hosts: 34.195.153.94 d2oh4tlt9mrke9.cloudfront.net
O1 - Hosts: 34.195.153.94 dpm.demdex.net
O1 - Hosts: 34.195.153.94 e.monetate.net
O1 - Hosts: 34.195.153.94 edge.quantserve.com
O1 - Hosts: 34.195.153.94 edx-uk.s3ae.com
O1 - Hosts: 34.195.153.94 eu-services.babator.com
O1 - Hosts: 34.195.153.94 fc.yahoo.com
O1 - Hosts: 34.195.153.94 gaua.hit.gemius.pl
O1 - Hosts: 34.195.153.94 gde-default.hit.gemius.pl
O1 - Hosts: 34.195.153.94 go.flx1.com
O1 - Hosts: 34.195.153.94 googleadservices.com
O1 - Hosts: 34.195.153.94 hpr.outbrain.com
O1 - Hosts: 34.195.153.94 i.cricketcb.com
O1 - Hosts: 34.195.153.94 i.tfag.de
O1 - Hosts: 34.195.153.94 ib.adnxs.com
O1 - Hosts: 34.195.153.94 imagesrv.adition.com
O1 - Hosts: 34.195.153.94 img.imgsmail.ru
O1 - Hosts: 34.195.153.94 img7.auto.ria.com
O1 - Hosts: 34.195.153.94 j.ophan.co.uk
O1 - Hosts: 34.195.153.94 js-agent.newrelic.com
O1 - Hosts: 34.195.153.94 js-sec.indexww.com
O1 - Hosts: 34.195.153.94 js.revsci.net
O1 - Hosts: 34.195.153.94 js.ui-portal.de
O1 - Hosts: 34.195.153.94 kamradamnaradost.ru
O1 - Hosts: 34.195.153.94 kpmediagaua.hit.gemius.pl
O1 - Hosts: 34.195.153.94 level1cdn.com
O1 - Hosts: 34.195.153.94 mc.yandex.ru
O1 - Hosts: 34.195.153.94 ml314.com
O1 - Hosts: 34.195.153.94 mtrx.go.sonobi.com
O1 - Hosts: 34.195.153.94 ninja.onap.io
O1 - Hosts: 34.195.153.94 o.aolcdn.com
O1 - Hosts: 34.195.153.94 odb.outbrain.com
O1 - Hosts: 34.195.153.94 ok-bar.love.mail.ru
O1 - Hosts: 34.195.153.94 ok-portal.mail.ru
O1 - Hosts: 34.195.153.94 optimize-stats.voxmedia.com
O1 - Hosts: 34.195.153.94 p.d.0fmm.com
O1 - Hosts: 34.195.153.94 p.t-online.de
O1 - Hosts: 34.195.153.94 pagead2.googlesyndication.com
O1 - Hosts: 34.195.153.94 peermapcontent.affino.com
O1 - Hosts: 34.195.153.94 pixel.vihub.ru
O1 - Hosts: 34.195.153.94 psma02.com
O1 - Hosts: 34.195.153.94 px.adhigh.net
O1 - Hosts: 34.195.153.94 qs.ioam.de
O1 - Hosts: 34.195.153.94 qsc.ec.quoracdn.net
O1 - Hosts: 34.195.153.94 rma-api.gravity.com
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Lenka\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Lenka\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATII4E.EXE /EPT "EPLTarget\P0000000000000000" /M "L355 Series"
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Lenka\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Lenka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [PCSpeedUp] C:\Program Files (x86)\Zrychleni Pocitace\PCSUNotifier.exe
O4 - HKUS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01192017175002223\..\Run: [] (User '?')
O4 - HKUS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01192017175015919\..\Run: [] (User '?')
O4 - HKUS\S-1-5-21-4127594241-2057818473-933541542-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01192017175005046\..\Run: [OneDrive] "C:\Users\Lenka\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background (User '?')
O4 - HKUS\S-1-5-21-4127594241-2057818473-933541542-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01192017175005046\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Lenka\AppData\Roaming\Seznam.cz\szninstall.exe" -c (User '?')
O4 - HKUS\S-1-5-21-4127594241-2057818473-933541542-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01192017175005046\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Lenka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q (User '?')
O4 - HKUS\S-1-5-21-4127594241-2057818473-933541542-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01192017175005046\..\Run: [PCSpeedUp] C:\Program Files (x86)\Zrychleni Pocitace\PCSUNotifier.exe (User '?')
O4 - HKUS\S-1-5-21-4127594241-2057818473-933541542-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01192017175020072\..\Run: [OneDrive] "C:\Users\Lenka\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background (User '?')
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: MalwarebytesAntiMalwareMcAfee - Unknown owner - rundll32.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: UC??????? (UCBrowserSvc) - Unknown owner - C:\Program Files (x86)\UCBrowser\Application\UCService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 15077 bytes

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119672
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím kontrola logu

#2 Příspěvek od Rudy »

Zdravím!
Dejte log FRST: http://forum.viry.cz/viewtopic.php?f=13&t=133100 . HijackThis je už za zenitem.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět