Stránka 1 z 2

při spuštění firefox naskakují 2 blokované odkazy

Napsal: 11 zář 2017 20:16
od šimi
info.txt logfile of random's system information tool 1.10 2017-09-11 20:55:02

======MBR======

0x33C08ED0BC007C8EC08ED8BE007CBF0006B90002FCF3A450681C06CBFBB90400BDBE07807E00007C0B0F850E0183C510E2F1CD1888560055C6461105C6461000B441BBAA55CD135D720F81FB55AA7509F7C101007403FE46106660807E1000742666680000000066FF760868000068007C680100681000B4428A56008BF4CD139F83C4109EEB14B80102BB007C8A56008A76018A4E028A6E03CD136661731CFE4E11750C807E00800F848A00B280EB845532E48A5600CD135DEB9E813EFE7D55AA756EFF7600E88D007517FAB0D1E664E88300B0DFE660E87C00B0FFE664E87500FBB800BBCD1A6623C0753B6681FB54435041753281F90201722C666807BB00006668000200006668080000006653665366556668000000006668007C0000666168000007CD1A5A32F6EA007C0000CD18A0B707EB08A0B607EB03A0B50732E40500078BF0AC3C007409BB0700B40ECD10EBF2F4EBFD2BC9E464EB002402E0F82402C3496E76616C696420706172746974696F6E207461626C65004572726F72206C6F6164696E67206F7065726174696E672073797374656D004D697373696E67206F7065726174696E672073797374656D000000637B9A14624A2900000020210007DF130C000800000020030080DF140C07FEFFFF00280300BB21722700FEFFFF27FEFFFF0050752700D01A0000FEFFFF07FEFFFF002890270030E04C55AA

======Uninstall list======

-->"C:\Program Files (x86)\Canon\Easy-WebPrint EX\uninst.exe" /UninstallRemove C:\Program Files (x86)\Canon\Easy-WebPrint EX\uninst.ini
Adobe Flash Player 26 NPAPI-->C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_26_0_0_151_Plugin.exe -maintain plugin
Adobe Reader XI (11.0.22) - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-AB0000000001}
Adobe Refresh Manager-->MsiExec.exe /I{AC76BA86-0804-1033-1959-001824237067}
AMD Catalyst Install Manager-->msiexec /q/x{5094145C-9F17-8099-7F4F-E5AADD5E4065} REBOOT=ReallySuppress
BS.Player PRO-->"C:\Program Files (x86)\Webteh\BSplayerPro\uninstall.exe"
Canon Easy-PhotoPrint EX-->C:\Program Files\Canon\Easy-PhotoPrint EX\uninst.exe Uninst.ini uinstrsc.dll
Canon Easy-WebPrint EX-->"C:\Program Files (x86)\Canon\Easy-WebPrint EX\uninst.exe" /UninstallRemove C:\Program Files (x86)\Canon\Easy-WebPrint EX\uninst.ini
Canon IJ Network Scanner Selector EX-->"C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSU.exe" /UninstallRemove C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\uninst.ini
Canon IJ Network Tool-->C:\Program Files (x86)\Canon\Canon IJ Network Tool\CNMNUU.exe
Canon MG3100 series MP Drivers-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3100_series\DELDRV64.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3100_series /L0x0005
Canon MG3100 series On-screen Manual-->C:\Program Files (x86)\Canon\IJ Manual\Canon MG3100 series\uninstall.exe
Canon MP Navigator EX 5.0-->"C:\Program Files (x86)\Canon\MP Navigator EX 5.0\Maint.exe" /UninstallRemove C:\Program Files (x86)\Canon\MP Navigator EX 5.0\uninst.ini
Canon My Image Garden Design Files-->"C:\Program Files (x86)\Canon\My Image Garden\AddOn\uninst.exe" /UninstallRemove C:\Program Files (x86)\Canon\My Image Garden\AddOn\uninst.ini
Canon My Image Garden-->"C:\Program Files (x86)\Canon\My Image Garden\uninst.exe" /UninstallRemove C:\Program Files (x86)\Canon\My Image Garden\uninst.ini
Canon My Printer-->"C:\Program Files\Canon\MyPrinter\uninst.exe" /UninstallRemove C:\Program Files\Canon\MyPrinter\uninst.ini
Canon Quick Menu-->"C:\Program Files (x86)\Canon\Quick Menu\uninst.exe" /UninstallRemove C:\Program Files (x86)\Canon\Quick Menu\uninst.ini
Catalyst Control Center - Branding-->MsiExec.exe /I{B820A5C2-0DD4-A49C-BC86-59E3B476D8CC}
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
DAEMON Tools Lite-->C:\Program Files\DAEMON Tools Lite\uninst.exe
DisplayLink Graphics Driver-->MsiExec.exe /X{9A3C0ADE-9A32-4C80-A527-38072609B9EE}
ESET Smart Security-->MsiExec.exe /I{E483B847-824D-4659-A760-0AC8FE24055E}
Farming Simulator 17-->"E:\hry\Farming Simulator 2017\unins000.exe"
FastShare.cz verze 2.3.1-->"C:\Program Files (x86)\FastShare\unins000.exe"
HP 3D DriveGuard-->MsiExec.exe /X{F8FEE05E-1CE4-4F52-8463-630A81DABD6A}
HP Client Security Manager-->C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\setup.exe
HP Client Security Manager-->MsiExec.exe /X{214E6139-6853-4144-AEEB-212C922159E9}
HP Hotkey Support-->MsiExec.exe /X{6E7401DB-B722-4428-BE94-DD4740CF6464}
HP Port Replicator Software Installer-->"C:\Program Files (x86)\InstallShield Installation Information\{6313BCDF-1109-4682-A19D-413189817787}\setup.exe" -runfromtemp -l0x0405 -removeonly
HP SoftPaq Download Manager-->MsiExec.exe /I{BB51845C-10A6-457F-A215-9B2D3E130889}
HP Universal Camera Driver-->"C:\Program Files (x86)\HP Universal Camera Driver\uninstall.exe"
HP Wireless Button Driver-->MsiExec.exe /X{099DAD2B-56C5-4919-9F82-418C2A018CAE}
LibreOffice 5.3.3.2-->MsiExec.exe /I{DB76C19A-1E2A-4A8F-9AB7-3FC315EC57C7}
Mass Effect™: Andromeda-->"C:\Program Files\Common Files\EAInstaller\Mass Effect Andromeda\Cleanup.exe" uninstall_game -autologging
Mediatek Bluetooth-->MsiExec.exe /X{3D986C98-83E6-78D1-97F3-0BF6D4484602}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022-->MsiExec.exe /X{350AA351-21FA-3270-8B7A-835434E766AD}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17-->MsiExec.exe /X{8220EEFE-38CD-377E-8595-13398D740ACE}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161-->MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219-->MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030-->"C:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe" /uninstall
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030-->"C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030-->MsiExec.exe /X{37B8F9C7-03FB-3253-8781-2517C99D7C00}
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030-->MsiExec.exe /X{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030-->MsiExec.exe /X{B175520C-86A2-35A7-8619-86DC379688B9}
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030-->MsiExec.exe /X{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501-->"C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe" /uninstall
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501-->"C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005-->MsiExec.exe /X{929FBD26-9020-399B-9A7A-751D61F0B942}
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005-->MsiExec.exe /X{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005-->MsiExec.exe /X{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005-->MsiExec.exe /X{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215-->"C:\ProgramData\Package Cache\{d992c12e-cab2-426f-bde3-fb8c53950b0d}\VC_redist.x64.exe" /uninstall
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212-->"C:\ProgramData\Package Cache\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}\VC_redist.x86.exe" /uninstall
Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.24215-->MsiExec.exe /X{EF1EC6A9-17DE-3DA9-B040-686A1E8A8B04}
Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.24215-->MsiExec.exe /X{50A2BC33-C9CD-3BF1-A8FF-53C10A0B183C}
Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24212-->MsiExec.exe /X{844ECB74-9B63-3D5C-958C-30BD23F19EE4}
Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24212-->MsiExec.exe /X{37B55901-995A-3650-80B1-BBFD047E2911}
Mozilla Firefox 55.0.3 (x64 cs)-->"C:\Program Files\Mozilla Firefox\uninstall\helper.exe"
OpenShot Video Editor verze 2.3.4-->"C:\Program Files\OpenShot Video Editor\unins000.exe"
Polda 6 verze 1.1-->"E:\hry\Polda 6\unins000.exe"
Ralink RT3290 802.11bgn Wi-Fi Adapter-->"C:\Program Files (x86)\InstallShield Installation Information\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}\Setup.exe" -runfromtemp -l0x0405 -removeonly
Realtek Card Reader-->"C:\Program Files (x86)\InstallShield Installation Information\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}\setup.exe" -runfromtemp -removeonly
Smart Defrag 5-->"C:\Program Files (x86)\IObit\Smart Defrag\unins000.exe"
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Synaptics WBF Fingerprint Reader-->MsiExec.exe /X{B0CB33D8-1426-4D61-A4F6-BDFD7407AE92}
TeamViewer 12-->"C:\Program Files (x86)\TeamViewer\uninstall.exe"
Total Commander 64-bit (Remove or Repair)-->c:\totalcmd\tcunin64.exe
Ulož.to FileManager verze 2.25-->"C:\Program Files (x86)\Ulozto File Manager\unins000.exe"
WinRAR 5.40 (64-bit)-->C:\Program Files\WinRAR\uninstall.exe

======Hosts File======

127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 distribution.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 linkmate.space
127.0.0.1 space1.adminpressure.space
127.0.0.1 trackpressure.website
127.0.0.1 doctorlink.space
127.0.0.1 plugpackdownload.net
127.0.0.1 texttotalk.org

======System event log======

Computer Name: DESKTOP-SC61Q7B
Event Code: 27
Message: Typ spuštění byl 0x0.
Record Number: 5
Source Name: Microsoft-Windows-Kernel-Boot
Time Written: 20170519175941.232588-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: DESKTOP-SC61Q7B
Event Code: 153
Message: Zabezpečení založené na virtualizaci (zásady: 0) je zakázáno.
Record Number: 4
Source Name: Microsoft-Windows-Kernel-Boot
Time Written: 20170519175941.232184-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: DESKTOP-SC61Q7B
Event Code: 6005
Message: Služba Event Log byla spuštěna.
Record Number: 3
Source Name: EventLog
Time Written: 20170519180112.408609-000
Event Type: Informace
User:

Computer Name: DESKTOP-SC61Q7B
Event Code: 6009
Message: Microsoft (R) Windows (R) 10.00. 15063 Multiprocessor Free.
Record Number: 2
Source Name: EventLog
Time Written: 20170519180112.408609-000
Event Type: Informace
User:

Computer Name: DESKTOP-SC61Q7B
Event Code: 12
Message: Operační systém se spustil v systémovém čase ‎2017‎-‎05‎-‎19T17:59:40.498915800Z.
Record Number: 1
Source Name: Microsoft-Windows-Kernel-General
Time Written: 20170519175941.232075-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

=====Application event log=====

Computer Name: DESKTOP-SC61Q7B
Event Code: 5617
Message: Subsystémy služby WMI (Windows Management Instrumentation) byly úspěšně inicializovány.
Record Number: 5
Source Name: Microsoft-Windows-WMI
Time Written: 20170519180222.644872-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: DESKTOP-SC61Q7B
Event Code: 5615
Message: Služba WMI (Windows Management Instrumentation) byla úspěšně spuštěna.
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20170519180120.014539-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: DESKTOP-SC61Q7B
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.


Record Number: 3
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20170519180113.128409-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: DESKTOP-SC61Q7B
Event Code: 4097
Message: Úspěšná automatická aktualizace kořenového certifikátu jiného výrobce: Subjekt: <CN=GlobalSign Root CA, OU=Root CA, O=GlobalSign nv-sa, C=BE> Kryptografický otisk SHA1: <B1BC968BD4F49D622AA89A81F2150152A41D829C>.
Record Number: 2
Source Name: Microsoft-Windows-CAPI2
Time Written: 20170519180106.486724-000
Event Type: Informace
User:

Computer Name: DESKTOP-SC61Q7B
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20170519180112.658543-000
Event Type: Informace
User:

=====Security event log=====

Computer Name: DESKTOP-SC61Q7B
Event Code: 4907
Message: Nastavení auditu objektu se změnila.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: DESKTOP-SC61Q7B$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7

Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Boot\hu-HU\memtest.exe.mui
ID popisovače: 0x2ec

Informace o procesu:
ID procesu: 0x884
Název procesu: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.410_none_9e914f9d2d85dacb\TiWorker.exe

Nastavení auditu:
Původní popisovač zabezpečení: S:AINO_ACCESS_CONTROL
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 72865
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20170811190837.162947-000
Event Type: Úspěšný audit
User:

Computer Name: DESKTOP-SC61Q7B
Event Code: 4907
Message: Nastavení auditu objektu se změnila.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: DESKTOP-SC61Q7B$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7

Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Boot\hu-HU\bootmgr.exe.mui
ID popisovače: 0x2ec

Informace o procesu:
ID procesu: 0x884
Název procesu: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.410_none_9e914f9d2d85dacb\TiWorker.exe

Nastavení auditu:
Původní popisovač zabezpečení: S:AINO_ACCESS_CONTROL
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 72864
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20170811190837.153767-000
Event Type: Úspěšný audit
User:

Computer Name: DESKTOP-SC61Q7B
Event Code: 4907
Message: Nastavení auditu objektu se změnila.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: DESKTOP-SC61Q7B$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7

Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Boot\hr-HR\bootmgr.exe.mui
ID popisovače: 0x2ec

Informace o procesu:
ID procesu: 0x884
Název procesu: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.410_none_9e914f9d2d85dacb\TiWorker.exe

Nastavení auditu:
Původní popisovač zabezpečení: S:AINO_ACCESS_CONTROL
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 72863
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20170811190837.140337-000
Event Type: Úspěšný audit
User:

Computer Name: DESKTOP-SC61Q7B
Event Code: 4907
Message: Nastavení auditu objektu se změnila.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: DESKTOP-SC61Q7B$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7

Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Boot\fr-FR\memtest.exe.mui
ID popisovače: 0x2ec

Informace o procesu:
ID procesu: 0x884
Název procesu: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.410_none_9e914f9d2d85dacb\TiWorker.exe

Nastavení auditu:
Původní popisovač zabezpečení: S:AINO_ACCESS_CONTROL
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 72862
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20170811190837.127842-000
Event Type: Úspěšný audit
User:

Computer Name: DESKTOP-SC61Q7B
Event Code: 4907
Message: Nastavení auditu objektu se změnila.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: DESKTOP-SC61Q7B$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7

Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Boot\fr-FR\bootmgr.exe.mui
ID popisovače: 0x2ec

Informace o procesu:
ID procesu: 0x884
Název procesu: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.410_none_9e914f9d2d85dacb\TiWorker.exe

Nastavení auditu:
Původní popisovač zabezpečení: S:AINO_ACCESS_CONTROL
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 72861
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20170811190837.120081-000
Event Type: Úspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"OS"=Windows_NT
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"PSModulePath"=%ProgramFiles%\WindowsPowerShell\Modules;%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=21
"PROCESSOR_IDENTIFIER"=AMD64 Family 21 Model 16 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=1001
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\AMD\ATI.ACE\Core-Static
"PTSMINSTALLPATH_X86"=C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\

-----------------EOF-----------------

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 11 zář 2017 21:02
od Rudy

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 12 zář 2017 16:29
od šimi
omlouvám se. spletl jsem se.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-09-2017 02
Ran by Šimečci (administrator) on DESKTOP-SC61Q7B (12-09-2017 17:25:19)
Running from C:\Users\Šimečci\Desktop
Loaded Profiles: Šimečci (Available Profiles: defaultuser0 & Šimečci)
Platform: Windows 10 Pro Version 1703 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(HP) C:\Windows\System32\hpservice.exe
() C:\Windows\System32\fpCSEvtSvc.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Synaptics Incorporated) C:\Windows\System32\valWBFPolicyService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpCardEngine.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag\SmartDefrag.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpAgent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(Wargaming.net) E:\hry\Warship\WargamingGameUpdater.exe
() C:\Users\Šimečci\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Šimečci\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(HP) C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [DisplayLinkUI] => C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe [2136296 2016-10-21] (DisplayLink Corp.)
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [127528 2015-06-29] (Hewlett-Packard Company)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [338000 2015-06-22] (Hewlett-Packard Company)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1314432 2016-06-09] (CANON INC.)
HKLM-x32\...\Run: [HPRadioMgr] => C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe [324488 2016-08-02] (HP)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9292504 2016-12-21] (Piriform Ltd)
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4701888 2016-12-22] (Disc Soft Ltd)
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\Run: [World of Warships] => E:\hry\Warship\WargamingGameUpdater.exe [3136264 2017-08-07] (Wargaming.net)
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Šimečci\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Šimečci\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\MountPoints2: {8569abb3-dfe6-11e6-bde8-806e6f6e6963} - "J:\LaunchU3.exe" -a
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\MountPoints2: {8569abbb-dfe6-11e6-bde8-806e6f6e6963} - "F:\autorun.exe"
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\MountPoints2: {8ea19c4a-722c-11e7-be61-a45d36c94384} - "K:\Startme.exe"
Lsa: [Notification Packages] DPPassFilter scecli
BootExecute: autocheck autochk * SmartDefragBootTime.exe
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.254 8.8.8.8 192.168.1.1
Tcpip\..\Interfaces\{2569023d-3921-4b5d-adab-dbd8facca736}: [DhcpNameServer] 192.168.2.254 8.8.8.8 192.168.1.1
Tcpip\..\Interfaces\{4196abea-d05c-4bad-8e7d-eb5042bf3585}: [DhcpNameServer] 192.168.2.254 8.8.8.8 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/?clid=13415
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)

FireFox:
========
FF DefaultProfile: jyb080aa.default
FF ProfilePath: C:\Users\Šimečci\AppData\Roaming\Mozilla\Firefox\Profiles\jyb080aa.default [2017-09-12]
FF user.js: detected! => C:\Users\Šimečci\AppData\Roaming\Mozilla\Firefox\Profiles\jyb080aa.default\user.js [2017-07-12]
FF Homepage: Mozilla\Firefox\Profiles\jyb080aa.default -> hxxps://www.google.cz/
FF Extension: (Seznam lištička) - C:\Users\Šimečci\AppData\Roaming\Mozilla\Firefox\Profiles\jyb080aa.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2017-09-03]
FF HKLM-x32\...\Firefox\Extensions: [dpmaxz_ng@jetpack] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome
FF Extension: (HP Client Security Manager) - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome [2017-01-22] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_26_0_0_151.dll [2017-08-11] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-11] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2016-04-14] (CANON INC.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-08-18] (Adobe Systems Inc.)
FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\components\npChromeDPAgent.dll [2015-09-28] (DigitalPersona, Inc.)

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome.crx [2015-09-28]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-19] (Advanced Micro Devices, Inc.) [File not signed]
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1471168 2016-12-22] (Disc Soft Ltd)
R2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [502232 2015-09-28] (DigitalPersona, Inc.)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2836296 2016-12-14] (ESET)
R2 fpCsEvtSvc; C:\WINDOWS\system32\fpCSEvtSvc.exe [22528 2017-03-16] ()
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [684624 2015-06-22] (Hewlett-Packard Company)
R2 hpsrv; C:\WINDOWS\system32\Hpservice.exe [38728 2016-10-12] (HP)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-20] (Microsoft Corporation)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [255584 2017-08-19] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10884848 2017-05-23] (TeamViewer GmbH)
R2 valWBFPolicyService; C:\WINDOWS\system32\valWBFPolicyService.exe [82944 2017-03-16] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 Accelerometer; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [56128 2016-10-12] (HP)
R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [91400 2015-10-08] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-07-21] (Advanced Micro Devices)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2017-01-22] (Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2017-01-22] (Disc Soft Ltd)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [132272 2016-12-13] (ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [106768 2016-12-13] (ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15488 2016-12-13] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [180544 2016-12-13] (ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [49672 2016-12-13] (ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [77616 2016-12-13] (ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [96856 2016-12-13] (ESET)
S3 ESETCleanersDriver; C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys [181160 2017-08-19] (ESET)
S3 gHidPnp; C:\WINDOWS\System32\Drivers\gHidPnp.Sys [25600 2011-10-26] () [File not signed]
S3 gMouUsb; C:\WINDOWS\System32\drivers\gMouUsb.sys [14336 2009-11-02] () [File not signed]
R0 hpdskflt; C:\WINDOWS\System32\DRIVERS\hpdskflt.sys [42312 2016-10-12] (HP)
R3 HpqKbFiltr; C:\WINDOWS\System32\drivers\HpqKbFiltr64.sys [37112 2015-06-17] (Hewlett-Packard Company)
S3 ioFakDrv; C:\WINDOWS\System32\drivers\ioFakDrv.sys [35928 2016-11-26] (KYE System Corp.)
S3 ioFakMap; C:\WINDOWS\System32\drivers\ioFakMap.sys [24664 2016-11-26] (KYE System Corp.)
R3 netr28x; C:\WINDOWS\System32\drivers\netr28x.sys [2537984 2017-03-18] (MediaTek Inc.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-03-18] (Realtek )
R3 rtbth; C:\WINDOWS\System32\drivers\rtbth.sys [1219200 2015-06-02] (Ralink Technology, Corp.)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
R0 SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [21360 2016-03-22] (IObit)
R3 SPUVCbv; C:\WINDOWS\System32\Drivers\SPUVCbv64.sys [1063520 2017-02-23] (Sunplus Innovation Technology Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\system32\DRIVERS\WirelessButtonDriver64.sys [32832 2016-07-31] (HP)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-09-12 17:25 - 2017-09-12 17:26 - 000014726 _____ C:\Users\Šimečci\Desktop\FRST.txt
2017-09-12 17:23 - 2017-09-12 17:25 - 000000000 ____D C:\FRST
2017-09-12 17:23 - 2017-09-12 17:23 - 002397184 _____ (Farbar) C:\Users\Šimečci\Desktop\FRST64.exe
2017-09-12 17:20 - 2017-09-12 17:20 - 000000000 ___HD C:\OneDriveTemp
2017-09-11 20:54 - 2017-09-11 20:55 - 000000000 ____D C:\rsit
2017-09-11 20:54 - 2017-09-11 20:54 - 001222144 _____ C:\Users\Šimečci\Desktop\RSITx64.exe
2017-09-11 20:54 - 2017-09-11 20:54 - 000000000 ____D C:\Program Files\trend micro
2017-09-11 19:10 - 2017-09-11 19:10 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2017-09-02 10:36 - 2017-09-02 10:36 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2017-08-26 23:15 - 2017-08-26 23:19 - 046918104 _____ C:\Users\Šimečci\Nepojmenovaný projekt.mp4
2017-08-25 20:31 - 2017-08-25 20:50 - 830892805 _____ C:\Users\Šimečci\Desktop\Reklama-pennyHD.rar
2017-08-25 08:46 - 2017-08-27 00:08 - 000000000 ____D C:\Users\Šimečci\.openshot_qt
2017-08-25 08:46 - 2017-08-25 08:46 - 000000944 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenShot Video Editor.lnk
2017-08-25 08:46 - 2017-08-25 08:46 - 000000932 _____ C:\Users\Public\Desktop\OpenShot Video Editor.lnk
2017-08-25 08:44 - 2017-08-25 08:46 - 000000000 ____D C:\Program Files\OpenShot Video Editor
2017-08-24 21:43 - 2017-08-24 21:43 - 000000000 ____D C:\Users\Šimečci\AppData\Local\ElevatedDiagnostics
2017-08-23 21:20 - 2017-08-23 21:20 - 000000000 ____D C:\ProgramData\InterVideo
2017-08-23 20:34 - 2017-08-25 08:45 - 000000000 ____D C:\Users\Šimečci\Documents\Corel VideoStudio Pro
2017-08-23 20:33 - 2017-08-23 20:34 - 000000000 ____D C:\ProgramData\Protexis64
2017-08-23 20:24 - 2017-08-23 20:24 - 000000110 _____ C:\WINDOWS\wininit.ini
2017-08-23 20:16 - 2008-10-15 06:22 - 005631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
2017-08-23 20:16 - 2008-10-15 06:22 - 004379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
2017-08-23 20:16 - 2008-10-15 06:22 - 002605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
2017-08-23 20:16 - 2008-10-15 06:22 - 002036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
2017-08-23 20:16 - 2008-10-15 06:22 - 000519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
2017-08-23 20:16 - 2008-10-15 06:22 - 000452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
2017-08-23 20:07 - 2017-08-25 08:50 - 000000000 ____D C:\Program Files (x86)\Corel
2017-08-20 12:12 - 2017-08-20 12:12 - 000000000 ____D C:\Users\Šimečci\AppData\Local\AdvinstAnalytics
2017-08-19 10:21 - 2017-08-19 10:21 - 000253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\0C402F3E.sys
2017-08-19 09:57 - 2017-08-19 10:21 - 000000000 ____D C:\AdwCleaner
2017-08-19 02:01 - 2017-08-19 02:01 - 000277600 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynTPAPI.dll
2017-08-19 02:01 - 2017-08-19 02:01 - 000066144 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\SynRMIHID_Aux.sys
2017-08-19 02:00 - 2017-08-19 02:00 - 000778848 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynCOM.dll
2017-08-19 02:00 - 2017-08-19 02:00 - 000429144 _____ (Synaptics Incorporated) C:\WINDOWS\SysWOW64\SynCom.dll
2017-08-19 02:00 - 2017-08-19 02:00 - 000051288 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\Smb_driver_Intel_Aux.sys
2017-08-19 02:00 - 2017-08-19 02:00 - 000050784 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\Smb_driver_AMDASF_Aux.sys
2017-08-19 00:56 - 2017-08-19 00:56 - 000001804 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Моzillа Firеfох.lnk
2017-08-19 00:46 - 2017-08-19 00:46 - 000181160 _____ (ESET) C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys
2017-08-19 00:12 - 2017-08-27 00:09 - 000000000 ____D C:\Program Files\Mozilla Firefox
2017-08-18 21:34 - 2017-08-18 21:34 - 000000000 ____D C:\Program Files (x86)\Seznam.cz
2017-08-18 21:33 - 2017-09-12 17:23 - 000000000 ____D C:\Users\Šimečci\AppData\Roaming\Seznam.cz
2017-08-18 21:33 - 2017-08-19 09:47 - 000000000 ____D C:\Program Files (x86)\ShutdownTime
2017-08-18 21:33 - 2017-08-18 21:40 - 000000000 ____D C:\Users\Šimečci\AppData\Roaming\jgqtinal4lj
2017-08-18 21:33 - 2017-08-18 21:33 - 000001658 _____ C:\Users\Šimečci\AppData\Roaming\TCREBJP.exe.config
2017-08-18 21:33 - 2017-08-18 21:33 - 000001658 _____ C:\Users\Šimečci\AppData\Roaming\AT2NRZA.exe.config
2017-08-18 21:33 - 2017-08-18 21:33 - 000000000 ____D C:\Program Files\94FQZBTE50
2017-08-17 17:43 - 2017-08-18 21:41 - 000000000 ____D C:\Users\Šimečci\AppData\Roaming\BitTorrent
2017-08-17 17:12 - 2017-08-17 17:12 - 000000000 ____D C:\Users\Šimečci\.fontconfig
2017-08-17 17:11 - 2017-08-20 12:35 - 000000000 ____D C:\Users\Šimečci\AppData\Local\Movavi
2017-08-17 17:11 - 2017-08-17 17:11 - 000000000 ____D C:\Users\Šimečci\AppData\Local\converter
2017-08-17 17:10 - 2017-08-17 17:10 - 000005108 _____ C:\ProgramData\mudtcpaz.vzs
2017-08-17 17:10 - 2017-08-17 17:10 - 000000016 _____ C:\ProgramData\mntemp
2017-08-17 17:10 - 2017-08-17 17:10 - 000000000 ____D C:\ProgramData\Movavi Video Converter 17
2017-08-17 17:10 - 2017-08-17 17:10 - 000000000 ____D C:\ProgramData\Movavi
2017-08-13 13:25 - 2017-08-13 14:19 - 1678892450 _____ C:\Users\Šimečci\Desktop\Balerína-CZ.SK.avi

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-09-12 17:26 - 2017-03-18 23:03 - 000000000 ___HD C:\Program Files\WindowsApps
2017-09-12 17:26 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-09-12 17:20 - 2017-01-21 17:06 - 000000000 ____D C:\Users\Šimečci\AppData\LocalLow\Mozilla
2017-09-12 17:20 - 2017-01-21 16:47 - 000000000 ___RD C:\Users\Šimečci\OneDrive
2017-09-12 17:17 - 2017-05-19 20:19 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-09-12 17:17 - 2017-05-19 20:04 - 000000000 ____D C:\Users\Šimečci
2017-09-12 17:17 - 2017-05-19 20:03 - 000000000 ____D C:\ProgramData\Synaptics
2017-09-11 21:24 - 2017-03-18 13:40 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2017-09-11 21:24 - 2017-01-21 18:12 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2017-09-11 20:45 - 2017-02-27 21:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Polda 6
2017-09-11 20:45 - 2017-01-22 16:40 - 000000000 ____D C:\Users\Šimečci\Documents\Ulozto
2017-09-11 20:26 - 2017-05-19 20:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-09-10 18:32 - 2017-03-18 23:01 - 000000000 ____D C:\WINDOWS\INF
2017-09-07 20:20 - 2017-05-23 22:11 - 000000000 ____D C:\ProgramData\ProductData
2017-09-03 11:19 - 2017-01-21 16:44 - 000000000 ____D C:\Users\Šimečci\AppData\Local\Packages
2017-08-26 23:37 - 2017-08-12 22:24 - 000000000 ____D C:\Users\Šimečci\Desktop\reklama penny
2017-08-25 20:08 - 2017-05-19 20:00 - 000474152 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-08-24 16:05 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2017-08-23 20:41 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-08-23 20:15 - 2017-01-22 11:45 - 000000000 ____D C:\ProgramData\Package Cache
2017-08-23 20:05 - 2017-05-19 20:21 - 002186950 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-08-23 20:05 - 2017-03-20 06:39 - 000964750 _____ C:\WINDOWS\system32\perfh005.dat
2017-08-23 20:05 - 2017-03-20 06:39 - 000213438 _____ C:\WINDOWS\system32\perfc005.dat
2017-08-20 22:03 - 2017-01-22 16:40 - 000001098 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ulož.to FileManager.lnk
2017-08-20 22:03 - 2017-01-22 16:40 - 000000000 ____D C:\Program Files (x86)\Ulozto File Manager
2017-08-19 02:01 - 2016-08-22 16:00 - 000639584 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\SynTP.sys
2017-08-19 02:01 - 2016-08-22 16:00 - 000290400 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynTPCo35-02.dll
2017-08-19 02:01 - 2012-08-27 15:03 - 001804688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01011.dll
2017-08-19 00:40 - 2017-01-21 18:21 - 000000000 ____D C:\Users\Šimečci\AppData\Local\ESET
2017-08-13 21:34 - 2017-08-12 21:45 - 000000000 ____D C:\Program Files (x86)\RADVideo
2017-08-13 14:42 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\rescache

==================== Files in the root of some directories =======

2017-08-18 21:33 - 2017-08-18 21:33 - 000001658 _____ () C:\Users\Šimečci\AppData\Roaming\AT2NRZA.exe.config
2017-08-18 21:33 - 2017-08-18 21:33 - 000001658 _____ () C:\Users\Šimečci\AppData\Roaming\TCREBJP.exe.config
2017-08-17 17:10 - 2017-08-17 17:10 - 000000016 _____ () C:\ProgramData\mntemp
2017-08-17 17:10 - 2017-08-17 17:10 - 000005108 _____ () C:\ProgramData\mudtcpaz.vzs

Files to move or delete:
====================
C:\Users\Šimečci\xobglu16.dll
C:\Users\Šimečci\xobglu32.dll


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-09-03 13:26

==================== End of FRST.txt ============================

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 12 zář 2017 17:52
od Rudy
Nyní spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 12 zář 2017 19:23
od šimi
spustil jsem scan,pote cleaner, restartoval se počítač, spustil scan a tady je výsledek logu

# AdwCleaner 7.0.2.1 - Logfile created on Tue Sep 12 18:21:22 2017
# Updated on 2017/29/08 by Malwarebytes
# Database: 09-12-2017.1
# Running on Windows 10 Pro (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries.

*************************

C:/AdwCleaner/AdwCleaner[C0].txt - [1614 B] - [2017/8/19 8:21:2]
C:/AdwCleaner/AdwCleaner[C1].txt - [1340 B] - [2017/9/12 18:9:20]
C:/AdwCleaner/AdwCleaner[S0].txt - [1541 B] - [2017/8/19 8:2:2]
C:/AdwCleaner/AdwCleaner[S1].txt - [1187 B] - [2017/9/12 18:7:43]
C:/AdwCleaner/AdwCleaner[S2].txt - [1209 B] - [2017/9/12 18:17:1]


########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt ##########

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 12 zář 2017 19:42
od Rudy
Toto je OK. Otevřte poznámkový blok a zkopírujte do něj:
Start
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\MountPoints2: {8569abb3-dfe6-11e6-bde8-806e6f6e6963} - "J:\LaunchU3.exe" -a
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\MountPoints2: {8569abbb-dfe6-11e6-bde8-806e6f6e6963} - "F:\autorun.exe"
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\MountPoints2: {8ea19c4a-722c-11e7-be61-a45d36c94384} - "K:\Startme.exe"
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
C:\WINDOWS\LastGood.Tmp
C:\Program Files\94FQZBTE50
C:\Users\Šimečci\AppData\Roaming\TCREBJP.exe.config
C:\Users\Šimečci\AppData\Roaming\AT2NRZA.exe.config
C:\ProgramData\mudtcpaz.vzs
C:\Users\Šimečci\xobglu16.dll
C:\Users\Šimečci\xobglu32.dll

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 12 zář 2017 19:55
od šimi
uložil jsem fix a spustil fix. Počítač se restartoval a tyto data se natáhly do souboru fix:

Fix result of Farbar Recovery Scan Tool (x64) Version: 11-09-2017 02
Ran by Šimečci (12-09-2017 20:44:48) Run:1
Running from C:\Users\Šimečci\Desktop
Loaded Profiles: Šimečci (Available Profiles: defaultuser0 & Šimečci)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\MountPoints2: {8569abb3-dfe6-11e6-bde8-806e6f6e6963} - "J:\LaunchU3.exe" -a
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\MountPoints2: {8569abbb-dfe6-11e6-bde8-806e6f6e6963} - "F:\autorun.exe"
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\...\MountPoints2: {8ea19c4a-722c-11e7-be61-a45d36c94384} - "K:\Startme.exe"
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
C:\WINDOWS\LastGood.Tmp
C:\Program Files\94FQZBTE50
C:\Users\�ime�ci\AppData\Roaming\TCREBJP.exe.config
C:\Users\�ime�ci\AppData\Roaming\AT2NRZA.exe.config
C:\ProgramData\mudtcpaz.vzs
C:\Users\�ime�ci\xobglu16.dll
C:\Users\�ime�ci\xobglu32.dll

EmptyTemp:
End
*****************

HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8569abb3-dfe6-11e6-bde8-806e6f6e6963} => key removed successfully
HKLM\Software\Classes\CLSID\{8569abb3-dfe6-11e6-bde8-806e6f6e6963} => key not found.
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8569abbb-dfe6-11e6-bde8-806e6f6e6963} => key removed successfully
HKLM\Software\Classes\CLSID\{8569abbb-dfe6-11e6-bde8-806e6f6e6963} => key not found.
HKU\S-1-5-21-2279006181-2028104904-2554600194-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8ea19c4a-722c-11e7-be61-a45d36c94384} => key removed successfully
HKLM\Software\Classes\CLSID\{8ea19c4a-722c-11e7-be61-a45d36c94384} => key not found.
HKLM\SOFTWARE\Policies\Google => key removed successfully
"C:\WINDOWS\LastGood.Tmp" => not found.
C:\Program Files\94FQZBTE50 => moved successfully
C:\Users\Šimečci\AppData\Roaming\TCREBJP.exe.config => moved successfully
C:\Users\Šimečci\AppData\Roaming\AT2NRZA.exe.config => moved successfully
C:\ProgramData\mudtcpaz.vzs => moved successfully
C:\Users\Šimečci\xobglu16.dll => moved successfully
C:\Users\Šimečci\xobglu32.dll => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 7888896 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 33723495 B
Java, Flash, Steam htmlcache => 506 B
Windows/system/drivers => 5594 B
Edge => 505 B
Chrome => 0 B
Firefox => 384719356 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 4082 B
NetworkService => 0 B
defaultuser0 => 7168 B
Šimečci => 224553936 B

RecycleBin => 459086769 B
EmptyTemp: => 1 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 20:45:31 ====

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 12 zář 2017 20:57
od Rudy
Smazáno. Nastala nějaká změna?

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 13 zář 2017 21:15
od šimi
Bouhžel beze změny

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 14 zář 2017 16:04
od Rudy
Vyčistíme prohlížeče. Spusťte postupně tyto utility:

1. Stahnete Zoek.exe http://download.bleepingcomputer.com/smeenk/zoek.exe a ulozte jej na plochu

Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
Do okna vlozte skript nize




autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;




Nasledne kliknete na Run Script
PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem.

a

2. Junkware removal tool: http://thisisudax.org/downloads/JRT.exe
•Ulozte nejlepe na plochu
•Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
•Probehne vytvoreni zalohy a nasledne prohledavani
•Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte.

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 15 zář 2017 21:12
od šimi
Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by ćimeźci on 15.09.2017 at 21:41:26,27.
Microsoft Windows 10 Pro 10.0.15063 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\IMECI~1\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

15.09.2017 21:43:04 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\Program Files\HP USB Port Replicator deleted successfully
C:\PROGRA~3\Canon IJ Network Tool deleted successfully
C:\PROGRA~3\CanonEPP deleted successfully
C:\PROGRA~3\CanonIJEPPEX2 deleted successfully
C:\PROGRA~3\Comms deleted successfully
C:\PROGRA~3\SoftwareDistribution deleted successfully
C:\PROGRA~3\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705} deleted successfully
C:\Users\defaultuser0\AppData\LocalLow deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\LocalLow deleted successfully
C:\Users\defaultuser0\AppData\Local\VirtualStore deleted successfully
C:\Users\IMECI~1\AppData\Local\ConnectedDevicesPlatform deleted successfully
C:\Users\IMECI~1\AppData\Local\DBG deleted successfully
C:\Users\IMECI~1\AppData\Local\GHISLER deleted successfully
C:\Users\IMECI~1\AppData\Local\PeerDistRepub deleted successfully
C:\Users\IMECI~1\AppData\Local\VirtualStore deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\PeerDistPub deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\PeerDistRepub deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\IMECI~1\AppData\Roaming\Mozilla\Firefox\Profiles\jyb080aa.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.cz/");

Added to C:\Users\IMECI~1\AppData\Roaming\Mozilla\Firefox\Profiles\jyb080aa.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\PROGRA~3\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705} not found
C:\PROGRA~2\HP Port Replicator Software Installer deleted
C:\PROGRA~2\HP Universal Camera Driver deleted
C:\PROGRA~3\ProductData deleted
C:\PROGRA~3\Package Cache deleted
C:\WINDOWS\wininit.ini deleted
"C:\ProgramData\mntemp" deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\IMECI~1\AppData\Roaming\Mozilla\Firefox\Profiles\jyb080aa.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"dpmaxz_ng@jetpack"="C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome" [22.01.2017 12:55]

==== Firefox Extensions ======================

ProfilePath: C:\Users\IMECI~1\AppData\Roaming\Mozilla\Firefox\Profiles\jyb080aa.default
- Undetermined - C:\Users\Šimečci\AppData\Roaming\Mozilla\Firefox\Profiles\jyb080aa.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}

AppDir: C:\Program Files\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

==== Firefox Plugins ======================


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
ncffjdbbodifgldkcbhmiiljfcnbgjab - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome.crx[28.09.2015 13:47]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/?clid=13415"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/?clid=13415"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"

==== Reset Google Chrome ======================

Nothing found to reset

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\IMECI~1\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\IMECI~1\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\IMECI~1\AppData\Local\Mozilla\Firefox\Profiles\jyb080aa.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=98 folders=46 92133879 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\IMECI~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 15.09.2017 at 22:09:44,90 ======================

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 15 zář 2017 21:18
od šimi
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Pro x64
Ran by ćimeźci (Administrator) on 15.09.2017 at 22:13:35,69
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 3

Successfully deleted: C:\ProgramData\productdata (Folder)
Successfully deleted: C:\Users\ćimeźci\AppData\Roaming\Mozilla\Firefox\Profiles\jyb080aa.default\user.js (File)
Successfully deleted: C:\WINDOWS\system32\Tasks\SmartDefrag_Startup (Task)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.09.2017 at 22:16:23,14
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 16 zář 2017 17:35
od Rudy
Utility něco smazaly. Zmenilo se něco k lepšímu?

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 17 zář 2017 11:04
od šimi
bouhžel vše je při starém. Nepomohlo by kdybych udělal sreen shot odkazů a vložil je sem?

Re: při spuštění firefox naskakují 2 blokované odkazy

Napsal: 17 zář 2017 11:19
od Rudy
FF zkusíme přeinstalovat. FF zazálohujte pomocí Mozbackup: http://www.stahuj.centrum.cz/utility_a_ ... mozbackup/ . Pak FF kompletně odinstalujte, vč. jeho profilu (podadresáře Mozilla v c:\users\ćimeźci\appdata\local, c:\users\ćimeźci\appdata\roaming, c:\users\ćimeźci\data aplikací, c:\users\ćimeźci\local settings a v c:\program data musí být smazány). Pak uděláte novou, čistou instalaci FF a zpět ze zálohy nakopírujete pouze hesla a záložky.