Re: Pravděpodobná infiltrace
Napsal: 15 úno 2019 19:29
Tak snad jsem provedla správně - vkládám výsledný log z FRST:
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-758666899-2211297156-3181642844-1002 -> DefaultScope {6537C524-DDDB-4964-B1C7-A9C977A0B269} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-758666899-2211297156-3181642844-1002 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-758666899-2211297156-3181642844-1002 -> {6537C524-DDDB-4964-B1C7-A9C977A0B269} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-758666899-2211297156-3181642844-1002 -> {D6E2E2A4-33B1-417A-9FC6-B24993BE4800} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_37180
Handler: WSKVAllmytubechrome - No CLSID Value �
CHR HKU\S-1-5-21-758666899-2211297156-3181642844-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - hxxp://clients2.google.com/service/update2/crx
U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
EmptyTemp:
End
*****************
Restore point was successfully created.
Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully.
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
"HKU\S-1-5-21-758666899-2211297156-3181642844-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully.
HKU\S-1-5-21-758666899-2211297156-3181642844-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} => removed successfully.
HKLM\Software\Classes\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => not found
HKU\S-1-5-21-758666899-2211297156-3181642844-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6537C524-DDDB-4964-B1C7-A9C977A0B269} => removed successfully.
HKLM\Software\Classes\CLSID\{6537C524-DDDB-4964-B1C7-A9C977A0B269} => not found
HKU\S-1-5-21-758666899-2211297156-3181642844-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D6E2E2A4-33B1-417A-9FC6-B24993BE4800} => removed successfully.
HKLM\Software\Classes\CLSID\{D6E2E2A4-33B1-417A-9FC6-B24993BE4800} => not found
HKLM\Software\Classes\PROTOCOLS\Handler\WSKVAllmytubechrome => removed successfully.
HKU\S-1-5-21-758666899-2211297156-3181642844-1002\SOFTWARE\Google\Chrome\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo => removed successfully.
HKLM\System\CurrentControlSet\Services\AppMgmt => removed successfully.
AppMgmt => service removed successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 4135251 B
Java, Flash, Steam htmlcache => 1155 B
Windows/system/drivers => 0 B
Edge => 0 B
Chrome => 0 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 0 B
LocalService => 0 B
NetworkService => 0 B
Žeryk => 5323580 B
RecycleBin => 0 B
EmptyTemp: => 17 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 19:16:38 ====
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-758666899-2211297156-3181642844-1002 -> DefaultScope {6537C524-DDDB-4964-B1C7-A9C977A0B269} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-758666899-2211297156-3181642844-1002 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-758666899-2211297156-3181642844-1002 -> {6537C524-DDDB-4964-B1C7-A9C977A0B269} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-758666899-2211297156-3181642844-1002 -> {D6E2E2A4-33B1-417A-9FC6-B24993BE4800} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_37180
Handler: WSKVAllmytubechrome - No CLSID Value �
CHR HKU\S-1-5-21-758666899-2211297156-3181642844-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - hxxp://clients2.google.com/service/update2/crx
U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
EmptyTemp:
End
*****************
Restore point was successfully created.
Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully.
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
"HKU\S-1-5-21-758666899-2211297156-3181642844-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully.
HKU\S-1-5-21-758666899-2211297156-3181642844-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} => removed successfully.
HKLM\Software\Classes\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => not found
HKU\S-1-5-21-758666899-2211297156-3181642844-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6537C524-DDDB-4964-B1C7-A9C977A0B269} => removed successfully.
HKLM\Software\Classes\CLSID\{6537C524-DDDB-4964-B1C7-A9C977A0B269} => not found
HKU\S-1-5-21-758666899-2211297156-3181642844-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D6E2E2A4-33B1-417A-9FC6-B24993BE4800} => removed successfully.
HKLM\Software\Classes\CLSID\{D6E2E2A4-33B1-417A-9FC6-B24993BE4800} => not found
HKLM\Software\Classes\PROTOCOLS\Handler\WSKVAllmytubechrome => removed successfully.
HKU\S-1-5-21-758666899-2211297156-3181642844-1002\SOFTWARE\Google\Chrome\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo => removed successfully.
HKLM\System\CurrentControlSet\Services\AppMgmt => removed successfully.
AppMgmt => service removed successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 4135251 B
Java, Flash, Steam htmlcache => 1155 B
Windows/system/drivers => 0 B
Edge => 0 B
Chrome => 0 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 0 B
LocalService => 0 B
NetworkService => 0 B
Žeryk => 5323580 B
RecycleBin => 0 B
EmptyTemp: => 17 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 19:16:38 ====