Gloyah nejde zastavit

Sekce věnovaná virům a jiným škodlivým kódům, rovněž ale nástrojům, kterým se lze proti nim bránit…

Moderátoři: Mods_senior, Security team

overlord48
nováček
Příspěvky: 26
Registrován: leden 16
Pohlaví: Muž
Stav:
Offline

Re: Gloyah nejde zastavit

Příspěvekod overlord48 » 12 črc 2019 13:00

Fix result of Farbar Recovery Scan Tool (x64) Version: 10-07-2019
Ran by acer (12-07-2019 12:49:58) Run:1
Running from C:\Users\acer\Desktop
Loaded Profiles: acer (Available Profiles: acer)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\acer\AppData\Roaming\Seznam.cz\szninstall.exe [1069296 2018-03-27] (Seznam.cz, a.s. -> )
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\acer\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [109808 2018-03-27] (Seznam.cz, a.s. -> )
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\...\MountPoints2: {010a4381-27b1-11e8-82e8-f8a963e3c09d} - "E:\Startme.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2018-07-17] () [File not signed]
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {A9860504-4D5B-4AB5-9BFF-6153C2B0A553} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-05] (Google Inc -> Google Inc.)
Task: {BCE8E201-2DBA-4F18-AE34-8CA926B3CAE9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-05] (Google Inc -> Google Inc.)
SearchScopes: HKU\S-1-5-21-2847046601-3309215626-2780992325-1001 -> {82D3FCE6-8CBE-4E3E-8EB3-D7DC0F409534} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_12454
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
CHR NewTab: Default -> Active:"chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/speeddial/newTab.html"
CHR HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bgjpfhpjcgdppjbgnpnjllokbmcdllig] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [olfeabkoenfaoljndfecamgilllcpiak] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
S3 cpuz139; \??\C:\Users\acer\AppData\Local\Temp\cpuz139\cpuz139_x64.sys [X] <==== ATTENTION
C:\Users\acer\AppData\Local\{BC26B681-C5EF-45F0-AB6C-8B77C621F924}
C:\Users\acer\AppData\Local\{B2396E2A-5BB0-4E68-B2F7-1EC1643F34C9}
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File

EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.
"HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate" => removed successfully
"HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop" => removed successfully
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{010a4381-27b1-11e8-82e8-f8a963e3c09d} => removed successfully
HKLM\Software\Classes\CLSID\{010a4381-27b1-11e8-82e8-f8a963e3c09d} => not found
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat => moved successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A9860504-4D5B-4AB5-9BFF-6153C2B0A553}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9860504-4D5B-4AB5-9BFF-6153C2B0A553}" => removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BCE8E201-2DBA-4F18-AE34-8CA926B3CAE9}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BCE8E201-2DBA-4F18-AE34-8CA926B3CAE9}" => removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{82D3FCE6-8CBE-4E3E-8EB3-D7DC0F409534} => removed successfully
HKLM\Software\Classes\CLSID\{82D3FCE6-8CBE-4E3E-8EB3-D7DC0F409534} => not found
"HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN" => not found
C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll => moved successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN" => not found
"C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll" => not found
"HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN" => not found
"C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll" => not found
"HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN" => not found
"C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll" => not found
"Chrome NewTab" => removed successfully
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\SOFTWARE\Google\Chrome\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig => removed successfully
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\SOFTWARE\Google\Chrome\Extensions\olfeabkoenfaoljndfecamgilllcpiak => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki => removed successfully
HKLM\System\CurrentControlSet\Services\cpuz139 => removed successfully
cpuz139 => service removed successfully
C:\Users\acer\AppData\Local\{BC26B681-C5EF-45F0-AB6C-8B77C621F924} => moved successfully
C:\Users\acer\AppData\Local\{B2396E2A-5BB0-4E68-B2F7-1EC1643F34C9} => moved successfully
"C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA" => not found
"C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore" => not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 139323240 B
Java, Flash, Steam htmlcache => 412128834 B
Windows/system/drivers => 35554362 B
Edge => 0 B
Chrome => 444123758 B
Firefox => 38997542 B
Opera => 500770992 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 1065858078 B
systemprofile32 => 134334923 B
LocalService => 45550 B
NetworkService => 0 B
acer => 314008274 B

RecycleBin => 55827310476 B
EmptyTemp: => 54.9 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 12:53:41 ====

Reklama
overlord48
nováček
Příspěvky: 26
Registrován: leden 16
Pohlaví: Muž
Stav:
Offline

Re: Gloyah nejde zastavit

Příspěvekod overlord48 » 12 črc 2019 13:02

Zatím asi dobrý. Po tom restartu se žádné okno neotevřelo.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Gloyah nejde zastavit

Příspěvekod jaro3 » 12 črc 2019 18:44

Ještě to sleduj.

kde je log AdwCleaner ?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “Viry, antiviry, firewally…”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 3 hosti