Plné a zároveń prázdné SSD log prosím o kontrolu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Plné a zároveń prázdné SSD log prosím o kontrolu

Příspěvekod Orcus » 30 čer 2015 18:59

Stáhni
Zoek.exe

a ulož si ho na plochu.
Zavři všechny ostatní programy, okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor, náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


Klikni na Run Script
Program provede sken, opravu, sken i oprava může trvat i více minut, je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů, jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

====================================================

Co problémy? + nový log z HJT

+ koukni přes spacemonger - http://www.slunecnice.cz/sw/spacemonger/ - co tam zabírá nejvíc místa.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Reklama
Uživatelský avatar
AdamProGaming
Level 3.5
Level 3.5
Příspěvky: 988
Registrován: červenec 14
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Plné a zároveń prázdné SSD log prosím o kontrolu

Příspěvekod AdamProGaming » 30 čer 2015 21:03

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Administratot on Łt 30. 06. 2015 at 20:47:35,07.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Administratot\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

30. 6. 2015 20:50:03 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\Origin Games deleted successfully
C:\PROGRA~3\LumaEmu_SteamCloud deleted successfully
C:\PROGRA~3\Unity deleted successfully
C:\Users\Administratot\AppData\Roaming\Publish Providers deleted successfully
C:\Users\Administratot\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\Administratot\AppData\Local\EmieSiteList deleted successfully
C:\Users\Administratot\AppData\Local\EmieUserList deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~2\Origin Games not found
C:\Users\Administratot\AppData\Roaming\.technic deleted
C:\found.000 deleted
C:\found.001 deleted
C:\found.004 deleted
C:\found.005 deleted
C:\PROGRA~3\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Windows\wininit.ini deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Users\Administratot\Desktop\4K Video Downloader.lnk deleted
C:\Users\Administratot\AppData\Roaming\Switchbotv3.exe deleted
"C:\Users\Administratot\AppData\Local\LumaEmu" deleted
"C:\Users\Administratot\AppData\Roaming\chrtmp" deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.0.2.17\coFFPlgn" [02. 01. 2015 13:39]

==== Chromium Look ======================

Google Chrome Version: 43.0.2357.130

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
cjabmdjcfcfdmffimndhafhblfmpjdpe - C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\Exts\Chrome.crx[05. 12. 2014 15:11]
iikflkcanblccfahdhdonehdalibjnif - No path found[]

TastyPlug - Administratot\AppData\Local\Google\Chrome\User Data\Default\Extensions\faccgibalfdoihmenknhpfhldkmgaang
Norton Identity Safe - Administratot\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif

==== Chromium Startpages ======================

C:\Users\Administratot\AppData\Local\Google\Chrome\User Data\Default\Preferences
Tg7E+h8gw9b30HI4Rk5O5sBpDuGlc=":1},"version":1}},"https://www.facebook.com:443,*":{"last_used":{"media-stream-mic":1429703965.489884},"media-stream-mic":1},"https://www.superparba.eu:443,https://www.superparba.eu:443":{"ssl-cert-decisions":{"cert_exceptions_map":{"4294967096DFGeMFNeisx8nv7+Rqne9sqO7B63AIaPQ6SrD0fCdnQ=":1},"guid":"7FB46954-122B-493C-9D1E-73C743C77546","version":1}}},"pref_version":1},"created_by_version":"41.0.2272.101","exit_type":"Crashed","exited_cleanly":true,"gaia_info_picture_url":"https://lh3.googleusercontent.com/-XdUIqdMkCWA/AAAAAAAAAAI/AAAAAAAAAAA/4252rscbv5M/s256-c/photo.jpg","gaia_info_update_time":"13080079477130368","icon_version":3,"managed_user_id":"","managed_users":{},"migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"PrvnĂ­ uĹľivatel","per_host_zoom_levels":{}},"protection":{"macs":{}},"reverse_autologin":{"enabled":false},"savefile":{"default_directory":"C:\\Users\\Administratot\\Desktop","type":1},"selectfile":{"last_directory":"G:\\CANON_SC\\DOCUMENT\\0001"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13071601294441058"},"signin":{"signedin_time":"13080079476157516"},"spellcheck":{"dictionary":"cs"},"sync":{"app_list":true,"app_settings":true,"apps":true,"autofill":true,"autofill_profile":true,"autofill_wallet":true,"bookmarks":true,"dictionary":true,"extension_settings":true,"extensions":true,"favicon_images":true,"favicon_tracking":true,"first_sync_time":"13072271422507629","has_setup_completed":true,"history_delete_directives":true,"keystore_encryption_bootstrap_token":"AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAq82hph/GeE6VWlsHHPgVHwAAAAACAAAAAAAQZgAAAAEAACAAAAAAyAzcJzUnDyV6+T6TaPwv9RD+jg+0U4+TPbrcRNqCGAAAAAAOgAAAAAIAACAAAAAJjX+HpTibYIr7eofwRscZFN6/LFCbQUaFoDOMyPMlJlAAAADu0lRcLISuwJeY3s1L+E9ArPkJ9MzNkDk41aIo7pN1Nc5aoX97qwKbLk4MI6DWWYV8/O5xf4zcj2nQsNbta6OodHDXa3pAPmNtJ4XPLBphWkAAAAABtdMOAOrSh1fqp3oLbVRR2x2nsDLJay8zi7oQ8xSJS44TtFc3ru/UT6+50UkVaNTndK6UgII3E6NFK10eWBkk","last_synced_time":"13080121311503846","managed_user_settings":true,"managed_user_shared_settings":true,"managed_user_whitelists":true,"managed_users":true,"passwords":true,"preferences":true,"priority_preferences":true,"search_engines":true,"session_sync_guid":"session_syncmoCZblAZNZQYh3f2s4Sjkg==","sessions":true,"suppress_start":false,"tabs":true,"themes":true,"typed_urls":true},"translate_accepted_count":{"de":1,"en":15,"it":0,"pl":0,"ru":1,"sk":0},"translate_blocked_languages":["cs"],"translate_denied_count":{"de":0,"en":0,"it":3,"pl":1,"ru":0,"sk":2},"translate_last_denied_time":1427131418822.434,"translate_site_blacklist":["java.com"],"translate_too_often_denied":true,"translate_whitelists":{},"zerosuggest":{"cachedresults":""}}
prove":true,"scopes":["https://www.googleapis.com/auth/googlenow"]},"optional_permissions":["background"],"permissions":["alarms","identity","metricsPrivate","notifications","pushMessaging","storage","tabs","webstorePrivate","*://*.google.com/*","*://*.gstatic.com/*","https://*.googleapis.com/chromenow/v1/*","https://*.googleusercontent.com/*"],"version":"1.2.0.1"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.101\\resources\\google_now","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":false,"was_installed_by_oem":false},"pjkljhegncpnkpknbcohdijeoejaedia":{"ack_external":true}}},"google":{"services":{"last_username":"adamprogaming@gmail.com","username":"adamprogaming@gmail.com"}},"homepage":"http://www.google.cz/","homepage_is_newtabpage":false,"pinned_tabs":[],"protection":{"macs":{"browser":{"show_home_button":"BED6EC25DC53132AD9262FEF0DB3FE50CFCA097EBF9AFA9B1CEF8593FC34055E"},"default_search_provider":{"keyword":"CE153904644170F331A9D65B3C3F6EC35223177670F9A9C565EEA8E53A182B98","name":"A4955BA2BF1E03A901A33AFD5247C313F05D4DADB22A9AD59940390F4E1FE480","search_url":"ED4054E85204C16901D919D716C5782C35D5AA937361F016347C853F9222767B"},"default_search_provider_data":{"template_url_data":"E57A4D96E225222E5BB45422A09A20E1F75263532FC38061F6FCFA41BD41C40C"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":"635C7BCF0012BFF4F08043A58CC4DA154374845DF28556906FE8C2E37326961D","aohghmighlieiainnegkcijnfilokake":"A25BBBF7842FDAD63B4DA3F1806E80A05A9ECBB93507C3522C8700F7468B33E5","apdfllckaahabafndbhieahigkjlhalf":"8837C84CC4C00371498ED77086CD52EFE811361082CC470AF452A5A3B8C90AF0","bepbmhgboaologfdajaanbcjmnhjmhfn":"F2E43BAE63E4F9E24DF125D3DFCD536E4B83EE219BD5FAD08744CA2A1B06EA80","blpcfgokakmgnkcojhhkbfbldkacnbeo":"D4DA9CCD84089F25E1D793956682719C69A877D3D5526D6A7E1BD808B0CA818B","coobgpohoikkiipiblmjeljniedjpjpf":"1F68822C0C5009EA2A1CEE7E6067831C3D9420EEB59296D709C87FDBD5964608","eemcgdkfndhakfknompkggombfjjjeno":"29F06C515A2A3110026A4872DF7657DCA2478155EA8C9985D907F9870FFA23CC","ennkphjdgehloodpbhlhldgbnhmacadg":"0B6B4763146DCBFC466242772E6F23BDFF5130B8F574688BC0757660869E0D67","faccgibalfdoihmenknhpfhldkmgaang":"B85D158CEA6A12AA3EDDBDAE2881208841280878DA8E1CB90096629D638F7B91","gfdkimpbcpahaombhbimeihdjnejgicl":"240A534ED514075514B7CFCEDB4D747A7882F8D1A65E4929755CD6E5E6C1926F","iikflkcanblccfahdhdonehdalibjnif":"0A4532411E326F925B610CB8389A14BAA5C9342D84A3120CBDC344CE5118782B","kmendfapggjehodndflmmgagdbamhnfd":"38284A21536FAAD567DCFE4AEAFC59DA39D29A873EC6AF393BC2856949CAA142","mfehgcgbbipciphmccgaenjidiccnmng":"0D2E6660D37427CFB8D3708D347A73021D9E82751D0A3A04EDEDAA99526D02FC","mfffpogegjflfpflabcdkioaeobkgjik":"0EC38ABC345BAA0F7534740B31B1949636EE12BAB4CE02FBB633C17AB319F5D9","mgndgikekgjfcpckkfioiadnlibdjbkf":"C91935E6C573693CF87AC900D827A3F98FE392F3A6CCCDACA9A9A5CCE4084314","mhjfbmdgcfjbbpaeojofohoefgiehjai":"849EF4C994C55A19BE4F4C5B190F2F3400D7556C59A39677E8CED259AC2B2C26","neajdppkdcdipfabeoofebfddakdcjhd":"F8807844DBF55ADF4678071707946FB1261BE6906FD796E572BCCEB143BC78A1","nkeimhogjdpnpccoofpliimaahmaaome":"3016B42330817B8C3C50E6A5BA95D9EDCB0AF1996D7DCB1F74525D106FE8D5D8","nmmhkkegccagdldgiimedpiccmgmieda":"47298DAE47D7901DB1BC10BF5A0C9497D4F4CAFA0798817E8A60FE313B06DC9A","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"857757FB4E4B2BB392B9CD6AF7BAD428749627D9BAD33A716E4462591FD81D0F","pjkljhegncpnkpknbcohdijeoejaedia":"7B1357EDF35B4621227DE8F1447A4FD5CFF973025EEA808DBCFD290645F49380"}},"google":{"services":{"last_username":"140690D02EE507817FA675033B23F19DB9587A6137C7C355E2AE48E36B787B96","username":"4759F973EC163837101CFEB7DA97A54ED98A3E138A73CB4878B3D963AEED90F9"}},"homepage":"66EB1B134945E426EB584BD527131150C3D0EA519DB048521E218072F1E780D1","homepage_is_newtabpage":"89FA2CD72612790335F4C21877FC632E761BB089F6BB05EB410F1209F5246C29","pinned_tabs":"71D3491DCBB32BE18937BCC01BE1BA0088B283DC9BBA8E5B52923E21E229CA94","prefs":{"preference_reset_time":"480E583C995A43280B7ABEE1ECBF8AEF79DA7C5095B5780A94C77670F19BED41"},"profile":{"reset_prompt_memento":"E8331018D0E933A8296DB8D38B3A7EAB0EDEDBC9AC45C63395A81A080E6D066E"},"safebrowsing":{"incidents_sent":"6F5A80E192DDF7DD689835BC81E475C5E9D01A742D3694AD6960FF9B47305193"},"search_provider_overrides":"63B335B68C44AAB978DA0ED1EEBEDABA2F3B24D2F12B887DE8BE4086EBA7CE73","session":{"restore_on_startup":"6079DB66EFC47D5A126B85B07C916A700D95EBEEB9C442D3EF887D3FD3BE2BD1","startup_urls":"D0C8C8BBD12A78FBEF87F398DF74A2B427914862BA8E1AC8CFB44010FE2A6CBA"},"software_reporter":{"prompt_reason":"A6B6AFB59114BFB012BA471992529981C1E3A27ABCD86F06F39C1E5FF6DD101E","prompt_seed":"BB3C5DF8D6C3A688A68AA79A1A45873352CC8E37D4919CE2B305E4C5021C7DA1","prompt_version":"B8A27B14E5AFFF6B71EE6F79D351353AB04126195834240651AFEB71B839364B"},"sync":{"remaining_rollback_tries":"A948B84F5E646CAFB9EC28A1DE569C8B3A3CAB1C9F713921CB81CFE38060E9CD"}},"super_mac":"650D1B4A554AD56B353BC95BC186CA1EBA0684FBB39C1BA610120EF399BB6EEF"},"session":{"restore_on_startup":4,"startup_urls":["http://www.google.cz/","http://www.youtube.com/","http://www.seznam.cz/"]},"sync":{"remaining_rollback_tries":0}}


==== Chromium Fix ======================

C:\Users\Administratot\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully
C:\Users\Administratot\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\Administratot\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Administratot\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Administratot\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Administratot\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Administratot\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Administratot\AppData\Local\Microsoft\Windows\INetCache\IE\3AVLD4YQ will be deleted at reboot
C:\Users\Administratot\AppData\Local\Microsoft\Windows\INetCache\IE\TRGZDHCO will be deleted at reboot
C:\Users\Administratot\AppData\Local\Microsoft\Windows\INetCache\IE\WZH8AH1Y will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\Administratot\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=525 folders=711 3384812401 bytes)

==== Empty Temp Folders ======================

C:\Users\Administratot\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\ADMINI~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Administratot\AppData\Local\Microsoft\Windows\INetCache\IE\3AVLD4YQ" not found
"C:\Users\Administratot\AppData\Local\Microsoft\Windows\INetCache\IE\TRGZDHCO" not found
"C:\Users\Administratot\AppData\Local\Microsoft\Windows\INetCache\IE\WZH8AH1Y" not found

==== EOF on Łt 30. 06. 2015 at 21:02:52,77 ======================
My Steam Profile (from SteamDB)


  • Worth: $1069 ($308 with sales)
  • Games owned: 86
  • Games played: 57 (66%)
  • Hours on record: 5,245.0h

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Plné a zároveń prázdné SSD log prosím o kontrolu

Příspěvekod jaro3 » 30 čer 2015 21:56

C:\System Volume Information
kolik tam máš ?

Vlož nový log z HJT

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 51 hostů