Kontrola logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

pisky111
nováček
Příspěvky: 17
Registrován: březen 16
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logu

Příspěvekod pisky111 » 17 bře 2016 12:03

Successfully deleted: C:\Users\Starosta\AppData\Local\{9E70FF68-BF91-4CAC-AB57-49E3AC390017} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{9FB54B42-DE6F-4BB4-9E53-043ADAA016DB} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{9FF66D41-52A5-4D1A-9BC2-9EA64A38A711} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A0503F74-EE12-4CD2-BB2C-05D5C0808930} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A0B1BC20-927D-410B-8FB0-8E8FBEB08E6E} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A1083138-D114-4C46-8B69-C8530FE2121C} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A10F27E8-190B-49D5-BC32-842303DBACF9} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A153C2D9-B9B5-473C-B9FE-92840D61A5FA} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A1639F84-8474-4CE6-A45F-D857306B59E9} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A171CA52-1A90-4D94-90CF-3CA9D69F5B44} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A1A7BDFA-01D3-43AD-B110-6F0540A3CD8E} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A1DE62F3-8F02-42BE-AD43-B5C276701C84} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A214AD68-4610-4BD3-9D29-749321AADDDF} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A2526375-0428-4BE9-8301-0993BF3DBE28} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A2CE4188-D023-467E-8526-D5061BBBA5D6} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A2E75440-171F-4555-AF9B-7855B9E3E6C1} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A2EFC1AC-15BF-4DE7-8FE1-29AA8E9D74FD} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A3640DC2-E03C-4144-8390-67A00B8BDD66} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A51537CB-B89E-450B-A74F-A1F7142C6932} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A516A8D7-6CB6-43B6-8A53-C8D6F8D6DA8D} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A5700E41-7143-4B21-93E5-E7F4C8CF3149} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A58DB5F2-7F7E-4B0D-913A-BC4C1001EFAF} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A5DAF035-D8D8-410E-AFAE-857AE08776D2} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A607ED64-5967-41C3-A31F-BA3FCA1186EA} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A67F2D82-DB35-47FC-B301-668A3598E705} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A6B3770F-1F5B-4A2E-81B0-50F5124FC111} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A7811EBA-CCDF-4B86-9673-869D525C0D69} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A9068381-18BC-456E-A91D-F8F9F7D00171} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A92780F8-30E3-4DE4-8208-D2FF835A7C04} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A941ED94-68B4-4BD7-AB70-0855F117C8FF} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A98039F5-C586-49A0-A46A-D29E00C26CF0} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A9C239A0-92DD-4067-AE86-727A5D178EC3} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{A9D07854-786F-499D-9D32-579D60F442BF} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{AA0FE714-6A3E-457A-BE6B-9119997B249C} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{AA164C57-739C-4EA2-9D4B-0D2B9B47886B} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{AAC4D7F2-3F76-4C46-AFD5-389ACA049D29} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{AB61D505-79C3-4A8E-B846-714C4655E7F8} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{ABBC0A30-11D5-456A-B85C-E227E840D3D3} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{ABE432AF-618E-43A3-A8CB-53659B17409D} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{ABFEED63-0FE9-480E-8F62-E5DA8502EB89} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{AC30D1A4-B9DF-487E-8642-A3EF38F4D181} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{ACA3AD00-16CB-45B3-90A9-3B05A5B6D0BC} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{ACD8F6F7-0564-43F4-9F86-998772F23EA9} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{ACF6E29E-56A6-4266-A3C2-AEE2BF28BFFE} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{AD682368-F0D1-4ECD-9520-03C4656C503B} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{AE35DF52-674E-4A31-8B70-E78B18BD9ABC} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{AE560BB7-7EC2-45B7-B865-556491CDE2D5} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{AEE7FBDB-8D0F-4997-BE27-31CDDB0313FC} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{AF10B449-4E1D-4162-B974-DD02D02148F1} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{AFCE72D2-B9A7-461F-AC35-8A29F146F755} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{AFDE64BD-8DCD-4E35-8CCB-39506B6F139F} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B0464546-ECC1-436D-9FE5-CFC20242CA43} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B0B8E751-83A2-4946-9023-5B4648156909} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B19AEFFF-C699-4F4B-AD67-72FD42713B19} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B1BECB41-F012-4765-82E5-3CE255896D38} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B2C1E678-1E8B-44A7-9CE9-D2FE553EC3A3} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B2EBAF5F-DF47-42CE-BCF8-EE6247FD675D} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B310F852-352B-4DAD-8AE1-40C7A0D4A438} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B37BE539-5E43-4E8D-9A1E-4095C60E5BCD} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B50A65FC-33E8-4A87-8ACD-3D19A9CA3141} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B534490C-580D-4AFB-BF51-18DDB90D92B1} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B55CA4DA-3678-49F9-BA8C-E47870589761} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B667EC52-667F-42C9-BC40-2D7A60BF027B} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B69AEAEF-A136-464A-99C2-044FE05E97C3} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B6BC1BE5-9516-4FED-86E7-622C041599EB} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B6DB748A-53F2-4F68-8D9C-AB4EC8D6D685} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B766A651-952B-464D-B60C-385F4D0D6B6A} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B7768322-7C65-4D58-A148-778D4D7EFC94} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B812BA06-C2F6-40E6-9A17-4C6707AC70CD} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B871208C-0F5E-4B63-81EC-DC6136881D8C} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B88C63BC-9A95-4623-A8FA-942BA2092AC9} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B8D89289-1ADE-47E4-AC6E-700860795266} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B932414B-2315-4155-87B0-3010D64F5315} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B980E92A-AB49-46D8-B122-1A383CBC11CA} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B9967C64-6ECB-43A1-8C29-83D81C844213} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B9970932-13E5-4621-A9B1-893B028BD677} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{B9BBAC6A-26E9-4461-8728-101A7487F212} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BA204B51-CFE6-4A10-9B11-3B53F48E4398} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BA2342B9-CDEC-4C94-8363-A47C91FF99FA} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BA620E15-C552-4200-9B60-21208E5B4E2F} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BA6B359E-9A57-4FD6-98FE-EB5593BEDB54} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BA70E0B5-8CD9-4DD8-BC0A-A90E504AE454} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BA86EB96-FAC2-4835-A12E-725F66E91A1F} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BAAA31A4-CFCE-4366-A9C0-8F745213BFC6} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BB4EA13C-56AE-4D21-A2E1-A017BAF64C09} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BB6AA0E8-81A3-449D-9C4C-8655DE0C05B2} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BB854D3B-53C6-4A95-B017-140D173C661F} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BBD0569B-2904-4AAE-858D-040CA6E6341C} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BBFC434C-181D-4F79-9D75-E4CC2C2C1103} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BCCCF1A5-6180-480B-87AF-FAE2873F4857} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BCEC5DA8-4C72-42F2-A098-482B47827124} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BD1D8F29-5295-4C2C-BF94-FBA4B30744B5} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BD32D3BB-30EE-40C6-91B0-AA63D91E045D} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BD51CC3A-DECA-4D5D-A18E-BDA9CCE519F5} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BDF5E3C6-C390-4DC2-86BB-A5BFC658FC09} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BDF66B89-A227-4690-BAF5-F44F4BEE4713} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BE3E5BAB-5467-4AAE-B253-8B5CC9DDD470} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BEA91B79-07A9-41B7-9205-41048EAFF73C} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BEB97C8C-2186-4AFA-A5AE-14CFBD668050} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BEDA8A0F-8B08-4571-BDFE-5D59304CA5B1} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{BF5009D1-E87E-4088-A004-4AADE3A9E035} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C0338CAF-A3CE-4EE1-A271-E1A2977005B7} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C041C6DB-BABD-43E0-AE93-BE688605DA84} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C0BC3AFF-C668-498A-A210-99B3BEEDD6FA} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C0C95E50-8311-4305-AAB4-7E9FC0ED2F40} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C0D25ED3-8D2C-49DC-B87C-19DFE5F9C00C} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C11D95F9-6E29-405B-AD7F-5284DC904D0A} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C17AD893-D7E2-4156-938C-21C3F57825DA} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C17C6541-9265-4189-974F-0AC9D2578893} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C1C98321-0E37-4D32-BB65-73A7DD20A7A8} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C20C647D-4D21-4D2F-A7D5-3930E8B11544} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C228B797-827A-48DA-B8DA-02C4F0B1D662} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C2837DCE-0B33-4D46-8846-F689BF646D7A} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C2BB02A7-42AB-4042-9ED8-5C8F5BA5D304} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C3F9CCCD-699B-4E42-AB12-A5BEC61B8EF0} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C5781A18-B57C-40D1-AC15-FFF7D27A0B3B} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C590D9AF-FC77-4C54-8BE3-111366539E93} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C6ED8BD5-B033-4D81-9A3E-F9E321D54EC5} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C7DDE3C5-A723-453F-8D09-D1A5341000AC} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C81FFC7E-7ACB-47A0-9ACE-405224DFC428} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C82EA650-9D57-484B-864D-9A945E42A23C} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C8488260-F52E-4AB6-B537-75AA9251F38D} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C9D2EDC1-EF78-4704-9C02-97158E52BC98} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{C9E594F3-BECC-41FD-B79C-2F6626674422} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CA2A9A0F-C06C-4A88-883E-0A322E577917} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CAE84749-B839-4751-8999-5E878860D0CE} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CAF1AA23-08A1-4BB9-B672-5841DC88865D} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CB00C223-35C6-4216-8CF1-A60409C1AC24} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CB2FD7E3-20E2-42BB-BF42-115C0A6B5E61} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CC6C216E-CDD4-4695-9F78-A8E082FC83C4} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CC76DC65-B6D5-4077-97B2-DCFE2EF9CB1C} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CD872D07-68A8-483B-95CB-2D1E94353DE8} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CD8D3C89-3847-401F-8F5E-3ED1419AB658} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CDF0D570-33F3-435A-B468-A36BB5CAAD25} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CE156FEC-FE42-4B37-9DF1-CD5C51EC14FB} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CE713ABD-21BC-4868-8059-51025C141B70} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CF8599F2-9505-4342-B9E9-E336825B8D1D} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{CFA500A7-769F-4C7B-B53E-A1BEDB943401} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D07785D6-D6F7-4CFF-AE32-CC68439FAB27} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D0989D09-1496-4FBB-9656-3E31FD8A4F73} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D0C768FB-23D6-4B53-9D98-7F942B52B3F4} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D1210E28-FB6E-4C64-A3D5-4A6BECC012FF} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D1B8A314-2033-46CB-BB1A-50958CE9F758} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D1BCA663-9956-47C6-9B8E-A885412ABC51} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D212003D-E1C6-4D63-AB47-5293C65D1BAD} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D2B96CDA-C0D9-4A35-9BA9-C31AE266D3F6} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D3B4F6C1-0363-4542-BE64-87081F5A6EA7} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D47FE43F-57AC-4EEB-B908-CEDF3154470E} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D53FDF56-8D2B-43EB-B560-755B1E8A18C9} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D576FAC0-C2C9-4AE7-A3DF-9977A9F34865} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D5C5E869-84B9-47DB-8624-535D50F829B0} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D60F049B-253F-4420-9961-430B7F445811} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D617AD5D-9AFC-440C-845A-32EC45A52714} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D634F662-0BDD-4862-A04D-564AE1BED382} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D66AAB8D-31CB-43AD-8824-A97948BDE3D1} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D6730EF6-9E07-4392-8FD5-E136C4C718E9} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D6740BCB-7E34-4E22-9124-16385BAD0D04} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D68AA253-9AEC-4E19-9E5A-C23ECB7D2E57} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D7F1CA37-E8C7-4F0F-BE4E-A1D878CEC5C9} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D853562F-9EAE-42F8-9E34-0E873BD73A97} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D86EB6B6-9CD7-48C0-AA1F-453C57714FA7} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{D99975ED-D325-4590-AAC4-9E390B8D271A} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DA4FF490-A0FC-42AE-8DC7-D4D118085C06} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DACEEB00-7EBE-4AC0-919B-02EDEFE260AB} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DB68B40E-6776-4DBA-9085-71BF24CCF587} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DC19A920-004F-4ED6-B530-F5F1D6E217FC} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DC43546D-26EC-4F13-B363-F863A3A45950} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DCCC4672-0116-4D7E-84C0-C3FB36BDD070} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DCD4C250-34B6-4693-B250-2382A3829DF5} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DD141856-8D67-4664-ADA3-FB6DD50A5DEA} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DD19B238-E694-425F-B360-DDD36ABC5972} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DD1C1186-79FC-4538-ABC5-3E0E2D9082D1} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DD258E51-948D-4F6F-927A-6E7C4E339D00} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DD2FD5BC-57FE-4931-8CDE-67CEA335B4F3} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DD304310-2E8C-432E-A273-42F4AB3F5ED5} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DD6C948C-E0F4-40AA-872E-453105DD3845} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DDAE7393-15EC-44E3-82BC-5FA86924543A} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DDB01D68-F226-4ED3-84A3-261A8F056883} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DE904B3A-FD63-490B-9571-4BBFC3CADEF4} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DEC81411-859C-460B-BC77-C4A0FFF9609C} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DF87F8E0-190E-497C-960F-418FFFE419FE} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{DFCA3A11-769D-4D63-9004-441FFEDBD336} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E04D813F-2485-46BF-80C9-7E4181FB475B} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E1F5E81A-B4CB-4AF1-B195-A9545C87A83D} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E235D4D8-9CFE-47C3-A8BD-30F19D80D37A} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E2411DE6-538C-4F28-86E3-9B5F84243EB6} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E25757AF-17DB-4750-82C5-A547B33852C4} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E26201B1-1952-40AB-B426-16F106CB8EE7} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E2E2922D-3EBF-4EF8-A640-4041DE256AE9} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E3315D1A-E53C-4D62-B7C8-11F1AC416FB1} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E3502EFA-D36E-47AB-9E82-A14B3096EF88} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E3CF7FC8-B209-4E80-BB28-44B7524D0EEC} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E3FE3869-7107-4AD5-B475-A9A78B33272B} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E4767E07-B3A6-4D59-928D-A80141346217} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E513114B-721C-4BE5-891E-C550C3592AAB} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E534058A-581D-464A-86B5-7CA38E766533} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E62279A3-EFA3-4205-AD5D-F50F2775FB43} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E6D0CBDA-2B27-495D-B1A9-E1F6AF4ED89A} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E7E0800A-9C44-41E4-B66D-042D9DEEAC2D} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E8D37C8F-53D5-4E88-B933-1330C6337792} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E9078F0F-1BB4-4C6C-9D90-B69E4BF5AD9F} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E930A051-A683-4350-8BC4-9A198E5AFBF7} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E95350ED-FB52-4D88-87A9-7A030449B0CC} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E9536F5B-A6BB-41DF-8C79-E5FB167B41A2} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E9A2543F-5F51-4F42-B14F-714457B6E69D} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E9BD10F2-59C9-4824-8CD8-F48038134F8D} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{E9C315E5-3340-42B9-9B7A-E0A02FEC4DD6} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{EA781156-8D2B-493D-9716-820D9FB50BD3} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{EA7C681A-A943-4DF4-B64D-BF5421D82DFE} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{EB93153C-2C76-4C09-BFEF-7F0ED7D64106} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{EC97B142-0CDD-489E-8AF5-DABE1233241E} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{ED03C29C-FE87-4F26-A760-2AE5D59D8857} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{ED3FAA05-445A-4A55-9459-D25E19F8F73E} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{ED5EFCC1-7E62-44E1-AAE3-1B8808A955CF} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{ED63B849-AFB5-4CAB-9C9A-EDB65DAE7124} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{ED71A062-1E13-4E2E-9AE2-DEFCEF576116} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{EDE98A26-A0D7-4210-9443-1105BDD7A52F} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{EE9AB32E-E12B-45F4-8372-EAB1C2EF7F0C} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{EEFE8297-8254-4048-A108-F4E9E1412933} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{EF5049B8-A2D7-459E-8564-B026A74FC122} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F031B830-DB8B-4B5A-BA1F-6EFCF3905C46} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F047FB13-2F97-45E0-8F9B-00D8646949FF} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F100C577-9C39-4A75-9DCB-CAC2A77418B7} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F173E146-8A5E-4DA2-AE0F-D0880BFBF9CB} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F17E66B3-2D0C-4681-B7A5-058332EE133B} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F1FEF6C7-43EF-448A-A8DB-A2CF53B47047} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F438E62D-C3AF-42CB-9C45-F8ED49A3540D} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F452C7C2-CC6E-40A2-A2C9-2C45082407CC} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F49EDD4D-438E-48CE-AE50-196E5A5B00C7} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F4A52711-A3E3-4B8D-A514-16357BE3A8DD} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F4DAFC54-A40E-4A9D-8342-3C69ABA6A263} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F52A725B-77F0-4424-8C4F-FE1305709EBE} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F5B14120-523F-4873-A881-4E1C3B68E411} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F6000C75-3DBF-448F-8894-43F2EC14BA38} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F616D71A-E0E0-4CC7-81F5-9E7491D83CD3} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F64BA2E5-BF17-476B-BB32-F635D645FF01} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F6AA3DAE-4AEA-4680-9013-0FFBCB7699A4} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F77E0526-FB30-45F8-ACC3-FD2F5A9D3925} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F79654EC-8ACC-4D0E-9CFB-146D37ECFA47} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F7CC232E-4A7A-441B-A3DA-6C73AE9341CE} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F7DB05C9-11D9-43EF-860C-0AE1DDA75026} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F814B974-1F62-45F6-92CB-0BC759CAD325} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F844D03D-4912-4494-9A32-68EEDEA07AF8} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F8627A4D-CF98-4793-A8E1-5123D78B3FF2} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F87B6C01-ADA3-4A52-8ED0-C2338809C614} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F8B0AC98-ECA6-43F1-AB54-A2ADDEC64CC9} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F8EC4916-8F57-428A-AA81-054690C82725} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F959616D-1B9A-4AD1-A5B5-3168DCB956ED} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F97BD8D3-D3ED-48B8-A785-6289F104EA57} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F97FCEE4-F553-46E8-9EB1-C3472CDC3B5A} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F9A42090-AE7C-445F-980C-909EC77E31C6} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{F9CB6D6E-C52B-4F70-9BC3-8B5B93D497B1} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FA1BC631-4E42-4C18-86B9-663231EBB172} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FA29B2EC-F126-4951-AE18-75C989D23FBE} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FA394C49-0855-4EE5-8F9C-40A71E0D83D9} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FA3AEDB7-D74F-4BBC-B4FC-1222117278E2} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FA505B53-BE97-463F-BCDD-3BF1DA820253} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FA960179-CF74-4592-8A99-902D725E98B2} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FBCEEF7A-7F67-4241-8BB5-40CCC3703499} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FD19262B-258E-4202-8216-2CD3F9C08C2F} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FD34D1BD-D1EC-425B-AF83-F8B7E7B28B52} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FD778665-C3F0-451A-8DC5-BD485EF7A757} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FD841D29-2FE4-4510-904F-F0C71C7A5043} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FD9285FD-E9B6-4BEC-9FA5-FF6ADB4F6BED} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FDAF32A5-62AB-4793-B0A2-C349C80E4CE3} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FDDB41F0-D1DA-4F43-BAA4-1C0E0AAAAE49} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FE1E7BB9-2290-4428-AC6F-D19F6CF712D7} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FEB4B64D-32DE-4FC9-80CF-1E67590FFED0} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FED940D5-2DC6-49E8-BB65-C13BB922DB08} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FF74803A-E687-4CB7-A8C0-52646D178669} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\{FFAF5A24-7FCA-4238-A3A2-3A2572554E7C} (Empty Folder)
Successfully deleted: C:\Users\Starosta\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_blmojkbhnkkphngknkmgccmlenfaelkd_0.localstorage (File)
Successfully deleted: C:\Users\Starosta\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_olfeabkoenfaoljndfecamgilllcpiak_0.localstorage (File)
Successfully deleted: C:\Users\Starosta\Appdata\LocalLow\onlinemapfinder_9pei (Folder)



Registry: 11

Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_re_021010253 (Registry Value)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\rec_en_225 (Registry Value)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\rec_en_226 (Registry Value)
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\PCSUUCDRV (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{158016B8-9589-42D6-8376-85AF1CA86781} (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EA729DF7-FEA8-443C-8781-327FA3AB7529} (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{589cd417-937b-4d56-bb76-55260209dc19} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a1abaf97-24b6-431c-80e9-63b9017637aa} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{589cd417-937b-4d56-bb76-55260209dc19} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a1abaf97-24b6-431c-80e9-63b9017637aa} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 17. 03. 2016 at 11:41:54,35
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Reklama
pisky111
nováček
Příspěvky: 17
Registrován: březen 16
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logu

Příspěvekod pisky111 » 17 bře 2016 12:40

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 17. 3. 2016
Čas skenování: 12:04
Protokol: log1.txt
Správce: Ano

Verze: 2.2.0.1024
Databáze malwaru: v2016.03.17.02
Databáze rootkitů: v2016.03.12.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows 8.1
CPU: x64
Souborový systém: NTFS
Uživatel: Starosta

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 441362
Uplynulý čas: 21 min, 31 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 0
(Nenalezeny žádné škodlivé položky)

Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 0
(Nenalezeny žádné škodlivé položky)

Soubory: 0
(Nenalezeny žádné škodlivé položky)

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

pisky111
nováček
Příspěvky: 17
Registrován: březen 16
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logu

Příspěvekod pisky111 » 17 bře 2016 13:13

ogueKiller V12.0.2.0 (x64) [Mar 14 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 8.1 (6.3.9600) 64 bits version
Spuštěno : Normální režim
Uživatel : Starosta [Práva správce]
Started from : C:\Users\Starosta\Desktop\RogueKillerX64.exe
Mód : Prohledat -- Datum : 03/17/2016 13:11:22

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 3 ¤¤¤
[VT.Trojan.Win32.Agent.neudhk] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce | WINDOWS_SCREEN_MANAGER_UPDATER : C:\Program Files\Windows Screen Manager\Windows screen manage updater.exe [-] -> Nalezeno
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1449171411-244178406-4128510552-1002\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.seznam.cz/ -> Nalezeno
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1449171411-244178406-4128510552-1002\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.seznam.cz/ -> Nalezeno

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 1 ¤¤¤
[PUP][Složka] C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F} -> Nalezeno

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST750LM022 HN-M750MBB +++++
--- User ---
[MBR] 5563ee86216a1c21e78cfa8297c1cea8
[BSP] 6a3125a7f090a24988d63ba5cae1a61d : Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 2048 | Size: 1000 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2050048 | Size: 100 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 2254848 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 2516992 | Size: 697959 MB
4 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1431939072 | Size: 858 MB
5 - [SYSTEM] Basic data partition | Offset (sectors): 1433696256 | Size: 13307 MB
6 - [SYSTEM] Basic data partition | Offset (sectors): 1460948992 | Size: 2044 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: Brother MFC-J5910DW USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu

Příspěvekod jaro3 » 17 bře 2016 13:55

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:

- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)


- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni antivir i firewall.
Stáhni
Zoek.exe

a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

pisky111
nováček
Příspěvky: 17
Registrován: březen 16
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logu

Příspěvekod pisky111 » 17 bře 2016 14:25

Ok děkuji udělám to zitra notebook je v práci....

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu

Příspěvekod jaro3 » 17 bře 2016 17:18

OK.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

pisky111
nováček
Příspěvky: 17
Registrován: březen 16
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logu

Příspěvekod pisky111 » 18 bře 2016 07:02

ogueKiller V12.0.2.0 (x64) [Mar 14 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 8.1 (6.3.9600) 64 bits version
Spuštěno : Normální režim
Uživatel : Starosta [Práva správce]
Started from : C:\Users\Starosta\Desktop\RogueKillerX64.exe
Mód : Smazat -- Datum : 03/18/2016 07:00:25

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 3 ¤¤¤
[VT.Trojan.Win32.Agent.neudhk] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce | WINDOWS_SCREEN_MANAGER_UPDATER : C:\Program Files\Windows Screen Manager\Windows screen manage updater.exe [-] -> Smazáno
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1449171411-244178406-4128510552-1002\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.seznam.cz/ -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1449171411-244178406-4128510552-1002\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.seznam.cz/ -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 1 ¤¤¤
[PUP][Složka] C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F} -> Smazáno
[PUP][Soubor] C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}\0x0409.ini -> Smazáno
[PUP][Soubor] C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}\HP Support Assistant.msi -> Smazáno

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST750LM022 HN-M750MBB +++++
--- User ---
[MBR] 5563ee86216a1c21e78cfa8297c1cea8
[BSP] 6a3125a7f090a24988d63ba5cae1a61d : Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 2048 | Size: 1000 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2050048 | Size: 100 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 2254848 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 2516992 | Size: 697959 MB
4 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1431939072 | Size: 858 MB
5 - [SYSTEM] Basic data partition | Offset (sectors): 1433696256 | Size: 13307 MB
6 - [SYSTEM] Basic data partition | Offset (sectors): 1460948992 | Size: 2044 MB
User = LL1 ... OK
User = LL2 ... OK

pisky111
nováček
Příspěvky: 17
Registrován: březen 16
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logu

Příspěvekod pisky111 » 18 bře 2016 07:44

Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Starosta on p  18. 03. 2016 at 7:04:34,36.
Microsoft Windows 8.1 Pro 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Starosta\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

18. 3. 2016 7:06:46 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Seznam.cz deleted successfully
C:\Users\Starosta\AppData\Roaming\hpqlog deleted successfully
C:\Users\Starosta\AppData\Roaming\Opera Software deleted successfully
C:\Users\Starosta\AppData\Roaming\Vso deleted successfully
C:\Users\Administrator\AppData\Local\PDFC deleted successfully
C:\Users\Starosta\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\Starosta\AppData\Local\EmieSiteList deleted successfully
C:\Users\Starosta\AppData\Local\EmieUserList deleted successfully
C:\Users\Starosta\AppData\Local\GHISLER deleted successfully
C:\Users\Starosta\AppData\Local\Opera Software deleted successfully
C:\Users\Starosta\AppData\Local\PDFC deleted successfully
C:\Users\Starosta\AppData\Local\Skype deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\PeerDistPub deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\PeerDistRepub deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1449171411-244178406-4128510552-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DCB7100-DF86-4384-8842-8FA844297B3F} deleted successfully
HKEY_USERS\S-1-5-21-1449171411-244178406-4128510552-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8DCB7100-DF86-4384-8842-8FA844297B3F} deleted successfully
HKEY_USERS\S-1-5-21-1449171411-244178406-4128510552-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully
HKEY_USERS\S-1-5-21-1449171411-244178406-4128510552-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{8DCB7100-DF86-4384-8842-8FA844297B3F} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{8DCB7100-DF86-4384-8842-8FA844297B3F} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8DCB7100-DF86-4384-8842-8FA844297B3F} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~2\Seznam.cz not found
C:\PROGRA~2\BitLord 2 deleted
C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\log.xml deleted
C:\AutoRun.inf deleted
C:\install.exe deleted
C:\instmsiw.exe deleted
C:\Setup.exe deleted
C:\Users\Starosta\AppData\Roaming\bitlord_log.txt deleted
C:\Users\Starosta\AppData\Roaming\pcouffin.log deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\Public\Documents\dmp deleted
C:\WINDOWS\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\gpt.ini deleted
"C:\Users\Starosta\AppData\Roaming\CMEFNV" deleted
"C:\Users\Starosta\AppData\Roaming\EULUOC" deleted

==== Orphaned Tasks deleted from Registry ======================

avast Emergency Update deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [14. 03. 2016 22:56]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [14. 03. 2016 22:56]

==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
eofcbnmajmjmplflapaojjnihcjkigck - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx[10. 02. 2016 08:07]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[10. 02. 2016 08:07]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[12. 10. 2015 08:31]

Avast SafePrice - Starosta\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Avast Online Security - Starosta\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMNTDFJS
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMNTDFJS
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMNTDFJS

==== Reset Google Chrome ======================

C:\Users\Starosta\AppData\Local\Google\Chrome\User Data\Default\Secure Preferencesgbak was reset successfully
C:\Users\Starosta\AppData\Local\Google\Chrome\User Data\Default\Web Datagbak was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\2aactouchcheck.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\3dphotoplayer.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\activate.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adobearmhelper.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aestsr64.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aestsrv.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ainfo.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\armsvc(76).exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avertvdiag.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\batterytest.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bonus.screenshotreader.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\callingcard.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\callingcardrc.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\callingcard_srv.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cl3dphototb.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cldrvchk.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\clupdater.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\contactoptionparameters.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\contacttechnicalsupport.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\detect_backuppasswordreminder.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\devicemanager.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\extract.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\feedback.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fileextractor.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hc_guestenabled.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hc_hibernateenable.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hc_hphcimprove.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hc_launch.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hc_srenable.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hc_windowsupdatecheck.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpbatteryservicelauncher.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpbc.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpdeletefftemp.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpdeleteietemp.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpdeletetemp.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpdevicedetection3.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpdiagnosticcoreui.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hphelpupdater.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hphksver.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpinstdrv64.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpnetworkcheck.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpresources.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsadeployer.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsalauncher.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsamessagebox.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsaobjectmetrics.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsaredirector.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsascript.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsaupdaterobj.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsaupgrade.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsa_buy_battery.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsa_cip.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsa_link_redirector.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsa_nodisplay.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsetsystemrestore.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsfpopcip.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsfreport.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsfupdater.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsf_utils.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsmartadapterhelp.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpsysinfo.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hptouchcheck.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hptuneup.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hptvtunercheck.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpvideocheck.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpwarrantychecker.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hpwsd.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\idtngui.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\idtnj.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\idtpima.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\idtpma64.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\idtsetup.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kb835221.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kb888111srvrtm.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kb888111w2ksp4.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kb888111xpsp1.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kb888111xpsp2.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kb901105.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\launchfanurl.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\launchhpforums.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\launchhpreg.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\launchhprm.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\launchmshelptopic.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\launchonlineclasses.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\launchwebchat.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\m6_console.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nclauncherfromie.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\olrstatecheck.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\olrsubmission.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfcreator.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfmerger.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfsaver4a.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdvd10serv.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdvdlaunchpolicy.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\popup.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerdvd10.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerdvdcox10.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prninstaller.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\productconfig.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psgredirector.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qlbcontroller.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ra64app.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\resource.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\serviceupdater.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shortcutcreator.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\skypebrowserhost.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\skypec2cautoupdatesvc.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\skypec2cpnrsvc.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\solexternalhdd.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\solution_backupandrestorelauncher.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\solution_recoverypgm.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stacsv.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sttray.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sttray64.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\suhlp.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\suhlp64.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\transformer.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\trigrammsinstaller.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsdiag.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsdiag3.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsresmon.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsupdatescheck.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsupdateslauncher.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vantagesystemstatus.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\video-diags.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\waitwindow.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windefrag.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winemptyrecycle.exe deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xmlviewerhpsf.exe deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Starosta\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Starosta\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Starosta\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Starosta\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\Starosta\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=1213 folders=267 77257219 bytes)

==== Empty Temp Folders ======================

C:\Users\Administrator\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Starosta\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Starosta\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on p  18. 03. 2016 at 7:34:31,38 ======================

pisky111
nováček
Příspěvky: 17
Registrován: březen 16
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logu

Příspěvekod pisky111 » 18 bře 2016 07:49

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 7:47:26, on 18. 3. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Users\Starosta\AppData\Local\Microsoft\Windows\INetCache\IE\CALPY4I1\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe /start
O4 - HKLM\..\Run: [BtTray] "c:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe"
O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
O4 - HKLM\..\Run: [CLVirtualDrive] "c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
O4 - HKLM\..\Run: [RemoteControl10] "c:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [PPort12reminder] "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.2 ... rol_32.CAB
O16 - DPF: {D8950D0E-FCE7-4AE4-9370-7E4CFBC04362} (FormApps Plug-in) - https://eportal.cssz.cz/fas/page/active ... bff_cs.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: BlueSoleilCS - IVT Corporation - C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe
O23 - Service: BsHelpCS - IVT Corporation - C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
O23 - Service: CyberLink Product - 2012/11/17 07:49:11 (CLKMSVC10_38F51D56) - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: @oem37.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\WINDOWS\system32\Hpservice.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\WINDOWS\SysWOW64\ssins.exe
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14873 bytes




Děkuji za spolupráci, problémy se podařily odstranit...takže už je všechno v pořádku

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu

Příspěvekod jaro3 » 18 bře 2016 09:57

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"


Stáhni si zde DelFix
https://toolslib.net/downloads/viewdownload/2-delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

pisky111
nováček
Příspěvky: 17
Registrován: březen 16
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logu  Vyřešeno

Příspěvekod pisky111 » 18 bře 2016 11:32

# DelFix v1.012 - Logfile created 18/03/2016 at 11:21:06
# Updated 04/03/2015 by Xplode
# Username : Starosta - URADJIRKA
# Operating System : Windows 8.1 Pro (64 bits)

~ Removing disinfection tools ...

Deleted : C:\zoek_backup
Deleted : C:\log.txt
Deleted : C:\zoek-results.log
Deleted : C:\Users\Starosta\Desktop\JRT.exe
Deleted : C:\Users\Starosta\Desktop\JRT.txt
Deleted : C:\Users\Starosta\Desktop\log.txt
Deleted : C:\Users\Starosta\Desktop\log1.txt
Deleted : C:\Users\Starosta\Desktop\RogueKillerX64.exe
Deleted : C:\Users\Starosta\Desktop\zoek.exe
Deleted : C:\Users\Starosta\Downloads\adwcleaner_5.102.exe
Deleted : C:\Users\Starosta\Downloads\HijackThis.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools

~ Cleaning system restore ...

Deleted : RP #141 [JRT Pre-Junkware Removal | 03/17/2016 10:36:18]

New restore point created !

########## - EOF - ##########


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 62 hostů