Problem s notebookem - log hijackthis

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Skytech
Level 1
Level 1
Příspěvky: 95
Registrován: červen 14
Pohlaví: Muž
Stav:
Offline

Re: Problem s notebookem - log hijackthis

Příspěvekod Skytech » 12 črc 2019 17:09

----------------------------------------------------------------------------
CrystalDiskInfo 8.2.0 (C) 2008-2019 hiyohiyo
Crystal Dew World : https://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 10 [10.0 Build 17134] (x64)
Date : 2019/07/12 17:08:49

-- Controller Map ----------------------------------------------------------
+ Intel(R) Pentium(R) processor N- and J-series / Intel(R) Celeron(R) processor N- and J-series AHCI - 0F23 [ATA]
- ST320LT012-1DG14C
- HL-DT-ST DVDRAM GUA0N
- Řadič prostorů úložišť [SCSI]

-- Disk List ---------------------------------------------------------------
(1) ST320LT012-1DG14C : 320,0 GB [0/0/0, pd1] - st

----------------------------------------------------------------------------
(1) ST320LT012-1DG14C
----------------------------------------------------------------------------
Model : ST320LT012-1DG14C
Firmware : 0002LVM1
Serial Number : W3P5218P
Disk Size : 320,0 GB (7,9/137,4/320,0/320,0)
Buffer Size : Neznámy údaj
Queue Depth : 32
# of Sectors : 625142448
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 4
Transfer Mode : SATA/300 | SATA/600
Power On Hours : 3839 hod.
Power On Count : 4148 krát
Temperature : 41 C (105 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 8080h [ON]
AAM Level : ----
Drive Letter : C: D:

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 120 _99 _34 00000E086BC0 Počet chyb čtení
03 100 _99 __0 000000000000 Čas na roztočení ploten
04 _83 _83 _20 0000000045DB Počet spuštění/zastavení
05 100 100 _36 000000000000 Počet přemapovaných sektorů
07 _81 _60 _30 0002111B10AB Počet chybných hledání
09 _96 _96 __0 000000000EFF Hodin v činnosti
0A 100 100 _97 000000000000 Počet opakovaných pokusů o roztočení ploten
0C _96 _96 _20 000000001034 Počet cyklů zapnutí zařízení
B8 100 100 _99 000000000000 Ukončovacích chyb
BB 100 100 __0 000000000000 Ohlášeno neopravitelných chyb
BC 100 _99 __0 000200020002 Časový limit příkazu
BD 100 100 __0 000000000000 Vysoká rychlost zápisu
BE _59 _46 _45 00002A290029 Teplota toku vzduchu
BF 100 100 __0 000000000073 Počet udalostí zaznamenaných otřesovým senzorem
C0 100 100 __0 000000000018 Počet vypnutí disku
C1 _72 _72 __0 00000000E1F2 Počet cyklů načítání/vymazání
C2 _41 _54 __0 000B00000029 Teplota
C5 100 100 __0 000000000000 Počet podezřelých sektorů
C6 100 100 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
FE 100 100 __0 000000000000 Ochrana proti pádu

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0C5A 3FFF C837 000F 0000 0000 003F 0000 0000 0000
010: 2020 2020 2020 2020 2020 2020 5733 5035 3231 3850
020: 0000 0000 0004 3030 3032 4C56 4D31 5354 3332 304C
030: 5430 3132 2D31 4447 3134 4320 2020 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0407 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 8F0E 0004 0048 0040
080: 01F8 0029 346B 7D29 6163 3469 BC09 6163 007F 0027
090: 0027 8080 FFFE 0000 FE00 0000 0000 0000 0000 0000
100: EAB0 2542 0000 0000 0000 0000 6003 0000 5000 C500
110: 73DB C695 0000 0000 0000 0000 0000 0000 0000 401E
120: 401E 0000 0000 0000 0000 0000 0000 0000 0029 EAB0
130: 2542 EAB0 2542 2020 0002 0140 0100 5000 3C06 3C0A
140: 0000 003C 0000 0008 0000 0000 7CFF 0280 0004 0000
150: 0008 0000 0000 0000 0000 0000 0000 0000 7500 8000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 1031 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0002 0000 103F 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 37A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 0A 00 01 0F 00 78 63 C0 6B 08 0E 00 00 00 03 03
010: 00 64 63 00 00 00 00 00 00 00 04 32 00 53 53 DB
020: 45 00 00 00 00 00 05 33 00 64 64 00 00 00 00 00
030: 00 00 07 0F 00 51 3C AB 10 1B 11 02 00 00 09 32
040: 00 60 60 FF 0E 00 00 00 00 00 0A 13 00 64 64 00
050: 00 00 00 00 00 00 0C 32 00 60 60 34 10 00 00 00
060: 00 00 B8 32 00 64 64 00 00 00 00 00 00 00 BB 32
070: 00 64 64 00 00 00 00 00 00 00 BC 32 00 64 63 02
080: 00 02 00 02 00 00 BD 3A 00 64 64 00 00 00 00 00
090: 00 00 BE 22 00 3B 2E 29 00 29 2A 00 00 00 BF 32
0A0: 00 64 64 73 00 00 00 00 00 00 C0 32 00 64 64 18
0B0: 00 00 00 00 00 00 C1 32 00 48 48 F2 E1 00 00 00
0C0: 00 00 C2 22 00 29 36 29 00 00 00 0B 00 00 C5 12
0D0: 00 64 64 00 00 00 00 00 00 00 C6 10 00 64 64 00
0E0: 00 00 00 00 00 00 C7 3E 00 C8 C8 00 00 00 00 00
0F0: 00 00 FE 32 00 64 64 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73
170: 03 00 01 00 01 52 02 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 03 01 01 00 01 01 01 01
190: 01 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00
1A0: 00 00 00 00 73 00 00 00 ED E1 83 68 97 0C 00 00
1B0: 00 00 00 00 01 00 34 44 7B 82 1B 09 03 00 00 00
1C0: 2C 9E 8E C7 04 00 00 00 00 00 00 00 00 00 00 00
1D0: 01 00 00 00 00 00 00 00 45 1C 00 00 48 00 06 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 06
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 EF

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 01 00 01 22 00 00 00 00 00 00 00 00 00 00 03 00
010: 00 00 00 00 00 00 00 00 00 00 04 14 00 00 00 00
020: 00 00 00 00 00 00 05 24 00 00 00 00 00 00 00 00
030: 00 00 07 1E 00 00 00 00 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 61 00 00 00 00
050: 00 00 00 00 00 00 0C 14 00 00 00 00 00 00 00 00
060: 00 00 B8 63 00 00 00 00 00 00 00 00 00 00 BB 00
070: 00 00 00 00 00 00 00 00 00 00 BC 00 00 00 00 00
080: 00 00 00 00 00 00 BD 00 00 00 00 00 00 00 00 00
090: 00 00 BE 2D 00 00 00 00 00 00 00 00 00 00 BF 00
0A0: 00 00 00 00 00 00 00 00 00 00 C0 00 00 00 00 00
0B0: 00 00 00 00 00 00 C1 00 00 00 00 00 00 00 00 00
0C0: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C5 00
0D0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00
0E0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
0F0: 00 00 FE 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 53

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43296
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Problem s notebookem - log hijackthis

Příspěvekod jaro3 » 12 črc 2019 18:42

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CreateRestorePoint:
CloseProcesses:
Task: {03121465-EA8A-476E-85E4-D28779F7991C} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION
Task: {0440C910-4BF9-4B19-8CFB-D9A015EF4DD2} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {048098E7-434D-43C7-A5F7-A620D78BA930} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {18727DA4-0342-4AE8-944A-AB0E1F6F1972} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {1D242436-A731-49CA-9C83-307AF6A41DD0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2044B5EF-5FE1-4BCF-959F-25FE6BE9ADD3} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> No File <==== ATTENTION
Task: {4E3EE142-A3DF-4AE0-B5D6-61A1C5C6824C} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {78FBCE3F-9E2E-4E9C-86D1-DA1DBE4195C2} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {812CC341-CC40-4A1B-B27A-6609AC98E076} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {82DBD46F-75A2-4221-AB01-8091639F8528} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {913867B9-94D9-42F4-AD35-59D277CFC815} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {ABD60F98-C51A-4136-9810-09CD8EFE0882} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {DD7582D8-4918-48F1-AC26-F2789A3E5A7B} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {ED134749-76AD-4797-AD9A-A0BE0E38B01D} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {F7DED190-D84C-4C30-BEF5-12F39778B1D2} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {FDC022C1-CA20-447A-81B8-904F4A2D825A} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {1C510631-D26C-4C64-B525-ED1F2F644BE8} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {2A651FCF-95E3-4BE3-9629-CF40FD00BE55} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {54A5B18D-3A5B-464C-A28B-F8089F256A16} URL = hxxp://www.mapy.cz/?query={searchTerms}&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {60AEE5E9-71BE-40BF-B65E-59D602F03AC5} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {6AF89F9C-D27E-4A1E-AC13-634EC81AED78} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {7B1F44F3-B79E-41C7-BF41-3A80EC72FC9C} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {82FF5651-E3DB-481D-BC1F-A2D09CE2CFAA} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {91B0AE32-A4D3-43A5-9029-09E97C00BE16} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&sourceid=QuickSearch_29530
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
HKLM\...\StartupApproved\Run32: => "mcpltui_exe"
FirewallRules: [{6CDCF501-F0EC-4BB5-9BD6-FFC015C5CA41}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{34195C5F-6EFF-4305-ADDC-7B5BE4278932}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{F6399429-DFA4-4176-A829-382BB2BCB7B2}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{F17BC138-25CA-4860-A036-911A18B07A58}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [TCP Query User{8A7E0DBD-0886-43C6-B534-52E27C470C19}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe No File
FirewallRules: [UDP Query User{D78E579C-7DF8-4107-96BE-90AA9F76FE57}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe No File
FirewallRules: [TCP Query User{776593CD-E45A-46F2-A77A-55A181EC71DC}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe No File
FirewallRules: [TCP Query User{F8C37C1E-C124-48DE-A0E7-51083ED3795C}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe No File
FirewallRules: [UDP Query User{17AFA010-49C4-4331-B9F1-6DCF8330BC5E}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe No File
FirewallRules: [{72078B93-31EF-4A97-8CCA-D68C496F9E74}] => (Block) C:\program files (x86)\kodi\kodi.exe No File
FirewallRules: [{5DFAA8C2-C18C-4148-9444-4700E7DA686B}] => (Block) C:\program files (x86)\kodi\kodi.exe No File
FirewallRules: [TCP Query User{6C61E7CD-A359-4B51-A123-5C348F064239}C:\sierra\empire earth - the art of conquest\ee-aoc.exe] => (Allow) C:\sierra\empire earth - the art of conquest\ee-aoc.exe No File
FirewallRules: [UDP Query User{734314F0-6E3B-413B-AD3F-19F77229C0C1}C:\sierra\empire earth - the art of conquest\ee-aoc.exe] => (Allow) C:\sierra\empire earth - the art of conquest\ee-aoc.exe No File
FirewallRules: [{247CC686-144B-4ADF-BCDD-468D070A0E5F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe No File
FirewallRules: [{9DFC0C8B-0DA3-4EFE-AD5D-D82CFBE918BE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe No File
FirewallRules: [{4530ED9A-365A-4843-8A0F-F1D45FBFBB2E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{DF7524B8-4161-4739-8A1A-0B77E9AD8EC9}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{4C57DF05-EC9B-47C3-A18E-FC774D71195A}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe No File
FirewallRules: [{3BCAE81B-DB81-44F7-9CBE-313E64EC54ED}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe No File

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt

Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.

Error: (07/12/2019 03:45:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: wuauclt.exe, verze: 10.0.17134.1, časové razítko: 0x22d334aa
Název chybujícího modulu: combase.dll, verze: 10.0.17134.523, časové razítko: 0x28000460
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000000b5d10
ID chybujícího procesu: 0x22dc
Čas spuštění chybující aplikace: 0x01d538b0c09f6e45
Cesta k chybující aplikaci: C:\WINDOWS\system32\wuauclt.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\combase.dll
ID zprávy: bee461ae-b79e-4d09-a5e0-59713e86fec3
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


možná nějaký problém u windows , opakuje se 3x..
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Skytech
Level 1
Level 1
Příspěvky: 95
Registrován: červen 14
Pohlaví: Muž
Stav:
Offline

Re: Problem s notebookem - log hijackthis

Příspěvekod Skytech » 12 črc 2019 19:29

Fix result of Farbar Recovery Scan Tool (x64) Version: 10-07-2019
Ran by Daniela (12-07-2019 19:16:07) Run:1
Running from C:\Users\Daniela\Desktop
Loaded Profiles: Daniela (Available Profiles: Daniela & Administrator)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
Task: {03121465-EA8A-476E-85E4-D28779F7991C} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION
Task: {0440C910-4BF9-4B19-8CFB-D9A015EF4DD2} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {048098E7-434D-43C7-A5F7-A620D78BA930} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {18727DA4-0342-4AE8-944A-AB0E1F6F1972} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {1D242436-A731-49CA-9C83-307AF6A41DD0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2044B5EF-5FE1-4BCF-959F-25FE6BE9ADD3} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> No File <==== ATTENTION
Task: {4E3EE142-A3DF-4AE0-B5D6-61A1C5C6824C} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {78FBCE3F-9E2E-4E9C-86D1-DA1DBE4195C2} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {812CC341-CC40-4A1B-B27A-6609AC98E076} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {82DBD46F-75A2-4221-AB01-8091639F8528} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {913867B9-94D9-42F4-AD35-59D277CFC815} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {ABD60F98-C51A-4136-9810-09CD8EFE0882} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {DD7582D8-4918-48F1-AC26-F2789A3E5A7B} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {ED134749-76AD-4797-AD9A-A0BE0E38B01D} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {F7DED190-D84C-4C30-BEF5-12F39778B1D2} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {FDC022C1-CA20-447A-81B8-904F4A2D825A} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {1C510631-D26C-4C64-B525-ED1F2F644BE8} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {2A651FCF-95E3-4BE3-9629-CF40FD00BE55} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {54A5B18D-3A5B-464C-A28B-F8089F256A16} URL = hxxp://www.mapy.cz/?query={searchTerms}&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {60AEE5E9-71BE-40BF-B65E-59D602F03AC5} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {6AF89F9C-D27E-4A1E-AC13-634EC81AED78} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {7B1F44F3-B79E-41C7-BF41-3A80EC72FC9C} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {82FF5651-E3DB-481D-BC1F-A2D09CE2CFAA} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_29530
SearchScopes: HKU\S-1-5-21-3912289609-2614299189-3837706224-1001 -> {91B0AE32-A4D3-43A5-9029-09E97C00BE16} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&sourceid=QuickSearch_29530
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
HKLM\...\StartupApproved\Run32: => "mcpltui_exe"
FirewallRules: [{6CDCF501-F0EC-4BB5-9BD6-FFC015C5CA41}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{34195C5F-6EFF-4305-ADDC-7B5BE4278932}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{F6399429-DFA4-4176-A829-382BB2BCB7B2}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{F17BC138-25CA-4860-A036-911A18B07A58}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [TCP Query User{8A7E0DBD-0886-43C6-B534-52E27C470C19}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe No File
FirewallRules: [UDP Query User{D78E579C-7DF8-4107-96BE-90AA9F76FE57}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe No File
FirewallRules: [TCP Query User{776593CD-E45A-46F2-A77A-55A181EC71DC}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe No File
FirewallRules: [TCP Query User{F8C37C1E-C124-48DE-A0E7-51083ED3795C}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe No File
FirewallRules: [UDP Query User{17AFA010-49C4-4331-B9F1-6DCF8330BC5E}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe No File
FirewallRules: [{72078B93-31EF-4A97-8CCA-D68C496F9E74}] => (Block) C:\program files (x86)\kodi\kodi.exe No File
FirewallRules: [{5DFAA8C2-C18C-4148-9444-4700E7DA686B}] => (Block) C:\program files (x86)\kodi\kodi.exe No File
FirewallRules: [TCP Query User{6C61E7CD-A359-4B51-A123-5C348F064239}C:\sierra\empire earth - the art of conquest\ee-aoc.exe] => (Allow) C:\sierra\empire earth - the art of conquest\ee-aoc.exe No File
FirewallRules: [UDP Query User{734314F0-6E3B-413B-AD3F-19F77229C0C1}C:\sierra\empire earth - the art of conquest\ee-aoc.exe] => (Allow) C:\sierra\empire earth - the art of conquest\ee-aoc.exe No File
FirewallRules: [{247CC686-144B-4ADF-BCDD-468D070A0E5F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe No File
FirewallRules: [{9DFC0C8B-0DA3-4EFE-AD5D-D82CFBE918BE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe No File
FirewallRules: [{4530ED9A-365A-4843-8A0F-F1D45FBFBB2E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{DF7524B8-4161-4739-8A1A-0B77E9AD8EC9}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{4C57DF05-EC9B-47C3-A18E-FC774D71195A}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe No File
FirewallRules: [{3BCAE81B-DB81-44F7-9CBE-313E64EC54ED}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe No File

EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{03121465-EA8A-476E-85E4-D28779F7991C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03121465-EA8A-476E-85E4-D28779F7991C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\rundetector" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0440C910-4BF9-4B19-8CFB-D9A015EF4DD2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0440C910-4BF9-4B19-8CFB-D9A015EF4DD2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{048098E7-434D-43C7-A5F7-A620D78BA930}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{048098E7-434D-43C7-A5F7-A620D78BA930}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{18727DA4-0342-4AE8-944A-AB0E1F6F1972}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{18727DA4-0342-4AE8-944A-AB0E1F6F1972}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1D242436-A731-49CA-9C83-307AF6A41DD0}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D242436-A731-49CA-9C83-307AF6A41DD0}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2044B5EF-5FE1-4BCF-959F-25FE6BE9ADD3}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2044B5EF-5FE1-4BCF-959F-25FE6BE9ADD3}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-Weekend" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4E3EE142-A3DF-4AE0-B5D6-61A1C5C6824C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E3EE142-A3DF-4AE0-B5D6-61A1C5C6824C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{78FBCE3F-9E2E-4E9C-86D1-DA1DBE4195C2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78FBCE3F-9E2E-4E9C-86D1-DA1DBE4195C2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{812CC341-CC40-4A1B-B27A-6609AC98E076}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{812CC341-CC40-4A1B-B27A-6609AC98E076}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{82DBD46F-75A2-4221-AB01-8091639F8528}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82DBD46F-75A2-4221-AB01-8091639F8528}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{913867B9-94D9-42F4-AD35-59D277CFC815}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{913867B9-94D9-42F4-AD35-59D277CFC815}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ABD60F98-C51A-4136-9810-09CD8EFE0882}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ABD60F98-C51A-4136-9810-09CD8EFE0882}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DD7582D8-4918-48F1-AC26-F2789A3E5A7B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD7582D8-4918-48F1-AC26-F2789A3E5A7B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ED134749-76AD-4797-AD9A-A0BE0E38B01D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ED134749-76AD-4797-AD9A-A0BE0E38B01D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F7DED190-D84C-4C30-BEF5-12F39778B1D2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F7DED190-D84C-4C30-BEF5-12F39778B1D2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FDC022C1-CA20-447A-81B8-904F4A2D825A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FDC022C1-CA20-447A-81B8-904F4A2D825A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => removed successfully
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
"HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} => removed successfully
HKLM\Software\Classes\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => not found
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1C510631-D26C-4C64-B525-ED1F2F644BE8} => removed successfully
HKLM\Software\Classes\CLSID\{1C510631-D26C-4C64-B525-ED1F2F644BE8} => not found
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2A651FCF-95E3-4BE3-9629-CF40FD00BE55} => removed successfully
HKLM\Software\Classes\CLSID\{2A651FCF-95E3-4BE3-9629-CF40FD00BE55} => not found
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{54A5B18D-3A5B-464C-A28B-F8089F256A16} => removed successfully
HKLM\Software\Classes\CLSID\{54A5B18D-3A5B-464C-A28B-F8089F256A16} => not found
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{60AEE5E9-71BE-40BF-B65E-59D602F03AC5} => removed successfully
HKLM\Software\Classes\CLSID\{60AEE5E9-71BE-40BF-B65E-59D602F03AC5} => not found
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6AF89F9C-D27E-4A1E-AC13-634EC81AED78} => removed successfully
HKLM\Software\Classes\CLSID\{6AF89F9C-D27E-4A1E-AC13-634EC81AED78} => not found
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7B1F44F3-B79E-41C7-BF41-3A80EC72FC9C} => removed successfully
HKLM\Software\Classes\CLSID\{7B1F44F3-B79E-41C7-BF41-3A80EC72FC9C} => not found
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{82FF5651-E3DB-481D-BC1F-A2D09CE2CFAA} => removed successfully
HKLM\Software\Classes\CLSID\{82FF5651-E3DB-481D-BC1F-A2D09CE2CFAA} => not found
HKU\S-1-5-21-3912289609-2614299189-3837706224-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{91B0AE32-A4D3-43A5-9029-09E97C00BE16} => removed successfully
HKLM\Software\Classes\CLSID\{91B0AE32-A4D3-43A5-9029-09E97C00BE16} => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\00avast => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\mcpltui_exe" => removed successfully
"HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mcpltui_exe" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6CDCF501-F0EC-4BB5-9BD6-FFC015C5CA41}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{34195C5F-6EFF-4305-ADDC-7B5BE4278932}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F6399429-DFA4-4176-A829-382BB2BCB7B2}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F17BC138-25CA-4860-A036-911A18B07A58}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8A7E0DBD-0886-43C6-B534-52E27C470C19}C:\program files (x86)\skype\phone\skype.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D78E579C-7DF8-4107-96BE-90AA9F76FE57}C:\program files (x86)\skype\phone\skype.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{776593CD-E45A-46F2-A77A-55A181EC71DC}C:\program files (x86)\skype\phone\skype.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{F8C37C1E-C124-48DE-A0E7-51083ED3795C}C:\program files (x86)\kodi\kodi.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{17AFA010-49C4-4331-B9F1-6DCF8330BC5E}C:\program files (x86)\kodi\kodi.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{72078B93-31EF-4A97-8CCA-D68C496F9E74}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5DFAA8C2-C18C-4148-9444-4700E7DA686B}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{6C61E7CD-A359-4B51-A123-5C348F064239}C:\sierra\empire earth - the art of conquest\ee-aoc.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{734314F0-6E3B-413B-AD3F-19F77229C0C1}C:\sierra\empire earth - the art of conquest\ee-aoc.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{247CC686-144B-4ADF-BCDD-468D070A0E5F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9DFC0C8B-0DA3-4EFE-AD5D-D82CFBE918BE}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4530ED9A-365A-4843-8A0F-F1D45FBFBB2E}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DF7524B8-4161-4739-8A1A-0B77E9AD8EC9}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4C57DF05-EC9B-47C3-A18E-FC774D71195A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3BCAE81B-DB81-44F7-9CBE-313E64EC54ED}" => removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 9199616 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 40379674 B
Java, Flash, Steam htmlcache => 23149013 B
Windows/system/drivers => 15810 B
Edge => 0 B
Chrome => 0 B
Firefox => 82778552 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
LocalService => 0 B
NetworkService => 7690 B
NetworkService => 0 B
Daniela => 9749745 B
Administrator => 16592 B

RecycleBin => 0 B
EmptyTemp: => 157.6 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 19:20:43 ====

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43296
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Problem s notebookem - log hijackthis

Příspěvekod jaro3 » 12 črc 2019 20:17

Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Skytech
Level 1
Level 1
Příspěvky: 95
Registrován: červen 14
Pohlaví: Muž
Stav:
Offline

Re: Problem s notebookem - log hijackthis

Příspěvekod Skytech » 12 črc 2019 20:51

Je to lepsi, i kdyz to nacitani po restartu je porad takovy pomaly. Ale neni to takova katastrofa, jako to bylo. Myslis tedy, ze to bude tim win?

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43296
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Problem s notebookem - log hijackthis

Příspěvekod jaro3 » 12 črc 2019 21:25

wuauclt.exe --- is part of Windows Update AutoUpdate Client of Microsoft
nějaké problémy s autom. aktualizacemi? Nebo je máš zakázané?

Stáhni si na svojí plochu StartupLite .exe by MalwareBytes

Tento program identifikuje a dává volbu k odstranění nepotřebných položek k vyprázdnění paměti.
Poklepej na ikonu StartupLite.exe (by MalwareBytes ) ke spuštění programu. Ve vistě a windows 7 spusť jako správce (pravým klik na ikonu a vyber-spustit jako správce).Vytvoří se list nepotřebných vstupů po spuštění. Nech všechny položky jako deaktivované a klikni na Continue . Restartuj PC.

Stáhni si Memtest:

Políčko , ve kterém je napsáno:
All unused RAM , změň na 2048.
-dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.
V případě vyšších kapacit RAM je třeba Memtest spustit několikrát , pro 2GB ( jednotlivá největší kapacita RAM) 2x , pro 4GB 3x , pro 8Gb 4x ap.
poklepej na Memtest , pak znovu a znovu , do políček všech Memtestů napiš 2048 , pak dej u všech Memtestů "Start".
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Skytech
Level 1
Level 1
Příspěvky: 95
Registrován: červen 14
Pohlaví: Muž
Stav:
Offline

Re: Problem s notebookem - log hijackthis

Příspěvekod Skytech » 14 črc 2019 10:41

Ted jsem na to koukal a posledni kontrola aktualizace probehla 10.7. 2019.

Jen mi to tam hlasi, ze pouzivam verzi win, ktere brzy skonci podpora... Ze mam prejit na win10.

Skytech
Level 1
Level 1
Příspěvky: 95
Registrován: červen 14
Pohlaví: Muž
Stav:
Offline

Re: Problem s notebookem - log hijackthis

Příspěvekod Skytech » 14 črc 2019 10:54

Tak malwarebytes startup napsal po spusteni “no unnecessary startups found”.

Skytech
Level 1
Level 1
Příspěvky: 95
Registrován: červen 14
Pohlaví: Muž
Stav:
Offline

Re: Problem s notebookem - log hijackthis

Příspěvekod Skytech » 14 črc 2019 11:07

Spustil jsem memtest a asi se hned zasekl. Mys nereaguje, ani klavesnice...a nic se nedeje. Takto chvili necham a uvidim. Kdyztak to natvrdo restartuju.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43296
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Problem s notebookem - log hijackthis

Příspěvekod jaro3 » 14 črc 2019 20:00

Pokud to nepůjde:
novy-program-pro-testovani-ram-na-chyby-memtest64
https://www.cnews.cz/novy-program-pro-t ... -restartu/

https://www.techpowerup.com/download/te ... memtest64/



Nebo:
Memtest 86
http://www.memtest86.com/
klikni vlevo na Free Download , vyber:
ISO image for creating bootable CD (Windows - zip) , stáhni , rozbal , otevři , vypal třeba v programu:
http://www.slunecnice.cz/sw/active-iso-burner/
Vlož do mechaniky a nabootuj z něj.
Test udělej alespoň 8h ( přes noc).

http://www.memtest86.com/download.htm
http://www.eopcservis.cz/jak-otestovat-ram.html
http://www.memtest86.com/download.htm

případně na USB klíč:
http://www.memtest86.com/downloads/memt ... sb.img.zip
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 123 hostů