Poprosím o kontrolu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Poprosím o kontrolu

Příspěvekod jaro3 » 08 lis 2021 23:57

Další dej zítra.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
kedar700
Level 2
Level 2
Příspěvky: 157
Registrován: květen 13
Pohlaví: Muž
Stav:
Offline

Re: Poprosím o kontrolu

Příspěvekod kedar700 » 12 lis 2021 11:03

Internet, už taky jede zjistil jsem, že to blokoval program LabView, který si zablokoval velkou část šířky pásma i když zrovna neběžel.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Poprosím o kontrolu

Příspěvekod jaro3 » 12 lis 2021 16:24

Ještě RogueKiller .
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

kedar700
Level 2
Level 2
Příspěvky: 157
Registrován: květen 13
Pohlaví: Muž
Stav:
Offline

Re: Poprosím o kontrolu

Příspěvekod kedar700 » 15 lis 2021 14:19

Program : RogueKiller Anti-Malware
Version : 15.1.2.0
x64 : Yes
Program Date : Nov 3 2021
Location : C:\Program Files\RogueKiller\RogueKiller64.exe
Premium : No
Company : Adlice Software
Website : https://www.adlice.com/
Contact : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19043) 64-bit
64-bit OS : Yes
Startup : 0
WindowsPE : No
User : kedar
User is Admin : Yes
Date : 2021/11/15 13:19:04
Type : Scan
Aborted : No
Scan Mode : Quick
Duration : 11
Found items : 0
Total scanned : 1208
Signatures Version : 20211108_111704
Truesight Driver : Yes
Updates Count : 0

************************* Warnings *************************

************************* Updates *************************

************************* Processes *************************

************************* Modules *************************

************************* Services *************************

************************* Scheduled Tasks *************************

************************* Registry *************************

************************* WMI *************************

************************* Hosts File *************************
is_too_big : No
hosts_file_path : N/A


************************* Filesystem *************************

************************* Web Browsers *************************

************************* Antirootkit *************************

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Poprosím o kontrolu

Příspěvekod jaro3 » 15 lis 2021 16:16

Vypni antivir i firewall, RogueKiller, Malwarebytes Antimalware, windowsDefender
Stáhni Zoek.exe
http://download.bleepingcomputer.com/smeenk/zoek.exe
https://uloz.to/file/nFH1LwSrGioP/zoek1-rar

Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;

klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log Zkopíruj sem celý obsah toho logu.
Pokud budou problémy , spusť zoek v nouz. režimu.

Stáhni si Zemana AntiMalware Free z tohoto odkazu:
https://www.zemana.com/Download/AntiMal ... .Setup.exe
a ulož si ho na plochu.
Poklepej na tento soubor na ploše a postupuj podle pokynů k instalaci programu.
Přijmi licenci k používání programu EULA , pokud se nabídne.
Pokud je k dispozici aktualizace programu , klepni na tlačítko „Update now“ ( aktualizovat nyní).
Zavři všechny otevřené soubory, složky a prohlížeče
Neměň žádné nastavení. Klikni na „Skenovat nyní“.
Po skenu lze vidět , zda jsou nějaké nákazy. Klikni na „Vykonat“ ( vymazat). Nákazy budou přemístěny do karantény.
Když je skenování dokončeno, klikni vlevo na „zprávy“ a pak na „otevři zprávu“ a zkopíruj sem celý obsah té zprávy.

Zkus pak znovu malwarebytes.
Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

kedar700
Level 2
Level 2
Příspěvky: 157
Registrován: květen 13
Pohlaví: Muž
Stav:
Offline

Re: Poprosím o kontrolu

Příspěvekod kedar700 » 16 lis 2021 16:05

Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by kedar on 16.11.2021 at 14:52:06,15.
Microsoft Windows 10 Home 10.0.19043 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\kedar\OneDrive\Plocha\cisteni\cist\zoek1\zoek (1).exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2021-11-08-203416.log 895994 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\Users\kedar\AppData\Local\DBG deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\hpikgdpu.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\hpikgdpu.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\lq14w118.default-1522607936553\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\lq14w118.default-1522607936553\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\nqbl1xsv.default-1581607266712\prefs.js:
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\nqbl1xsv.default-1581607266712\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\Users\kedar\AppData\Roaming\discord deleted
C:\Users\kedar\AppData\Roaming\Spotify deleted
C:\PROGRA~3\{6A1798B4-4BC3-42D3-8545-B1A43208F7FC} deleted
C:\Users\kedar\AppData\Local\oobelibMkey.log deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-19234b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-19239b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-1923ad.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-1923be.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-1923d0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-1923e2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-192403.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-192405.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-192426.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-192447.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-192469.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-1924a9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-1924ea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-19252a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-19256b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-19257c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-1925cc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-19263c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1868-116c-192747.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-579735.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-579737.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-579749.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-57974b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-57974d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-57974f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-579760.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-579762.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-579764.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-579766.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-579788.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-57978a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-5797ab.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-5797cc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-5797de.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-5797ff.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-579811.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-579813.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c34-39c8-579815.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c3d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c3f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c50.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c52.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c54.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c66.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c68.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c6a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c7c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c7e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c80.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c91.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702c93.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702ca5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702ca7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702ca9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702cbb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702cbd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e2c-5658-702cce.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d5775.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d5777.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d5788.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d578a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d578c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d579e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57a0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57a2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57b4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57b6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57b8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57ba.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57cb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57cd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57cf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57e1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57e3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57e5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3e4-5788-d57f7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a57b2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a57c4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a57c6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a57d7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a57f8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a580a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a580c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a581e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a582f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a5831.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a5833.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a5845.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a5847.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a5859.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a587a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a588b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a588d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a588f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-45d4-3c58-a58a1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254add.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254aef.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254af1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254af3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b05.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b07.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b09.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b1a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b1c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b1e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b30.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b32.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b34.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b46.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b48.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b4a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b4c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b5d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-520c-4ce0-254b5f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539af03.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539af15.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539af26.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539af28.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539af3a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539af3c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539af4d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539af6f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539af71.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539af82.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539af84.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539af96.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539afa8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539afd8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539afda.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539affc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539b02d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539b03e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-72dc-8ce0-539b050.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc660.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc662.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc674.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc685.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc697.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc6a9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc6da.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc6dc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc6de.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc6ef.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc701.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc712.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc714.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc736.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc747.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc759.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc76b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc77c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-d68-d5c-cc78e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-26ff25.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-26ff46.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-26ff58.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-26ff79.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-26ff8b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-26ff8d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-26ff9e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-27006b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-27008d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-2700be.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-2700ee.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-270110.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-270131.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-270152.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-270173.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-270185.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-2701a6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-2701b8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-df0-3e94-2701ca.tmp deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deleted
"C:\DumpStack.log.tmp" not deleted
"C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\oobelibMkey.log" not deleted
"C:\Users\kedar\AppData\Local\Avast Software\Avast\datascan.json" not deleted
"C:\Users\kedar\AppData\Local\Avast Software" not deleted
"C:\Users\kedar\AppData\Local\Avast Software\Avast" not deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\hpikgdpu.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\lq14w118.default-1522607936553
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\nqbl1xsv.default-1581607266712
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

ProfilePath: C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\hpikgdpu.default
- __MSG_avastAppName__ - %ProfilePath%\extensions\sp@avast.com.xpi
- Avast Online Security - %ProfilePath%\extensions\wrc@avast.com.xpi
- short_ __MSG_name__ - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\lq14w118.default-1522607936553
- short_ FFZ - %ProfilePath%\extensions\frankerfacez@frankerfacez.com.xpi
- short_ passwords - %ProfilePath%\extensions\jid1-r1tDuNiNb4SEww@jetpack.xpi
- Avast Online Security - %ProfilePath%\extensions\wrc@avast.com.xpi
- short_ __MSG_name__ - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\nqbl1xsv.default-1581607266712
- short_ FFZ - %ProfilePath%\extensions\frankerfacez@frankerfacez.com.xpi
- short_ uBlock\u2080 - %ProfilePath%\extensions\uBlock0@raymondhill.net.xpi
- short_ 1Password - %ProfilePath%\extensions\{d634138d-c276-4fc8-924b-40a0ea21d284}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\hpikgdpu.default
- C:\Windows\system32\Macromed\Flash\NPSWF64_29_0_0_113.dll - [?]
- C:\Program Files x86\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll - [?]
- C:\Program Files x86\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll - [?]

Profilepath: C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\lq14w118.default-1522607936553
- C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_142.dll - [?]
- C:\Program Files x86\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll - [?]
- C:\Program Files x86\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll - [?]

Profilepath: C:\Users\kedar\AppData\Roaming\Mozilla\Firefox\Profiles\nqbl1xsv.default-1581607266712
- C:\Program Files x86\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll - [?]
- C:\Program Files x86\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll - [?]
124FA95972259D35F25B6133DD4DC425 - C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll - Silverlight Plug-In
29D9DD280A871C15C8517D30969A65D5 - C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrlui.dll - Microsoft® Silverlight


==== Chromium Look ======================


Streamlabs Export To StreamElements - kedar\AppData\Local\Google\Chrome\User Data\Default\Extensions\micpdieddpifbgnnlbelgamnfpeonkpe

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02

==== Reset Google Chrome ======================

C:\Users\kedar\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\kedar\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\kedar\AppData\Local\Microsoft\Edge\User Data\Default\Preferences was reset successfully
C:\Users\kedar\AppData\Local\Microsoft\Edge\User Data\Default\Secure Preferences was reset successfully
C:\Users\kedar\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\kedar\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\kedar\AppData\Local\Microsoft\Edge\User Data\Default\Web Data was reset successfully
C:\Users\kedar\AppData\Local\Microsoft\Edge\User Data\Default\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\kedar\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\kedar\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\kedar\AppData\Local\Mozilla\Firefox\Profiles\nqbl1xsv.default-1581607266712\cache2 emptied successfully

==== Empty Edge Cache ======================

Edge Cache Emptied Successfully

==== Empty Chrome Cache ======================

C:\Users\kedar\AppData\Local\CCleaner Browser\User Data\Default\Cache emptied successfully
C:\Users\kedar\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\kedar\AppData\Local\Microsoft\Edge\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=14309 folders=11909 4344274083 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\kedar\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\kedar\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\DumpStack.log.tmp" not deleted
"C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\oobelibMkey.log" not deleted
"C:\Users\kedar\AppData\Local\Avast Software\Avast\datascan.json" not found
"C:\Users\kedar\AppData\Local\Avast Software" not found

==== EOF on 16.11.2021 at 15:48:49,17 ======================

produktu    :  Zemana AntiMalware
Stav kontroly    :  Dokončena
Datum kontroly    :  16.11.2021 15:55:49
Typ kontroly    :  Inteligentní kontrola
Čas trvání    :  00:00:33
Zkontrolované objekty    :  2639
Zjištěné objekty    :  0
Vyloučené objekty    :  0
Automatické odesílání    :  Ano
Operační systém    :  Windows 10 x64
Procesor    :  8X Intel(R) Core(TM) i7-4790K CPU @ 4.00GHz
Režim systému BIOS    :  UEFI
Informace o doméně    :  WORKGROUP,False,NetSetupWorkgroupName
CUID    :  12A128054FC0BD8C9B6786

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 16.11.21
Čas skenování: 15:57
Logovací soubor: 790db218-46ed-11ec-a1e1-40167ead14e1.json

-Informace o softwaru-
Verze: 4.4.10.144
Verze komponentů: 1.0.1499
Aktualizovat verzi balíku komponent: 1.0.47256
Licence: Zkušební

-Systémová informace-
OS: Windows 10 (Build 19043.1348)
CPU: x64
Systém souborů: NTFS
Uživatel: Kjodar\kedar

-Shrnutí skenování-
Typ skenování: Skenování hrozeb (Threat Scan)
Spuštění skenování: Ruční
Výsledek: Dokončeno
Skenované objekty: 506055
Zjištěné hrozby: 0
Hrozby umístěné do karantény: 0
Uplynulý čas: 6 min, 12 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Zakázáno
Heuristika: Povoleno
Potenciálně nežádoucí program: Detekovat
Potenciálně nežádoucí modifikace: Detekovat

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 0
(Nebyly zjištěny žádné škodlivé položky)

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)

WMI: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

kedar700
Level 2
Level 2
Příspěvky: 157
Registrován: květen 13
Pohlaví: Muž
Stav:
Offline

Re: Poprosím o kontrolu

Příspěvekod kedar700 » 16 lis 2021 16:07

Dobrý den,
tak problémy už žadné nepociťuji.

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 16:06:48, on 16.11.2021
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.19041.1202)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
E:\Steam\steam.exe
C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe
C:\Program Files (x86)\Razer\Synapse3\Service\..\UserProcess\Razer Synapse Service Process.exe
C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe
C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe
C:\Program Files\WindowsApps\Microsoft.SurfaceWirelessDisplayAdapter_4.232.137.0_x64__8wekyb3d8bbwe\Desktop\WDADesktopService.exe
C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe
C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe
C:\Program Files (x86)\Razer\Synapse3\AudioVisualizer\ChromaVisualizer.exe
C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
C:\ProgramData\Razer\Synapse3\Service\Bin\RzLightingEngineHelper.exe
C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
D:\Stažené Soubory\HijackThis.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\95.0.1020.53\BHO\ie_to_edge_bho.dll
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_291\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_291\bin\jp2ssv.dll
O4 - HKLM\..\Run: [VirtualCloneDrive] "D:\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [Adobe CCXProcess] C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
O4 - HKLM\..\Run: [NI Device Monitor] "C:\Program Files (x86)\National Instruments\NI Device Monitor\DeviceMonitor.exe" --startup
O4 - HKLM\..\Run: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX2] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe /FORCE
O4 - HKCU\..\Run: [OneDrive] "C:\Users\kedar\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "E:\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Synapse3] C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe /StartMinimized
O4 - HKCU\..\Run: [NIRegistrationWizard] C:\Program Files (x86)\National Instruments\Shared\RegistrationWizard\Bin\RegistrationWizard.exe -autoDiscover 1 -displayIfNoneFound 0 -displayRegisterOptions 1 -sleepIfNoneFound 0 -locale 9
O4 - HKCU\..\Run: [EADM] "D:\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [1Password] "C:\Users\kedar\AppData\Local\1Password\app\7\1Password.exe" --silent
O4 - HKCU\..\Run: [Spotify] C:\Users\kedar\AppData\Roaming\Spotify\Spotify.exe --autostart --minimized
O4 - HKCU\..\RunOnce: [Application Restart #3] C:\Program Files\Razer\RzAppEngine\rzappengine.exe --application-host=apps.razer.com --start-hidden --no-sandbox --disable-gpu --disable-background-timer-throttling --disable-extensions --new-window --flag-switches-begin --flag-switches-end --file-url-path-alias="/gen=C:\Program Files\Razer\RzAppEngine\gen" --restore-last-session https://apps.razer.com/app-launcher/RzU ... utoStart=1
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Synapse3] C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe /StartMinimized (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Synapse3] C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe /StartMinimized (User 'Default user')
O4 - Startup: Peace.lnk = D:\Equalizer Apo\config\Peace.exe
O4 - Global Startup: NI Error Reporting (64-bit).lnk = C:\Program Files\National Instruments\Shared\NI Error Reporting\nierserver.exe
O4 - Global Startup: NI Error Reporting.lnk = C:\Program Files (x86)\National Instruments\Shared\NI Error Reporting\nierserver.exe
O4 - Global Startup: VIPM Service.lnk = C:\Program Files (x86)\JKI\VI Package Manager\support\VIPM Service.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\national instruments\shared\mdns responder\nimdnsnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Inc. - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AdobeUpdateService - Adobe Inc. - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
O23 - Service: Adobe Genuine Monitor Service (AGMService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
O23 - Service: AsusFanControlService - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsusFanControlService\1.04.01\AsusFanControlService.exe
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\Avast Software\Avast\aswidsagent.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\Avast Software\Avast\AvastSvc.exe
O23 - Service: Avast Firewall Service (avast! Firewall) - AVAST Software - C:\Program Files\Avast Software\Avast\afwServ.exe
O23 - Service: Avast Tools (avast! Tools) - AVAST Software - C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
O23 - Service: AvastWscReporter - AVAST Software - C:\Program Files\Avast Software\Avast\wsc_proxy.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_5026c - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Epic Online Services (EpicOnlineServices) - Epic Games, Inc. - C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe
O23 - Service: FACEITService - Unknown owner - E:\FACEIT AC\FACEITService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: NVIDIA FrameView SDK service (FvSvc) - NVIDIA - C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) (GoogleChromeElevationService) - Google LLC - C:\Program Files\Google\Chrome\Application\96.0.4664.45\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\WINDOWS\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_44dc4eefedc0d082\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\SysWOW64\Opcenum.exe
O23 - Service: Origin Client Service - Electronic Arts - D:\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - D:\Origin\OriginWebHelperService.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: Razer Chroma SDK Server - Razer Inc. - C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe
O23 - Service: Razer Chroma SDK Service - Razer Inc. - C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
O23 - Service: Razer Chroma Stream Server - Razer Inc. - C:\Program Files (x86)\Razer Chroma SDK\bin\RzChromaStreamServer.exe
O23 - Service: Razer Game Manager (Razer Game Manager Service) - Razer Inc - C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe
O23 - Service: Razer Synapse Service - Razer Inc. - C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe
O23 - Service: RogueKiller RTP (rkrtservice) - Unknown owner - C:\Program Files\RogueKiller\RogueKillerSvc.exe
O23 - Service: Rockstar Game Library Service (Rockstar Service) - Rockstar Games - E:\RockstarLauncher\RockstarService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Razer Central Service (RzActionSvc) - Razer Inc. - C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe
O23 - Service: Razer Surround Audio Service (RzSurroundVADStreamingService) - Unknown owner - C:\Program Files (x86)\Razer\Razer Surround\Driver\RzSurroundVADStreamingService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer - TeamViewer Germany GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: Uncheater for BattleGrounds_GL (ucldr_battlegrounds_gl) - Wellbia.com Co., Ltd. - C:\Program Files\Common Files\Uncheater\ucldr_battlegrounds_gl.exe
O23 - Service: UltraViewer Service (UltraViewService) - Unknown owner - C:\Program Files (x86)\UltraViewer\UltraViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: VirtualBox system service (VBoxSDS) - Oracle Corporation - E:\virtualbox\VBoxSDS.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: vgc - Riot Games, Inc. - C:\Program Files\Riot Vanguard\vgc.exe
O23 - Service: Cisco AnyConnect Secure Mobility Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: Wallpaper Engine Service - Unknown owner - E:\Steam\steamapps\common\wallpaper_engine\bin\wallpaperservice32_c.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Zakynthos Service (zksvc) - PUBG Corporation - C:\Program Files\Common Files\PUBG\zksvc.exe

--
End of file - 20103 bytes

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Poprosím o kontrolu  Vyřešeno

Příspěvekod jaro3 » 16 lis 2021 16:11

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

Stáhni si zde DelFix
Další odkazy:
https://toolslib.net/downloads/viewdownload/2-delfix/
http://ccm.net/download/download-24087-delfix
https://www.bleepingcomputer.com/download/delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7, 8 a10 musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

kedar700
Level 2
Level 2
Příspěvky: 157
Registrován: květen 13
Pohlaví: Muž
Stav:
Offline

Re: Poprosím o kontrolu

Příspěvekod kedar700 » 18 lis 2021 10:57

Děkuji za pomoc

# DelFix v1.013 - Logfile created 18/11/2021 at 10:52:31
# Updated 17/04/2016 by Xplode
# Username : kedar - KJODAR
# Operating System : Windows 10 Home (64 bits)

~ Removing disinfection tools ...

Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\zoek-results.log
Deleted : C:\zoek-results2021-11-08-203416.log
Deleted : C:\Users\kedar\OneDrive\Plocha\AdwCleaner.exe
Deleted : C:\Users\Public\Desktop\RogueKiller.lnk
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis

~ Cleaning system restore ...

Deleted : RP #86 [Naplánovaný kontrolní bod | 11/14/2021 16:37:54]

New restore point created !

########## - EOF - ##########


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 10 hostů