Prosím o Kontrolu Logu-HijackThis Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

adios12
nováček
Příspěvky: 12
Registrován: červen 14
Pohlaví: Muž
Stav:
Offline

Re: Prosím o Kontrolu Logu-HijackThis

Příspěvekod adios12 » 10 zář 2014 09:04

aswMBR version 1.0.1.2041 Copyright(c) 2014 AVAST Software
Run date: 2014-09-10 08:34:36
-----------------------------
08:34:36.892 OS Version: Windows x64 6.1.7601 Service Pack 1
08:34:36.892 Number of processors: 4 586 0x503
08:34:36.892 ComputerName: GANDALF UserName: dady
08:34:52.573 Initialize success
08:34:52.721 VM: initialized successfully
08:34:52.736 VM: Amd CPU BiosDisabled
08:34:58.378 VM: not used
08:35:04.881 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000068
08:35:04.884 Disk 0 Vendor: ST332061 CC2J Size: 305245MB BusType: 3
08:35:04.886 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000069
08:35:04.890 Disk 1 Vendor: WDC_WD64 01.0 Size: 610480MB BusType: 3
08:35:04.895 Disk 2 \Device\Harddisk2\DR2 -> \Device\0000006b
08:35:04.899 Disk 2 Vendor: ST332062 3.AA Size: 305245MB BusType: 3
08:35:05.100 Disk 0 MBR read successfully
08:35:05.105 Disk 0 MBR scan
08:35:05.110 Disk 0 Windows 7 default MBR code
08:35:05.118 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 305242 MB offset 63
08:35:05.246 Disk 0 default boot code
08:35:05.539 Disk 0 scanning C:\Windows\system32\drivers
08:35:24.414 Service scanning
08:36:34.935 Modules scanning
08:36:34.941 Disk 0 trace - called modules:
08:36:34.955 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor.sys
08:36:34.959 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004559060]
08:36:34.963 3 CLASSPNP.SYS[fffff8800193a43f] -> nt!IofCallDriver -> [0xfffffa80036fa040]
08:36:34.968 5 ACPI.sys[fffff88000f257a1] -> nt!IofCallDriver -> \Device\00000068[0xfffffa80040d29c0]
08:36:34.971 Scan finished successfully
08:36:45.881 Disk 0 MBR has been saved successfully to "C:\Users\dady\Downloads\MBR.dat"
08:36:45.886 The log file has been saved successfully to "C:\Users\dady\Downloads\aswMBR.txt"


Zoek.exe v5.0.0.0 Updated 08-September-2014
Tool run by dady on st 10.09.2014 at 8:38:41,23.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\dady\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

10.9.2014 8:41:33 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3294375473-1623827402-248629090-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} deleted successfully
HKEY_USERS\S-1-5-21-3294375473-1623827402-248629090-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
HKEY_USERS\S-1-5-21-3294375473-1623827402-248629090-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-3294375473-1623827402-248629090-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\ADMINI~1\AppData\Roaming\Mozilla\Firefox\Profiles\subde8h1.default\prefs.js:

Added to C:\Users\ADMINI~1\AppData\Roaming\Mozilla\Firefox\Profiles\subde8h1.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\dady\AppData\Roaming\Mozilla\Firefox\Profiles\a34dafjb.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.seznam.cz/");
user_pref("keyword.URL", "");

Added to C:\Users\dady\AppData\Roaming\Mozilla\Firefox\Profiles\a34dafjb.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

==== Batch Command(s) Run By Tool======================

C:\Windows\system32\appdata deleted

==== Deleting Files \ Folders ======================

C:\Windows\syswow64\appdata deleted
C:\PROGRA~3\eSellerate deleted
C:\Users\dady\.android deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\PROGRA~2\SopCast deleted
C:\TeamViewer_Setup_cs.exe deleted
C:\Users\Administrator\AppData\Roaming\GetRightToGo deleted
C:\Users\dady\AppData\Roaming\GetRightToGo deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Administrator\AppData\Local\CrashRpt deleted
C:\Users\dady\AppData\Local\CrashRpt deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Windows\SysWow64\AI_RecycleBin deleted
C:\Users\Public\Desktop\YTD Video Downloader.lnk deleted
"C:\Windows\Installer\116984e.msi" deleted
"C:\Users\dady\AppData\Local\{337C94A0-BCEB-4813-B2AC-4990DBEDCE61}" deleted
"C:\Users\dady\AppData\Roaming\narg" deleted

==== Firefox Extensions ======================

ProfilePath: C:\Users\dady\AppData\Roaming\Mozilla\Firefox\Profiles\a34dafjb.default
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Battlefield Heroes Updater - %AppDir%\extensions\battlefieldheroespatcher@ea.com
- Battlefield Play4Free - %AppDir%\extensions\battlefieldplay4free@ea.com
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Adblock Plus - %AppDir%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\dady\AppData\Roaming\Mozilla\Firefox\Profiles\a34dafjb.default
4390CCD3790F8D9C427C0C29590C62D7 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash
0E8B2D0D9E3415A91EF259CE1112C579 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll - Shockwave for Director / Shockwave for Director
B33B016B77560C7832BF4D311EA23328 - C:\Users\dady\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
E7BC792810EC02DD1F7ED25D830E9324 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll - Shockwave Flash
87132527E2256CF6683A18C4EB34DD3B - C:\Windows\system32\Wat\npWatWeb.dll - Windows Activation Technologies


==== Chrome Look ======================

Seznam Lištička - Email - dady\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Seznam Lištička - Slovník - dady\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd
Battlefield Heroes - dady\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh
GFACE Experience Plugin - dady\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejdlfmdbdibkbfdpjocdaolcheehmpol
Grand Theft Auto V Theme - dady\AppData\Local\Google\Chrome\User Data\Default\Extensions\fifpefgiomhnkmkkcldjopjcfadhmhhn
Seznam Lištička - Rychlá volba - dady\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://search.daum.net/search?nil_profile=ie&ref_code=ms&q=%s"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{1AF8D6C5-B6DF-4C38-93CD-31A8619617B0} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_13415"

==== Reset Google Chrome ======================

C:\Users\dady\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\dady\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\75DEC8D2BDCC68D40978B3CBEAF8F822 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2D8CED57-CCDB-4D86-9087-3BBCAE8F8F22} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\75DEC8D2BDCC68D40978B3CBEAF8F822 deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\dady\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\dady\AppData\Local\Mozilla\Firefox\Profiles\a34dafjb.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\dady\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=157 folders=73 51484032 bytes)

==== Empty Temp Folders ======================

C:\Users\Administrator\AppData\Local\Temp emptied successfully
C:\Users\dady\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\dady\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on st 10.09.2014 at 9:01:02,71 ======================

Reklama
Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o Kontrolu Logu-HijackThis  Vyřešeno

Příspěvekod memphisto » 10 zář 2014 09:37

Problémy? Pokud ne, tak poprosím o zelenou fajku ;)
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

adios12
nováček
Příspěvky: 12
Registrován: červen 14
Pohlaví: Muž
Stav:
Offline

Re: Prosím o Kontrolu Logu-HijackThis

Příspěvekod adios12 » 10 zář 2014 11:47

O dost lepší :) Díky! Fajfku jsem dal všem co mi pomohli :)


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 115 hostů