Prosím o kontrolu logu- Sekání NTB a pomalý NTB Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
extrem
Level 4
Level 4
Příspěvky: 1256
Registrován: leden 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu- Sekání NTB a pomalý NTB

Příspěvekod extrem » 06 čer 2015 17:59

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Omi on so 06.06.2015 at 17:34:25,65.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Omi\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2015-06-06-153013.log 1296 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Electronic Arts deleted successfully
C:\PROGRA~2\GamePark deleted successfully
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~3\Ubisoft deleted successfully
C:\Users\Omi\AppData\Local\GHISLER deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Omi\AppData\Roaming\Mozilla\Firefox\Profiles\5fx9ip06.default\prefs.js:

Added to C:\Users\Omi\AppData\Roaming\Mozilla\Firefox\Profiles\5fx9ip06.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Electronic Arts not found
C:\PROGRA~2\GamePark not found
C:\PROGRA~2\Windows Live SkyDrive deleted
C:\Users\Omi\AppData\Local\HWVendorDetection.log deleted
C:\Users\Omi\AppData\Local\MyWinLockerInstaller.txt-20150210.log deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Omi\AppData\Roaming\Mozilla\Firefox\Profiles\5fx9ip06.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Omi\AppData\Roaming\Mozilla\Firefox\Profiles\5fx9ip06.default
9AE02005247DA91AB1743F5208DBEF76 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll - Shockwave Flash
FBF151BDF3156D1FEFD5E992D89D65CC - C:\Users\Omi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player


==== Chromium Look ======================

Bookmark Manager - Omi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik

==== Chromium Startpages ======================

C:\Users\Omi\AppData\Local\Google\Chrome\User Data\Default\Preferences
ot3dmX9xnn0KzoVc9gDOHSIkBLbkkr6Sp3LGXCCM4L0DJgxdFwaLr5WBzgC3y5x0/wwPIwN4PtIaK3BhH6njlksfnKwwIJ9iRT41V4BqbWu4mszO/7VJ3HJyw2DBpIc2grU9ZRRxrV3fRQG4wIDAQAB","manifest_version":2,"name":"Google Now","oauth2":{"auto_approve":true,"scopes":["https://www.googleapis.com/auth/googlenow"]},"optional_permissions":["background"],"permissions":["alarms","identity","metricsPrivate","notifications","pushMessaging","storage","tabs","webstorePrivate","*://*.google.com/*","*://*.gstatic.com/*","https://*.googleapis.com/chromenow/v1/*","https://*.googleusercontent.com/*"],"version":"1.2.0.1"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\40.0.2214.111\\resources\\google_now","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":false,"was_installed_by_oem":false},"pjkljhegncpnkpknbcohdijeoejaedia":{"ack_external":true,"active_permissions":{"api":["notifications"],"manifest_permissions":[]},"app_launcher_ordinal":"q","commands":{},"content_settings":[],"creation_flags":137,"events":[],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["notifications"],"manifest_permissions":[]},"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13072005363819610","lastpingday":"13078047597760270","location":1,"manifest":{"app":{"launch":{"container":"tab","web_url":"https://mail.google.com/mail/ca"},"urls":["*://mail.google.com/mail/ca"]},"current_locale":"cs","default_locale":"en","description":"Rychlý e-mail s možností vyhledávání a menším množstvím spamu.","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB","manifest_version":2,"name":"Gmail","options_page":"https://mail.google.com/mail/ca/#settings","permissions":["notifications"],"update_url":"http://clients2.google.com/service/update2/crx","version":"8.1"},"page_ordinal":"n","path":"pjkljhegncpnkpknbcohdijeoejaedia\\8.1_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false}}},"google":{"services":{"last_username":"extrremistacz@gmail.com","username":"extrremistacz@gmail.com"}},"homepage":"http://www.seznam.cz/","homepage_is_newtabpage":false,"pinned_tabs":[],"protection":{"macs":{"browser":{"show_home_button":"1C2A78D442A0FA9F7A6E52686AE80DA1322C3A50DA2B44F87C12EF416EF44A60"},"default_search_provider":{"keyword":"444ABDE0F74328FA9F6F0EC67CF82EBB656846B4F3F5188CBD42CFB314598D4F","name":"B871FC4147B62F1EA4922B3232C2BEC77463A822953A8DA6632E3D8C7FA47BAF","search_url":"61AF3906B928D24464DAF7AF13737A11686F993D1180CE43A62EAA5C262F442C"},"default_search_provider_data":{"template_url_data":"2417799DBD4D56A40DA37ABCBCB297D5F05719EE6B53140B961E176D24E8DDB2"},"extensions":{"settings":{"aapocclcgogkmnckokdopfmhonfmgoek":"125D48CA632E191390D6C01DD7A959482205A627294DA8D2F1D7DF61DAD1B1DE","ahfgeienlihckogmohjhadlkjgocpleb":"B278F7E738D5DCCC1E054D04A5503BE4C6073EFCB3A40C3E9BF031363C118715","aohghmighlieiainnegkcijnfilokake":"CB5A2068377FDB31FC900C1524BBA579E0D13CE2D30CEFF7AD0A6EAD6FFB308C","apdfllckaahabafndbhieahigkjlhalf":"667B05228D238CE6A8B67A60E7902D2DA9B11689C6EE5D0528CBA71A7A11A4E5","bepbmhgboaologfdajaanbcjmnhjmhfn":"543A5F63006466C8BEBC9DB85A870F5DDB27078F5F14255511225EC124E4A803","blpcfgokakmgnkcojhhkbfbldkacnbeo":"6ECD2AD03DCD8DFD6B8DBC8BF3DB10316DC320A51BF16670D8CF898FA78E7847","coobgpohoikkiipiblmjeljniedjpjpf":"220C16A8DBB93C776926B7708D6E90C30F309B21EE24FFE79D391A96F658B1AC","eemcgdkfndhakfknompkggombfjjjeno":"4A2CF48C58AA68162DC15167FC00D8E473B6FD4F687BB764F68AA451332154AA","ennkphjdgehloodpbhlhldgbnhmacadg":"33536E30CD25DE5AA2A919B7F2A02D812AEF6DC51A6EBA4C5A9DD0E3EC961998","felcaaldnbdncclmgdcncolpebgiejap":"7DCB1178724129BAE141904FCFC4A85F91A76B57F5A71B28AC45A1B72D2C6811","gfdkimpbcpahaombhbimeihdjnejgicl":"A4C7395576838266654E81704D7FF652F7EE7CBA7F4AC5BB1A07CECB3F5AEEB6","gmlllbghnfkpflemihljekbapjopfjik":"9FF3BCE9939DA620DA675036D7D8EAD505045279139E9B38696CBA5AFB4FB96D","kmendfapggjehodndflmmgagdbamhnfd":"31D08647F46B8349A4F9C0E98523B414099AEEFEB9836919E023CECF0EE2EF68","mfehgcgbbipciphmccgaenjidiccnmng":"BEAF93F89EE669031D0D850C7099715DD86AAB2342FC727090F668419686D7CB","mfffpogegjflfpflabcdkioaeobkgjik":"D4C9B305107781A4538F0328BCDCE8323927EF8118A07A648A3DA2D9504BD419","mgndgikekgjfcpckkfioiadnlibdjbkf":"0316342088765491AB94A6394290A0F1845663A34717EBCE252389E547433686","mhjfbmdgcfjbbpaeojofohoefgiehjai":"87E24731A0926F8141F289797DAA3C8E36E872DB21C9B7019CE74F273506E04B","neajdppkdcdipfabeoofebfddakdcjhd":"D431564DBEE78D120376D0F89D4CD66F10A3D93156BC7117D04B955B50E6472D","nkeimhogjdpnpccoofpliimaahmaaome":"D32BDAB32CD342751590696923A51497B59B68565AA2D0C5FDA4579DCB3797F3","nmmhkkegccagdldgiimedpiccmgmieda":"AA28A1396F60DF5C74BEC86428ED1E8C2BC9F65102C69F8EEBCA0622C5625C3B","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"F801808D43CD3FAA3DAF2750BD52A88A20AE3948B50FF56B4220D4BCDFF5A2F3","pjkljhegncpnkpknbcohdijeoejaedia":"ADF0963FD6C995F754E738F95B3D184BF3A5AC12B6E62215F48077E413AEF6AC"}},"google":{"services":{"last_username":"11CD05C6B928D92328C7C9C8151158CE7EC599DB565524BAA3B4DFB9A2E0F3F5","username":"00130D2BE521E6EC5E370E9C2CD936CE4EFC0121CBF82740928DE03817E2DE25"}},"homepage":"8B8A2538689B042A46121B5D7BAA11C317DF192B6F1AB359A2F297125C31F46C","homepage_is_newtabpage":"782F5D3A9FF9380B43ED5B1237D6D86872A3D4947C09C00D68B0C6812BA69928","pinned_tabs":"EACB90FC4E6CB477BB70B472EDA9D04C9F818F472A98E80D2F1F2D9D74494707","prefs":{"preference_reset_time":"E88D5D58DE4FFA031B9EBEA92991F3461F1E161C8B9AC51F0313EA8D0D58486E"},"profile":{"reset_prompt_memento":"B21153CEC8DF7F84C37714B16674410135AB07CA42C35507B0DF31AF17353582"},"safebrowsing":{"incidents_sent":"95B94DEBA72A78AC7C925EFEC363E8B94AD19F811645A34B545223EC9BA1721A"},"search_provider_overrides":"222107088DE267671CDCD0AB2D96B1935D55AD57C9C544A1883AF387A032C5C7","session":{"restore_on_startup":"B0467FB498D6E8649E590928A978CCD8217FE08C43EF345A774F3E54C2A39F97","startup_urls":"E8A1F0CA4705C1FA39F5B101C3FC19DDE7A38499A50B36D561A1D39D0B0EB0F4"},"software_reporter":{"prompt_reason":"A17058B6A040CF0F773D8B287C897A4ADDA4B52794909C0BA54C0016CDC530F2","prompt_seed":"58D3D1FCE7C36DC8987D193B8157AC12184478AC7140B1E282402097DBDDA2E5","prompt_version":"55DC0A3C55B34B40F05A74F490AF556C3C36A803662420E1E8F94F70452A6BBF"},"sync":{"remaining_rollback_tries":"9E8C4C7A89B7302D12F3B04E5E8DECBE2B95DA430B936FB38021B8FD62E9DDB7"}},"super_mac":"D73AEF090989B6B676E7909A89D73DDE1E45ACFEF73D9C1CD6BD64CE5C62A4BE"},"session":{"restore_on_startup":1,"startup_urls":["http://www.seznam.cz/"]},"sync":{"remaining_rollback_tries":0}}


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Old Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Old Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{67A2568C-7A0A-4EED-AECC-B5405DE63B64} Google Url="http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_csCZ627"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7"

==== Reset Google Chrome ======================

C:\Users\Omi\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Omi\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Omi\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Omi\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Omi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Omi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\Omi\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=4 folders=1 261361 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Omi\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Omi\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Omi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found

==== EOF on so 06.06.2015 at 17:57:20,80 ======================
Ryzen 5 5600, RX 6600XT. 16GB 3200 Mhz

Reklama
Uživatelský avatar
extrem
Level 4
Level 4
Příspěvky: 1256
Registrován: leden 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu- Sekání NTB a pomalý NTB

Příspěvekod extrem » 06 čer 2015 18:01

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:00:36, on 6.6.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)

FIREFOX: 37.0.2 (x86 cs)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Users\Omi\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10847 bytes
Ryzen 5 5600, RX 6600XT. 16GB 3200 Mhz

Uživatelský avatar
extrem
Level 4
Level 4
Příspěvky: 1256
Registrován: leden 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu- Sekání NTB a pomalý NTB

Příspěvekod extrem » 06 čer 2015 18:01

No , připadá mi , že už je PC po startu rychlejší ! :)
Ryzen 5 5600, RX 6600XT. 16GB 3200 Mhz

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu- Sekání NTB a pomalý NTB

Příspěvekod jaro3 » 06 čer 2015 18:19

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')


Stáhni si zde DelFix
https://toolslib.net/downloads/viewdownload/2-delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt

Vyčisti systém CCleanerem

Vše OK?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
extrem
Level 4
Level 4
Příspěvky: 1256
Registrován: leden 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu- Sekání NTB a pomalý NTB

Příspěvekod extrem » 06 čer 2015 18:29

# DelFix v1.010 - Logfile created 06/06/2015 at 18:27:38
# Updated 26/04/2015 by Xplode
# Username : Omi - OMI-PC
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\RegBackup
Deleted : C:\zoek-results.log
Deleted : C:\zoek-results2015-06-06-153013.log
Deleted : C:\Users\Omi\Desktop\JRT.exe
Deleted : C:\Users\Omi\Desktop\JRT.txt
Deleted : C:\Users\Omi\Desktop\RogueKillerX64.exe
Deleted : C:\Users\Omi\Desktop\zoek.exe
Deleted : C:\Users\Omi\Downloads\AdwCleaner.exe
Deleted : C:\Users\Omi\Downloads\JRT.exe
Deleted : C:\Users\Omi\Downloads\HijackThis.exe
Deleted : C:\Users\Omi\Downloads\hijackthis.log
Deleted : C:\Users\Omi\Downloads\RogueKillerX64.exe
Deleted : C:\Users\Omi\Downloads\TFC.exe
Deleted : C:\Users\Omi\Downloads\zoek.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis

~ Cleaning system restore ...

Deleted : RP #68 [Naplánovaný kontrolní bod | 05/22/2015 18:30:45]
Deleted : RP #69 [Installed Centrum zařízení Windows Mobile | 05/23/2015 15:22:41]
Deleted : RP #70 [Nainstalováno rozhraní DirectX | 05/27/2015 17:35:34]
Deleted : RP #71 [Removed Need for Speed™ SHIFT | 05/29/2015 15:37:29]
Deleted : RP #72 [Removed Skype™ 7.4 | 05/29/2015 15:40:46]
Deleted : RP #73 [Nainstalováno rozhraní DirectX | 05/29/2015 16:10:36]
Deleted : RP #74 [Naplánovaný kontrolní bod | 06/05/2015 18:08:35]
Deleted : RP #75 [zoek.exe restore point | 06/06/2015 15:26:11]

New restore point created !

########## - EOF - ##########
Ryzen 5 5600, RX 6600XT. 16GB 3200 Mhz

Uživatelský avatar
extrem
Level 4
Level 4
Příspěvky: 1256
Registrován: leden 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu- Sekání NTB a pomalý NTB

Příspěvekod extrem » 06 čer 2015 18:33

Prohlížeč se mi zrychlil a to o hodně ! Jen co na něj kliknu , tak naběhne. Kdyby se něco objevilo , tak znovu napíšu. Zatím tedy děkuji :)
Ryzen 5 5600, RX 6600XT. 16GB 3200 Mhz

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu- Sekání NTB a pomalý NTB

Příspěvekod jerabina » 06 čer 2015 18:43

Tak pokud je to doopravdy vše, můžeš dát vyřešeno - zelenou "fajfku" ;)
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 71 hostů