Prosím o kontrolu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod jaro3 » 26 srp 2015 08:48

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3296281421-397883660-745250294-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF NewTab: about:newtab
FF Extension: No Name - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\kbhmwv7t.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [not found]
Task: {1DF5E449-B1E8-4880-97CB-ABEB84305EA5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {C8425ED1-3EF2-4BD5-8797-4B6AD6A1A8E4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\100sexlinks.com -> 100sexlinks.com
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.


Zadej si téma v sekci "Problém s HW".
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
nermitus
Level 2
Level 2
Příspěvky: 210
Registrován: prosinec 14
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod nermitus » 26 srp 2015 09:30

Fix result of Farbar Recovery Scan Tool (x64) Version:25-08-2015
Ran by Marek (2015-08-26 09:24:44) Run:1
Running from C:\Users\Marek\Desktop
Loaded Profiles: Marek (Available Profiles: Marek)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3296281421-397883660-745250294-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF NewTab: about:newtab
FF Extension: No Name - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\kbhmwv7t.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [not found]
Task: {1DF5E449-B1E8-4880-97CB-ABEB84305EA5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {C8425ED1-3EF2-4BD5-8797-4B6AD6A1A8E4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-3296281421-397883660-745250294-1001\...\100sexlinks.com -> 100sexlinks.com
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
EmptyTemp:
End
*****************

Processes closed successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
Firefox "newtab" removed successfully
C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\kbhmwv7t.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi => path removed successfully"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1DF5E449-B1E8-4880-97CB-ABEB84305EA5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1DF5E449-B1E8-4880-97CB-ABEB84305EA5}" => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C8425ED1-3EF2-4BD5-8797-4B6AD6A1A8E4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C8425ED1-3EF2-4BD5-8797-4B6AD6A1A8E4}" => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008i.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008k.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\00hq.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0190-dialers.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\01i.info" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\02pmnzy5eo29bfk4.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\05p.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\07ic5do2myz3vzpk.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\08nigbmwk43i01y6.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\093qpeuqpmz6ebfa.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0calories.net" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0cj.net" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0scan.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-britney-spears-nude.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-domains-registrations.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-se.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1001movie.com" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1001night.biz" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\100gal.net" => key removed successfully
"HKU\S-1-5-21-3296281421-397883660-745250294-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\100sexlinks.com" => key removed successfully
MSCONFIG\Services: gupdate => 2 => Error: No automatic fix found for this entry.
MSCONFIG\Services: gupdatem => 3 => Error: No automatic fix found for this entry.
EmptyTemp: => 521.7 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 09:25:07 ====


PC sa zrýchlilo

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod jaro3 » 26 srp 2015 15:35

Stáhni si zde DelFix
https://toolslib.net/downloads/viewdownload/2-delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

nermitus
Level 2
Level 2
Příspěvky: 210
Registrován: prosinec 14
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod nermitus » 27 srp 2015 09:34

# DelFix v1.011 - Logfile created 27/08/2015 at 09:32:18
# Updated 18/08/2015 by Xplode
# Username : Marek - MAREK-PC
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\_OTL
Deleted : C:\FRST
Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\RegBackup
Deleted : C:\zoek-results.log
Deleted : C:\zoek-results2015-04-03-160629.log
Deleted : C:\zoek-results2015-06-27-093858.log
Deleted : C:\Users\Marek\Desktop\Addition.txt
Deleted : C:\Users\Marek\Desktop\Extras.Txt
Deleted : C:\Users\Marek\Desktop\Fixlog.txt
Deleted : C:\Users\Marek\Desktop\FRST.txt
Deleted : C:\Users\Marek\Desktop\FRST64.exe
Deleted : C:\Users\Marek\Desktop\HijackThis.exe
Deleted : C:\Users\Marek\Desktop\hijackthis.log
Deleted : C:\Users\Marek\Desktop\MBR.dat
Deleted : C:\Users\Marek\Desktop\OTL.Txt
Deleted : C:\Users\Marek\Desktop\OTL.exe
Deleted : C:\Users\Marek\Desktop\zoek-results.txt
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR

~ Cleaning system restore ...

Deleted : RP #164 [ComboFix created restore point | 08/25/2015 08:41:16]

New restore point created !

########## - EOF - ##########


Ešte sa chcem spýtať pár príspevkov dozadu bolo písane o založení témy ohladne hw čo konkrétne mám napísať?

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod jaro3 » 27 srp 2015 14:46

Napiš tam , jaké máš problémy a virama to není.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 73 hostů