Zase breberky

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Speed_dead
Level 6
Level 6
Příspěvky: 3213
Registrován: duben 10
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Zase breberky

Příspěvekod Speed_dead » 07 lis 2017 23:01

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Pro x64
Ran by User (Administrator) on Łt 07.11.2017 at 22:51:48,27
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 4

Successfully deleted: C:\ProgramData\mntemp (File)
Successfully deleted: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\eiimolhnbbbdagljikeckdkldgemmmlj (Folder)
Successfully deleted: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\obciceimmggglbmelaidpjlmodcebijb (Folder)
Successfully deleted: C:\Users\User\AppData\Roaming\productdata (Folder)



Registry: 1

Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\SWDUMon (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 07.11.2017 at 22:57:19,94
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Google ví skoro vše. Ale někdy je problém co tam napsat, aby to našlo to, co hledám.
Pokud se to nepovede, vypadne tuna nepoužitelných odkazů a nebo taky nic.

Reklama
Uživatelský avatar
Speed_dead
Level 6
Level 6
Příspěvky: 3213
Registrován: duben 10
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Zase breberky

Příspěvekod Speed_dead » 08 lis 2017 06:23

Nevěděl jsem, zda mám nalezený problémy smazat a tak jsem je nemazal. Kdyžtak to pustím ještě jednou.

RogueKiller V12.11.23.0 (x64) [Nov 6 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Webová stránka : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 10 (10.0.15063) 64 bits version
Spuštěno : Normální režim
Uživatel : User [Práva správce]
Started from : C:\Users\User\Desktop\RogueKiller_portable64.exe
Mód : Prohledat -- Datum : 11/07/2017 23:14:24 (Duration : 01:22:14)

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 2 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {3AE06E1C-F9C6-499E-82C3-1A7F27E9A4ED} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\ProgramData\NexonEU\NGM\NGM.exe|Name=Nexon Game Manager| [7] -> Nalezeno
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {32C74343-D610-45E3-99B1-A42AD366463B} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\ProgramData\NexonEU\NGM\NGM.exe|Name=Nexon Game Manager| [7] -> Nalezeno

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 4 ¤¤¤
[PUP.AutoIt.Gen][Soubor] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs\Settings Application.lnk [LNK@] C:\PROGRA~2\WIN7CO~1\Tools\SETTIN~1.EXE -> Nalezeno
[PUP.AutoIt.Gen][Soubor] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs\UNINSTALL.lnk [LNK@] C:\PROGRA~2\WIN7CO~1\Tools\SETTIN~1.EXE uninstall -> Nalezeno
[PUP.AutoIt.Gen][Soubor] C:\Program Files (x86)\Win7codecs\Tools\conflict.exe -> Nalezeno
[PUP.AutoIt.Gen][Soubor] C:\Program Files (x86)\Win7codecs\Tools\Settings32.exe -> Nalezeno

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD30EZRX-00MMMB0 ATA Device +++++
--- User ---
[MBR] 911d611a122b83e78ee99fca2ab3a784
[BSP] 0dfd37f6e2900d6a1a37d352ed26b40a : Empty MBR Code
Partition table:
0 - Microsoft reserved partition | Offset (sectors): 34 | Size: 128 MB
1 - Basic data partition | Offset (sectors): 264192 | Size: 2861459 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD20EZRZ-00Z5HB0 ATA Device +++++
--- User ---
[MBR] 5b5ce8b164007e8c6e48ab1696a0adfd
[BSP] 57027d4430434fcfe3cb055cf04be0bf : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1907727 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: KINGSTON SV300S37A120G ATA Device +++++
--- User ---
[MBR] d8066d361a04741da7f40e08eea7622a
[BSP] 5e66531f82ab49e1762bbb2f86d21edd : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 113921 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 233517056 | Size: 450 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive3: Generic USB SD Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive4: Generic USB CF Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive5: Generic USB SM Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive6: Generic USB MS Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
Google ví skoro vše. Ale někdy je problém co tam napsat, aby to našlo to, co hledám.
Pokud se to nepovede, vypadne tuna nepoužitelných odkazů a nebo taky nic.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Zase breberky

Příspěvekod jaro3 » 08 lis 2017 09:35

Sophos , nedal si log z něj , abysme viděli , co našel..
je zde:
C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“,
po jeho skončení - vše zatrhni (dej zatržítka vlevo od nálezů , do bílých políček)
- pak klikni na "Remove Selected"
- Počkej, dokud Status box nezobrazí " Removal finished, please review result "
- Klikni na "Open report " a pak na " Open TXT“ a zkopíruj ten log a vlož obsah té zprávy prosím sem. Log je možno nalézt v C:\ProgramData\RogueKiller\Logs - Zavři RogueKiller.


Vypni antivir i firewall.
Stáhni Zoek.exe
http://download.bleepingcomputer.com/smeenk/zoek.exe
http://leteckaposta.cz/415997425
klik nahoře vpravo na .rar-file a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;

klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log Zkopíruj sem celý obsah toho logu.
Pokud budou problémy , spusť zoek v nouz. režimu.

Vlož nový log z HJT + informuj o problémech.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Speed_dead
Level 6
Level 6
Příspěvky: 3213
Registrován: duben 10
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Zase breberky

Příspěvekod Speed_dead » 08 lis 2017 19:39

Omlouvám se, tady je:

2017-11-06 21:19:01.282 Sophos Virus Removal Tool version 2.6.1
2017-11-06 21:19:01.282 Copyright (c) 2009-2017 Sophos Limited. All rights reserved.

2017-11-06 21:19:01.282 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2017-11-06 21:19:01.282 Windows version 6.2 SP 0.0 build 9200 SM=0x100 PT=0x1 WOW64
2017-11-06 21:19:01.282 Checking for updates...
2017-11-06 21:19:01.340 Update progress: proxy server not available
2017-11-06 21:19:12.433 Option all = no
2017-11-06 21:19:12.433 Option recurse = yes
2017-11-06 21:19:12.433 Option archive = no
2017-11-06 21:19:12.434 Option service = yes
2017-11-06 21:19:12.434 Option confirm = yes
2017-11-06 21:19:12.434 Option sxl = yes
2017-11-06 21:19:12.435 Option max-data-age = 35
2017-11-06 21:19:12.435 Option vdl-logging = yes
2017-11-06 21:19:12.440 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2017-11-06 21:19:12.440 Machine ID: d16eb408d8a04e76bbc871713841589d
2017-11-06 21:19:12.441 Component SVRTcli.exe version 2.6.1
2017-11-06 21:19:12.442 Component control.dll version 2.6.1
2017-11-06 21:19:12.442 Component SVRTservice.exe version 2.6.1
2017-11-06 21:19:12.442 Component engine\osdp.dll version 1.44.1.2286
2017-11-06 21:19:12.442 Component engine\veex.dll version 3.68.6.2286
2017-11-06 21:19:12.442 Component engine\savi.dll version 9.0.7.2286
2017-11-06 21:19:12.443 Component rkdisk.dll version 1.5.31.1
2017-11-06 21:19:12.443 Version info: Product version 2.6.1
2017-11-06 21:19:12.443 Version info: Detection engine 3.68.6
2017-11-06 21:19:12.443 Version info: Detection data 5.44
2017-11-06 21:19:12.443 Version info: Build date 19.9.2017
2017-11-06 21:19:12.443 Version info: Data files added 353
2017-11-06 21:19:12.443 Version info: Last successful update (not yet updated)
2017-11-06 21:19:25.097 Downloading updates...
2017-11-06 21:19:25.100 Update progress: [I96736] sdds.svrt_10: adding primary package C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED baseVersion=1
2017-11-06 21:19:25.100 Update progress: [I95020] sdds.svrt_10: looking for packages included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2017-11-06 21:19:25.100 Update progress: [I22529] sdds.svrt_10: looking for supplements included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2017-11-06 21:19:25.100 Update progress: [I49502] sdds.savi0910.xml: found supplement SAVIW32 LATEST path= baseVersion= [included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=]
2017-11-06 21:19:25.100 Update progress: [I95020] sdds.savi0910.xml: looking for packages included from product SAVIW32 LATEST path=
2017-11-06 21:19:25.100 Update progress: [I22529] sdds.savi0910.xml: looking for supplements included from product SAVIW32 LATEST path=
2017-11-06 21:19:25.100 Update progress: [I49502] sdds.data0910.xml: found supplement IDE545 LATEST path= baseVersion= [included from product SAVIW32 LATEST path=]
2017-11-06 21:19:25.100 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE545 LATEST path=
2017-11-06 21:19:25.100 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE545 LATEST path=
2017-11-06 21:19:25.100 Update progress: [I49502] sdds.data0910.xml: found supplement IDE546 LATEST path= baseVersion= [included from product IDE545 LATEST path=]
2017-11-06 21:19:25.100 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE546 LATEST path=
2017-11-06 21:19:25.100 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE546 LATEST path=
2017-11-06 21:19:25.100 Update progress: [I49502] sdds.data0910.xml: found supplement IDE547 LATEST path= baseVersion= [included from product IDE546 LATEST path=]
2017-11-06 21:19:25.100 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE547 LATEST path=
2017-11-06 21:19:25.100 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE547 LATEST path=
2017-11-06 21:19:25.100 Update progress: [I49502] sdds.data0910.xml: found supplement IDE548 LATEST path= baseVersion= [included from product IDE547 LATEST path=]
2017-11-06 21:19:25.100 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE548 LATEST path=
2017-11-06 21:19:25.100 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE548 LATEST path=
2017-11-06 21:19:25.100 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2017-11-06 21:19:25.852 Update progress: [I19463] Syncing product SAVIW32 LATEST path=
2017-11-06 21:19:25.852 Update progress: [I19463] Product download size 174235198 bytes
2017-11-06 21:19:28.759 Update progress: [I19463] Syncing product IDE545 LATEST path=
2017-11-06 21:19:28.759 Update progress: [I19463] Product download size 2585002 bytes
2017-11-06 21:19:29.316 Update progress: [I19463] Syncing product IDE546 LATEST path=
2017-11-06 21:19:29.316 Update progress: [I19463] Product download size 3165416 bytes
2017-11-06 21:19:29.694 Update progress: [I19463] Syncing product IDE547 LATEST path=
2017-11-06 21:19:29.694 Update progress: [I19463] Product download size 304626 bytes
2017-11-06 21:19:29.738 Update progress: [I19463] Syncing product IDE548 LATEST path=
2017-11-06 21:19:29.769 Installing updates...
2017-11-06 21:19:30.372 Error level 1
2017-11-06 21:19:34.601 Update successful
2017-11-06 21:19:44.520 Option all = no
2017-11-06 21:19:44.520 Option recurse = yes
2017-11-06 21:19:44.520 Option archive = no
2017-11-06 21:19:44.520 Option service = yes
2017-11-06 21:19:44.520 Option confirm = yes
2017-11-06 21:19:44.520 Option sxl = yes
2017-11-06 21:19:44.521 Option max-data-age = 35
2017-11-06 21:19:44.521 Option vdl-logging = yes
2017-11-06 21:19:44.528 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2017-11-06 21:19:44.528 Machine ID: d16eb408d8a04e76bbc871713841589d
2017-11-06 21:19:44.528 Component SVRTcli.exe version 2.6.1
2017-11-06 21:19:44.529 Component control.dll version 2.6.1
2017-11-06 21:19:44.529 Component SVRTservice.exe version 2.6.1
2017-11-06 21:19:44.529 Component engine\osdp.dll version 1.44.1.2286
2017-11-06 21:19:44.529 Component engine\veex.dll version 3.68.6.2286
2017-11-06 21:19:44.529 Component engine\savi.dll version 9.0.7.2286
2017-11-06 21:19:44.530 Component rkdisk.dll version 1.5.31.1
2017-11-06 21:19:44.530 Version info: Product version 2.6.1
2017-11-06 21:19:44.530 Version info: Detection engine 3.68.6
2017-11-06 21:19:44.530 Version info: Detection data 5.44
2017-11-06 21:19:44.530 Version info: Build date 19.9.2017
2017-11-06 21:19:44.530 Version info: Data files added 353
2017-11-06 21:19:44.530 Version info: Last successful update 6.11.2017 22:19:34

2017-11-06 22:13:59.074 Could not open C:\swapfile.sys
2017-11-06 22:14:24.847 Could not open C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Current Session
2017-11-06 22:26:30.642 Could not open C:\Windows\System32\config\BBI
2017-11-06 22:26:30.667 Could not open C:\Windows\System32\config\DRIVERS
2017-11-06 22:26:30.674 Could not open C:\Windows\System32\config\RegBack\DEFAULT
2017-11-06 22:26:30.676 Could not open C:\Windows\System32\config\RegBack\SAM
2017-11-06 22:26:30.678 Could not open C:\Windows\System32\config\RegBack\SECURITY
2017-11-06 22:26:30.680 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
2017-11-06 22:26:30.683 Could not open C:\Windows\System32\config\RegBack\SYSTEM
2017-11-06 22:38:48.533 Could not open LOGICAL:0003:00000000
2017-11-06 22:38:48.539 Could not open D:\
2017-11-06 22:50:36.540 Could not check E:\ebook\Brown, Sandra - V žáru lásky.doc (corrupt)
2017-11-06 22:53:23.504 Could not check E:\ebook\Neff, Ondřej - Pravda o pekle.doc (corrupt)
2017-11-06 22:53:28.608 Could not check E:\ebook\ODKAZ_DR.DOC (corrupt)
2017-11-06 22:54:03.307 Could not check E:\ebook\Shakespeare, William - Komedie plná omylů.doc (corrupt)
2017-11-06 22:54:27.845 Could not check E:\ebook\VZNESEN5.DOC (corrupt)
2017-11-07 00:52:34.765 Could not check F:\= Záloha =\Home store 1\Věci z céčka\Program Files\No23 Recorder\No23Recorder.exe\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0000 (archive files nested too deeply)
2017-11-07 00:52:34.765 Could not check F:\= Záloha =\Home store 1\Věci z céčka\Program Files\No23 Recorder\No23Recorder.exe\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0000 (archive files nested too deeply)
2017-11-07 00:52:34.965 Could not check F:\= Záloha =\Home store 1\Věci z céčka\Program Files\No23 Recorder\No23Recorder.exe\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0000 (archive files nested too deeply)
2017-11-07 00:52:45.463 Could not check F:\= Záloha =\Home store 1\Věci z céčka\Program Files\No23 Recorder\No23Recorder.exe\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0000 (archive files nested too deeply)
2017-11-07 00:52:45.463 Could not check F:\= Záloha =\Home store 1\Věci z céčka\Program Files\No23 Recorder\No23Recorder.exe\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0002\FILE:0000 (archive files nested too deeply)
2017-11-07 00:54:58.526 >>> Virus 'Mal/Generic-S' found in file F:\= Záloha =\Home store 1\Věci z céčka\zaloha dokumenty - moznna jsou tu 2x\--- O D L O Ž E N O ---\Te\Filmy\centrum-notifikator-bobika.exe
2017-11-07 00:56:10.358 >>> Virus 'Mal/Generic-S' found in file F:\= Záloha =\Home store 1\Věci z céčka\zaloha dokumenty - moznna jsou tu 2x\--- O D L O Ž E N O ---\Te\Others\book\Asimov__Povidky.part1.exe
2017-11-07 01:01:41.132 >>> Virus 'Mal/Gendal-B' found in file F:\= Záloha =\Home store 1\Věci z céčka\zaloha dokumenty - moznna jsou tu 2x\Nokia\6600\Games\novinky 22x12\2\keygen.exe
2017-11-07 01:01:41.615 >>> Virus 'Mal/Gendal-B' found in file F:\= Záloha =\Home store 1\Věci z céčka\zaloha dokumenty - moznna jsou tu 2x\Nokia\6600\Games\novinky 22x12\Průzkumník.zip\eFileMan_v1.71/keygen.exe
2017-11-07 01:01:41.615 Disinfection not offered
2017-11-07 01:01:44.123 >>> Virus 'Mal/Gendal-B' found in file F:\= Záloha =\Home store 1\Věci z céčka\zaloha dokumenty - moznna jsou tu 2x\Nokia\6600\Průzkumník.zip\eFileMan_v1.71/keygen.exe
2017-11-07 01:01:44.123 Disinfection not offered
2017-11-07 02:10:58.534 Could not open LOGICAL:0006:00000000
2017-11-07 02:10:58.545 Could not open G:\
2017-11-07 02:10:58.551 Could not open LOGICAL:0007:00000000
2017-11-07 02:10:58.563 Could not open H:\
2017-11-07 02:10:58.571 Could not open LOGICAL:0008:00000000
2017-11-07 02:10:58.583 Could not open I:\
2017-11-07 02:10:58.590 Could not open LOGICAL:000A:00000000
2017-11-07 02:10:58.607 Could not open K:\
2017-11-07 02:10:58.994 Could not open PHYSICAL:0083:0000:0000:0001
2017-11-07 02:10:58.997 Could not open PHYSICAL:0084:0000:0000:0001
2017-11-07 02:10:59.001 Could not open PHYSICAL:0085:0000:0000:0001
2017-11-07 02:10:59.004 Could not open PHYSICAL:0086:0000:0000:0001
2017-11-07 02:10:59.007 The following items will be cleaned up:
2017-11-07 02:10:59.007 Mal/Generic-S
2017-11-07 02:10:59.007 Mal/Gendal-B
2017-11-07 02:10:59.007 Mal/Gendal-B
2017-11-07 02:10:59.007 Mal/Gendal-B
2017-11-07 06:28:51.976 Threat 'Mal/Generic-S' was not cleaned up. (error 0xa0040208)
2017-11-07 06:28:51.976 Removal failed
2017-11-07 06:30:33.929 Sophos Virus Removal Tool version 2.6.1
2017-11-07 06:30:33.930 Copyright (c) 2009-2017 Sophos Limited. All rights reserved.

2017-11-07 06:30:33.930 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2017-11-07 06:30:33.930 Windows version 6.2 SP 0.0 build 9200 SM=0x100 PT=0x1 WOW64
2017-11-07 06:30:33.930 Checking for updates...
2017-11-07 06:30:33.984 Update progress: proxy server not available
2017-11-07 06:31:07.227 Option all = no
2017-11-07 06:31:07.227 Option recurse = yes
2017-11-07 06:31:07.227 Option archive = no
2017-11-07 06:31:07.227 Option service = yes
2017-11-07 06:31:07.227 Option confirm = yes
2017-11-07 06:31:07.227 Option sxl = yes
2017-11-07 06:31:07.228 Option max-data-age = 35
2017-11-07 06:31:07.228 Option vdl-logging = yes
2017-11-07 06:31:07.247 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2017-11-07 06:31:07.247 Machine ID: d16eb408d8a04e76bbc871713841589d
2017-11-07 06:31:07.303 Component SVRTcli.exe version 2.6.1
2017-11-07 06:31:07.303 Component control.dll version 2.6.1
2017-11-07 06:31:07.304 Component SVRTservice.exe version 2.6.1
2017-11-07 06:31:07.304 Component engine\osdp.dll version 1.44.1.2286
2017-11-07 06:31:07.304 Component engine\veex.dll version 3.68.6.2286
2017-11-07 06:31:07.304 Component engine\savi.dll version 9.0.7.2286
2017-11-07 06:31:07.327 Component rkdisk.dll version 1.5.31.1
2017-11-07 06:31:07.327 Version info: Product version 2.6.1
2017-11-07 06:31:07.327 Version info: Detection engine 3.68.6
2017-11-07 06:31:07.327 Version info: Detection data 5.44
2017-11-07 06:31:07.327 Version info: Build date 19.9.2017
2017-11-07 06:31:07.327 Version info: Data files added 353
2017-11-07 06:31:07.328 Version info: Last successful update 6.11.2017 22:19:34
2017-11-07 06:31:12.959 Downloading updates...
2017-11-07 06:31:12.960 Update progress: [I96736] sdds.svrt_10: adding primary package C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED baseVersion=1
2017-11-07 06:31:12.961 Update progress: [I95020] sdds.svrt_10: looking for packages included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2017-11-07 06:31:12.961 Update progress: [I22529] sdds.svrt_10: looking for supplements included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2017-11-07 06:31:12.961 Update progress: [I49502] sdds.savi0910.xml: found supplement SAVIW32 LATEST path= baseVersion= [included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=]
2017-11-07 06:31:12.961 Update progress: [I95020] sdds.savi0910.xml: looking for packages included from product SAVIW32 LATEST path=
2017-11-07 06:31:12.961 Update progress: [I22529] sdds.savi0910.xml: looking for supplements included from product SAVIW32 LATEST path=
2017-11-07 06:31:12.961 Update progress: [I49502] sdds.data0910.xml: found supplement IDE545 LATEST path= baseVersion= [included from product SAVIW32 LATEST path=]
2017-11-07 06:31:12.961 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE545 LATEST path=
2017-11-07 06:31:12.961 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE545 LATEST path=
2017-11-07 06:31:12.961 Update progress: [I49502] sdds.data0910.xml: found supplement IDE546 LATEST path= baseVersion= [included from product IDE545 LATEST path=]
2017-11-07 06:31:12.961 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE546 LATEST path=
2017-11-07 06:31:12.961 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE546 LATEST path=
2017-11-07 06:31:12.961 Update progress: [I49502] sdds.data0910.xml: found supplement IDE547 LATEST path= baseVersion= [included from product IDE546 LATEST path=]
2017-11-07 06:31:12.961 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE547 LATEST path=
2017-11-07 06:31:12.961 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE547 LATEST path=
2017-11-07 06:31:12.961 Update progress: [I49502] sdds.data0910.xml: found supplement IDE548 LATEST path= baseVersion= [included from product IDE547 LATEST path=]
2017-11-07 06:31:12.961 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE548 LATEST path=
2017-11-07 06:31:12.961 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE548 LATEST path=
2017-11-07 06:31:12.961 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2017-11-07 06:31:23.125 Update progress: [I19463] Syncing product SAVIW32 LATEST path=
2017-11-07 06:31:32.407 Error level 1
2017-11-07 06:31:35.858 Update progress: [I19463] Syncing product IDE545 LATEST path=
2017-11-07 06:31:36.201 Update error: cancelled synchronise
Google ví skoro vše. Ale někdy je problém co tam napsat, aby to našlo to, co hledám.
Pokud se to nepovede, vypadne tuna nepoužitelných odkazů a nebo taky nic.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Zase breberky

Příspěvekod jaro3 » 08 lis 2017 20:44

2017-11-07 00:54:58.526 >>> Virus 'Mal/Generic-S' found in file F:\= Záloha =\Home store 1\Věci z céčka\zaloha dokumenty - moznna jsou tu 2x\--- O D L O Ž E N O ---\Te\Filmy\centrum-notifikator-bobika.exe
2017-11-07 00:56:10.358 >>> Virus 'Mal/Generic-S' found in file F:\= Záloha =\Home store 1\Věci z céčka\zaloha dokumenty - moznna jsou tu 2x\--- O D L O Ž E N O ---\Te\Others\book\Asimov__Povidky.part1.exe
2017-11-07 01:01:41.132 >>> Virus 'Mal/Gendal-B' found in file F:\= Záloha =\Home store 1\Věci z céčka\zaloha dokumenty - moznna jsou tu 2x\Nokia\6600\Games\novinky 22x12\2\keygen.exe
2017-11-07 01:01:41.615 >>> Virus 'Mal/Gendal-B' found in file F:\= Záloha =\Home store 1\Věci z céčka\zaloha dokumenty - moznna jsou tu 2x\Nokia\6600\Games\novinky 22x12\Průzkumník.zip\eFileMan_v1.71/keygen.exe
2017-11-07 01:01:41.615 Disinfection not offered
2017-11-07 01:01:44.123 >>> Virus 'Mal/Gendal-B' found in file F:\= Záloha =\Home store 1\Věci z céčka\zaloha dokumenty - moznna jsou tu 2x\Nokia\6600\Průzkumník.zip\eFileMan_v1.71/keygen.exe

to můžeš smazat sám..

udělej to další.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Speed_dead
Level 6
Level 6
Příspěvky: 3213
Registrován: duben 10
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Zase breberky

Příspěvekod Speed_dead » 09 lis 2017 07:36

RogueKiller V12.11.23.0 (x64) [Nov 6 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Webová stránka : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 10 (10.0.15063) 64 bits version
Spuštěno : Normální režim
Uživatel : User [Práva správce]
Started from : C:\Users\User\Desktop\RogueKiller_portable64.exe
Mód : Prohledat -- Datum : 11/09/2017 00:22:58 (Duration : 01:24:12)

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 2 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {3AE06E1C-F9C6-499E-82C3-1A7F27E9A4ED} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\ProgramData\NexonEU\NGM\NGM.exe|Name=Nexon Game Manager| [7] -> Nalezeno
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {32C74343-D610-45E3-99B1-A42AD366463B} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\ProgramData\NexonEU\NGM\NGM.exe|Name=Nexon Game Manager| [7] -> Nalezeno

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 4 ¤¤¤
[PUP.AutoIt.Gen][Soubor] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs\Settings Application.lnk [LNK@] C:\PROGRA~2\WIN7CO~1\Tools\SETTIN~1.EXE -> Nalezeno
[PUP.AutoIt.Gen][Soubor] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs\UNINSTALL.lnk [LNK@] C:\PROGRA~2\WIN7CO~1\Tools\SETTIN~1.EXE uninstall -> Nalezeno
[PUP.AutoIt.Gen][Soubor] C:\Program Files (x86)\Win7codecs\Tools\conflict.exe -> Nalezeno
[PUP.AutoIt.Gen][Soubor] C:\Program Files (x86)\Win7codecs\Tools\Settings32.exe -> Nalezeno

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: KINGSTON SV300S37A120G ATA Device +++++
--- User ---
[MBR] d8066d361a04741da7f40e08eea7622a
[BSP] 5e66531f82ab49e1762bbb2f86d21edd : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 113921 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 233517056 | Size: 450 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD30EZRX-00MMMB0 ATA Device +++++
--- User ---
[MBR] 911d611a122b83e78ee99fca2ab3a784
[BSP] 0dfd37f6e2900d6a1a37d352ed26b40a : Empty MBR Code
Partition table:
0 - Microsoft reserved partition | Offset (sectors): 34 | Size: 128 MB
1 - Basic data partition | Offset (sectors): 264192 | Size: 2861459 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: WDC WD20EZRZ-00Z5HB0 ATA Device +++++
--- User ---
[MBR] 5b5ce8b164007e8c6e48ab1696a0adfd
[BSP] 57027d4430434fcfe3cb055cf04be0bf : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1907727 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive3: Generic USB SD Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive4: Generic USB CF Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive5: Generic USB SM Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive6: Generic USB MS Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
Google ví skoro vše. Ale někdy je problém co tam napsat, aby to našlo to, co hledám.
Pokud se to nepovede, vypadne tuna nepoužitelných odkazů a nebo taky nic.

Uživatelský avatar
Speed_dead
Level 6
Level 6
Příspěvky: 3213
Registrován: duben 10
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Zase breberky

Příspěvekod Speed_dead » 09 lis 2017 07:39

Zoek a HTJ až se vrátím z práce.
Google ví skoro vše. Ale někdy je problém co tam napsat, aby to našlo to, co hledám.
Pokud se to nepovede, vypadne tuna nepoužitelných odkazů a nebo taky nic.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Zase breberky

Příspěvekod jaro3 » 09 lis 2017 09:24

OK.

Ještě jednou:
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“,
po jeho skončení - vše zatrhni (dej zatržítka vlevo od nálezů , do bílých políček)
- pak klikni na "Remove Selected"
- Počkej, dokud Status box nezobrazí " Removal finished, please review result "
- Klikni na "Open report " a pak na " Open TXT“ a zkopíruj ten log a vlož obsah té zprávy prosím sem. Log je možno nalézt v C:\ProgramData\RogueKiller\Logs - Zavři RogueKiller.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Speed_dead
Level 6
Level 6
Příspěvky: 3213
Registrován: duben 10
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Zase breberky

Příspěvekod Speed_dead » 09 lis 2017 20:26

Zoek.exe v5.0.0.1 Updated 24-October-2017
Tool run by User on źt 09.11.2017 at 20:13:48,04.
Microsoft Windows 10 Pro 10.0.15063 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\User\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2016-08-07-065034.log 16856 bytes
C:\zoek-results2016-08-08-043041.log 10147 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== FireFox Fix ======================

Deleted from C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\castzo37.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\castzo37.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\castzo37.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"Player@Wondershare.com"="C:\ProgramData\Wondershare\Player\Player@Wondershare.com" [24.07.2014 11:41]

==== Firefox Extensions ======================

ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\castzo37.default
- Undetermined - %ProfilePath%\extensions\sko-extension@firma.seznam.cz
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}

==== Firefox Plugins ======================

Profilepath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\castzo37.default
99E2145307150EB8AB78F4F888F97DBE - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll - Nexon Game Controller
D0621E248FE23302CB379AA664CA17ED - C:\ProgramData\id Software\QuakeLive\npquakezero.dll - QUAKE LIVE
546A28FBC44B984FD92530227BF6F5C2 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll - Shockwave for Director / Shockwave for Director


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{01C031E7-3980-4FAE-B3FE-E844FA9956AD} - http://www.firmy.cz/?q={searchTerms}&sourceid=QuickSearch_13415
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04
HKCU\SearchScopes\{116884F0-A27C-4A9F-982A-57A698549E4D} - http://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_13415
HKCU\SearchScopes\{29C6FC91-F846-42C8-9117-577D35E537D4} - http://www.novinky.cz/hledej?w={searchTerms}&sourceid=QuickSearch_13415
HKCU\SearchScopes\{3254011D-EC95-417E-8D5B-CED98F2CDDD6} - http://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_13415
HKCU\SearchScopes\{7B0F5D68-327A-4032-8864-19781DAFA3FF} - http://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_13415
HKCU\SearchScopes\{878526F5-4836-4BE7-B8E1-AA63CE97B9E5} - http://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_13415
HKCU\SearchScopes\{9F61494B-5357-4519-AE95-B6A68FEE40AC} - http://www.mapy.cz/?query={searchTerms}&sourceid=QuickSearch_13415

==== Reset Google Chrome ======================

C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\User\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\User\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\User\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\User\AppData\Local\Comodo\Dragon\User Data\Default\Cache emptied successfully
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=0 folders=0 0 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\User\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on źt 09.11.2017 at 20:21:06,01 ======================
Google ví skoro vše. Ale někdy je problém co tam napsat, aby to našlo to, co hledám.
Pokud se to nepovede, vypadne tuna nepoužitelných odkazů a nebo taky nic.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Zase breberky

Příspěvekod jaro3 » 09 lis 2017 21:47

prosím Tě , 2x jsem psal abys to v RK dal smazat a dal pak log , nikde ho nevidím..
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Speed_dead
Level 6
Level 6
Příspěvky: 3213
Registrován: duben 10
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Zase breberky

Příspěvekod Speed_dead » 10 lis 2017 07:28

Mazat nrbylo co.




RogueKiller V12.11.23.0 (x64) [Nov 6 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Webová stránka : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 10 (10.0.15063) 64 bits version
Spuštěno : Normální režim
Uživatel : User [Práva správce]
Started from : C:\Users\User\Desktop\RogueKiller_portable64.exe
Mód : Prohledat -- Datum : 11/09/2017 23:31:41 (Duration : 01:22:33)

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: KINGSTON SV300S37A120G ATA Device +++++
--- User ---
[MBR] d8066d361a04741da7f40e08eea7622a
[BSP] 5e66531f82ab49e1762bbb2f86d21edd : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 113921 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 233517056 | Size: 450 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD30EZRX-00MMMB0 ATA Device +++++
--- User ---
[MBR] 911d611a122b83e78ee99fca2ab3a784
[BSP] 0dfd37f6e2900d6a1a37d352ed26b40a : Empty MBR Code
Partition table:
0 - Microsoft reserved partition | Offset (sectors): 34 | Size: 128 MB
1 - Basic data partition | Offset (sectors): 264192 | Size: 2861459 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: WDC WD20EZRZ-00Z5HB0 ATA Device +++++
--- User ---
[MBR] 5b5ce8b164007e8c6e48ab1696a0adfd
[BSP] 57027d4430434fcfe3cb055cf04be0bf : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1907727 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive3: Generic USB SD Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive4: Generic USB CF Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive5: Generic USB SM Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive6: Generic USB MS Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
Google ví skoro vše. Ale někdy je problém co tam napsat, aby to našlo to, co hledám.
Pokud se to nepovede, vypadne tuna nepoužitelných odkazů a nebo taky nic.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Zase breberky

Příspěvekod jaro3 » 10 lis 2017 09:19

Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 6 hostů