prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

casperdeluxe
Level 3.5
Level 3.5
Příspěvky: 748
Registrován: duben 18
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod casperdeluxe » 24 pro 2018 08:49

2018-12-23 19:52:05.548 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 6d5b42261b0873d2548169c32a11d986x000.xml: 79124 bytes
2018-12-23 19:52:05.548 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 6d5b42261b0873d2548169c32a11d986x000.xml: 78 ms
2018-12-23 19:52:05.548 Update progress: [I19463] Product download size 207692565 bytes
2018-12-23 19:52:09.857 Update progress: [I19463] Syncing product IDE558 LATEST path=
2018-12-23 19:52:09.857 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 732041eb13cb23c2be762e60d5ab61c4x000.xml: 27989 bytes
2018-12-23 19:52:09.857 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 732041eb13cb23c2be762e60d5ab61c4x000.xml: 47 ms
2018-12-23 19:52:09.857 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 5df6d916ebd759c7de5e202e929fb4f0x000.xml: 397 bytes
2018-12-23 19:52:09.857 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 5df6d916ebd759c7de5e202e929fb4f0x000.xml: 16 ms
2018-12-23 19:52:09.857 Update progress: [I19463] Product download size 2892480 bytes
2018-12-23 19:52:21.480 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 7d0ca7a2cbca8feda6e9913168fe1f45x000.xml: 7881 bytes
2018-12-23 19:52:21.480 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 7d0ca7a2cbca8feda6e9913168fe1f45x000.xml: 15 ms
2018-12-23 19:52:21.528 Update progress: [I19463] Syncing product IDE559 LATEST path=
2018-12-23 19:52:21.528 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: ffe07b2c1d4a1c629a74c478bd79885dx000.xml: 28259 bytes
2018-12-23 19:52:21.528 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: ffe07b2c1d4a1c629a74c478bd79885dx000.xml: 32 ms
2018-12-23 19:52:21.528 Update progress: [I19463] Product download size 3964037 bytes
2018-12-23 19:52:27.767 Update progress: [I19463] Syncing product IDE560 LATEST path=
2018-12-23 19:52:27.767 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: d7f7e650cac46152671f92c070907f28x000.xml: 11796 bytes
2018-12-23 19:52:27.767 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: d7f7e650cac46152671f92c070907f28x000.xml: 16 ms
2018-12-23 19:52:27.767 Update progress: [I19463] Product download size 1257341 bytes
2018-12-23 19:52:30.105 Update progress: [I19463] Syncing product IDE561 LATEST path=
2018-12-23 19:52:30.105 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: f430c089bf466bb070b959d79391e4c2x000.xml: 124 bytes
2018-12-23 19:52:30.105 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: f430c089bf466bb070b959d79391e4c2x000.xml: 31 ms
2018-12-23 19:52:30.134 Installing updates...
2018-12-23 19:52:30.537 Error level 1
2018-12-23 19:52:34.777 Update successful
2018-12-23 19:52:39.393 Option all = no
2018-12-23 19:52:39.393 Option recurse = yes
2018-12-23 19:52:39.393 Option archive = no
2018-12-23 19:52:39.393 Option service = yes
2018-12-23 19:52:39.393 Option confirm = yes
2018-12-23 19:52:39.393 Option sxl = yes
2018-12-23 19:52:39.394 Option max-data-age = 35
2018-12-23 19:52:39.394 Option vdl-logging = yes
2018-12-23 19:52:39.397 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2018-12-23 19:52:39.397 Machine ID: 8e30c2bf579747bc85077426e0ee9eab
2018-12-23 19:52:39.397 Component SVRTcli.exe version 2.7.0
2018-12-23 19:52:39.397 Component control.dll version 2.7.0
2018-12-23 19:52:39.397 Component SVRTservice.exe version 2.7.0
2018-12-23 19:52:39.397 Component engine\osdp.dll version 1.44.1.2432
2018-12-23 19:52:39.397 Component engine\veex.dll version 3.74.1.2432
2018-12-23 19:52:39.397 Component engine\savi.dll version 9.0.12.2432
2018-12-23 19:52:39.397 Component rkdisk.dll version 1.5.33.1
2018-12-23 19:52:39.398 Version info: Product version 2.7.0
2018-12-23 19:52:39.398 Version info: Detection engine 3.74.1
2018-12-23 19:52:39.398 Version info: Detection data 5.57
2018-12-23 19:52:39.398 Version info: Build date 13.11.2018
2018-12-23 19:52:39.398 Version info: Data files added 272
2018-12-23 19:52:39.398 Version info: Last successful update 23.12.2018 20:52:34

2018-12-23 19:59:36.690 Error level 0

2018-12-23 19:59:44.492 Scan cancelled by user.
2018-12-23 19:59:44.492

------------------------------------------------------------

2018-12-24 07:11:56.296 Sophos Virus Removal Tool version 2.7.0
2018-12-24 07:11:56.296 Copyright (c) 2009-2018 Sophos Limited. All rights reserved.

2018-12-24 07:11:56.296 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2018-12-24 07:11:56.296 Windows version 6.2 SP 0.0 build 9200 SM=0x100 PT=0x1 WOW64
2018-12-24 07:11:56.296 Checking for updates...
2018-12-24 07:11:56.300 Update progress: proxy server not available
2018-12-24 07:11:58.777 Downloading updates...
2018-12-24 07:11:58.778 Update progress: [I96736] sdds.svrt_v1.8: adding primary package C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED baseVersion=1
2018-12-24 07:11:58.778 Update progress: [I95020] sdds.svrt_v1.8: looking for packages included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2018-12-24 07:11:58.778 Update progress: [I22529] sdds.svrt_v1.8: looking for supplements included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2018-12-24 07:11:58.778 Update progress: [V81533] SU::createCachedPackageSource creating cached package source for http://d2.sophosupd.com/update-B: url=SOPHOS
2018-12-24 07:11:58.778 Update progress: [V81533] SU::createCachedPackageSource creating http_source_specific_data to download customer file
2018-12-24 07:11:58.778 Update progress: [V81533] SU::createCachedPackageSource creating package source to download customer file
2018-12-24 07:11:58.778 Update progress: [V81533] SU::createCachedPackageSource creating cached package source
2018-12-24 07:11:58.778 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.data0910.xml
2018-12-24 07:11:58.778 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.data0910.xml: 63 ms
2018-12-24 07:11:58.778 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 486a71c32edd809193023ad1b94769b3x000.xml: 3170 bytes
2018-12-24 07:11:58.778 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 486a71c32edd809193023ad1b94769b3x000.xml: 16 ms
2018-12-24 07:11:58.778 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 46d80dcc91e6250a7367fedbb7e8c9c6x000.xml: 8673 bytes
2018-12-24 07:11:58.778 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 46d80dcc91e6250a7367fedbb7e8c9c6x000.xml: 15 ms
2018-12-24 07:11:58.778 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE560/c1b5dbc62572dd055aaa3ab749f79eb6x000.xml: 24094 bytes
2018-12-24 07:11:58.778 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE560/c1b5dbc62572dd055aaa3ab749f79eb6x000.xml: 16 ms
2018-12-24 07:11:58.778 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 24b6bcfcb58080be8b8922e1677f618ax000.xml: 877 bytes
2018-12-24 07:11:58.778 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 24b6bcfcb58080be8b8922e1677f618ax000.xml: 16 ms
2018-12-24 07:11:58.778 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 7215c21e642ae58e4b6000510253a102x000.xml: 877 bytes
2018-12-24 07:11:58.778 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 7215c21e642ae58e4b6000510253a102x000.xml: 31 ms
2018-12-24 07:11:58.778 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 53d0f24d0233dafd8b9cf3f143302384x000.xml: 336 bytes
2018-12-24 07:11:58.778 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 53d0f24d0233dafd8b9cf3f143302384x000.xml: 15 ms
2018-12-24 07:11:58.778 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 94a9e2c9cf5696c4ed4eb8af5d5031dbx000.xml: 1027 bytes
2018-12-24 07:11:58.778 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 94a9e2c9cf5696c4ed4eb8af5d5031dbx000.xml: 16 ms
2018-12-24 07:11:58.779 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: fea508f14fd1a16242f08d5301ff6d8cx000.xml: 336 bytes
2018-12-24 07:11:58.779 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: fea508f14fd1a16242f08d5301ff6d8cx000.xml: 16 ms
2018-12-24 07:11:58.779 Update progress: [I49502] sdds.data0910.xml: found supplement IDE558 LATEST path= baseVersion= [included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=]
2018-12-24 07:11:58.779 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE558 LATEST path=
2018-12-24 07:11:58.779 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE558 LATEST path=
2018-12-24 07:11:58.779 Update progress: [I49502] sdds.data0910.xml: found supplement IDE559 LATEST path= baseVersion= [included from product IDE558 LATEST path=]
2018-12-24 07:11:58.779 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE559 LATEST path=
2018-12-24 07:11:58.779 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE559 LATEST path=
2018-12-24 07:11:58.779 Update progress: [I49502] sdds.data0910.xml: found supplement IDE560 LATEST path= baseVersion= [included from product IDE559 LATEST path=]
2018-12-24 07:11:58.779 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE560 LATEST path=
2018-12-24 07:11:58.779 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE560 LATEST path=
2018-12-24 07:11:58.779 Update progress: [I49502] sdds.data0910.xml: found supplement IDE561 LATEST path= baseVersion= [included from product IDE560 LATEST path=]
2018-12-24 07:11:58.779 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE561 LATEST path=
2018-12-24 07:11:58.779 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE561 LATEST path=
2018-12-24 07:11:58.779 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2018-12-24 07:11:59.164 Update progress: [I19463] Syncing product IDE558 LATEST path=
2018-12-24 07:11:59.164 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: abd0d497e5d620a63049165b44932536x000.xml: 397 bytes
2018-12-24 07:11:59.164 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: abd0d497e5d620a63049165b44932536x000.xml: 15 ms
2018-12-24 07:11:59.164 Update progress: [I19463] Product download size 8075 bytes
2018-12-24 07:11:59.186 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: e79c09e657d9b323ee463804882a63c3x000.xml: 8075 bytes
2018-12-24 07:11:59.186 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: e79c09e657d9b323ee463804882a63c3x000.xml: 15 ms
2018-12-24 07:11:59.518 Update progress: [I19463] Syncing product IDE559 LATEST path=
2018-12-24 07:11:59.668 Update progress: [I19463] Syncing product IDE560 LATEST path=
2018-12-24 07:11:59.668 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: a2581cf91e3a77391fae93adaf90e1bcx000.xml: 12294 bytes
2018-12-24 07:11:59.668 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: a2581cf91e3a77391fae93adaf90e1bcx000.xml: 31 ms
2018-12-24 07:11:59.668 Update progress: [I19463] Product download size 33582 bytes
2018-12-24 07:11:59.715 Update progress: [I19463] Syncing product IDE561 LATEST path=
2018-12-24 07:11:59.741 Installing updates...
2018-12-24 07:12:02.937 Option all = no
2018-12-24 07:12:03.539 Option recurse = yes
2018-12-24 07:12:03.539 Option archive = no
2018-12-24 07:12:03.539 Option service = yes
2018-12-24 07:12:03.539 Option confirm = yes
2018-12-24 07:12:03.539 Option sxl = yes
2018-12-24 07:12:03.539 Option max-data-age = 35
2018-12-24 07:12:03.539 Option vdl-logging = yes
2018-12-24 07:12:03.539 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2018-12-24 07:12:03.539 Machine ID: ac995dbe40d045e0b203694acac01daa
2018-12-24 07:12:03.539 Component SVRTcli.exe version 2.7.0
2018-12-24 07:12:03.539 Component control.dll version 2.7.0
2018-12-24 07:12:03.539 Component SVRTservice.exe version 2.7.0
2018-12-24 07:12:03.539 Component engine\osdp.dll version 1.44.1.2420
2018-12-24 07:12:03.539 Component engine\veex.dll version 3.73.0.2420
2018-12-24 07:12:03.539 Component engine\savi.dll version 9.0.11.2420
2018-12-24 07:12:03.539 Component rkdisk.dll version 1.5.33.1
2018-12-24 07:12:03.539 Version info: Product version 2.7.0
2018-12-24 07:12:03.539 Version info: Detection engine 3.73.0
2018-12-24 07:12:03.539 Version info: Detection data 5.55
2018-12-24 07:12:03.539 Version info: Build date 18.09.2018
2018-12-24 07:12:03.539 Version info: Data files added 173
2018-12-24 07:12:03.539 Version info: Last successful update (not yet updated)
2018-12-24 07:12:03.539 Error level 1
2018-12-24 07:12:05.223 Update successful
2018-12-24 07:12:09.954 Option all = no
2018-12-24 07:12:09.954 Option recurse = yes
2018-12-24 07:12:09.954 Option archive = no
2018-12-24 07:12:09.954 Option service = yes
2018-12-24 07:12:09.954 Option confirm = yes
2018-12-24 07:12:09.954 Option sxl = yes
2018-12-24 07:12:09.955 Option max-data-age = 35
2018-12-24 07:12:09.955 Option vdl-logging = yes
2018-12-24 07:12:09.957 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2018-12-24 07:12:09.957 Machine ID: ac995dbe40d045e0b203694acac01daa
2018-12-24 07:12:09.957 Component SVRTcli.exe version 2.7.0
2018-12-24 07:12:09.957 Component control.dll version 2.7.0
2018-12-24 07:12:09.957 Component SVRTservice.exe version 2.7.0
2018-12-24 07:12:09.958 Component engine\osdp.dll version 1.44.1.2432
2018-12-24 07:12:09.958 Component engine\veex.dll version 3.74.1.2432
2018-12-24 07:12:09.958 Component engine\savi.dll version 9.0.12.2432
2018-12-24 07:12:09.958 Component rkdisk.dll version 1.5.33.1
2018-12-24 07:12:09.958 Version info: Product version 2.7.0
2018-12-24 07:12:09.958 Version info: Detection engine 3.74.1
2018-12-24 07:12:09.958 Version info: Detection data 5.57
2018-12-24 07:12:09.958 Version info: Build date 13.11.2018
2018-12-24 07:12:09.958 Version info: Data files added 274
2018-12-24 07:12:09.958 Version info: Last successful update 24.12.2018 8:12:05

2018-12-24 07:27:37.479 Could not open C:\hiberfil.sys
2018-12-24 07:27:37.502 Could not open C:\pagefile.sys
2018-12-24 07:30:59.218 Could not open C:\swapfile.sys
2018-12-24 07:30:59.240 Could not open C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-12-24 07:30:59.241 Could not open C:\System Volume Information\{d83c7f56-02e0-11e9-964d-2cfda1e2dcdc}{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-12-24 07:30:59.241 Could not open C:\System Volume Information\{e9bfbf73-06ea-11e9-9651-2cfda1e2dcdc}{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-12-24 07:30:59.241 Could not open C:\System Volume Information\{e9bfc187-06ea-11e9-9651-2cfda1e2dcdc}{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-12-24 07:31:15.004 Could not open C:\Users\Casper\AppData\Local\Microsoft\WindowsApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
2018-12-24 07:31:15.005 Could not open C:\Users\Casper\AppData\Local\Microsoft\WindowsApps\MicrosoftEdge.exe
2018-12-24 07:31:32.173 Could not open C:\Users\Casper\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\Local\Microsoft\OneDrive\OneDrive.exe
2018-12-24 07:31:32.192 Could not open C:\Users\Casper\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_BEB37ABADF39714871232B4792417E04
2018-12-24 07:31:32.192 Could not open C:\Users\Casper\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_D9817BD5013875AD517DA73475345203
2018-12-24 07:31:32.192 Could not open C:\Users\Casper\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_592839A8569F831D0F2306AE4BB5C24B
2018-12-24 07:31:32.193 Could not open C:\Users\Casper\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\Content\F6F92FBF4E8096C9272B135AF6140AA8_7A4E2A388EC0A74C0B0563A058DB29DE
2018-12-24 07:31:32.199 Could not open C:\Users\Casper\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_BEB37ABADF39714871232B4792417E04
2018-12-24 07:31:32.199 Could not open C:\Users\Casper\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_D9817BD5013875AD517DA73475345203
2018-12-24 07:31:32.200 Could not open C:\Users\Casper\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_592839A8569F831D0F2306AE4BB5C24B
2018-12-24 07:31:32.200 Could not open C:\Users\Casper\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F6F92FBF4E8096C9272B135AF6140AA8_7A4E2A388EC0A74C0B0563A058DB29DE
2018-12-24 07:31:41.865 Could not open C:\Users\Casper\AppData\Roaming\Opera Software\Opera Stable\Current Session
2018-12-24 07:31:41.865 Could not open C:\Users\Casper\AppData\Roaming\Opera Software\Opera Stable\Current Tabs
2018-12-24 07:33:55.707 Could not open C:\Windows\System32\config\BBI
2018-12-24 07:33:55.713 Could not open C:\Windows\System32\config\DRIVERS
2018-12-24 07:33:55.717 Could not open C:\Windows\System32\config\RegBack\DEFAULT
2018-12-24 07:33:55.717 Could not open C:\Windows\System32\config\RegBack\SAM
2018-12-24 07:33:55.717 Could not open C:\Windows\System32\config\RegBack\SECURITY
2018-12-24 07:33:55.718 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
2018-12-24 07:33:55.718 Could not open C:\Windows\System32\config\RegBack\SYSTEM
2018-12-24 07:41:24.208 >>> Virus 'Mal/Generic-S' found in file E:\RECYCLER\S-1-5-21-746137067-1425521274-1417001333-1004\Dk3\Assassins Creed 2 - Crack Fix Razor1911\Ubisoft Game Launcher\UbisoftGameLauncher.exe
2018-12-24 07:41:24.208 >>> Virus 'Mal/Generic-S' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
2018-12-24 07:41:24.208 >>> Virus 'Mal/Generic-S' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
2018-12-24 07:47:08.928 The following items will be cleaned up:
2018-12-24 07:47:08.928 Mal/Generic-S
Phanteks Enthoo Evolv X, Intel i7 12700KF, G.Skill TridentZ 4x8 4000 CL18, Asus ROG STRIX Z690-A Asus TUF RTX 3070, Phanteks Revolt X 1200, EKWB Custom loop, Samsung 970 PRO 1TB, Gigabyte Aorus Gen4 500GB, DELL Alienware AW3420DW, Corsair K95 Platinum, Steelseries Rival 600, Sennheiser GSP600, Sennheiser GSX1000

Reklama
casperdeluxe
Level 3.5
Level 3.5
Příspěvky: 748
Registrován: duben 18
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod casperdeluxe » 24 pro 2018 09:05

RogueKiller Anti-Malware V13.0.17.0 (x64) [Dec 17 2018] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.17134) 64 bits
Started in : Normal mode
User : Casper [Administrator]
Started from : C:\Users\Casper\Desktop\RogueKiller_portable64.exe
Mode : Standard Scan, Scan -- Date : 2018/12/24 09:01:41 (Duration : 00:02:22)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> O101 - Clsid
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_CLASSES_ROOT\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD} -- (Google Inc) "C:\Users\Casper\AppData\Local\Google\Chrome\Application\71.0.3578.98\notification_helper.exe" -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Phanteks Enthoo Evolv X, Intel i7 12700KF, G.Skill TridentZ 4x8 4000 CL18, Asus ROG STRIX Z690-A Asus TUF RTX 3070, Phanteks Revolt X 1200, EKWB Custom loop, Samsung 970 PRO 1TB, Gigabyte Aorus Gen4 500GB, DELL Alienware AW3420DW, Corsair K95 Platinum, Steelseries Rival 600, Sennheiser GSP600, Sennheiser GSX1000

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 24 pro 2018 17:01

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“,
po jeho skončení - vše zatrhni (dej zatržítka vlevo od nálezů , do bílých políček)
- pak klikni na "Remove Selected"
- Počkej, dokud Status box nezobrazí " Removal finished, please review result "
- Klikni na "Open report " a pak na " Open TXT“ a zkopíruj ten log a vlož obsah té zprávy prosím sem. Log je možno nalézt v C:\ProgramData\RogueKiller\Logs - Zavři RogueKiller.

Vypni antivir i firewall.
Stáhni Zoek.exe
http://download.bleepingcomputer.com/smeenk/zoek.exe

Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;

klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log Zkopíruj sem celý obsah toho logu.
Pokud budou problémy , spusť zoek v nouz. režimu.

Stáhni si Zemana AntiMalware Free z tohoto odkazu:
https://www.zemana.com/Download/AntiMal ... .Setup.exe
a ulož si ho na plochu.
Poklepej na tento soubor na ploše a postupuj podle pokynů k instalaci programu.
Přijmi licenci k používání programu EULA , pokud se nabídne.
Pokud je k dispozici aktualizace programu , klepni na tlačítko „Update now“ ( aktualizovat nyní).
Můžeš si zatrhnout i vytvoření bodu obnovy:
Klikni na ozubené kolečko , poté na „Skenování“ a zatrhni „vytvářet body obnovy“.
Vrať se zpět ( klikni na domeček).
Zavři všechny otevřené soubory, složky a prohlížeče
Neměň žádné nastavení. Klikni na „Skenovat“.
Po skenu lze vidět , zda jsou nějaké nákazy. Klikni na „Další“. Nákazy budou přemístěny do karantény.
Když je skenování dokončeno, objeví se tisková zpráva , zkopíruj sem celý obsah té zprávy.
Jinak můžeš zprávy vidět , když klikneš vpravo nahoře na „ zprávy“.


Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

casperdeluxe
Level 3.5
Level 3.5
Příspěvky: 748
Registrován: duben 18
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod casperdeluxe » 24 pro 2018 21:52

RogueKiller Anti-Malware V13.0.17.0 (x64) [Dec 17 2018] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.17134) 64 bits
Started in : Normal mode
User : Casper [Administrator]
Started from : C:\Users\Casper\Desktop\RogueKiller_portable64.exe
Mode : Standard Scan, Delete -- Date : 2018/12/24 21:51:12 (Duration : 00:02:16)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[Suspicious.Path (Potentially Malicious)] HKEY_CLASSES_ROOT\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD} -- [%localappdata%\Google\Chrome\Application\71.0.3578.98\notification_helper.exe] -> Deleted
Phanteks Enthoo Evolv X, Intel i7 12700KF, G.Skill TridentZ 4x8 4000 CL18, Asus ROG STRIX Z690-A Asus TUF RTX 3070, Phanteks Revolt X 1200, EKWB Custom loop, Samsung 970 PRO 1TB, Gigabyte Aorus Gen4 500GB, DELL Alienware AW3420DW, Corsair K95 Platinum, Steelseries Rival 600, Sennheiser GSP600, Sennheiser GSX1000

casperdeluxe
Level 3.5
Level 3.5
Příspěvky: 748
Registrován: duben 18
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod casperdeluxe » 24 pro 2018 22:05

Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by Casper on 24.12.2018 at 21:54:21,53.
Microsoft Windows 10 Pro 10.0.17134 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Casper\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

24.12.2018 21:55:00 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Ubisoft deleted successfully
C:\Program Files\Malwarebytes deleted successfully
C:\PROGRA~3\Malwarebytes deleted successfully
C:\PROGRA~3\SoftwareDistribution deleted successfully
C:\Users\Casper\AppData\Roaming\Movavi Video Converter 18 Premium deleted successfully
C:\Users\Casper\AppData\Local\DBG deleted successfully
C:\Users\Casper\AppData\Local\PeerDistRepub deleted successfully
C:\Users\Casper\AppData\Local\Ubisoft Game Launcher deleted successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Packages deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~2\Ubisoft not found
C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\Safer-Networking.log deleted
C:\PROGRA~3\Package Cache deleted

==== Chromium Look ======================

Chrome Media Router - Casper\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

==== Reset Google Chrome ======================

C:\Users\Casper\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Casper\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Casper\Appdata\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Casper\Appdata\Roaming\Opera Software\Opera Stable\Preferences.backup was reset successfully
C:\Users\Casper\Appdata\Roaming\Opera Software\Opera Stable\Secure Preferences was reset successfully
C:\Users\Casper\Appdata\Roaming\Opera Software\Opera Stable\Secure Preferences.backup was reset successfully
C:\Users\Casper\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Casper\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\Casper\Appdata\Roaming\Opera Software\Opera Stable\Web Data was reset successfully
C:\Users\Casper\Appdata\Roaming\Opera Software\Opera Stable\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Casper\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Casper\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Edge Cache ======================

Edge Cache Emptied Successfully

==== Empty Chrome Cache ======================

C:\Users\Casper\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Casper\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=62 folders=59 105897118 bytes)

==== Empty Temp Folders ======================

C:\Users\Casper\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Casper\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 24.12.2018 at 22:05:01,27 ======================
Phanteks Enthoo Evolv X, Intel i7 12700KF, G.Skill TridentZ 4x8 4000 CL18, Asus ROG STRIX Z690-A Asus TUF RTX 3070, Phanteks Revolt X 1200, EKWB Custom loop, Samsung 970 PRO 1TB, Gigabyte Aorus Gen4 500GB, DELL Alienware AW3420DW, Corsair K95 Platinum, Steelseries Rival 600, Sennheiser GSP600, Sennheiser GSX1000

casperdeluxe
Level 3.5
Level 3.5
Příspěvky: 748
Registrován: duben 18
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod casperdeluxe » 24 pro 2018 23:32

Zemana AntiMalware 2.74.2.150 (instalační verze)

-------------------------------------------------------
Scan Result : Dokončeno
Scan Date : 2018.12.24
Operating System : Windows 10 64-bit
Processor : 12X Intel(R) Core(TM) i7-8700 CPU @ 3.20GHz
BIOS Mode : UEFI
CUID : 14D7BCCFAAE177565CE027
Scan Type : Skenování systému
Duration : 0m 32s
Scanned Objects : 45521
Detected Objects : 1
Excluded Objects : 0
Read Level : SCSI
Auto Upload : Zapnuto
Detect All Extensions : Vypnuto
Scan Documents : Vypnuto
Domain Info : WORKGROUP,0,2

Detected Objects
-------------------------------------------------------

steam_api.dll
Status : Skenováno
Object : %userprofile%\desktop\ducktales_ remastered + čeština (no install)\steam_api.dll
MD5 : A19CEDFEB0D5FA3CFB2D350699C6A891
Publisher : -
Size : 295940
Version : -
Detection : PUA:Win32/SoftCrack.Gen
Cleaning Action : Karanténa
Related Objects :
Soubor - %userprofile%\desktop\ducktales_ remastered + čeština (no install)\steam_api.dll


Cleaning Result
-------------------------------------------------------
Cleaned : 1
Reported as safe : 0
Failed : 0
Phanteks Enthoo Evolv X, Intel i7 12700KF, G.Skill TridentZ 4x8 4000 CL18, Asus ROG STRIX Z690-A Asus TUF RTX 3070, Phanteks Revolt X 1200, EKWB Custom loop, Samsung 970 PRO 1TB, Gigabyte Aorus Gen4 500GB, DELL Alienware AW3420DW, Corsair K95 Platinum, Steelseries Rival 600, Sennheiser GSP600, Sennheiser GSX1000

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 25 pro 2018 17:03

Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

casperdeluxe
Level 3.5
Level 3.5
Příspěvky: 748
Registrován: duben 18
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod casperdeluxe » 25 pro 2018 17:26

Problémy zatím nejsou...Oni teda nebyly ani předtím nijak extra. Jen se občas stalo, že tam cosi vyskakovalo. Ale to dělalo třeba jeden den a pak třeba týden nic. Pak zas třeba den nebo dva a pak zase 3 dny nic. Prostě jak se tomu chtělo. Zeptám se ještě: Je nějakej dobrej antivir nebo nějaká niná ochrana, kterou byste mi doporučil? klidně i placená. Díky. Tady je log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:23:25, on 25.12.2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17134.0001)
CHROME: 71.0.3578.98

Boot mode: Normal

Running processes:
C:\Program Files (x86)\LightingService\1.00.42\AsRogAuraGpuDllServer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files\ASUSTeKcomputer.Inc\Sonic Suite 3\Foundation\SS3svc32.exe
C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
C:\Users\Casper\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Users\Casper\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\Users\Casper\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Casper\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Google Update] C:\Users\Casper\AppData\Local\Google\Update\1.3.33.23\GoogleUpdateCore.exe
O4 - HKCU\..\Run: [Ubisoft Game Launcher] "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe" -uplay_silent
O4 - HKCU\..\Run: [EpicGamesLauncher] "E:\fortnite\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://files.creative.com/Web/softwareu ... PIDPDE.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://files.creative.com/Web/softwareu ... /CTPID.cab
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightingService - ASUSTek Computer Inc. - C:\Program Files (x86)\LightingService\1.00.42\LightingService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001 (Sense) - Unknown owner - C:\Program Files (x86)\Windows Defender Advanced Threat Protection\MsSense.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\Windows\system32\SgrmBroker.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\Windows\system32\xbgmsvc.exe (file missing)
O23 - Service: ZAM Controller Service (ZAMSvc) - Copyright 2017. - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe

--
End of file - 9371 bytes
Phanteks Enthoo Evolv X, Intel i7 12700KF, G.Skill TridentZ 4x8 4000 CL18, Asus ROG STRIX Z690-A Asus TUF RTX 3070, Phanteks Revolt X 1200, EKWB Custom loop, Samsung 970 PRO 1TB, Gigabyte Aorus Gen4 500GB, DELL Alienware AW3420DW, Corsair K95 Platinum, Steelseries Rival 600, Sennheiser GSP600, Sennheiser GSX1000

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 25 pro 2018 18:16

Odinstaluj:
Spybot - Search & Destroy 2

Místo WD můžeš dát Avast , Comodo nebo Aviru ap.


Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O1 - Hosts: ::1 localhost
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)


Stáhni si zde DelFix
https://toolslib.net/downloads/viewdownload/2-delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt
Další odkazy:
http://ccm.net/download/download-24087-delfix
https://www.bleepingcomputer.com/download/delfix/

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

casperdeluxe
Level 3.5
Level 3.5
Příspěvky: 748
Registrován: duben 18
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu  Vyřešeno

Příspěvekod casperdeluxe » 26 pro 2018 09:07

# DelFix v1.013 - Logfile created 26/12/2018 at 09:06:39
# Updated 17/04/2016 by Xplode
# Username : Casper - DESKTOP-NRDI2Q2
# Operating System : Windows 10 Enterprise (64 bits)

~ Removing disinfection tools ...

Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\zoek-results.log
Deleted : C:\Users\Casper\Desktop\AdwCleaner.exe
Deleted : C:\Users\Casper\Desktop\adwcleaner_7.2.6.0.exe
Deleted : C:\Users\Casper\Desktop\JRT.exe
Deleted : C:\Users\Casper\Desktop\HijackThis.exe
Deleted : C:\Users\Casper\Desktop\hijackthis.log
Deleted : C:\Users\Casper\Desktop\RogueKiller_portable64.exe
Deleted : C:\Users\Casper\Desktop\TFC.exe
Deleted : C:\Users\Casper\Desktop\zoek.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis

~ Cleaning system restore ...

Deleted : RP #96 [Windows Update | 12/19/2018 19:31:51]
Deleted : RP #97 [JRT Pre-Junkware Removal | 12/23/2018 19:45:59]
Deleted : RP #98 [JRT Pre-Junkware Removal | 12/23/2018 19:48:52]
Deleted : RP #99 [zoek.exe restore point | 12/24/2018 20:54:56]

New restore point created !

########## - EOF - ##########
Phanteks Enthoo Evolv X, Intel i7 12700KF, G.Skill TridentZ 4x8 4000 CL18, Asus ROG STRIX Z690-A Asus TUF RTX 3070, Phanteks Revolt X 1200, EKWB Custom loop, Samsung 970 PRO 1TB, Gigabyte Aorus Gen4 500GB, DELL Alienware AW3420DW, Corsair K95 Platinum, Steelseries Rival 600, Sennheiser GSP600, Sennheiser GSX1000


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 3 hosti