Kontrola logu: Win:32 BitcoinMiner

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

jdvori
Level 1
Level 1
Příspěvky: 73
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Kontrola logu: Win:32 BitcoinMiner

Příspěvekod jdvori » 16 úno 2019 18:18

Dobrý den,
prosím o kontrolu logu - avast mi hlásí hrozbu Win32: BitCoinMiner-IW [Trj], ale neumí se s tím vypořádat natrvalo...
děkuji

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:11:05, on 16.02.2019
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17134.0001)


Boot mode: Normal

Running processes:
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Users\Rodinka\AppData\Local\Microsoft\OneDrive\OneDrive.exe
Q:\2018\Photo.scr
C:\Program Files (x86)\Simnet\Simple Sticky Notes\ssn.exe
C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
C:\Users\Rodinka\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo17win10.msn.com/?pc=LCTE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo17win10.msn.com/?pc=LCTE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [Print2PDF Print Monitor] "C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe" /server
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Rodinka\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [vidnotifier.exe] C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\vidnotifier\vidnotifier.exe
O4 - HKCU\..\Run: [Run] Q:\2018\Photo.scr
O4 - HKCU\..\Run: [Simple Sticky Notes] C:\Program Files (x86)\Simnet\Simple Sticky Notes\ssn.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: AtherosSvc - Unknown owner - C:\WINDOWS\system32\DRIVERS\AdminService.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastWscReporter - AVAST Software - C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7948ecc1af5c27e1\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7948ecc1af5c27e1\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Dolby DAX2 API Service - Dolby Laboratories, Inc. - C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google Inc. - C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.109\elevation_service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem21.inf,%iaStorAfsWindowsService.Name%;Intel(R) Optane(TM) Memory Service (iaStorAfsService) - Intel Corporation - C:\WINDOWS\IAStorAfsService\iaStorAfsService.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7948ecc1af5c27e1\igfxCUIService.exe
O23 - Service: @oem9.inf,%ImcSvcDisplayName%;System Interface Foundation Service (ImControllerService) - Lenovo Group Ltd. - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: PDFsam Manager - ANDREA VACONDIO - C:\ProgramData\ANDREA VACONDIO\PDFsam Manager\PDFsam Enhanced\PDFsam Manager.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wacom ISD Service (WTabletServiceISD) - Wacom Technology, Corp. - C:\Program Files\Tablet\ISD\WTabletServiceISD.exe
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\WINDOWS\system32\xbgmsvc.exe (file missing)
O23 - Service: @oem11.inf,%YMC.SvcDesc%;ymc (YMC) - Unknown owner - C:\WINDOWS\system32\ymc.exe (file missing)

--
End of file - 11281 bytes

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu: Win:32 BitcoinMiner

Příspěvekod jaro3 » 16 úno 2019 19:40

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
http://www.geekstogo.com/forum/files/fi ... -oldtimer/
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode
http://www.bleepingcomputer.com/download/adwcleaner/
http://www.adlice.com/downloadprogress/

Ulož si ho na svojí plochu . Klikni na „Souhlasím“ k povrzení podmínek.
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Skenování“
Po skenu se objeví log , který se otevře. ( jinak je uložen systémovem disku jako C:\AdwCleaner [C?].txt ), jeho obsah sem celý vlož.


Stáhni si Malwarebytes' Anti-Malware na plochu , nainstaluj a spusť ho
-Pokud není program aktuální , klikni na možnost „Aktualizovat nyní“ či „Opravit nyní“.
- bude nalezena aktualizace a nainstaluje se.
- poté klikni na Spustit skenování
- po proběhnutí skenu se ti objeví hláška vpravo dole, tak klikni na Zobrazit zprávu a vyber Export a vyber Kopírovat do schránky a vlož sem celý log. Nebo klikni na „Textový soubor ( .txt)“ a log si ulož.
-jinak se log nachází v programu po kliknutí na „Zprávy“ , nebo je uložen zde: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs

- po té klikni na tlačítko Dokončit, a program zavři křížkem vpravo nahoře.
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

jdvori
Level 1
Level 1
Příspěvky: 73
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu: Win:32 BitcoinMiner

Příspěvekod jdvori » 16 úno 2019 21:34

přes ATF a TFC jsem to protáhnul
nížel logy přes ADW Cleaner a Malwarebytes

ADW Cleaner:
# -------------------------------
# Malwarebytes AdwCleaner 7.2.7.0
# -------------------------------
# Build: 01-30-2019
# Database: 2019-02-15.6 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 02-16-2019
# Duration: 00:00:10
# OS: Windows 10 Home
# Scanned: 31826
# Detected: 18


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

Adware.pokki C:\Windows\ServiceProfiles\LocalService\AppData\Local\Host App Service
Adware.pokki C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Host App Service
Adware.pokki C:\ProgramData\Host App Service
Adware.pokki C:\Users\Rodinka\AppData\Local\Host App Service
PUP.Optional.Solvusoft C:\Users\Rodinka\AppData\Roaming\WinThruster

***** [ Files ] *****

Adware.pokki C:\Windows\System32\Tasks_Migrated\App Explorer

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

Adware.pokki C:\Windows\System32\Tasks\App Explorer

***** [ Registry ] *****

Adware.pokki HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
Adware.pokki HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
Adware.pokki HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
Adware.pokki HKCU\Software\Host App Service
Adware.pokki HKU\S-1-5-20\Software\Host App Service
Adware.pokki HKU\S-1-5-19\Software\Host App Service
Adware.pokki HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5E50EC24-47A6-40BC-AB9B-AD83336CB955}
Adware.pokki HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\App Explorer
PUP.Optional.Conduit HKCU\Software\Conduit
PUP.Optional.Conduit HKLM\Software\Wow6432Node\Conduit

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

PUP.Optional.Legacy jistebnice.cz

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.



########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########

Malwarebytes:
Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 16.02.19
Čas skenování: 21:28
Logovací soubor: 628d2b8a-3229-11e9-976d-000000000000.json

-Informace o softwaru-
Verze: 3.6.1.2711
Verze komponentů: 1.0.527
Aktualizovat verzi balíku komponent: 1.0.9298
Licence: Bezplatný

-Systémová informace-
OS: Windows 10 (Build 17134.590)
CPU: x64
Systém souborů: NTFS
Uživatel: DESKTOP-U600JNK\Rodinka

-Shrnutí skenování-
Typ skenování: Skenování hrozeb (Threat Scan)
Spuštění skenování: Ruční
Výsledek: Dokončeno
Skenované objekty: 291584
Zjištěné hrozby: 1
Hrozby umístěné do karantény: 0
Uplynulý čas: 1 min, 21 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Zakázáno
Heuristika: Povoleno
Potenciálně nežádoucí program: Detekovat
Potenciálně nežádoucí modifikace: Detekovat

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 1
PUP.Optional.BitCoinMiner, HKU\S-1-5-21-1393534132-704261357-4263535994-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|RUN, Žádná uživatelská akce, [1111], [324359],1.0.9298

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 0
(Nebyly zjištěny žádné škodlivé položky)

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)

WMI: 0
(Nebyly zjištěny žádné škodlivé položky)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu: Win:32 BitcoinMiner

Příspěvekod jaro3 » 16 úno 2019 22:35

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Skenování“ , po prohledání klikni na „ Čištění

Program provede opravu, po automatickém restartu klikni na „Log soubor“ a pak poklepej na odpovídají log, (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
https://downloads.malwarebytes.com/file/JRT-EOL
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.


. spusť znovu Malwarebytes' Anti-Malware a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Sophos Virus Removal Tool je praktický softwarový nástroj, který by mohl odstranit infekce, které antivirový program nedetekuje .
Stáhněte si ho zde z některého odkazu:
http://www.majorgeeks.com/files/details ... _tool.html
http://www.majorgeeks.com/mg/get/sophos ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,2.html

Viry mohou zpomalit počítač, nebo se snaží ukrást vaše data, a ani nevíte , že je máte. Co potřebujete, je rychlý a snadný způsob, jak je najít a zbavit se jich, pokud již máte antivirový program v počítači nainstalován , můžete nainstalovat i nástroj Sophos Virus Removal , který identifikuje a vyčistí zbylé infekce, které mohl Váš antivirový program přehlédnout.
K použití Sophos Virus Removal Tool na něj poklepejte a stiskněte tlačítko „Start scanning“ . Pak bude Sophos Virus Removal Tool vyhledávat a odstraňovat viry, které najde. Může být vyžadován restart.
Pokud byly nalezeny viry , tak po skenu klikni na „Details…“ a potom na „View log file“. Zkopíruj celý log a vlož ho sem. Potom zavři „threat detail“ a klikni na „Start cleanup“.
Jinak se log nachází zde:
C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.adlice.com/download/roguekil ... HlwZT14ODY
64bit.:
http://www.adlice.com/download/roguekil ... HlwZT14NjQ
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7,8,10 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Open Report “ , v okně pak na „Open TXT“ a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků

další odkazy:
http://www.adlice.com/download/roguekiller/
http://www.bleepingcomputer.com/download/roguekiller/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

jdvori
Level 1
Level 1
Příspěvky: 73
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu: Win:32 BitcoinMiner

Příspěvekod jdvori » 17 úno 2019 17:05

Tady je log z AdwCleaner a JRT

# -------------------------------
# Malwarebytes AdwCleaner 7.2.7.0
# -------------------------------
# Build: 01-30-2019
# Database: 2019-02-15.6 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 02-17-2019
# Duration: 00:00:03
# OS: Windows 10 Home
# Cleaned: 18
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\Windows\ServiceProfiles\LocalService\AppData\Local\Host App Service
Deleted C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Host App Service
Deleted C:\ProgramData\Host App Service
Deleted C:\Users\Rodinka\AppData\Local\Host App Service
Deleted C:\Users\Rodinka\AppData\Roaming\WinThruster

***** [ Files ] *****

Deleted C:\Windows\System32\Tasks_Migrated\App Explorer

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted C:\Windows\System32\Tasks\App Explorer

***** [ Registry ] *****

Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
Deleted HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
Deleted HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
Deleted HKCU\Software\Host App Service
Deleted HKU\S-1-5-20\Software\Host App Service
Deleted HKU\S-1-5-19\Software\Host App Service
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5E50EC24-47A6-40BC-AB9B-AD83336CB955}
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\App Explorer
Deleted HKCU\Software\Conduit
Deleted HKLM\Software\Wow6432Node\Conduit

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

Deleted jistebnice.cz

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [2664 octets] - [16/02/2019 21:26:18]
AdwCleaner[S01].txt - [2725 octets] - [17/02/2019 16:37:46]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########



JRT


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64
Ran by Rodinka (Administrator) on 17.02.2019 at 16:46:01,63
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 0




Registry: 1

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6EEB5862-FD8B-4472-8A32-39C0DC839FAA} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17.02.2019 at 16:49:07,58
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

jdvori
Level 1
Level 1
Příspěvky: 73
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu: Win:32 BitcoinMiner

Příspěvekod jdvori » 17 úno 2019 17:05

Malwarebytes

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 17.02.19
Čas skenování: 16:50
Logovací soubor: d08aa746-32cb-11e9-a4d5-000000000000.json

-Informace o softwaru-
Verze: 3.6.1.2711
Verze komponentů: 1.0.527
Aktualizovat verzi balíku komponent: 1.0.9308
Licence: Bezplatný

-Systémová informace-
OS: Windows 10 (Build 17134.590)
CPU: x64
Systém souborů: NTFS
Uživatel: DESKTOP-U600JNK\Rodinka

-Shrnutí skenování-
Typ skenování: Skenování hrozeb (Threat Scan)
Spuštění skenování: Ruční
Výsledek: Dokončeno
Skenované objekty: 291366
Zjištěné hrozby: 1
Hrozby umístěné do karantény: 1
Uplynulý čas: 1 min, 19 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Zakázáno
Heuristika: Povoleno
Potenciálně nežádoucí program: Detekovat
Potenciálně nežádoucí modifikace: Detekovat

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 1
PUP.Optional.BitCoinMiner, HKU\S-1-5-21-1393534132-704261357-4263535994-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|RUN, V karanténě, [1111], [324359],1.0.9308

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 0
(Nebyly zjištěny žádné škodlivé položky)

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)

WMI: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu: Win:32 BitcoinMiner

Příspěvekod jaro3 » 17 úno 2019 18:32

Ještě to další.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

jdvori
Level 1
Level 1
Příspěvky: 73
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu: Win:32 BitcoinMiner

Příspěvekod jdvori » 18 úno 2019 08:10

Sophos
2019-02-17 16:15:11.781 Sophos Virus Removal Tool version 2.7.0
2019-02-17 16:15:11.781 Copyright (c) 2009-2018 Sophos Limited. All rights reserved.

2019-02-17 16:15:11.781 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2019-02-17 16:15:11.781 Windows version 6.2 SP 0.0 build 9200 SM=0x300 PT=0x1 WOW64
2019-02-17 16:15:11.781 Checking for updates...
2019-02-17 16:15:11.794 Update progress: proxy server not available
2019-02-17 16:15:23.075 Downloading updates...
2019-02-17 16:15:23.080 Update progress: [I96736] sdds.svrt_v1.9: adding primary package C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED baseVersion=1
2019-02-17 16:15:23.081 Update progress: [I95020] sdds.svrt_v1.9: looking for packages included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2019-02-17 16:15:23.081 Update progress: [I22529] sdds.svrt_v1.9: looking for supplements included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2019-02-17 16:15:23.081 Update progress: [V81533] SU::createCachedPackageSource creating cached package source for http://d2.sophosupd.com/update-B: url=SOPHOS
2019-02-17 16:15:23.081 Update progress: [V81533] SU::createCachedPackageSource creating http_source_specific_data to download customer file
2019-02-17 16:15:23.081 Update progress: [V81533] SU::createCachedPackageSource creating package source to download customer file
2019-02-17 16:15:23.081 Update progress: [V81533] SU::createCachedPackageSource creating cached package source
2019-02-17 16:15:23.081 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.data0910.xml
2019-02-17 16:15:23.081 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.data0910.xml: 63 ms
2019-02-17 16:15:23.081 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 280b70327d216fa5dd5a8b20d37da3e7x000.xml: 3602 bytes
2019-02-17 16:15:23.081 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 280b70327d216fa5dd5a8b20d37da3e7x000.xml: 15 ms
2019-02-17 16:15:23.081 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 22b22fae5a5313548a92b2e81c349138x000.xml: 8673 bytes
2019-02-17 16:15:23.081 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 22b22fae5a5313548a92b2e81c349138x000.xml: 63 ms
2019-02-17 16:15:23.081 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE563/7d4dc0d1bc44fdf6136416ffe08d620ax000.xml: 590 bytes
2019-02-17 16:15:23.081 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE563/7d4dc0d1bc44fdf6136416ffe08d620ax000.xml: 47 ms
2019-02-17 16:15:23.081 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: SXLSUP/9658bb75e4104455fe802645d41af3dax000.xml: 598 bytes
2019-02-17 16:15:23.081 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: SXLSUP/9658bb75e4104455fe802645d41af3dax000.xml: 78 ms
2019-02-17 16:15:23.081 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE560/0167d8cf884d717c1779abc52d17cb71x000.xml: 601 bytes
2019-02-17 16:15:23.081 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE560/0167d8cf884d717c1779abc52d17cb71x000.xml: 31 ms
2019-02-17 16:15:23.081 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE557/13239828b0b1bf83de4692d775629148x000.xml: 601 bytes
2019-02-17 16:15:23.081 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE557/13239828b0b1bf83de4692d775629148x000.xml: 297 ms
2019-02-17 16:15:23.081 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE554/1883db40022af8cbc8fd680f1c4185ddx000.xml: 601 bytes
2019-02-17 16:15:23.081 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE554/1883db40022af8cbc8fd680f1c4185ddx000.xml: 203 ms
2019-02-17 16:15:23.081 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE550/1e04bd4f6cc5b189217b416d0cacd23ax000.xml: 601 bytes
2019-02-17 16:15:23.081 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE550/1e04bd4f6cc5b189217b416d0cacd23ax000.xml: 203 ms
2019-02-17 16:15:23.081 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE553/236bb4ca0d2561a8e59124e4a65837c9x000.xml: 601 bytes
2019-02-17 16:15:23.081 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE553/236bb4ca0d2561a8e59124e4a65837c9x000.xml: 203 ms
2019-02-17 16:15:23.081 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE558/3a1dfb2d23615d09497b1db3305e32dax000.xml: 601 bytes
2019-02-17 16:15:23.082 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE558/3a1dfb2d23615d09497b1db3305e32dax000.xml: 31 ms
2019-02-17 16:15:23.082 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE552/49e28e1f82adf19b43a3acfb11c919bax000.xml: 601 bytes
2019-02-17 16:15:23.082 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE552/49e28e1f82adf19b43a3acfb11c919bax000.xml: 110 ms
2019-02-17 16:15:23.082 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE551/69eda22632d06ac2df0c576c5946841fx000.xml: 601 bytes
2019-02-17 16:15:23.082 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE551/69eda22632d06ac2df0c576c5946841fx000.xml: 94 ms
2019-02-17 16:15:23.082 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE555/9f59846a02fa77254f4813df557d969bx000.xml: 601 bytes
2019-02-17 16:15:23.082 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE555/9f59846a02fa77254f4813df557d969bx000.xml: 187 ms
2019-02-17 16:15:23.082 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE559/bf3b91a4649162f3b240ef9f3d9d7c65x000.xml: 601 bytes
2019-02-17 16:15:23.082 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE559/bf3b91a4649162f3b240ef9f3d9d7c65x000.xml: 16 ms
2019-02-17 16:15:23.082 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE556/cd085cdff0109eb84b9c16d718521445x000.xml: 601 bytes
2019-02-17 16:15:23.082 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE556/cd085cdff0109eb84b9c16d718521445x000.xml: 15 ms
2019-02-17 16:15:23.082 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE561/26bd9165632f5b4c72035a920cfc88d1x000.xml: 1093 bytes
2019-02-17 16:15:23.082 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE561/26bd9165632f5b4c72035a920cfc88d1x000.xml: 47 ms
2019-02-17 16:15:23.082 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: IDE562/f8b505cfcfd635107447ac4c94e381acx000.xml: 9394 bytes
2019-02-17 16:15:23.082 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: IDE562/f8b505cfcfd635107447ac4c94e381acx000.xml: 31 ms
2019-02-17 16:15:23.082 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: ba14751b5438be1078ee14f0ee90c499x000.xml: 615 bytes
2019-02-17 16:15:23.082 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: ba14751b5438be1078ee14f0ee90c499x000.xml: 47 ms
2019-02-17 16:15:23.082 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 5e361cc2fc5444f3aac34cca3ecd82b4x000.xml: 320 bytes
2019-02-17 16:15:23.082 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 5e361cc2fc5444f3aac34cca3ecd82b4x000.xml: 32 ms
2019-02-17 16:15:23.082 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 0c458d84352f35f2b272f8b87e9f9576x000.xml: 753 bytes
2019-02-17 16:15:23.082 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 0c458d84352f35f2b272f8b87e9f9576x000.xml: 218 ms
2019-02-17 16:15:23.082 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 5c7f0eec8cb5f488397216dcfb7e98e8x000.xml: 331 bytes
2019-02-17 16:15:23.083 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 5c7f0eec8cb5f488397216dcfb7e98e8x000.xml: 172 ms
2019-02-17 16:15:23.083 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 5c518d5be60608ac6bd5325ef02b8a7ex000.xml: 1027 bytes
2019-02-17 16:15:23.083 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 5c518d5be60608ac6bd5325ef02b8a7ex000.xml: 63 ms
2019-02-17 16:15:23.083 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 211a9b2ae569945c9fe3e1ca74a2c644x000.xml: 338 bytes
2019-02-17 16:15:23.083 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 211a9b2ae569945c9fe3e1ca74a2c644x000.xml: 47 ms
2019-02-17 16:15:23.083 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 24be0fc59a0372038b7fbb3af3e19d21x000.xml: 1027 bytes
2019-02-17 16:15:23.083 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 24be0fc59a0372038b7fbb3af3e19d21x000.xml: 46 ms
2019-02-17 16:15:23.083 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: e4ccc0244dafdc3a404f8bb420c2a165x000.xml: 338 bytes
2019-02-17 16:15:23.083 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: e4ccc0244dafdc3a404f8bb420c2a165x000.xml: 16 ms
2019-02-17 16:15:23.083 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 1b5385d6d93fc43e87fc7d723b90aab9x000.xml: 1027 bytes
2019-02-17 16:15:23.083 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 1b5385d6d93fc43e87fc7d723b90aab9x000.xml: 94 ms
2019-02-17 16:15:23.083 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 44df079c17c27192400c73a86d16785fx000.xml: 338 bytes
2019-02-17 16:15:23.083 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 44df079c17c27192400c73a86d16785fx000.xml: 172 ms
2019-02-17 16:15:23.083 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 9e72c50dc4507dfba988367b178eda4ax000.xml: 1027 bytes
2019-02-17 16:15:23.083 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 9e72c50dc4507dfba988367b178eda4ax000.xml: 93 ms
2019-02-17 16:15:23.083 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: e0a2f9d4b770945eb817f82acf76dc76x000.xml: 338 bytes
2019-02-17 16:15:23.083 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: e0a2f9d4b770945eb817f82acf76dc76x000.xml: 94 ms
2019-02-17 16:15:23.083 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 4c204ac4b99df718739c309d0f4ab76bx000.xml: 1027 bytes
2019-02-17 16:15:23.083 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 4c204ac4b99df718739c309d0f4ab76bx000.xml: 94 ms
2019-02-17 16:15:23.083 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 46e9b0f78df0d20502af43f391ffc506x000.xml: 338 bytes
2019-02-17 16:15:23.083 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 46e9b0f78df0d20502af43f391ffc506x000.xml: 125 ms
2019-02-17 16:15:23.083 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 7fe1eebcf235024389043a634ef20366x000.xml: 1027 bytes
2019-02-17 16:15:23.083 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 7fe1eebcf235024389043a634ef20366x000.xml: 94 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 9ec625dcb3a242e1fece93286451a352x000.xml: 338 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 9ec625dcb3a242e1fece93286451a352x000.xml: 93 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: eaba289b0a9e187ed96137c42bf85645x000.xml: 1027 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: eaba289b0a9e187ed96137c42bf85645x000.xml: 125 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: e4e261308128b5b42bf54c232030ea27x000.xml: 338 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: e4e261308128b5b42bf54c232030ea27x000.xml: 79 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: d9072ffa19fc0ff71a828d7ca2bc7828x000.xml: 1027 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: d9072ffa19fc0ff71a828d7ca2bc7828x000.xml: 109 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 1d98051334b3ea8a0b042e0bb99bc283x000.xml: 338 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 1d98051334b3ea8a0b042e0bb99bc283x000.xml: 219 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 65b7509646b00610cf1732a01f49a46fx000.xml: 1027 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 65b7509646b00610cf1732a01f49a46fx000.xml: 15 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: f6ec5061dd7e77923111541727311aa2x000.xml: 338 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: f6ec5061dd7e77923111541727311aa2x000.xml: 47 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 4f4a648042a613c869eddf17703b772ax000.xml: 1027 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 4f4a648042a613c869eddf17703b772ax000.xml: 15 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: d86540a0b23bc7236508f5b443729232x000.xml: 338 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: d86540a0b23bc7236508f5b443729232x000.xml: 47 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 59c292069cc0fcbe6fbcf8d4289432a4x000.xml: 1027 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 59c292069cc0fcbe6fbcf8d4289432a4x000.xml: 47 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: ace8e7b646829af68be5b32bbcc82570x000.xml: 338 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: ace8e7b646829af68be5b32bbcc82570x000.xml: 63 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: ec903a8da18d2f78aad7ed6747b5ca0fx000.xml: 877 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: ec903a8da18d2f78aad7ed6747b5ca0fx000.xml: 47 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: a414dad5f30cd2486eca21c72bdca41fx000.xml: 338 bytes
2019-02-17 16:15:23.084 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: a414dad5f30cd2486eca21c72bdca41fx000.xml: 15 ms
2019-02-17 16:15:23.084 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: da92f17acb85d0a5bdb85ace75b37afcx000.xml: 1027 bytes
2019-02-17 16:15:23.085 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: da92f17acb85d0a5bdb85ace75b37afcx000.xml: 47 ms
2019-02-17 16:15:23.085 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: d2bd1911114961b92c55d33d6faa1a9ax000.xml: 338 bytes
2019-02-17 16:15:23.085 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: d2bd1911114961b92c55d33d6faa1a9ax000.xml: 16 ms
2019-02-17 16:15:23.085 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: edcfdadba6d9bdfb05e55b36513ab6fdx000.xml: 877 bytes
2019-02-17 16:15:23.085 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: edcfdadba6d9bdfb05e55b36513ab6fdx000.xml: 15 ms
2019-02-17 16:15:23.085 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: be2d272e2eaf16409234eef929bbcbf4x000.xml: 320 bytes
2019-02-17 16:15:23.085 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: be2d272e2eaf16409234eef929bbcbf4x000.xml: 219 ms
2019-02-17 16:15:23.085 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: b283c2a1edc6d282ce3cf6c7e70c08ffx000.xml: 877 bytes
2019-02-17 16:15:23.085 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: b283c2a1edc6d282ce3cf6c7e70c08ffx000.xml: 31 ms
2019-02-17 16:15:23.085 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 2a9fa65415b98ccfe349b1d69ba5386ex000.xml: 332 bytes
2019-02-17 16:15:23.085 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 2a9fa65415b98ccfe349b1d69ba5386ex000.xml: 47 ms
2019-02-17 16:15:23.085 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 06d08ca48fe39ceaefa5490a12237ce7x000.xml: 877 bytes
2019-02-17 16:15:23.085 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 06d08ca48fe39ceaefa5490a12237ce7x000.xml: 16 ms
2019-02-17 16:15:23.085 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: c6ab30ee1fffc286e5e0eda7ce9a9275x000.xml: 332 bytes
2019-02-17 16:15:23.085 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: c6ab30ee1fffc286e5e0eda7ce9a9275x000.xml: 47 ms
2019-02-17 16:15:23.085 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: b12a7e6a67fb1fe683761496f4d21e9ax000.xml: 877 bytes
2019-02-17 16:15:23.085 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: b12a7e6a67fb1fe683761496f4d21e9ax000.xml: 15 ms
2019-02-17 16:15:23.085 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: b7f2bde525cd31cacc334eb167efdbf2x000.xml: 332 bytes
2019-02-17 16:15:23.085 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: b7f2bde525cd31cacc334eb167efdbf2x000.xml: 16 ms
2019-02-17 16:15:23.085 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 99c5433ee4eb2bf1466e72561179719dx000.xml: 877 bytes
2019-02-17 16:15:23.085 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 99c5433ee4eb2bf1466e72561179719dx000.xml: 16 ms
2019-02-17 16:15:23.085 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 131960c0aba701c54cefbdf4fc56ca55x000.xml: 333 bytes
2019-02-17 16:15:23.085 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 131960c0aba701c54cefbdf4fc56ca55x000.xml: 46 ms
2019-02-17 16:15:23.086 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 1c8b9474cb2c400a5dc56a435e4823dex000.xml: 877 bytes
2019-02-17 16:15:23.086 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 1c8b9474cb2c400a5dc56a435e4823dex000.xml: 79 ms
2019-02-17 16:15:23.086 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 504dc4ec058545cd54d4e6b7a0f371a4x000.xml: 333 bytes
2019-02-17 16:15:23.086 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 504dc4ec058545cd54d4e6b7a0f371a4x000.xml: 312 ms
2019-02-17 16:15:23.086 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: f6ce3fa4b09824f025860e43dbb3b786x000.xml: 877 bytes
2019-02-17 16:15:23.086 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: f6ce3fa4b09824f025860e43dbb3b786x000.xml: 16 ms
2019-02-17 16:15:23.086 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 1d76c94dbb459f5fbd9244c61852ee1cx000.xml: 333 bytes
2019-02-17 16:15:23.086 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 1d76c94dbb459f5fbd9244c61852ee1cx000.xml: 15 ms
2019-02-17 16:15:23.086 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 295c0b0ebaecf6522eb6b096506d64fdx000.xml: 877 bytes
2019-02-17 16:15:23.086 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 295c0b0ebaecf6522eb6b096506d64fdx000.xml: 47 ms
2019-02-17 16:15:23.086 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 2327779aa9fd1d5bf663176f8ce6548ax000.xml: 333 bytes
2019-02-17 16:15:23.086 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 2327779aa9fd1d5bf663176f8ce6548ax000.xml: 16 ms
2019-02-17 16:15:23.086 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 4762ddee795dc2d05e543dfa8d0db4bdx000.xml: 877 bytes
2019-02-17 16:15:23.086 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 4762ddee795dc2d05e543dfa8d0db4bdx000.xml: 15 ms
2019-02-17 16:15:23.086 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: e0c3d47de18f0f7dd94a86d50075ec2dx000.xml: 333 bytes
2019-02-17 16:15:23.086 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: e0c3d47de18f0f7dd94a86d50075ec2dx000.xml: 16 ms
2019-02-17 16:15:23.086 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: ecbc5fc0266c3a8aae58e2a70d17d6d6x000.xml: 877 bytes
2019-02-17 16:15:23.086 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: ecbc5fc0266c3a8aae58e2a70d17d6d6x000.xml: 47 ms
2019-02-17 16:15:23.086 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 8025ea843b2e0ac244bbfdbadddc6b6ex000.xml: 333 bytes
2019-02-17 16:15:23.086 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 8025ea843b2e0ac244bbfdbadddc6b6ex000.xml: 62 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: b66fb064bdd10655d15d8d0c3145a615x000.xml: 877 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: b66fb064bdd10655d15d8d0c3145a615x000.xml: 16 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: ed0b7fd553a76053c7c5208c41efecdax000.xml: 335 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: ed0b7fd553a76053c7c5208c41efecdax000.xml: 47 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 517c50e9e4866c9043c54cffd1700660x000.xml: 877 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 517c50e9e4866c9043c54cffd1700660x000.xml: 16 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: cd97b6839f6fa0eca7f2724765a64193x000.xml: 335 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: cd97b6839f6fa0eca7f2724765a64193x000.xml: 31 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: f6907579760af73afb17b7c2d8313d54x000.xml: 877 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: f6907579760af73afb17b7c2d8313d54x000.xml: 15 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 85368e00e4c17377b24ec0d536b9fbcbx000.xml: 335 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 85368e00e4c17377b24ec0d536b9fbcbx000.xml: 16 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 11ab5cf8bcb7b592db734025725ada38x000.xml: 877 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 11ab5cf8bcb7b592db734025725ada38x000.xml: 16 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: ae9d46269570f3e130223bf7d37d1288x000.xml: 335 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: ae9d46269570f3e130223bf7d37d1288x000.xml: 47 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: cd359b31e41e414ec6bea002be5d7236x000.xml: 877 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: cd359b31e41e414ec6bea002be5d7236x000.xml: 16 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: fb534a5c0fefdc48458fd137ba2b1a01x000.xml: 335 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: fb534a5c0fefdc48458fd137ba2b1a01x000.xml: 31 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 97573c42af051ee3fc3a0c3af3826e59x000.xml: 877 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 97573c42af051ee3fc3a0c3af3826e59x000.xml: 16 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 7359fcef2451130ef318a69578eddbd4x000.xml: 335 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 7359fcef2451130ef318a69578eddbd4x000.xml: 16 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 834871f639a0b2177e03945576c3a24cx000.xml: 877 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 834871f639a0b2177e03945576c3a24cx000.xml: 47 ms
2019-02-17 16:15:23.087 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: b9b13cb991d674d8d286464ca7444112x000.xml: 335 bytes
2019-02-17 16:15:23.087 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: b9b13cb991d674d8d286464ca7444112x000.xml: 15 ms
2019-02-17 16:15:23.088 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 0a132dfd7c765f1fb8c4246ccd5c2e95x000.xml: 877 bytes
2019-02-17 16:15:23.088 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 0a132dfd7c765f1fb8c4246ccd5c2e95x000.xml: 16 ms
2019-02-17 16:15:23.088 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 9c3b5412bb2d93ea7ecb7d7b96164047x000.xml: 335 bytes
2019-02-17 16:15:23.088 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 9c3b5412bb2d93ea7ecb7d7b96164047x000.xml: 16 ms
2019-02-17 16:15:23.088 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 7b780aab08504f3f75cdb2376d2f59c8x000.xml: 1027 bytes
2019-02-17 16:15:23.088 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 7b780aab08504f3f75cdb2376d2f59c8x000.xml: 47 ms
2019-02-17 16:15:23.088 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 1b933448d04aeca6cd984f0566866b3bx000.xml: 335 bytes
2019-02-17 16:15:23.088 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 1b933448d04aeca6cd984f0566866b3bx000.xml: 15 ms
2019-02-17 16:15:23.088 Update progress: [I49502] sdds.data0910.xml: found supplement IDE560 LATEST path= baseVersion= [included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=]
2019-02-17 16:15:23.088 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE560 LATEST path=
2019-02-17 16:15:23.088 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE560 LATEST path=
2019-02-17 16:15:23.088 Update progress: [I49502] sdds.data0910.xml: found supplement IDE561 LATEST path= baseVersion= [included from product IDE560 LATEST path=]
2019-02-17 16:15:23.088 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE561 LATEST path=
2019-02-17 16:15:23.088 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE561 LATEST path=
2019-02-17 16:15:23.088 Update progress: [I49502] sdds.data0910.xml: found supplement IDE562 LATEST path= baseVersion= [included from product IDE561 LATEST path=]
2019-02-17 16:15:23.088 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE562 LATEST path=
2019-02-17 16:15:23.088 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE562 LATEST path=
2019-02-17 16:15:23.088 Update progress: [I49502] sdds.data0910.xml: found supplement IDE563 LATEST path= baseVersion= [included from product IDE562 LATEST path=]
2019-02-17 16:15:23.088 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE563 LATEST path=
2019-02-17 16:15:23.088 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE563 LATEST path=
2019-02-17 16:15:23.088 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2019-02-17 16:15:23.088 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 700ff02fecb20950178f12a9881c2002x000.xml: 80124 bytes
2019-02-17 16:15:23.088 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 700ff02fecb20950178f12a9881c2002x000.xml: 125 ms
2019-02-17 16:15:23.088 Update progress: [I19463] Product download size 213677536 bytes
2019-02-17 16:15:25.082 Option all = no
2019-02-17 16:15:25.082 Option recurse = yes
2019-02-17 16:15:25.082 Option archive = no
2019-02-17 16:15:25.082 Option service = yes
2019-02-17 16:15:25.082 Option confirm = yes
2019-02-17 16:15:25.082 Option sxl = yes
2019-02-17 16:15:25.089 Option max-data-age = 35
2019-02-17 16:15:25.089 Option vdl-logging = yes
2019-02-17 16:15:25.096 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2019-02-17 16:15:25.096 Machine ID: a1d3ba1bb1e844fe930c00677fa17513
2019-02-17 16:15:25.097 Component SVRTcli.exe version 2.7.0
2019-02-17 16:15:25.097 Component control.dll version 2.7.0
2019-02-17 16:15:25.097 Component SVRTservice.exe version 2.7.0
2019-02-17 16:15:25.097 Component engine\osdp.dll version 1.44.1.2420
2019-02-17 16:15:25.097 Component engine\veex.dll version 3.73.0.2420
2019-02-17 16:15:25.097 Component engine\savi.dll version 9.0.11.2420
2019-02-17 16:15:25.098 Component rkdisk.dll version 1.5.33.1
2019-02-17 16:15:25.098 Version info: Product version 2.7.0
2019-02-17 16:15:25.099 Version info: Detection engine 3.73.0
2019-02-17 16:15:25.099 Version info: Detection data 5.55
2019-02-17 16:15:25.099 Version info: Build date 18.09.2018
2019-02-17 16:15:25.099 Version info: Data files added 173
2019-02-17 16:15:25.099 Version info: Last successful update (not yet updated)
2019-02-17 16:15:38.737 Update progress: [I19463] Syncing product IDE560 LATEST path=
2019-02-17 16:15:38.752 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: de42a8b95fcd71194778ce516fe67c03x000.xml: 34911 bytes
2019-02-17 16:15:38.752 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: de42a8b95fcd71194778ce516fe67c03x000.xml: 187 ms
2019-02-17 16:15:38.752 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 8874591745bdf901816d305547be0140x000.xml: 397 bytes
2019-02-17 16:15:38.752 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 8874591745bdf901816d305547be0140x000.xml: 31 ms
2019-02-17 16:15:38.752 Update progress: [I19463] Product download size 3087691 bytes
2019-02-17 16:16:29.824 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 2c9a1fc09bec14e7b5cb0317aba69c75x000.xml: 5604 bytes
2019-02-17 16:16:29.824 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 2c9a1fc09bec14e7b5cb0317aba69c75x000.xml: 31 ms
2019-02-17 16:16:29.903 Update progress: [I19463] Syncing product IDE561 LATEST path=
2019-02-17 16:16:29.903 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 5e8b1c96389c03d34997fc6c11c632b7x000.xml: 27264 bytes
2019-02-17 16:16:29.903 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 5e8b1c96389c03d34997fc6c11c632b7x000.xml: 63 ms
2019-02-17 16:16:29.903 Update progress: [I19463] Product download size 2649016 bytes
2019-02-17 16:16:38.617 Update progress: [I19463] Syncing product IDE562 LATEST path=
2019-02-17 16:16:38.617 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 40d2240212a8f82a1bea5e198e2af5e6x000.xml: 4611 bytes
2019-02-17 16:16:38.622 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: 40d2240212a8f82a1bea5e198e2af5e6x000.xml: 16 ms
2019-02-17 16:16:38.622 Update progress: [I19463] Product download size 380187 bytes
2019-02-17 16:16:39.527 Update progress: [I19463] Syncing product IDE563 LATEST path=
2019-02-17 16:16:39.527 Update progress: [V52614] SU::LoggingAdvisor::start_file [metadata] Syncing: f430c089bf466bb070b959d79391e4c2x000.xml: 124 bytes
2019-02-17 16:16:39.527 Update progress: [V52615] SU::LoggingAdvisor::end_file [metadata] Success: f430c089bf466bb070b959d79391e4c2x000.xml: 203 ms
2019-02-17 16:16:39.584 Installing updates...
2019-02-17 16:16:40.218 Error level 1
2019-02-17 16:16:44.005 Update successful
2019-02-17 16:16:58.091 Option all = no
2019-02-17 16:16:58.091 Option recurse = yes
2019-02-17 16:16:58.091 Option archive = no
2019-02-17 16:16:58.091 Option service = yes
2019-02-17 16:16:58.091 Option confirm = yes
2019-02-17 16:16:58.091 Option sxl = yes
2019-02-17 16:16:58.091 Option max-data-age = 35
2019-02-17 16:16:58.091 Option vdl-logging = yes
2019-02-17 16:16:58.112 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2019-02-17 16:16:58.112 Machine ID: a1d3ba1bb1e844fe930c00677fa17513
2019-02-17 16:16:58.113 Component SVRTcli.exe version 2.7.0
2019-02-17 16:16:58.113 Component control.dll version 2.7.0
2019-02-17 16:16:58.114 Component SVRTservice.exe version 2.7.0
2019-02-17 16:16:58.114 Component engine\osdp.dll version 1.44.1.2443
2019-02-17 16:16:58.114 Component engine\veex.dll version 3.75.0.2443
2019-02-17 16:16:58.114 Component engine\savi.dll version 9.0.13.2443
2019-02-17 16:16:58.114 Component rkdisk.dll version 1.5.33.1
2019-02-17 16:16:58.114 Version info: Product version 2.7.0
2019-02-17 16:16:58.115 Version info: Detection engine 3.75.0
2019-02-17 16:16:58.115 Version info: Detection data 5.59
2019-02-17 16:16:58.115 Version info: Build date 15.01.2019
2019-02-17 16:16:58.115 Version info: Data files added 267
2019-02-17 16:16:58.115 Version info: Last successful update 17.02.2019 17:16:44

2019-02-17 16:21:19.078 Could not open C:\hiberfil.sys
2019-02-17 16:21:19.784 Could not open C:\pagefile.sys
2019-02-17 16:28:43.156 Could not open C:\swapfile.sys
2019-02-17 16:28:43.292 Could not open C:\System Volume Information\{0bd89f1b-32ca-11e9-823d-841af5b5c13b}{3808876b-c176-4e48-b7ae-04046e6cc752}
2019-02-17 16:28:43.292 Could not open C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
2019-02-17 16:28:43.293 Could not open C:\System Volume Information\{8722ab05-2284-11e9-8237-646e69dc13ea}{3808876b-c176-4e48-b7ae-04046e6cc752}
2019-02-17 16:28:43.293 Could not open C:\System Volume Information\{f1cbd200-2a2e-11e9-823a-646e69dc13ea}{3808876b-c176-4e48-b7ae-04046e6cc752}
2019-02-17 16:28:43.295 Could not open C:\System Volume Information\{f1cbecf6-2a2e-11e9-823a-646e69dc13ea}{3808876b-c176-4e48-b7ae-04046e6cc752}
2019-02-17 16:29:09.954 Could not open C:\Users\Rodinka\AppData\Local\Google\Chrome\User Data\Default\Current Session
2019-02-17 16:29:09.954 Could not open C:\Users\Rodinka\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
2019-02-17 16:29:37.921 Could not open C:\Users\Rodinka\AppData\Local\Microsoft\WindowsApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
2019-02-17 16:29:37.923 Could not open C:\Users\Rodinka\AppData\Local\Microsoft\WindowsApps\MicrosoftEdge.exe
2019-02-17 16:35:35.488 Could not open C:\Windows\System32\config\BBI
2019-02-17 16:35:35.551 Could not open C:\Windows\System32\config\RegBack\DEFAULT
2019-02-17 16:35:35.554 Could not open C:\Windows\System32\config\RegBack\SAM
2019-02-17 16:35:35.555 Could not open C:\Windows\System32\config\RegBack\SECURITY
2019-02-17 16:35:35.556 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
2019-02-17 16:35:35.557 Could not open C:\Windows\System32\config\RegBack\SYSTEM
2019-02-17 16:58:09.833 >>> Virus 'Troj/Miner-CZ' found in file D:\Photo.scr
2019-02-17 16:58:09.848 The following items will be cleaned up:
2019-02-17 16:58:09.848 Troj/Miner-CZ

jdvori
Level 1
Level 1
Příspěvky: 73
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu: Win:32 BitcoinMiner

Příspěvekod jdvori » 18 úno 2019 08:19

Rogue

RogueKiller Anti-Malware V13.1.4.0 (x64) [Feb 4 2019] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.17134) 64 bits
Started in : Normal mode
User : Rodinka [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20190204_072850, Driver : Loaded
Mode : Standard Scan, Scan -- Date : 2019/02/18 08:12:04 (Duration : 00:04:46)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> O87 - Firewall
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{34DF8A5A-EFF0-42F4-A959-2D45061940FC}C:\windows\kmsemulator.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|Profile=Public|App=C:\windows\kmsemulator.exe|Name=kmsemulator|Desc=kmsemulator|Defer=User| (C:\windows\kmsemulator.exe) (missing) -> Found
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{2289D58B-D0E9-4B3C-B38E-80025AC40D52}C:\windows\kmsemulator.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=C:\windows\kmsemulator.exe|Name=kmsemulator|Desc=kmsemulator|Defer=User| (C:\windows\kmsemulator.exe) (missing) -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu: Win:32 BitcoinMiner

Příspěvekod jaro3 » 18 úno 2019 18:35

Virus 'Troj/Miner-CZ' found in file D:\Photo.scrm -- podívej se , zda-li je to smazáno.

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“,
po jeho skončení - vše zatrhni (dej zatržítka vlevo od nálezů , do bílých políček)
- pak klikni na "Remove Selected"
- Počkej, dokud Status box nezobrazí " Removal finished, please review result "
- Klikni na "Open report " a pak na " Open TXT“ a zkopíruj ten log a vlož obsah té zprávy prosím sem. Log je možno nalézt v C:\ProgramData\RogueKiller\Logs - Zavři RogueKiller.

Stáhni si Zemana AntiMalware Free z tohoto odkazu:
https://www.zemana.com/Download/AntiMal ... .Setup.exe
a ulož si ho na plochu.
Poklepej na tento soubor na ploše a postupuj podle pokynů k instalaci programu.
Přijmi licenci k používání programu EULA , pokud se nabídne.
Pokud je k dispozici aktualizace programu , klepni na tlačítko „Update now“ ( aktualizovat nyní).
Můžeš si zatrhnout i vytvoření bodu obnovy:
Klikni na ozubené kolečko , poté na „Skenování“ a zatrhni „vytvářet body obnovy“.
Vrať se zpět ( klikni na domeček).
Zavři všechny otevřené soubory, složky a prohlížeče
Neměň žádné nastavení. Klikni na „Skenovat“.
Po skenu lze vidět , zda jsou nějaké nákazy. Klikni na „Další“. Nákazy budou přemístěny do karantény.
Když je skenování dokončeno, objeví se tisková zpráva , zkopíruj sem celý obsah té zprávy.
Jinak můžeš zprávy vidět , když klikneš vpravo nahoře na „ zprávy“.


Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

jdvori
Level 1
Level 1
Příspěvky: 73
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu: Win:32 BitcoinMiner

Příspěvekod jdvori » 18 úno 2019 20:20

File D:\Photo.scrm zmizelo

Zemana jsem spustil, našlo to dvě věci, které jsem dal do karantény, ale nešlo mi vygenerovat log...

Tady je nový report z roguekiller:

RogueKiller Anti-Malware V13.1.4.0 (x64) [Feb 4 2019] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.17134) 64 bits
Started in : Normal mode
User : Rodinka [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20190204_072850, Driver : Loaded
Mode : Standard Scan, Scan -- Date : 2019/02/18 20:06:46 (Duration : 00:04:54)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

jdvori
Level 1
Level 1
Příspěvky: 73
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu: Win:32 BitcoinMiner

Příspěvekod jdvori » 18 úno 2019 20:22

Nový Hijackthis níže, jinak já již žádné problémy nevnímám. Akorát ten stejný problém se mi objevil na síťovém disku (NASce). Je možné postupovat nějak obdobně při odstranění?
děkuji

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:20:52, on 18.02.2019
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17134.0001)


Boot mode: Normal

Running processes:
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Users\Rodinka\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Simnet\Simple Sticky Notes\ssn.exe
C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
C:\Users\Rodinka\Desktop\Cisteni\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo17win10.msn.com/?pc=LCTE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo17win10.msn.com/?pc=LCTE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [Print2PDF Print Monitor] "C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe" /server
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Rodinka\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [vidnotifier.exe] C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\vidnotifier\vidnotifier.exe
O4 - HKCU\..\Run: [Simple Sticky Notes] C:\Program Files (x86)\Simnet\Simple Sticky Notes\ssn.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: AtherosSvc - Unknown owner - C:\WINDOWS\system32\DRIVERS\AdminService.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastWscReporter - AVAST Software - C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7948ecc1af5c27e1\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7948ecc1af5c27e1\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Dolby DAX2 API Service - Dolby Laboratories, Inc. - C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google Inc. - C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.109\elevation_service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem21.inf,%iaStorAfsWindowsService.Name%;Intel(R) Optane(TM) Memory Service (iaStorAfsService) - Intel Corporation - C:\WINDOWS\IAStorAfsService\iaStorAfsService.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7948ecc1af5c27e1\igfxCUIService.exe
O23 - Service: @oem9.inf,%ImcSvcDisplayName%;System Interface Foundation Service (ImControllerService) - Lenovo Group Ltd. - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: PDFsam Manager - ANDREA VACONDIO - C:\ProgramData\ANDREA VACONDIO\PDFsam Manager\PDFsam Enhanced\PDFsam Manager.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wacom ISD Service (WTabletServiceISD) - Wacom Technology, Corp. - C:\Program Files\Tablet\ISD\WTabletServiceISD.exe
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\WINDOWS\system32\xbgmsvc.exe (file missing)
O23 - Service: @oem11.inf,%YMC.SvcDesc%;ymc (YMC) - Unknown owner - C:\WINDOWS\system32\ymc.exe (file missing)
O23 - Service: ZAM Controller Service (ZAMSvc) - Copyright 2018. - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe

--
End of file - 11236 bytes


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 4 hosti