Re: Prosím o kontrolu logu HJT pc se vypíná Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT pc se vypíná

Příspěvekod jaro3 » 15 lis 2019 21:04

Log je celý? To je nákaz..
Ještě to další.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Re: Prosím o kontrolu logu HJT pc se vypíná

Příspěvekod standacich » 15 lis 2019 22:02

log by měl být celý a tady je ještě log RogueKiller


RogueKiller Anti-Malware V13.5.6.0 (x64) [Nov 7 2019] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : Ha?ís [Administrator]
Started from : C:\Users\Ha?ís\Desktop\RogueKiller_portable64.exe
Signatures : 20191114_090610, Driver : Loaded
Mode : Standard Scan, Scan -- Date : 2019/11/15 17:21:26 (Duration : 00:16:15)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> O23 - Services
[PUP.RelevantKnowledge (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RelevantKnowledge -- "C:\Program Files (x86)\RelevantKnowledge\rlservice.exe \service" (missing) -> Found
>>>>>> O87 - Firewall
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{F7D2B809-2EC5-47D7-BB05-6961C76CB7D0}C:\windows\temp\files\bin\kmss.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\windows\temp\files\bin\kmss.exe|Name=kmss.exe|Desc=kmss.exe|Defer=User| (C:\windows\temp\files\bin\kmss.exe) (missing) -> Found
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{0FDAAC88-A113-4BDC-9174-BFA7CA05001D}C:\windows\temp\files\bin\kmss.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\windows\temp\files\bin\kmss.exe|Name=kmss.exe|Desc=kmss.exe|Defer=User| (C:\windows\temp\files\bin\kmss.exe) (missing) -> Found
[PUP.RelevantKnowledge (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{CA4B3177-F82E-4387-9DCE-7BB5AEA22AE3} -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe|Name=rlvknlg.exe| (C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe) (missing) -> Found
[PUP.RelevantKnowledge (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{B84CCE16-1D95-48D1-ABC2-6F32C095705F} -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe|Name=rlvknlg.exe| (C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe) (missing) -> Found
[PUP.RelevantKnowledge (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{FA2A6849-A781-4DC6-BE12-8801112C7A02} -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe|Name=rlvknlg.exe| (C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe) (missing) -> Found
[PUP.RelevantKnowledge (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{57AD36E3-E6B3-47F1-8040-250694A3A728} -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe|Name=rlvknlg.exe| (C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe) (missing) -> Found
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{F7D2B809-2EC5-47D7-BB05-6961C76CB7D0}C:\windows\temp\files\bin\kmss.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\windows\temp\files\bin\kmss.exe|Name=kmss.exe|Desc=kmss.exe|Defer=User| (C:\windows\temp\files\bin\kmss.exe) (missing) -> Found
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{0FDAAC88-A113-4BDC-9174-BFA7CA05001D}C:\windows\temp\files\bin\kmss.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\windows\temp\files\bin\kmss.exe|Name=kmss.exe|Desc=kmss.exe|Defer=User| (C:\windows\temp\files\bin\kmss.exe) (missing) -> Found
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{F7D2B809-2EC5-47D7-BB05-6961C76CB7D0}C:\windows\temp\files\bin\kmss.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\windows\temp\files\bin\kmss.exe|Name=kmss.exe|Desc=kmss.exe|Defer=User| (C:\windows\temp\files\bin\kmss.exe) (missing) -> Found
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{0FDAAC88-A113-4BDC-9174-BFA7CA05001D}C:\windows\temp\files\bin\kmss.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\windows\temp\files\bin\kmss.exe|Name=kmss.exe|Desc=kmss.exe|Defer=User| (C:\windows\temp\files\bin\kmss.exe) (missing) -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[VT.Detected (Malicious)] (file) Fortnite MULTI-platform play 2018) PC game.vbs -- C:\Users\Ha?ís\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Fortnite MULTI-platform play 2018) PC game.vbs -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT pc se vypíná

Příspěvekod jaro3 » 15 lis 2019 22:59

Propána , kdes to pobral? :D

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“,
po jeho skončení - vše zatrhni (dej zatržítka vlevo od nálezů , do bílých políček)
- pak klikni na "Remove Selected"
- Počkej, dokud Status box nezobrazí " Removal finished, please review result "
- Klikni na "Open report " a pak na " Open TXT“ a zkopíruj ten log a vlož obsah té zprávy prosím sem. Log je možno nalézt v C:\ProgramData\RogueKiller\Logs - Zavři RogueKiller.

Vypni antivir i firewall.
Stáhni Zoek.exe
http://download.bleepingcomputer.com/smeenk/zoek.exe

Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;

klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log Zkopíruj sem celý obsah toho logu.
Pokud budou problémy , spusť zoek v nouz. režimu.

Stáhni si Zemana AntiMalware Free z tohoto odkazu:
https://www.zemana.com/Download/AntiMal ... .Setup.exe
a ulož si ho na plochu.
Poklepej na tento soubor na ploše a postupuj podle pokynů k instalaci programu.
Přijmi licenci k používání programu EULA , pokud se nabídne.
Pokud je k dispozici aktualizace programu , klepni na tlačítko „Update now“ ( aktualizovat nyní).
Můžeš si zatrhnout i vytvoření bodu obnovy:
Klikni na ozubené kolečko , poté na „Skenování“ a zatrhni „vytvářet body obnovy“.
Vrať se zpět ( klikni na domeček).
Zavři všechny otevřené soubory, složky a prohlížeče
Neměň žádné nastavení. Klikni na „Skenovat“.
Po skenu lze vidět , zda jsou nějaké nákazy. Klikni na „Další“. Nákazy budou přemístěny do karantény.
Když je skenování dokončeno, objeví se tisková zpráva , zkopíruj sem celý obsah té zprávy.
Jinak můžeš zprávy vidět , když klikneš vpravo nahoře na „ zprávy“.

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Re: Prosím o kontrolu logu HJT pc se vypíná

Příspěvekod standacich » 16 lis 2019 12:10

RogueKiller Anti-Malware V13.5.6.0 (x64) [Nov 7 2019] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : Ha?ís [Administrator]
Started from : C:\Users\Ha?ís\Desktop\RogueKiller_portable64.exe
Signatures : 20191115_125959, Driver : Loaded
Mode : Standard Scan, Delete Aborted -- Date : 2019/11/16 11:16:09 (Duration : 00:17:07)
Switches : -minimize

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.RelevantKnowledge (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RelevantKnowledge -- [%programfiles(x86)%\RelevantKnowledge\rlservice.exe \service] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{F7D2B809-2EC5-47D7-BB05-6961C76CB7D0}C:\windows\temp\files\bin\kmss.exe -- [%SystemRoot%\temp\files\bin\kmss.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{0FDAAC88-A113-4BDC-9174-BFA7CA05001D}C:\windows\temp\files\bin\kmss.exe -- [%SystemRoot%\temp\files\bin\kmss.exe] -> Deleted
[PUP.RelevantKnowledge (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{CA4B3177-F82E-4387-9DCE-7BB5AEA22AE3} -- [%programfiles(x86)%\RelevantKnowledge\rlvknlg.exe] -> Deleted
[PUP.RelevantKnowledge (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{B84CCE16-1D95-48D1-ABC2-6F32C095705F} -- [%programfiles(x86)%\RelevantKnowledge\rlvknlg.exe] -> Deleted
[PUP.RelevantKnowledge (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{FA2A6849-A781-4DC6-BE12-8801112C7A02} -- [%programfiles(x86)%\RelevantKnowledge\rlvknlg.exe] -> Deleted
[PUP.RelevantKnowledge (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{57AD36E3-E6B3-47F1-8040-250694A3A728} -- [%programfiles(x86)%\RelevantKnowledge\rlvknlg.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{F7D2B809-2EC5-47D7-BB05-6961C76CB7D0}C:\windows\temp\files\bin\kmss.exe -- [%SystemRoot%\temp\files\bin\kmss.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{0FDAAC88-A113-4BDC-9174-BFA7CA05001D}C:\windows\temp\files\bin\kmss.exe -- [%SystemRoot%\temp\files\bin\kmss.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{F7D2B809-2EC5-47D7-BB05-6961C76CB7D0}C:\windows\temp\files\bin\kmss.exe -- [%SystemRoot%\temp\files\bin\kmss.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{0FDAAC88-A113-4BDC-9174-BFA7CA05001D}C:\windows\temp\files\bin\kmss.exe -- [%SystemRoot%\temp\files\bin\kmss.exe] -> Deleted
[VT.Detected (Malicious)] Fortnite MULTI-platform play 2018) PC game.vbs -- %_Ha?ís_appdata%\Microsoft\Windows\Start Menu\Programs\Startup\Fortnite MULTI-platform play 2018) PC game.vbs -> Deleted

standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Re: Prosím o kontrolu logu HJT pc se vypíná

Příspěvekod standacich » 16 lis 2019 12:10

Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by Haźˇs on so 16.11.2019 at 11:19:16,19.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\HAS~1\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

16.11.2019 11:21:39 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Zemana AntiMalware deleted successfully
C:\Program Files\DVDFab 11 deleted successfully
C:\PROGRA~3\Freemake deleted successfully
C:\Users\Haźˇs\AppData\Local\GHISLER deleted successfully
C:\Users\Haźˇs\AppData\Local\Opera Software deleted successfully
C:\Users\Haźˇs\AppData\Local\Ubisoft Game Launcher deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\HAS~1\AppData\Roaming\Mozilla\Firefox\Profiles\liomqgv9.default-1524246403824\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\HAS~1\AppData\Roaming\Mozilla\Firefox\Profiles\liomqgv9.default-1524246403824\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\HAS~1\AppData\Roaming\Mozilla\Firefox\Profiles\rk8u8k6q.default-1538247061974\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\HAS~1\AppData\Roaming\Mozilla\Firefox\Profiles\rk8u8k6q.default-1538247061974\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Zemana AntiMalware not found
C:\Users\Hačís\.android not found
C:\Users\Hačís\AppData\Local\cache not found
C:\PROGRA~2\USB Disk Storage Format Tool deleted
C:\found.000 deleted
C:\PROGRA~3\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crash Bandicoot Collection 2016 deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\HAS~1\AppData\Roaming\Mozilla\Firefox\Profiles\liomqgv9.default-1524246403824
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\HAS~1\AppData\Roaming\Mozilla\Firefox\Profiles\rk8u8k6q.default-1538247061974
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

==== Firefox Plugins ======================


==== Fake Chromium Profiles Check ======================

Fake profile C:\Users\Hačís\AppData\Local\Google\Chrome deleted

==== Chromium Look ======================

Google Chrome Version: 78.0.3904.97


Chrome Media Router - DTI~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] not found

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"=""
HKLM\Wow6432Node\SearchScopes "DefaultScope"=""
HKCU\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

==== Reset Google Chrome ======================

Nothing found to reset

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Hačís\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Hačís\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Hačís\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\DTI~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=28 folders=21 319796925 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Hačís\AppData\Local\Temp emptied successfully
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Users\DTI~1\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\HAS~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found

==== EOF on so 16.11.2019 at 11:45:10,89 ======================

standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Re: Prosím o kontrolu logu HJT pc se vypíná

Příspěvekod standacich » 16 lis 2019 12:13

Log mi nevyjel tak jsem udelal screen zprávy :smile:

zemana.png
Naposledy upravil(a) standacich dne 16 lis 2019 12:15, celkem upraveno 1 x.

standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Re: Prosím o kontrolu logu HJT pc se vypíná

Příspěvekod standacich » 16 lis 2019 12:14

ComboFix 19-11-04.01 - Hačís 16.11.2019 11:57:14.3.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.4024.2669 [GMT 1:00]
Spuštěný z: c:\users\HaŔÝs\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\crash bandicoot collection\plugins\Desktop_.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2019-10-16 do 2019-11-16 )))))))))))))))))))))))))))))))
.
.
2019-11-16 11:06 . 2019-11-16 11:06 -------- d-----w- c:\users\Public\AppData\Local\temp
2019-11-16 10:47 . 2019-11-16 10:47 -------- d-----w- c:\program files (x86)\Zemana
2019-11-16 10:47 . 2019-11-16 10:47 232792 ----a-w- c:\windows\system32\drivers\amsdk.sys
2019-11-16 10:47 . 2019-11-16 10:48 -------- d-----w- c:\users\Hačís\AppData\Local\AMSDK
2019-11-16 10:42 . 2014-02-13 22:59 24064 ----a-w- c:\windows\zoek-delete.exe
2019-11-16 10:42 . 2019-11-16 11:06 -------- d-----w- c:\users\Hačís\AppData\Local\Temp
2019-11-16 10:42 . 2019-11-16 10:42 -------- d-----w- c:\users\HaŔÝs
2019-11-16 10:19 . 2019-11-16 10:37 -------- d-----w- C:\zoek_backup
2019-11-16 07:16 . 2019-11-16 07:16 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8EF6F44F-221E-43EA-8CAD-209819392824}\offreg.2636.dll
2019-11-16 07:12 . 2019-10-17 22:53 14459904 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8EF6F44F-221E-43EA-8CAD-209819392824}\mpengine.dll
2019-11-15 15:06 . 2019-11-15 15:06 -------- d-----w- c:\program files (x86)\Sophos
2019-11-14 17:55 . 2019-11-14 17:55 -------- d-----w- c:\users\Hačís\AppData\Local\cache
2019-11-14 17:55 . 2019-11-14 17:54 153312 ----a-w- c:\windows\system32\drivers\mbae64.sys
2019-11-14 17:54 . 2019-11-14 17:54 -------- d-----w- c:\programdata\Malwarebytes
2019-11-14 17:53 . 2019-11-14 17:53 -------- d-----w- c:\program files\Malwarebytes
2019-11-13 16:31 . 2019-11-13 16:31 4986936 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2019-10-31 16:06 . 2019-10-31 16:06 -------- d-----w- c:\users\Hačís\ansel
2019-10-31 10:03 . 2019-10-31 10:03 -------- d-----w- c:\programdata\IP-TV Player
2019-10-22 15:33 . 2019-10-22 15:33 -------- d-----w- c:\program files\Disk Check
2019-10-22 15:29 . 2019-10-22 15:29 -------- d-----w- c:\users\Hačís\AppData\Roaming\Hard Disk Sentinel
2019-10-22 15:27 . 2019-11-13 16:51 -------- d-----w- c:\program files (x86)\Hard Disk Sentinel
2019-10-19 15:04 . 2019-10-19 15:11 -------- d-----w- c:\program files (x86)\Ubisoft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2019-11-13 16:31 . 2017-11-16 21:10 842296 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2019-11-13 16:31 . 2017-11-16 21:10 175160 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2019-11-12 21:03 . 2018-09-11 14:54 748816 ------w- c:\windows\system32\MpSigStub.exe
2019-10-23 14:14 . 2019-10-09 15:31 510856 ----a-w- c:\windows\system32\nvumdshimx.dll
2019-10-23 14:09 . 2019-01-09 22:38 39814992 ----a-w- c:\windows\system32\nvwgf2umx.dll
2019-10-23 14:09 . 2019-01-09 22:38 22086904 ----a-w- c:\windows\system32\nvd3dumx.dll
2019-10-23 14:08 . 2019-01-09 22:38 4784872 ----a-w- c:\windows\system32\nvapi64.dll
2019-10-22 18:10 . 2019-01-09 22:39 5530608 ----a-w- c:\windows\system32\nvcpl.dll
2019-10-22 18:10 . 2019-01-09 22:39 2637152 ----a-w- c:\windows\system32\nvsvc64.dll
2019-10-22 18:10 . 2019-01-09 22:39 1768456 ----a-w- c:\windows\system32\nvsvcr.dll
2019-10-22 18:10 . 2019-10-09 15:34 83392 ----a-w- c:\windows\system32\nv3dappshextr.dll
2019-10-22 18:10 . 2019-10-09 15:34 655808 ----a-w- c:\windows\system32\nv3dappshext.dll
2019-10-22 18:10 . 2019-01-09 22:39 451608 ----a-w- c:\windows\system32\nvmctray.dll
2019-10-22 18:10 . 2019-01-09 22:39 124784 ----a-w- c:\windows\system32\nvshext.dll
2019-10-22 17:37 . 2019-01-09 22:39 8764732 ----a-w- c:\windows\system32\nvcoproc.bin
2019-10-10 18:02 . 2018-11-22 19:31 7249240 ------w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2019-09-27 21:10 . 2019-10-09 15:31 1491144 ----a-w- c:\windows\system32\nvdispgenco6443648.dll
2019-09-27 21:10 . 2019-10-09 15:31 1726720 ----a-w- c:\windows\system32\nvdispco6443648.dll
2019-09-27 18:20 . 2019-10-09 15:31 47272 ----a-w- c:\windows\system32\nvhdap64.dll
2019-09-27 18:20 . 2019-10-09 15:31 228792 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2019-09-27 18:20 . 2019-01-09 22:38 1683032 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2019-09-05 10:50 . 2019-10-09 15:38 2206704 ----a-w- c:\windows\SysWow64\nvspcap.dll
2019-09-05 10:50 . 2019-10-09 15:38 1321968 ----a-w- c:\windows\system32\NvRtmpStreamer64.dll
2019-09-05 10:50 . 2019-10-09 15:38 2843120 ----a-w- c:\windows\system32\nvspcap64.dll
2019-08-23 03:47 . 2019-10-09 15:31 75600 ----a-w- c:\windows\system32\drivers\nvvhci.sys
2019-08-22 12:53 . 2019-08-22 12:53 119808 ----a-r- c:\users\Hačís\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
2019-08-22 12:53 . 2019-08-22 12:53 119808 ----a-r- c:\users\Hačís\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-10-18 00:46 1524528 ----a-w- c:\progra~2\MICROS~2\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-10-18 00:46 1524528 ----a-w- c:\progra~2\MICROS~2\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-10-18 00:46 1524528 ----a-w- c:\progra~2\MICROS~2\Office16\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-10-23 3108480]
"MiPhoneManager"="c:\users\Hačís\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe" [2019-09-05 157624]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\qttask.exe" [2018-12-20 98304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
@="Service"
.
R1 ZAM;ZAM Helper Driver;c:\windows\System32\drivers\zam64.sys;c:\windows\SYSNATIVE\drivers\zam64.sys [x]
R1 ZAM_Guard;ZAM Guard Driver;c:\windows\System32\drivers\zamguard64.sys;c:\windows\SYSNATIVE\drivers\zamguard64.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
R3 DroidCam;DroidCam Virtual Audio;c:\windows\system32\DRIVERS\droidcam.sys;c:\windows\SYSNATIVE\DRIVERS\droidcam.sys [x]
R3 DroidCamVideo;DroidCam Source 3;c:\windows\system32\DRIVERS\droidcamvideo.sys;c:\windows\SYSNATIVE\DRIVERS\droidcamvideo.sys [x]
R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\Metin2\GameGuard\dump_wmimmc.sys;c:\program files (x86)\Metin2\GameGuard\dump_wmimmc.sys [x]
R3 GoogleChromeElevationService;Google Chrome Elevation Service;c:\program files (x86)\Google\Chrome\Application\78.0.3904.97\elevation_service.exe;c:\program files (x86)\Google\Chrome\Application\78.0.3904.97\elevation_service.exe [x]
R3 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\MBAMService.exe;c:\program files\Malwarebytes\Anti-Malware\MBAMService.exe [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 NvContainerNetworkService;NVIDIA NetworkService Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
R3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys;c:\windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 wdm_usb;wdm_usb;c:\windows\system32\DRIVERS\usb2ser.sys;c:\windows\SYSNATIVE\DRIVERS\usb2ser.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S0 amdide64;amdide64;c:\windows\system32\DRIVERS\amdide64.sys;c:\windows\SYSNATIVE\DRIVERS\amdide64.sys [x]
S1 amsdk;AMSDK Driver;c:\windows\system32\drivers\amsdk.sys;c:\windows\SYSNATIVE\drivers\amsdk.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 NvContainerLocalSystem;NVIDIA LocalSystem Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
S2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [x]
S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]
S3 anvsnddrv;AnvSoft Virtual Sound Device;c:\windows\system32\drivers\anvsnddrv.sys;c:\windows\SYSNATIVE\drivers\anvsnddrv.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 nvvhci;NVVHCI Enumerator Service;c:\windows\system32\DRIVERS\nvvhci.sys;c:\windows\SYSNATIVE\DRIVERS\nvvhci.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - AMSDK
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
MicroServiceGroup REG_MULTI_SZ MicroService
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-10-18 00:45 2179888 ----a-w- c:\progra~1\MICROS~3\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-10-18 00:45 2179888 ----a-w- c:\progra~1\MICROS~3\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-10-18 00:45 2179888 ----a-w- c:\progra~1\MICROS~3\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2018-09-11 18388936]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\program files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{DB0A3BFC-3FE9-4523-83AC-91C68D0BC2E7}: DhcpNameServer = 192.168.1.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE16\MSOXMLMF.DLL
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - c:\program files (x86)\Microsoft Office\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - c:\program files (x86)\Microsoft Office\Office16\MSOSB.DLL
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-USB Disk Storage Format Tool_is1 - c:\program files (x86)\USB Disk Storage Format Tool\unins000.exe
AddRemove-{050d4fc8-5d48-4b8f-8972-47c82c46020f} - c:\programdata\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe
AddRemove-{23658c02-145e-483d-ba6b-1eb82c580529} - c:\programdata\Package Cache\{23658c02-145e-483d-ba6b-1eb82c580529}\VC_redist.x86.exe
AddRemove-{2e085fd2-a3e4-4b39-8e10-6b8d35f55244} - c:\programdata\Package Cache\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}\VC_redist.x86.exe
AddRemove-{323dad84-0974-4d90-a1c1-e006c7fdbb7d} - c:\programdata\Package Cache\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\VC_redist.x64.exe
AddRemove-{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} - c:\programdata\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe
AddRemove-{9eef9797-2bbd-4659-9dc1-db8dcf95f05d} - c:\programdata\Package Cache\{9eef9797-2bbd-4659-9dc1-db8dcf95f05d}\Photolemur_Setup.exe
AddRemove-{c6c5a357-c7ca-4a5f-9789-3bb1af579253} - c:\programdata\Package Cache\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}\LauncherPrereqSetup_x64.exe
AddRemove-{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} - c:\programdata\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe
AddRemove-{f65db027-aff3-4070-886a-0d87064aabb1} - c:\programdata\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2123216125-335965321-1693192355-1000\Software\SecuROM\License information*]
"datasecu"=hex:ab,92,58,ec,a5,54,86,40,8a,3a,63,7b,25,73,00,20,ab,74,e4,36,3c,
3b,cc,0b,86,c3,d6,85,87,90,f2,44,75,b1,56,1c,3a,fe,cd,5b,10,08,48,48,f9,12,\
"rkeysecu"=hex:8c,bc,74,a4,7d,67,37,53,c9,b9,e2,a5,16,49,07,f8
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_32_0_0_293_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_32_0_0_293_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.3g2\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.3gp\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.3gp2\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.3gpp\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.aac\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.ape\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.asf\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.avi\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.dat\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.flac\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.flv\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.ifo\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.m2t\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.m2ts\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.m4v\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mkv\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mod\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mov\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mp2\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mp3\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mp4\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mpa\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mpeg\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mpg\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mts\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.ogg\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.qt\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.vob\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.vro\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.wav\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.wma\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.wmv\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_32_0_0_293_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_32_0_0_293_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_293.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.32"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_293.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_293.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_293.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2019-11-16 12:08:03
ComboFix-quarantined-files.txt 2019-11-16 11:08
.
Před spuštěním: Volných bajtů: 74 464 653 312
Po spuštění: Volných bajtů: 74 352 517 120
.
- - End Of File - - 6CEA0F2F3D552A60F0613B6FF088E906
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT pc se vypíná

Příspěvekod jaro3 » 16 lis 2019 17:39

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::
KillAll::
RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_32_0_0_293_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_32_0_0_293_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.3g2\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.3gp\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.3gp2\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.3gpp\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.aac\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.ape\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.asf\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.avi\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.dat\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.flac\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.flv\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.ifo\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.m2t\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.m2ts\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.m4v\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mkv\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mod\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mov\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mp2\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mp3\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mp4\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mpa\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mpeg\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mpg\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mts\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.ogg\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.qt\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.vob\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.vro\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.wav\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.wma\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.wmv\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_32_0_0_293_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_32_0_0_293_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_293.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.32"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_293.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_293.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_293.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na https://www.virustotal.com/#/home/uploadVirustotal
c:\users\Hačís\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
c:\users\Hačís\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Re: Prosím o kontrolu logu HJT pc se vypíná

Příspěvekod standacich » 16 lis 2019 18:04

ComboFix 19-11-04.01 - Hačís 16.11.2019 17:46:36.4.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.4024.2745 [GMT 1:00]
Spuštěný z: c:\users\HaŔÝs\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\HaŔÝs\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2019-10-16 do 2019-11-16 )))))))))))))))))))))))))))))))
.
.
2019-11-16 16:54 . 2019-11-16 16:54 -------- d-----w- c:\users\Public\AppData\Local\temp
2019-11-16 16:54 . 2019-11-16 16:54 -------- d-----w- c:\users\HAS~2\AppData\Local\temp
2019-11-16 16:54 . 2019-11-16 16:54 -------- d-----w- c:\users\Děti\AppData\Local\temp
2019-11-16 16:54 . 2019-11-16 16:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2019-11-16 11:08 . 2019-11-16 11:08 -------- d-----w- c:\users\Haźˇs\AppData
2019-11-16 10:56 . 2019-11-16 10:56 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8EF6F44F-221E-43EA-8CAD-209819392824}\offreg.2052.dll
2019-11-16 10:47 . 2019-11-16 10:47 -------- d-----w- c:\program files (x86)\Zemana
2019-11-16 10:47 . 2019-11-16 10:47 232792 ----a-w- c:\windows\system32\drivers\amsdk.sys
2019-11-16 10:47 . 2019-11-16 10:48 -------- d-----w- c:\users\Hačís\AppData\Local\AMSDK
2019-11-16 10:42 . 2014-02-13 22:59 24064 ----a-w- c:\windows\zoek-delete.exe
2019-11-16 10:42 . 2019-11-16 16:54 -------- d-----w- c:\users\Hačís\AppData\Local\Temp
2019-11-16 10:42 . 2019-11-16 10:42 -------- d-----w- c:\users\HaŔÝs
2019-11-16 10:19 . 2019-11-16 10:37 -------- d-----w- C:\zoek_backup
2019-11-16 07:16 . 2019-11-16 07:16 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8EF6F44F-221E-43EA-8CAD-209819392824}\offreg.2636.dll
2019-11-16 07:12 . 2019-10-17 22:53 14459904 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8EF6F44F-221E-43EA-8CAD-209819392824}\mpengine.dll
2019-11-15 15:06 . 2019-11-15 15:06 -------- d-----w- c:\program files (x86)\Sophos
2019-11-14 17:55 . 2019-11-14 17:55 -------- d-----w- c:\users\Hačís\AppData\Local\cache
2019-11-14 17:55 . 2019-11-14 17:54 153312 ----a-w- c:\windows\system32\drivers\mbae64.sys
2019-11-14 17:54 . 2019-11-14 17:54 -------- d-----w- c:\programdata\Malwarebytes
2019-11-14 17:53 . 2019-11-14 17:53 -------- d-----w- c:\program files\Malwarebytes
2019-11-13 16:31 . 2019-11-13 16:31 4986936 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2019-10-31 16:06 . 2019-10-31 16:06 -------- d-----w- c:\users\Hačís\ansel
2019-10-31 10:03 . 2019-10-31 10:03 -------- d-----w- c:\programdata\IP-TV Player
2019-10-22 15:33 . 2019-10-22 15:33 -------- d-----w- c:\program files\Disk Check
2019-10-22 15:29 . 2019-10-22 15:29 -------- d-----w- c:\users\Hačís\AppData\Roaming\Hard Disk Sentinel
2019-10-22 15:27 . 2019-11-13 16:51 -------- d-----w- c:\program files (x86)\Hard Disk Sentinel
2019-10-19 15:04 . 2019-10-19 15:11 -------- d-----w- c:\program files (x86)\Ubisoft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2019-11-13 16:31 . 2017-11-16 21:10 842296 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2019-11-13 16:31 . 2017-11-16 21:10 175160 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2019-11-12 21:03 . 2018-09-11 14:54 748816 ------w- c:\windows\system32\MpSigStub.exe
2019-10-23 14:14 . 2019-10-09 15:31 510856 ----a-w- c:\windows\system32\nvumdshimx.dll
2019-10-23 14:09 . 2019-01-09 22:38 39814992 ----a-w- c:\windows\system32\nvwgf2umx.dll
2019-10-23 14:09 . 2019-01-09 22:38 22086904 ----a-w- c:\windows\system32\nvd3dumx.dll
2019-10-23 14:08 . 2019-01-09 22:38 4784872 ----a-w- c:\windows\system32\nvapi64.dll
2019-10-22 18:10 . 2019-01-09 22:39 5530608 ----a-w- c:\windows\system32\nvcpl.dll
2019-10-22 18:10 . 2019-01-09 22:39 2637152 ----a-w- c:\windows\system32\nvsvc64.dll
2019-10-22 18:10 . 2019-01-09 22:39 1768456 ----a-w- c:\windows\system32\nvsvcr.dll
2019-10-22 18:10 . 2019-10-09 15:34 83392 ----a-w- c:\windows\system32\nv3dappshextr.dll
2019-10-22 18:10 . 2019-10-09 15:34 655808 ----a-w- c:\windows\system32\nv3dappshext.dll
2019-10-22 18:10 . 2019-01-09 22:39 451608 ----a-w- c:\windows\system32\nvmctray.dll
2019-10-22 18:10 . 2019-01-09 22:39 124784 ----a-w- c:\windows\system32\nvshext.dll
2019-10-22 17:37 . 2019-01-09 22:39 8764732 ----a-w- c:\windows\system32\nvcoproc.bin
2019-10-10 18:02 . 2018-11-22 19:31 7249240 ------w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2019-09-27 21:10 . 2019-10-09 15:31 1491144 ----a-w- c:\windows\system32\nvdispgenco6443648.dll
2019-09-27 21:10 . 2019-10-09 15:31 1726720 ----a-w- c:\windows\system32\nvdispco6443648.dll
2019-09-27 18:20 . 2019-10-09 15:31 47272 ----a-w- c:\windows\system32\nvhdap64.dll
2019-09-27 18:20 . 2019-10-09 15:31 228792 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2019-09-27 18:20 . 2019-01-09 22:38 1683032 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2019-09-05 10:50 . 2019-10-09 15:38 2206704 ----a-w- c:\windows\SysWow64\nvspcap.dll
2019-09-05 10:50 . 2019-10-09 15:38 1321968 ----a-w- c:\windows\system32\NvRtmpStreamer64.dll
2019-09-05 10:50 . 2019-10-09 15:38 2843120 ----a-w- c:\windows\system32\nvspcap64.dll
2019-08-23 03:47 . 2019-10-09 15:31 75600 ----a-w- c:\windows\system32\drivers\nvvhci.sys
2019-08-22 12:53 . 2019-08-22 12:53 119808 ----a-r- c:\users\Hačís\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
2019-08-22 12:53 . 2019-08-22 12:53 119808 ----a-r- c:\users\Hačís\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-10-18 00:46 1524528 ----a-w- c:\progra~2\MICROS~2\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-10-18 00:46 1524528 ----a-w- c:\progra~2\MICROS~2\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-10-18 00:46 1524528 ----a-w- c:\progra~2\MICROS~2\Office16\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-10-23 3108480]
"MiPhoneManager"="c:\users\Hačís\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe" [2019-09-05 157624]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\qttask.exe" [2018-12-20 98304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
@="Service"
.
R1 ZAM;ZAM Helper Driver;c:\windows\System32\drivers\zam64.sys;c:\windows\SYSNATIVE\drivers\zam64.sys [x]
R1 ZAM_Guard;ZAM Guard Driver;c:\windows\System32\drivers\zamguard64.sys;c:\windows\SYSNATIVE\drivers\zamguard64.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
R3 DroidCam;DroidCam Virtual Audio;c:\windows\system32\DRIVERS\droidcam.sys;c:\windows\SYSNATIVE\DRIVERS\droidcam.sys [x]
R3 DroidCamVideo;DroidCam Source 3;c:\windows\system32\DRIVERS\droidcamvideo.sys;c:\windows\SYSNATIVE\DRIVERS\droidcamvideo.sys [x]
R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\Metin2\GameGuard\dump_wmimmc.sys;c:\program files (x86)\Metin2\GameGuard\dump_wmimmc.sys [x]
R3 GoogleChromeElevationService;Google Chrome Elevation Service;c:\program files (x86)\Google\Chrome\Application\78.0.3904.97\elevation_service.exe;c:\program files (x86)\Google\Chrome\Application\78.0.3904.97\elevation_service.exe [x]
R3 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\MBAMService.exe;c:\program files\Malwarebytes\Anti-Malware\MBAMService.exe [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 NvContainerNetworkService;NVIDIA NetworkService Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
R3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys;c:\windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 wdm_usb;wdm_usb;c:\windows\system32\DRIVERS\usb2ser.sys;c:\windows\SYSNATIVE\DRIVERS\usb2ser.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S0 amdide64;amdide64;c:\windows\system32\DRIVERS\amdide64.sys;c:\windows\SYSNATIVE\DRIVERS\amdide64.sys [x]
S1 amsdk;AMSDK Driver;c:\windows\system32\drivers\amsdk.sys;c:\windows\SYSNATIVE\drivers\amsdk.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 NvContainerLocalSystem;NVIDIA LocalSystem Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
S2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [x]
S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]
S3 anvsnddrv;AnvSoft Virtual Sound Device;c:\windows\system32\drivers\anvsnddrv.sys;c:\windows\SYSNATIVE\drivers\anvsnddrv.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 nvvhci;NVVHCI Enumerator Service;c:\windows\system32\DRIVERS\nvvhci.sys;c:\windows\SYSNATIVE\DRIVERS\nvvhci.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - AMSDK
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
MicroServiceGroup REG_MULTI_SZ MicroService
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-10-18 00:45 2179888 ----a-w- c:\progra~1\MICROS~3\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-10-18 00:45 2179888 ----a-w- c:\progra~1\MICROS~3\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-10-18 00:45 2179888 ----a-w- c:\progra~1\MICROS~3\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2018-09-11 18388936]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\program files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{DB0A3BFC-3FE9-4523-83AC-91C68D0BC2E7}: DhcpNameServer = 192.168.1.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE16\MSOXMLMF.DLL
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - c:\program files (x86)\Microsoft Office\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - c:\program files (x86)\Microsoft Office\Office16\MSOSB.DLL
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-{050d4fc8-5d48-4b8f-8972-47c82c46020f} - c:\programdata\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe
AddRemove-{23658c02-145e-483d-ba6b-1eb82c580529} - c:\programdata\Package Cache\{23658c02-145e-483d-ba6b-1eb82c580529}\VC_redist.x86.exe
AddRemove-{2e085fd2-a3e4-4b39-8e10-6b8d35f55244} - c:\programdata\Package Cache\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}\VC_redist.x86.exe
AddRemove-{323dad84-0974-4d90-a1c1-e006c7fdbb7d} - c:\programdata\Package Cache\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}\VC_redist.x64.exe
AddRemove-{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} - c:\programdata\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe
AddRemove-{9eef9797-2bbd-4659-9dc1-db8dcf95f05d} - c:\programdata\Package Cache\{9eef9797-2bbd-4659-9dc1-db8dcf95f05d}\Photolemur_Setup.exe
AddRemove-{c6c5a357-c7ca-4a5f-9789-3bb1af579253} - c:\programdata\Package Cache\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}\LauncherPrereqSetup_x64.exe
AddRemove-{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} - c:\programdata\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe
AddRemove-{f65db027-aff3-4070-886a-0d87064aabb1} - c:\programdata\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2123216125-335965321-1693192355-1000\Software\SecuROM\License information*]
"datasecu"=hex:ab,92,58,ec,a5,54,86,40,8a,3a,63,7b,25,73,00,20,ab,74,e4,36,3c,
3b,cc,0b,86,c3,d6,85,87,90,f2,44,75,b1,56,1c,3a,fe,cd,5b,10,08,48,48,f9,12,\
"rkeysecu"=hex:8c,bc,74,a4,7d,67,37,53,c9,b9,e2,a5,16,49,07,f8
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_32_0_0_293_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_32_0_0_293_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.3g2\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.3gp\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.3gp2\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.3gpp\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.aac\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.ape\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.asf\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.avi\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.dat\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.flac\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.flv\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.ifo\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.m2t\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.m2ts\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.m4v\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mkv\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mod\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mov\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mp2\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mp3\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mp4\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mpa\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mpeg\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mpg\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.mts\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.ogg\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.qt\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.vob\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.vro\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.wav\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.wma\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.wmv\shell\C*o*n*v*e*r*t*& \command]
@="\"c:\\Program Files (x86)\\Movavi Video Converter 17\\converter.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_32_0_0_293_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_32_0_0_293_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_293.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.32"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_293.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_293.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_293.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2019-11-16 17:55:55
ComboFix-quarantined-files.txt 2019-11-16 16:55
ComboFix2.txt 2019-11-16 11:08
.
Před spuštěním: Volných bajtů: 74 100 940 800
Po spuštění: Volných bajtů: 73 988 591 616
.
- - End Of File - - 79B6C30406A23A65CBEC25EDF78EA182
A36C5E4F47E84449FF07ED3517B43A31


standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Re: Prosím o kontrolu logu HJT pc se vypíná

Příspěvekod standacich » 16 lis 2019 18:07

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:06:22, on 16.11.2019
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.19104)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Users\Hačís\Desktop\HijackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office16\URLREDIR.DLL
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~2\Office16\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [MiPhoneManager] "C:\Users\Hačís\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Poslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Poslat do On&eNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: @%CommonProgramFiles%\Microsoft Shared\Office16\oregres.dll,-430 - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: @%CommonProgramFiles%\Microsoft Shared\Office16\oregres.dll,-430 - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O18 - Protocol: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\78.0.3904.97\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - Unknown owner - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (file missing)
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - Unknown owner - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Corel License Validation Service V2, Powered by arvato (PSI_SVC_2) - arvato digital services llc - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8429 bytes

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT pc se vypíná

Příspěvekod jaro3 » 16 lis 2019 19:27

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime


ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

Vyčisti systém CCleanerem

Stáhni si OTC

na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.

Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 11 hostů