Prosím o kontrolu - taskeng.exe Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu - taskeng.exe

Příspěvekod jerabina » 09 kvě 2015 21:53

Když dáte Ovládací panely -> Odinstalovat program tak ani v tom seznamu není?

Ještě jedna instrukce, vypněte prosím trvale Windows Defender, Avast ho bohatě zastupuje :-)
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Reklama
Kanovka
Level 2
Level 2
Příspěvky: 187
Registrován: říjen 13
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu - taskeng.exe

Příspěvekod Kanovka » 09 kvě 2015 22:02

Windows defender vypnut, v ovládacích panelech jsem koukala právě a tam není, ani nikde jinde (když dám start a hledat)

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu - taskeng.exe

Příspěvekod jerabina » 09 kvě 2015 22:10

Tak jinak:

Stáhni si z některého odkazu SystemLook
SystemLook (32-bit)
http://jpshortstuff.247fixes.com/SystemLook.exe
SystemLook (64-bit)
http://jpshortstuff.247fixes.com/SystemLook_x64.exe

a ulož si ho na plochu.

Poklepej na stažený SystemLook , zkopíruj do hlavního text. okna tento následující text:

Kód: Vybrat vše

:filefind
*bingbar*
*BingBar*

:folderfind
*bingbar*
*BingBar*

:regfind
*bingbar*
*BingBar*


Klikni na Look ke startu skenu. Když program skončí objeví se v poznámkovém bloku zpráva skenu. Zkopíruj sem celý jeho obsah. Log se také nachází na ploše pod názvem SystemLook.txt.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Kanovka
Level 2
Level 2
Příspěvky: 187
Registrován: říjen 13
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu - taskeng.exe

Příspěvekod Kanovka » 09 kvě 2015 22:36

SystemLook 30.07.11 by jpshortstuff
Log created at 22:21 on 09/05/2015 by Lucka
Administrator - Elevation successful

========== filefind ==========

Searching for "*bingbar*"
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingBar.exe --a---- 425240 bytes [09:28 10/02/2012] [09:28 10/02/2012] E49AC994EB17111E5D324831D1CFC6F4
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\apps\finance\7.1.361\images\GreenBingBarTickF.png --a---- 269 bytes [14:15 31/01/2012] [14:15 31/01/2012] CC47B76912D2C6A1DD8397D59F95D409
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.007DB18B1C508450BB28D3ACBA12F59EE\MUExe\7.1.361.0\BingBarSetup-Partner.EXE --a---- 5915648 bytes [01:00 04/05/2012] [10:43 10/02/2012] D58BA8CED10B0EE0B79ED3FBDD970FC8
C:\Program Files (x86)\Microsoft\BingBar\Installers\BingBar7.1.361.0\BingBar.msi --a---- 475136 bytes [07:33 12/05/2012] [09:38 10/02/2012] 591EC048F441F92CE7B56D61A1EE92E1

Searching for "*BingBar*"
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingBar.exe --a---- 425240 bytes [09:28 10/02/2012] [09:28 10/02/2012] E49AC994EB17111E5D324831D1CFC6F4
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\apps\finance\7.1.361\images\GreenBingBarTickF.png --a---- 269 bytes [14:15 31/01/2012] [14:15 31/01/2012] CC47B76912D2C6A1DD8397D59F95D409
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.007DB18B1C508450BB28D3ACBA12F59EE\MUExe\7.1.361.0\BingBarSetup-Partner.EXE --a---- 5915648 bytes [01:00 04/05/2012] [10:43 10/02/2012] D58BA8CED10B0EE0B79ED3FBDD970FC8
C:\Program Files (x86)\Microsoft\BingBar\Installers\BingBar7.1.361.0\BingBar.msi --a---- 475136 bytes [07:33 12/05/2012] [09:38 10/02/2012] 591EC048F441F92CE7B56D61A1EE92E1

========== folderfind ==========

Searching for "*bingbar*"
C:\Program Files (x86)\Microsoft\BingBar d------ [01:00 04/05/2012]
C:\Program Files (x86)\Microsoft\BingBar\Installers\BingBar7.1.361.0 d------ [07:33 12/05/2012]
C:\ProgramData\Microsoft\BingBar d------ [07:33 12/05/2012]
C:\Users\All Users\Microsoft\BingBar d------ [07:33 12/05/2012]

Searching for "*BingBar*"
C:\Program Files (x86)\Microsoft\BingBar d------ [01:00 04/05/2012]
C:\Program Files (x86)\Microsoft\BingBar\Installers\BingBar7.1.361.0 d------ [07:33 12/05/2012]
C:\ProgramData\Microsoft\BingBar d------ [07:33 12/05/2012]
C:\Users\All Users\Microsoft\BingBar d------ [07:33 12/05/2012]

========== regfind ==========

Searching for "*bingbar*"
No data found.

Searching for "*BingBar* "
No data found.

-= EOF =-

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu - taskeng.exe

Příspěvekod jerabina » 09 kvě 2015 22:45

Stáhni si OTM na plochu. Spusťte a do levého okna zkopíruj následující text:

Kód: Vybrat vše

:files
C:\Program Files (x86)\Microsoft\BingBar
C:\ProgramData\Microsoft\BingBar
C:\Users\All Users\Microsoft\BingBar

:commands
[Purity]
[Emptytemp]
[Emptyflash]


a klikni na >MoveIt!<. Po skenu restartuj počítač

Po restartu se přesuneme už na samotný OTL:

Poklepej na ikonu OTL na ploše. Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE (Microsoft Corporation.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (BBUpdate) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE (Microsoft Corporation.)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll File not found
[2010.06.22 09:17:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lucka\AppData\Roaming\Mozilla\Extensions
[2010.06.22 09:17:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lucka\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2015.03.06 21:17:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lucka\AppData\Roaming\Mozilla\Firefox\Profiles\2yzghyrg.default\extensions
[2010.07.07 21:44:41 | 000,000,000 | ---D | M] (Illimitux) -- C:\Users\Lucka\AppData\Roaming\Mozilla\Firefox\Profiles\2yzghyrg.default\extensions\illimitux@illimitux.net
[2015.05.08 12:22:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2014.06.05 21:56:59 | 000,000,000 | ---D | M] (QuickStores-Toolbar) -- C:\Program Files (x86)\Mozilla Firefox\extensions\quickstores@quickstores.de
[2014.10.27 22:12:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: No name found = C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: No name found = C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\osf - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Program Files\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\Program Files (x86)\*.tmp
C:\Users\Lucka\Desktop\mbar-1.09.1.1004.exe
C:\Users\Lucka\Desktop\ESETPoweliksCleaner.exe_20150508.155630.6012.zip
C:\Users\Lucka\Desktop\ESETPoweliksCleaner.exe_20150508.155728.6856.zip
C:\Users\Lucka\Desktop\pc-decrapifier-3.0.0.exe
C:\Users\Lucka\Desktop\mbar-1.09.1.1004.exe
C:\Users\Lucka\Desktop\mbam-setup-2.1.6.1022.exe

:commands
[Purity]
[Emptytemp]
[Emptyjava]
[Emptyflash]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

+ udělej nový SystemLook se stejným skriptem :-)
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Kanovka
Level 2
Level 2
Příspěvky: 187
Registrován: říjen 13
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu - taskeng.exe

Příspěvekod Kanovka » 09 kvě 2015 23:33

teď se mi objevily takovéto (viz příloha) "duchařské" soubory nejen na ploše, ale i třeba ve stažených souborech, nevím co to je :D, teda ano všechno to vypadá, že jsem někdy vytvořila, ale na ploše to už nemá delší dobu co dělat, takže jsem radši ten další krok nedělala, nevím, jestli můžu
Přílohy
Clipboard01.jpg

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu - taskeng.exe

Příspěvekod jerabina » 09 kvě 2015 23:34

Pokračuj fixem v OTL, následně zkusíme vyhnat duchy ;-)
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Kanovka
Level 2
Level 2
Příspěvky: 187
Registrován: říjen 13
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu - taskeng.exe

Příspěvekod Kanovka » 09 kvě 2015 23:43

ani restart na duchy nepomohl, jdu na to otl

Kanovka
Level 2
Level 2
Příspěvky: 187
Registrován: říjen 13
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu - taskeng.exe

Příspěvekod Kanovka » 10 kvě 2015 01:06

All processes killed
========== OTL ==========
No active process named Program Files was found!
Service WinDefend stopped successfully!
Service WinDefend deleted successfully!
File move failed. C:\Program Files\Windows Defender\MpSvc.dll scheduled to be moved on reboot.
Service BBUpdate stopped successfully!
Service BBUpdate deleted successfully!
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE moved successfully.
Service BBSvc stopped successfully!
Service BBSvc deleted successfully!
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE moved successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0\ deleted successfully.
C:\Users\Lucka\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} folder moved successfully.
C:\Users\Lucka\AppData\Roaming\Mozilla\Extensions folder moved successfully.
Folder C:\Users\Lucka\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\ not found.
C:\Users\Lucka\AppData\Roaming\Mozilla\Firefox\Profiles\2yzghyrg.default\extensions\illimitux@illimitux.net\chrome folder moved successfully.
C:\Users\Lucka\AppData\Roaming\Mozilla\Firefox\Profiles\2yzghyrg.default\extensions\illimitux@illimitux.net folder moved successfully.
C:\Users\Lucka\AppData\Roaming\Mozilla\Firefox\Profiles\2yzghyrg.default\extensions folder moved successfully.
Folder C:\Users\Lucka\AppData\Roaming\Mozilla\Firefox\Profiles\2yzghyrg.default\extensions\illimitux@illimitux.net\ not found.
C:\Program Files (x86)\Mozilla Firefox\extensions\quickstores@quickstores.de\chrome folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\quickstores@quickstores.de folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions folder moved successfully.
Folder C:\Program Files (x86)\Mozilla Firefox\extensions\quickstores@quickstores.de\ not found.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions folder moved successfully.
File C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll not found.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0 folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_metadata folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\zh_TW folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\zh_CN folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\vi folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\uk folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\tr folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\th folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\sv folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\sr folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\sl folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\sk folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\ru folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\ro folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\pt_PT folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\pt_BR folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\pl folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\nl folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\nb folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\lv folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\lt folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\ko folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\ja folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\it folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\id folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\hu folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\hr folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\hi folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\fr folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\fil folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\fi folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\et folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\es_419 folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\es folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\en_GB folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\en folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\el folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\de folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\da folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\cs folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\ca folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\bg folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\images folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\html folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\css folder moved successfully.
C:\Users\Lucka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0 folder moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\RESTART_STICKY_NOTES not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
Starting removal of ActiveX control {166B1BCA-3F9C-11CF-8075-444553540000}
C:\Windows\Downloaded Program Files\swdir.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{166B1BCA-3F9C-11CF-8075-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\grooveLocalGWS\ deleted successfully.
File Protocol\Handler\grooveLocalGWS - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\osf\ deleted successfully.
File Protocol\Handler\osf - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
C:\WINDOWS\B9DB4C7601A446D58910F7AA6376DBAF.TMP folder moved successfully.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\system32\DUMP*.tmp not found.
File\Folder c:\windows\Tasks\*.job not found.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File\Folder C:\Program Files\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
File\Folder C:\Windows\SysNative\drivers\*.tmp not found.
File\Folder C:\Windows\SysWow64\drivers\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
File\Folder C:\Windows\SysWow64\*.tmp not found.
File\Folder C:\Windows\SysNative\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
C:\Users\Lucka\Desktop\mbar-1.09.1.1004.exe moved successfully.
C:\Users\Lucka\Desktop\ESETPoweliksCleaner.exe_20150508.155630.6012.zip moved successfully.
C:\Users\Lucka\Desktop\ESETPoweliksCleaner.exe_20150508.155728.6856.zip moved successfully.
C:\Users\Lucka\Desktop\pc-decrapifier-3.0.0.exe moved successfully.
File\Folder C:\Users\Lucka\Desktop\mbar-1.09.1.1004.exe not found.
C:\Users\Lucka\Desktop\mbam-setup-2.1.6.1022.exe moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 57472 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Hanka
->Temp folder emptied: 0 bytes

User: Lucka
->Temp folder emptied: 12556195 bytes
->Temporary Internet Files folder emptied: 253412741 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 7416988 bytes
->Apple Safari cache emptied: 18041856 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 60633 bytes

User: Michal
->Temp folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 600758 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 279,00 mb


[EMPTYJAVA]

User: Administrator

User: All Users

User: Default

User: Default User

User: Hanka

User: Lucka
->Java cache emptied: 0 bytes

User: Michal

User: Public

Total Java Files Cleaned = 0,00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Hanka

User: Lucka
->Flash cache emptied: 0 bytes

User: Michal

User: Public

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 05102015_005846

Files\Folders moved on Reboot...
File move failed. C:\Program Files\Windows Defender\MpSvc.dll scheduled to be moved on reboot.
C:\Users\Lucka\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\windows\temp\_avast_\AvastLock.txt scheduled to be moved on reboot.
C:\windows\temp\LUCKA-PC-20150510-0053.log moved successfully.
File\Folder C:\windows\temp\officeclicktorun.exe_c2ruidll(201505100053388A4).log not found!
File\Folder C:\windows\temp\officeclicktorun.exe_streamserver(201505100053398A4).log not found!
File move failed. C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Kanovka
Level 2
Level 2
Příspěvky: 187
Registrován: říjen 13
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu - taskeng.exe

Příspěvekod Kanovka » 10 kvě 2015 01:07

duchové už nejsou

Kanovka
Level 2
Level 2
Příspěvky: 187
Registrován: říjen 13
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu - taskeng.exe

Příspěvekod Kanovka » 10 kvě 2015 01:17

SystemLook 30.07.11 by jpshortstuff
Log created at 01:12 on 10/05/2015 by Lucka
Administrator - Elevation successful

========== filefind ==========

Searching for "*bingbar*"
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingBar.exe --a---- 425240 bytes [09:28 10/02/2012] [09:28 10/02/2012] E49AC994EB17111E5D324831D1CFC6F4
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\apps\finance\7.1.361\images\GreenBingBarTickF.png --a---- 269 bytes [14:15 31/01/2012] [14:15 31/01/2012] CC47B76912D2C6A1DD8397D59F95D409
C:\_OTM\MovedFiles\05092015_232720\C_Program Files (x86)\Microsoft\BingBar\7.1.361.007DB18B1C508450BB28D3ACBA12F59EE\MUExe\7.1.361.0\BingBarSetup-Partner.EXE --a---- 5915648 bytes [01:00 04/05/2012] [10:43 10/02/2012] D58BA8CED10B0EE0B79ED3FBDD970FC8
C:\_OTM\MovedFiles\05092015_232720\C_Program Files (x86)\Microsoft\BingBar\Installers\BingBar7.1.361.0\BingBar.msi --a---- 475136 bytes [07:33 12/05/2012] [09:38 10/02/2012] 591EC048F441F92CE7B56D61A1EE92E1

Searching for "*BingBar*"
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingBar.exe --a---- 425240 bytes [09:28 10/02/2012] [09:28 10/02/2012] E49AC994EB17111E5D324831D1CFC6F4
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\apps\finance\7.1.361\images\GreenBingBarTickF.png --a---- 269 bytes [14:15 31/01/2012] [14:15 31/01/2012] CC47B76912D2C6A1DD8397D59F95D409
C:\_OTM\MovedFiles\05092015_232720\C_Program Files (x86)\Microsoft\BingBar\7.1.361.007DB18B1C508450BB28D3ACBA12F59EE\MUExe\7.1.361.0\BingBarSetup-Partner.EXE --a---- 5915648 bytes [01:00 04/05/2012] [10:43 10/02/2012] D58BA8CED10B0EE0B79ED3FBDD970FC8
C:\_OTM\MovedFiles\05092015_232720\C_Program Files (x86)\Microsoft\BingBar\Installers\BingBar7.1.361.0\BingBar.msi --a---- 475136 bytes [07:33 12/05/2012] [09:38 10/02/2012] 591EC048F441F92CE7B56D61A1EE92E1

========== folderfind ==========

Searching for "*bingbar*"
C:\Program Files (x86)\Microsoft\BingBar d------ [01:00 04/05/2012]
C:\ProgramData\Microsoft\BingBar d------ [07:33 12/05/2012]
C:\Users\All Users\Microsoft\BingBar d------ [07:33 12/05/2012]
C:\_OTL\MovedFiles\05102015_005846\C_Program Files (x86)\Microsoft\BingBar d------ [22:58 09/05/2015]
C:\_OTM\MovedFiles\05092015_225021\C_Program Files (x86)\Microsoft\BingBar d------ [20:50 09/05/2015]
C:\_OTM\MovedFiles\05092015_232720\C_Program Files (x86)\Microsoft\BingBar d------ [21:27 09/05/2015]
C:\_OTM\MovedFiles\05092015_232720\C_Program Files (x86)\Microsoft\BingBar\Installers\BingBar7.1.361.0 d------ [07:33 12/05/2012]

Searching for "*BingBar*"
C:\Program Files (x86)\Microsoft\BingBar d------ [01:00 04/05/2012]
C:\ProgramData\Microsoft\BingBar d------ [07:33 12/05/2012]
C:\Users\All Users\Microsoft\BingBar d------ [07:33 12/05/2012]
C:\_OTL\MovedFiles\05102015_005846\C_Program Files (x86)\Microsoft\BingBar d------ [22:58 09/05/2015]
C:\_OTM\MovedFiles\05092015_225021\C_Program Files (x86)\Microsoft\BingBar d------ [20:50 09/05/2015]
C:\_OTM\MovedFiles\05092015_232720\C_Program Files (x86)\Microsoft\BingBar d------ [21:27 09/05/2015]
C:\_OTM\MovedFiles\05092015_232720\C_Program Files (x86)\Microsoft\BingBar\Installers\BingBar7.1.361.0 d------ [07:33 12/05/2012]

========== regfind ==========

Searching for "*bingbar*"
No data found.

Searching for "*BingBar* "
No data found.

-= EOF =-

Kanovka
Level 2
Level 2
Příspěvky: 187
Registrován: říjen 13
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu - taskeng.exe

Příspěvekod Kanovka » 10 kvě 2015 01:17

tak snad vše uděláno :)


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 44 hostů