Prosim o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu

Příspěvekod jaro3 » 02 led 2017 22:54

zoek zkus v nouz. režimu.

pak dej vědět.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
Uživatelský avatar
Yelkinson
Level 3
Level 3
Příspěvky: 582
Registrován: listopad 07
Bydliště: Plzen
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosim o kontrolu logu

Příspěvekod Yelkinson » 03 led 2017 17:53

Tak konecne se zadarilo v nouzaku



Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by XEON on Łt 03.01.2017 at 17:34:16,99.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Safe Mode MINIMAL No Internet Access Detected
Launched: C:\Users\XEON\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2017-01-02-192107.log 4606 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\Users\XEON\AppData\Roaming\WinRAR deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\XEON\AppData\Roaming\Profiles\Zaceiedrejiing.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\XEON\AppData\Roaming\Profiles\Zaceiedrejiing.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\XEON\AppData\Roaming\Mozilla\Firefox\Profiles\mhxjrqqr.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\XEON\AppData\Roaming\Mozilla\Firefox\Profiles\mhxjrqqr.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================


==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\XEON\AppData\Roaming\Profiles\Zaceiedrejiing.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\XEON\AppData\Roaming\Mozilla\Firefox\Profiles\mhxjrqqr.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\XEON\AppData\Roaming\Mozilla\Firefox\Profiles\mhxjrqqr.default
E8D38E8FB6EC88E7B0E0B4D9AC9B0725 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_186.dll - Shockwave Flash
6AA7BCD40ED4F133D4ACC4F7B337674E - C:\Users\XEON\AppData\Local\Roblox\Versions\version-934c86ec4aa148f0\NPRobloxProxy.dll - Roblox Launcher Plugin
5CC69A389B56347B51416671B31859AC - C:\Users\XEON\AppData\Local\Roblox\Versions\version-934c86ec4aa148f0\NPRobloxProxy64.dll - Roblox Launcher Plugin


==== Chromium Look ======================


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131228663686535129&GUID=2E3224AC-F273-4CDB-B7C9-F8AD94E1E8EB"
"Use Search Asst"="yes"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131228663686535129&GUID=2E3224AC-F273-4CDB-B7C9-F8AD94E1E8EB"
"Use Search Asst"="no"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Windows\sysWoW64\config\systemprofile\AppData\Local\UCBrowser\User Data\Default\Preferences was reset successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\UCBrowser\User Data\Default\Web Data.65 was reset successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\UCBrowser\User Data\Default\Web Data.65-journal was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\XEON\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\XEON\AppData\Local\Mozilla\Firefox\Profiles\mhxjrqqr.default\cache2 emptied successfully
C:\Users\XEON\AppData\Roaming\Mozilla\Firefox\Profiles\mhxjrqqr.default\storage\default\https+++www.youtube.com\cache emptied successfully

==== Empty Chrome Cache ======================

No Chrome Cache found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=3 folders=0 50102 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\XEON\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\XEON\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on Łt 03.01.2017 at 17:50:34,06 ======================

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu

Příspěvekod jaro3 » 03 led 2017 18:36

Stáhni si zde DelFix
https://toolslib.net/downloads/viewdownload/2-delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Yelkinson
Level 3
Level 3
Příspěvky: 582
Registrován: listopad 07
Bydliště: Plzen
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosim o kontrolu logu  Vyřešeno

Příspěvekod Yelkinson » 03 led 2017 23:24

ok zatim to vypada dobre tak dik


# DelFix v1.013 - Logfile created 03/01/2017 at 23:24:11
# Updated 17/04/2016 by Xplode
# Username : XEON - XEON-PC
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\zoek-results.log
Deleted : C:\zoek-results2017-01-02-192107.log
Deleted : C:\Users\XEON\Desktop\adwcleaner_6.041.exe
Deleted : C:\Users\XEON\Desktop\JRT.exe
Deleted : C:\Users\XEON\Desktop\JRT.txt
Deleted : C:\Users\XEON\Desktop\hijackthis.exe
Deleted : C:\Users\XEON\Desktop\hijackthis.log
Deleted : C:\Users\XEON\Desktop\RogueKillerX64.exe
Deleted : C:\Users\XEON\Desktop\TFC.exe
Deleted : C:\Users\XEON\Desktop\zoek.exe

~ Cleaning system restore ...

Deleted : RP #142 [Windows Update | 12/25/2016 12:37:07]
Deleted : RP #143 [Windows Update | 12/30/2016 10:15:32]
Deleted : RP #144 [JRT Pre-Junkware Removal | 01/01/2017 11:23:39]
Deleted : RP #145 [zoek.exe restore point | 01/02/2017 19:06:17]
Deleted : RP #146 [Windows Update | 01/02/2017 19:58:37]

New restore point created !

########## - EOF - ##########


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 8 hostů