MbAM log --------------------------------------------------------------------------------------------------------------------------------------Malwarebytes Anti-Malware
http://www.malwarebytes.orgDatum skenování: 29.07.2015
Čas skenování: 13:40
Protokol: trol.txt
Správce: Ano
Verze: 2.1.8.1057
Databáze malwaru: v2015.07.29.02
Databáze rootkitů: v2015.07.29.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto
OS: Windows 10
CPU: x64
Souborový systém: NTFS
Uživatel: luke1
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 534548
Uplynulý čas: 45 min, 22 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Nenalezeny žádné škodlivé položky)
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 0
(Nenalezeny žádné škodlivé položky)
Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 2
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\bitstreams, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Soubory: 17
PUP.Optional.Bitcoin, C:\Windows\SysWOW64\acumncgjlamg.exe, Do karantény, [1c6a7e693b4f979f9810a138a45d6f91],
PUP.BitCoinMiner, C:\Windows\SysWOW64\lcpmncgjlamg.exe, Do karantény, [8cfab1364b3f53e31e14c626936dd52b],
Trojan.BitMiner, C:\Windows\SysWOW64\dcgmncgjlamg.exe, Do karantény, [c5c1f5f2ee9c03334e75647aed14f709],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\diablo130302.cl, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\diakgcn121016.cl, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\libcurl-4.dll, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\libeay32.dll, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\libidn-11.dll, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\librtmp.dll, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\libssh2.dll, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\mncrwfks.exe, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\phatk121016.cl, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\poclbm130302.cl, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\scrypt130511.cl, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\ssleay32.dll, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\zlib1.dll, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Trojan.Agent.BCM, C:\Windows\INF\mncrwfks\bitstreams\fpgaminer_top_fixed7_197MHz.ncd, Do karantény, [add9a344a9e17abcb3477269bd45857b],
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)
AdwCleaner log --------------------------------------------------------------------------------------------------------------------------------------# AdwCleaner v4.208 - Log vytvořen 29/07/2015 v 16:37:40
# Aktualizováno 09/07/2015 by Xplode
# Databáze : 2015-07-26.2 [Server]
# Operační system : Windows 10 Home (x64)
# Uživatelské jméno : luke1 - EPICON
# Spuštěno z : C:\Users\luke1\Downloads\adwcleaner_4.208 (1).exe
# Nastavení : Čištění
***** [ Služby ] *****
[#] Služba Smazáno : vToolbarUpdater18.8.0
***** [ Soubory / Složky ] *****
***** [ Naplánované úlohy ] *****
***** [ Zástupci ] *****
***** [ Registry ] *****
***** [ Prohlížeče ] *****
-\\ Internet Explorer v11.0.10240.16384
-\\ Google Chrome v44.0.2403.107
[C:\Users\luke1\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Homepage] : management","nativeMessaging","searchProvider","startupPages","storage","tabs","unlimitedStorage","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"commands":{"_execute_page_action":{"suggested_key":"Alt+Shift+P"}},"content_settings":[],"creation_flags":9,"disable_reasons":32,"events":[],"extension_can_script_all_urls":true,"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["browsingData","cookies","downloads","downloadsInternal","history","homepage","management","nativeMessaging","searchProvider","startupPages","storage","tabs","unlimitedStorage","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13081635642794171","lastpingday":"13082626769611368","location":1,"manifest":{"background":{"page":"background.html","persistent":true},"chrome_settings_overrides":{"homepage":"hxxps://mysearch.avg.com/?rvt=1","search_provider":{"encoding":"UTF-8","favicon_url":"hxxps://mysearch.avg.com/favicon.ico","is_default":true,"keyword":"hxxps://mysearch.avg.com","name":"AVG Secure Search
[C:\Users\lukec\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Homepage] : management","nativeMessaging","searchProvider","startupPages","storage","tabs","unlimitedStorage","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"commands":{"_execute_page_action":{"suggested_key":"Alt+Shift+P"}},"content_settings":[],"creation_flags":9,"disable_reasons":32,"events":[],"extension_can_script_all_urls":true,"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["browsingData","cookies","downloads","downloadsInternal","history","homepage","management","nativeMessaging","searchProvider","startupPages","storage","tabs","unlimitedStorage","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13081349504324940","lastpingday":"13081589994294544","location":1,"manifest":{"background":{"page":"background.html","persistent":true},"chrome_settings_overrides":{"homepage":"hxxps://mysearch.avg.com/?rvt=1","search_provider":{"encoding":"UTF-8","favicon_url":"hxxps://mysearch.avg.com/favicon.ico","is_default":true,"keyword":"hxxps://mysearch.avg.com","name":"AVG Secure Search
[C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Homepage] : management","nativeMessaging","searchProvider","startupPages","storage","tabs","unlimitedStorage","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"commands":{"_execute_page_action":{"suggested_key":"Alt+Shift+P","was_assigned":true}},"content_settings":[],"creation_flags":9,"disable_reasons":33,"events":[],"extension_can_script_all_urls":true,"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["browsingData","cookies","downloads","downloadsInternal","history","homepage","management","nativeMessaging","searchProvider","startupPages","storage","tabs","unlimitedStorage","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13081274932762821","lastpingday":"13081244401570394","location":1,"manifest":{"background":{"page":"background.html","persistent":true},"chrome_settings_overrides":{"homepage":"hxxps://mysearch.avg.com/?rvt=1","search_provider":{"encoding":"UTF-8","favicon_url":"hxxps://mysearch.avg.com/favicon.ico","is_default":true,"keyword":"hxxps://mysearch.avg.com","name":"AVG Secure Search
*************************
AdwCleaner[R3].txt - [5211 bytů] - [29/07/2015 16:37:28]
AdwCleaner[S1].txt - [5136 bytů] - [29/07/2015 16:37:40]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [5194 bytů] ##########
JRT log --------------------------------------------------------------------------------------------------------------------------------------~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.4 (07.27.2015:1)
OS: Windows 10 Home x64
Ran by luke1 on 29.07.2015 at 16:42:52,55
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Driver Booster Scan
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Driver Booster SkipUAC (Luk ç)
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Driver Booster Update
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3023154953-198692014-4210139472-1079\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update Kozaka
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util Kozaka
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\Program Files (x86)\company
Successfully deleted: [Folder] C:\Program Files (x86)\IObit\Driver Booster
Successfully deleted: [Folder] C:\ProgramData\Alawar
Successfully deleted: [Folder] C:\ProgramData\AlawarWrapper
Successfully deleted: [Folder] C:\ProgramData\IObit\Driver Booster
Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\driver booster 2
Successfully deleted: [Folder] C:\ProgramData\productdata
Successfully deleted: [Folder] C:\Users\luke1\AppData\Roaming\productdata
Successfully deleted: [Folder] C:\users\Public\Documents\alawarwrapper
Successfully deleted: [Folder] C:\WINDOWS\SysWOW64\ai_recyclebin
~~~ Chrome
[C:\Users\luke1\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\luke1\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\luke1\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\luke1\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.07.2015 at 16:52:34,56
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
RogueKiller log --------------------------------------------------------------------------------------------------------------------------------------RogueKiller V10.9.3.0 (x64) [Jul 21 2015] by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
http://forum.adlice.comWebová stránka :
http://www.adlice.com/softwares/roguekiller/Blog :
http://www.adlice.comOperační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno : Normální režim
Uživatel : luke1 [Práva správce]
Started from : C:\Users\luke1\Desktop\RogueKillerX64.exe
Mód : Smazat -- Datum : 07/29/2015 17:17:17
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 4 ¤¤¤
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page :
http://www.bing.com?pc=CMNTDFJS -> Nahrazeno (
http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
http://www.bing.com?pc=CMNTDFJS -> Nahrazeno (
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3023154953-198692014-4210139472-1079\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
http://www.bing.com?pc=CMNTDFJS -> Nahrazeno (
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3023154953-198692014-4210139472-1079\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
http://www.bing.com?pc=CMNTDFJS -> Nahrazeno (
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome)
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS547575A9E384 +++++
--- User ---
[MBR] 5563ee86216a1c21e78cfa8297c1cea8
[BSP] 6a3125a7f090a24988d63ba5cae1a61d : Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 2048 | Size: 1000 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2050048 | Size: 100 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 2254848 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 2516992 | Size: 544112 MB
4 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1116860416 | Size: 480 MB
5 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1122215936 | Size: 519 MB
6 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1123278848 | Size: 537 MB
7 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1124378624 | Size: 350 MB
8 - Basic data partition | Offset (sectors): 1125095424 | Size: 150023 MB
9 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1432344576 | Size: 350 MB
10 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1433061376 | Size: 350 MB
11 - [SYSTEM] Basic data partition | Offset (sectors): 1433778176 | Size: 13267 MB
12 - [SYSTEM] Basic data partition | Offset (sectors): 1460948992 | Size: 2044 MB
User = LL1 ... OK
User = LL2 ... OK