Stránka 1 z 1

Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 07 dub 2019 11:23
od gastrotop
Logy v příloze.. moc děkuji!

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 08 dub 2019 12:31
od Rudy
Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 08 dub 2019 12:54
od gastrotop
# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build: 04-04-2019
# Database: 2019-04-05.4 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 04-08-2019
# Duration: 00:00:01
# OS: Windows 10 Home
# Cleaned: 1
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKLM\Software\Classes\REI_AxControl.ReiEngine.1

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1242 octets] - [24/04/2018 17:04:43]
AdwCleaner[C00].txt - [1367 octets] - [24/04/2018 17:06:55]
AdwCleaner[S01].txt - [1242 octets] - [09/05/2018 20:38:54]
AdwCleaner[S02].txt - [1242 octets] - [24/05/2018 20:04:41]
AdwCleaner[S03].txt - [1242 octets] - [26/05/2018 17:09:18]
AdwCleaner[S04].txt - [1242 octets] - [01/06/2018 05:04:51]
AdwCleaner[S05].txt - [1242 octets] - [18/06/2018 17:26:26]
AdwCleaner[S06].txt - [1273 octets] - [25/06/2018 16:55:35]
AdwCleaner[C06].txt - [1378 octets] - [25/06/2018 16:55:58]
AdwCleaner[S07].txt - [1242 octets] - [27/06/2018 06:08:08]
AdwCleaner[S08].txt - [1242 octets] - [06/07/2018 07:26:18]
AdwCleaner[S09].txt - [1242 octets] - [21/07/2018 02:36:28]
AdwCleaner[S10].txt - [1242 octets] - [26/08/2018 22:11:32]
AdwCleaner[S11].txt - [2043 octets] - [09/09/2018 21:47:16]
AdwCleaner[S12].txt - [1230 octets] - [02/10/2018 19:54:16]
AdwCleaner[S13].txt - [1230 octets] - [10/10/2018 21:28:02]
AdwCleaner[S14].txt - [1230 octets] - [10/10/2018 21:28:42]
AdwCleaner[S15].txt - [1242 octets] - [07/11/2018 17:26:01]
AdwCleaner[S16].txt - [1230 octets] - [05/02/2019 14:54:36]
AdwCleaner[S17].txt - [1230 octets] - [05/02/2019 14:56:22]
AdwCleaner[S18].txt - [2470 octets] - [12/02/2019 10:05:40]
AdwCleaner[C18].txt - [2656 octets] - [12/02/2019 10:06:03]
AdwCleaner[S19].txt - [1230 octets] - [19/02/2019 22:05:45]
AdwCleaner[C19].txt - [1355 octets] - [19/02/2019 22:06:18]
AdwCleaner[S20].txt - [1230 octets] - [24/02/2019 22:37:25]
AdwCleaner[S21].txt - [1230 octets] - [14/03/2019 07:55:21]
AdwCleaner[S22].txt - [1242 octets] - [17/03/2019 21:32:39]
AdwCleaner[S23].txt - [3236 octets] - [07/04/2019 00:05:53]
AdwCleaner[C23].txt - [3015 octets] - [07/04/2019 00:07:07]
AdwCleaner[S24].txt - [2398 octets] - [07/04/2019 00:18:53]
AdwCleaner[S25].txt - [2465 octets] - [07/04/2019 12:05:36]
AdwCleaner[C25].txt - [2354 octets] - [07/04/2019 12:05:48]
AdwCleaner[S26].txt - [3245 octets] - [08/04/2019 13:50:41]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C26].txt ##########

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 08 dub 2019 14:05
od Rudy
Dejte nové logy FRST+Addition.

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 08 dub 2019 14:55
od gastrotop
v příloze..

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 08 dub 2019 17:01
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKLM\...\Run: [] => [X]
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
C:\Users\DetialStav\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {237669CB-4B63-4C9D-B367-F61298BE894E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {7D9AF41E-F71C-435D-9510-9B178A6E3550} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {E40FFA92-5B5F-429A-B0E5-46DEFE9A20D5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
FirewallRules: [{4BFB7000-01E5-4EED-A90E-BEDE9A700976}] => (Allow) E:\HRA\Steam.exe No File
FirewallRules: [{2D2C925C-E946-4E68-AB1A-34BF8D2E0727}] => (Allow) E:\HRA\Steam.exe No File
FirewallRules: [{330FDB33-E5CC-48FF-B345-888A0D73DAEE}] => (Allow) E:\HRA\bin\cef\cef.win7x64\steamwebhelper.exe No File
FirewallRules: [{37FE1E91-CC1D-4220-A854-ED21635FFA91}] => (Allow) E:\HRA\bin\cef\cef.win7x64\steamwebhelper.exe No File
FirewallRules: [{99C8FB72-652C-414F-A6F4-9754B22C99A3}] => (Allow) E:\HRA\steamapps\common\Sniper Ghost Warrior 3\win_x64\SGW3.exe No File
FirewallRules: [{B84C9469-D271-4FA0-A30C-917B1406EE21}] => (Allow) E:\HRA\steamapps\common\Sniper Ghost Warrior 3\win_x64\SGW3.exe No File

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 08 dub 2019 17:19
od gastrotop
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found


The system needed a reboot.

==== End of Fixlog 18:13:05 ====

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 08 dub 2019 17:50
od Rudy
gastrotop píše:HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found


The system needed a reboot.

==== End of Fixlog 18:13:05 ====
To je celé?

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 08 dub 2019 18:02
od gastrotop
Hmm.. je, víc se v tom neukázalo, ještě to dám do přílohy.

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 08 dub 2019 19:52
od Rudy
To je divné. Zkuste to spustit v nouz. režimu.

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 08 dub 2019 20:18
od gastrotop
Fix result of Farbar Recovery Scan Tool (x64) Version: 17.03.2019
Ran by DetialStav (08-04-2019 21:10:59) Run:3
Running from C:\Users\DetialStav\Desktop
Loaded Profiles: DetialStav (Available Profiles: defaultuser0 & DetialStav)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
HKLM\...\Run: [] => [X]
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
C:\Users\DetialStav\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {237669CB-4B63-4C9D-B367-F61298BE894E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {7D9AF41E-F71C-435D-9510-9B178A6E3550} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {E40FFA92-5B5F-429A-B0E5-46DEFE9A20D5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
FirewallRules: [{4BFB7000-01E5-4EED-A90E-BEDE9A700976}] => (Allow) E:\HRA\Steam.exe No File
FirewallRules: [{2D2C925C-E946-4E68-AB1A-34BF8D2E0727}] => (Allow) E:\HRA\Steam.exe No File
FirewallRules: [{330FDB33-E5CC-48FF-B345-888A0D73DAEE}] => (Allow) E:\HRA\bin\cef\cef.win7x64\steamwebhelper.exe No File
FirewallRules: [{37FE1E91-CC1D-4220-A854-ED21635FFA91}] => (Allow) E:\HRA\bin\cef\cef.win7x64\steamwebhelper.exe No File
FirewallRules: [{99C8FB72-652C-414F-A6F4-9754B22C99A3}] => (Allow) E:\HRA\steamapps\common\Sniper Ghost Warrior 3\win_x64\SGW3.exe No File
FirewallRules: [{B84C9469-D271-4FA0-A30C-917B1406EE21}] => (Allow) E:\HRA\steamapps\common\Sniper Ghost Warrior 3\win_x64\SGW3.exe No File

EmptyTemp:
End
*****************

Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\" => not found
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA" => not found
"C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore" => not found
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => moved successfully
"C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat" => not found
"C:\Users\DetialStav\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini" => not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => not found
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{237669CB-4B63-4C9D-B367-F61298BE894E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{237669CB-4B63-4C9D-B367-F61298BE894E}" => removed successfully
"C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7D9AF41E-F71C-435D-9510-9B178A6E3550}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D9AF41E-F71C-435D-9510-9B178A6E3550}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CCleanerSkipUAC" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E40FFA92-5B5F-429A-B0E5-46DEFE9A20D5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E40FFA92-5B5F-429A-B0E5-46DEFE9A20D5}" => removed successfully
"C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4BFB7000-01E5-4EED-A90E-BEDE9A700976}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2D2C925C-E946-4E68-AB1A-34BF8D2E0727}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{330FDB33-E5CC-48FF-B345-888A0D73DAEE}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{37FE1E91-CC1D-4220-A854-ED21635FFA91}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{99C8FB72-652C-414F-A6F4-9754B22C99A3}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B84C9469-D271-4FA0-A30C-917B1406EE21}" => removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 54593019 B
Java, Flash, Steam htmlcache => 42842584 B
Windows/system/drivers => 130257 B
Edge => 1104197 B
Chrome => 146086 B
Firefox => 1088156553 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 6656 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 7218 B
LocalService => 0 B
NetworkService => 5971096 B
NetworkService => 0 B
defaultuser0 => 6656 B
DetialStav => 227861944 B

RecycleBin => 34830982 B
EmptyTemp: => 1.4 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 21:13:35 ====

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 08 dub 2019 20:57
od Rudy
Smazáno, log by již měl být OK.

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 08 dub 2019 21:03
od gastrotop
Moc děkuji!

Re: Dobrý den, prosím o kontrolu. Děkuji!

Napsal: 09 dub 2019 09:09
od Rudy
Rádo se stalo! :)