Stránka 1 z 1

trojan golroted, fakems podle spyhunter prosím o kontrolu

Napsal: 03 lis 2019 17:38
od kubanecjam
Zdravím a předem Vám díky za pomoc. Větráček zdá se jede i když je notebook v režimu spánku. Měl jsem podezření že mi někdo sosá kuli bitcoinum - paranoia, nevím. Tak jsem zapl spyhunter - našel golroted a fakems, pak jsem projel noťas malwarebytes programem a eset online. Přikládám log z FRST. Nejsem v tom moc zdatný tak snad to bude stačit. Díky

ps. Textu bylo příliš - zabalil jsem tedy vše do zipu a přikládám v příloze logy z FRST atd. .

Jakub
kontrola malware.zip
(187.39 KiB) Staženo 67 x

Re: trojan golroted, fakems podle spyhunter prosím o kontrol

Napsal: 03 lis 2019 17:58
od Rudy
Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi

Re: trojan golroted, fakems podle spyhunter prosím o kontrol

Napsal: 03 lis 2019 18:17
od kubanecjam
Cisteni a opravy (Clean and Repair) nebylo v nabídce - pouze quaranten nebo tak nějak. Po té proběhl restart a log je zde :

# -------------------------------
# Malwarebytes AdwCleaner 7.4.2.0
# -------------------------------
# Build: 10-21-2019
# Database: 2019-10-21.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 11-03-2019
# Duration: 00:00:22
# OS: Windows 10 Home
# Cleaned: 29
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\Program Files (x86)\IOBIT\Driver Booster
Deleted C:\ProgramData\Application Data\Lavasoft\Web Companion
Deleted C:\ProgramData\Host App Service
Deleted C:\ProgramData\IOBIT\Driver Booster
Deleted C:\ProgramData\IObit\Advanced SystemCare
Deleted C:\Users\Default\AppData\Local\Host App Service
Deleted C:\Users\defaultuser0\AppData\Local\Host App Service
Deleted C:\Users\kubanecjam\AppData\Local\Host App Service
Deleted C:\Users\kubanecjam\AppData\Roaming\IOBIT\Driver Booster
Deleted C:\Users\kubanecjam\AppData\Roaming\IObit\Advanced SystemCare
Deleted C:\Windows\ServiceProfiles\LocalService\AppData\Local\Host App Service
Deleted C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Host App Service

***** [ Files ] *****

Deleted C:\Users\kubanecjam\Downloads\SpyHunter-Installer.exe
Deleted C:\Windows\System32\Tasks_Migrated\App Explorer

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted C:\Windows\System32\Tasks\DRIVER BOOSTER SCHEDULER

***** [ Registry ] *****

Deleted HKCU\Software\App Host Service
Deleted HKCU\Software\Host App Service
Deleted HKCU\Software\Lavasoft\Web Companion
Deleted HKCU\Software\Microsoft\Internet Explorer\Main|Start Page
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2974C985-8151-4DE5-B23C-B875F0A8522F}
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9D7CC28A-60CE-409A-9795-5C51FB136737}
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler
Deleted HKLM\Software\Wow6432Node\IObit\Driver Booster
Deleted HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Ext\Stats\{2974C985-8151-4DE5-B23C-B875F0A8522F}
Deleted HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Driver Booster_is1

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner_Debug.log - [101152 octets] - [03/11/2019 18:10:42]
AdwCleaner[S00].txt - [6274 octets] - [03/11/2019 18:11:48]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Re: trojan golroted, fakems podle spyhunter prosím o kontrol

Napsal: 03 lis 2019 18:56
od Rudy
OK. Dejte nové logy FRST+Addition.

Re: trojan golroted, fakems podle spyhunter prosím o kontrol

Napsal: 03 lis 2019 19:07
od kubanecjam
Log FRST nic neobsahuje pouze oznámení "end of frst". Dá se již vyčíst co je kde špatně ? Díky.

Addition zde :

==================== Memory info ===========================

BIOS: LENOVO 5PCN24WW 10/29/2018
Motherboard: LENOVO LNVNB161216
Processor: AMD A9-9420 RADEON R5, 5 COMPUTE CORES 2C+3G
Percentage of memory in use: 42%
Total physical RAM: 7567.98 MB
Available physical RAM: 4376.21 MB
Total Virtual: 8783.98 MB
Available Virtual: 5238.79 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:905.27 GB) (Free:708.25 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:23.69 GB) NTFS
Drive f: (ableton_live_suite_10.0.1) (CDROM) (Total:2.55 GB) (Free:0 GB) UDF

\\?\Volume{9277e051-5bed-402d-a6a0-df1ce3096a01}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.46 GB) NTFS
\\?\Volume{8b2f2769-4027-4d6a-bbc2-b0fea055e01f}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 558FB2A7)

Partition: GPT.

==================== End of Addition.txt =======================

Re: trojan golroted, fakems podle spyhunter prosím o kontrol

Napsal: 03 lis 2019 19:50
od Rudy
To se dá vyčíst jen z kompletních logů. Tohle je divné, když ty původní, co jste dal, byly kompletní. ADW jsme spouštěli jen proto, aby se vyčistilo něco, co je možné automaticky a tím to ubylo v systému. Proto požaduji nové logy.

Re: trojan golroted, fakems podle spyhunter prosím o kontrol

Napsal: 03 lis 2019 20:02
od kubanecjam
Tak znovu, teď už je plný.

Zase moc dlouhé - posílám zip.
frst + addition 03.zip
(40.11 KiB) Staženo 77 x

Re: trojan golroted, fakems podle spyhunter prosím o kontrol

Napsal: 03 lis 2019 20:23
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-12-19] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001\...\MountPoints2: {dfc62933-5915-11e9-8458-54e1ad6756d2} - "G:\Setup.exe"
GroupPolicy: Restriction ? <==== ATTENTION
Task: {2491FEA9-0EFC-45FD-A79B-55C298FBBCCB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-08-02] (Google Inc -> Google Inc.)
Task: {49296EBB-C67C-40CE-B3E4-C34E3852B14A} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {71DF4F4B-4129-4928-B495-AFAD3CFD00E9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-08-02] (Google Inc -> Google Inc.)
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
SearchScopes: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001 -> DefaultScope {C5562735-3D71-4143-8D59-4AC0A44F7BF8} URL =
SearchScopes: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001 -> {C5562735-3D71-4143-8D59-4AC0A44F7BF8} URL =
BHO: No Name -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> No File
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll => No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers1: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers4: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
FirewallRules: [{6986F3CC-352A-4987-ABE4-ABE5FD1EDB8A}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\AutoUpdate.exe No File
FirewallRules: [{641C7125-17D3-4D10-BA46-64F20AF2A63C}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\AutoUpdate.exe No File
FirewallRules: [{4F6C71A8-F62D-426E-B487-CD3BDF7E78E4}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DBDownloader.exe No File
FirewallRules: [{24A0C771-2914-45AD-BFB8-77E0203E26E2}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DBDownloader.exe No File
FirewallRules: [{79CF4AD9-9E87-43E0-8D5B-6F3AB5352F17}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DriverBooster.exe No File
FirewallRules: [{DEC3F769-C7DC-4662-A23A-FDEC89C235C9}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DriverBooster.exe No File

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: trojan golroted, fakems podle spyhunter prosím o kontrol

Napsal: 03 lis 2019 21:17
od kubanecjam
Fix jsem spouštěl 2x - poprvé zamrzl FRST u "delete....... history/low/IE5/container - nebo tak nějak, bohužel si nepamatuji přesně tu cestu (10 min. se nehnul "neodpovídá"). Po druhé projel bez problémů a po té proběhl restart. IE jako internet explorer ? Co to maže když ho nepoužívám ?


Fix result of Farbar Recovery Scan Tool (x64) Version: 01-11-2019
Ran by kubanecjam (03-11-2019 21:10:51) Run:2
Running from C:\Users\kubanecjam\Desktop
Loaded Profiles: kubanecjam (Available Profiles: defaultuser0 & kubanecjam)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-12-19] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001\...\MountPoints2: {dfc62933-5915-11e9-8458-54e1ad6756d2} - "G:\Setup.exe"
GroupPolicy: Restriction ? <==== ATTENTION
Task: {2491FEA9-0EFC-45FD-A79B-55C298FBBCCB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-08-02] (Google Inc -> Google Inc.)
Task: {49296EBB-C67C-40CE-B3E4-C34E3852B14A} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {71DF4F4B-4129-4928-B495-AFAD3CFD00E9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-08-02] (Google Inc -> Google Inc.)
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
SearchScopes: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001 -> DefaultScope {C5562735-3D71-4143-8D59-4AC0A44F7BF8} URL =
SearchScopes: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001 -> {C5562735-3D71-4143-8D59-4AC0A44F7BF8} URL =
BHO: No Name -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> No File
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll => No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers1: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers4: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
FirewallRules: [{6986F3CC-352A-4987-ABE4-ABE5FD1EDB8A}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\AutoUpdate.exe No File
FirewallRules: [{641C7125-17D3-4D10-BA46-64F20AF2A63C}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\AutoUpdate.exe No File
FirewallRules: [{4F6C71A8-F62D-426E-B487-CD3BDF7E78E4}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DBDownloader.exe No File
FirewallRules: [{24A0C771-2914-45AD-BFB8-77E0203E26E2}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DBDownloader.exe No File
FirewallRules: [{79CF4AD9-9E87-43E0-8D5B-6F3AB5352F17}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DriverBooster.exe No File
FirewallRules: [{DEC3F769-C7DC-4662-A23A-FDEC89C235C9}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DriverBooster.exe No File

EmptyTemp:
End
*****************

Processes closed successfully.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => not found
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => not found
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{dfc62933-5915-11e9-8458-54e1ad6756d2} => not found
"C:\WINDOWS\system32\GroupPolicy\Machine" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2491FEA9-0EFC-45FD-A79B-55C298FBBCCB}" => not found
"C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{49296EBB-C67C-40CE-B3E4-C34E3852B14A}" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71DF4F4B-4129-4928-B495-AFAD3CFD00E9}" => not found
"C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => not found
"HKU\S-1-5-21-3336338966-3122574598-2895618767-1001\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages" => not found
"HKU\S-1-5-21-3336338966-3122574598-2895618767-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C5562735-3D71-4143-8D59-4AC0A44F7BF8} => not found
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814} => not found
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA" => not found
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore" => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220} => not found
HKU\S-1-5-21-3336338966-3122574598-2895618767-1001_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\IObitUnstaler => not found
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\IObitUnstaler => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\IObitUnstaler => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6986F3CC-352A-4987-ABE4-ABE5FD1EDB8A}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{641C7125-17D3-4D10-BA46-64F20AF2A63C}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4F6C71A8-F62D-426E-B487-CD3BDF7E78E4}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{24A0C771-2914-45AD-BFB8-77E0203E26E2}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{79CF4AD9-9E87-43E0-8D5B-6F3AB5352F17}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DEC3F769-C7DC-4662-A23A-FDEC89C235C9}" => not found

=========== EmptyTemp: ==========

BITS transfer queue => 10772480 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 8388632 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 1119 B
Edge => 0 B
Chrome => 0 B
Firefox => 14442109 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
defaultuser0 => 0 B
kubanecjam => 7184 B

RecycleBin => 2224337559 B
EmptyTemp: => 2.1 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 21:11:53 ====

Re: trojan golroted, fakems podle spyhunter prosím o kontrol

Napsal: 03 lis 2019 22:05
od Rudy
Když FRST nepoužíváte, pak sám od sebe nemaže nic. Je schopen mazat jen za pomocí skriptu kliknutím na tlačítko "Fix". V našm případěš mazal převážně zbytečnosti a zbytky po aplikacích, které v PC už nejsou (byly smazány, nebo odinstalovány). IE je opravdu internet explorer. Zřejmě jste ho někdy použil a zůstaly tam nějaké zbytky.

Re: trojan golroted, fakems podle spyhunter prosím o kontrol

Napsal: 12 lis 2019 18:52
od kubanecjam
Tak díky, tímto to končí ? Zakoupil jsem konečně eset licenci tak jsem to projel a nikde nic - dle esetu. Mám ještě nějak pokračovat v čištění ? Občas spustit nějaký nástroj na kontrolu a čištění nebo v případě pochybností se obrátit na toto forum ? A ještě by mě zajímalo co znamenal ten trojan golroted, fakems co našel spyhunter ?

Díky moc. Je pravda, že noťas se trochu uklidnil.

Re: trojan golroted, fakems podle spyhunter prosím o kontrol

Napsal: 12 lis 2019 18:59
od Rudy
Pokud nemáte další problém, je to ode mne vše. Co se týče trojanu golroted, nějaké info zde: https://translate.google.com/translate? ... rev=search .