Stránka 1 z 1

Prosím o kontrolu.. Někdo se mi dostává na účty google, fb, instagram

Napsal: 02 bře 2022 20:32
od ferneticek
Hezký den, prosím o kontrolu logů. Zřejmě jsem si něco natáhl do pc. V posledních dnech jsem přišel o přístup k účtu na facebooku a Instagramu.. google mám zatím pozastavený do vyřešení. Počítač jsem kontroloval WinDefernder a Esetem. Soubor s logy přikládám. Moc děkuji Roman

Re: Prosím o kontrolu.. Někdo se mi dostává na účty google, fb, instagram

Napsal: 02 bře 2022 20:49
od Rudy
Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi

Re: Prosím o kontrolu.. Někdo se mi dostává na účty google, fb, instagram

Napsal: 02 bře 2022 20:57
od ferneticek
Snad jsem to udělal správně, menu bylo trochu jiné než v návodu. Zasílám log a děkuji

# -------------------------------
# Malwarebytes AdwCleaner 8.3.1.0
# -------------------------------
# Build: 11-18-2021
# Database: 2022-02-03.4 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 03-02-2022
# Duration: 00:00:01
# OS: Windows 10 Home
# Cleaned: 6
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKCU\Software\csastats

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

Deleted Preinstalled.SonyPlayMemoriesHome File C:\Users\Public\Desktop\PlayMemories Home Help.lnk
Deleted Preinstalled.SonyPlayMemoriesHome File C:\Users\Public\Desktop\PlayMemories Home.lnk
Deleted Preinstalled.SonyPlayMemoriesHome Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|PMBVolumeWatcher
Deleted Preinstalled.SonyPlayMemoriesHome Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Run|PMBVolumeWatcher
Deleted Preinstalled.SonyPlayMemoriesHome Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{AEB04E0E-0A28-4014-A96A-282E43B7227B}


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [2010 octets] - [02/03/2022 20:53:10]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Re: Prosím o kontrolu.. Někdo se mi dostává na účty google, fb, instagram

Napsal: 02 bře 2022 21:49
od Rudy
Je to OK. Dejte nové logy FRST+Addition.

Re: Prosím o kontrolu.. Někdo se mi dostává na účty google, fb, instagram

Napsal: 02 bře 2022 21:58
od ferneticek
Děkuji, posílám logy

Re: Prosím o kontrolu.. Někdo se mi dostává na účty google, fb, instagram

Napsal: 03 bře 2022 10:37
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [707256 2021-12-15] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {346dbe04-130a-11eb-a527-f894c23540cf} - "E:\Setup.exe"
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {3bd275bf-92bb-11eb-a54f-f894c23540cf} - "E:\Setup.exe"
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {3bd2761d-92bb-11eb-a54f-f894c23540cf} - "E:\Setup.exe"
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {779ed778-3a22-11eb-a531-f894c23540cf} - "E:\autorun.exe"
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {d6eec80a-1507-11eb-a527-f894c23540cf} - "E:\Setup.exe"
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {f9195cb8-fc81-11eb-a561-f894c23540cf} - "E:\Setup.exe"
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {f9195cc0-fc81-11eb-a561-f894c23540cf} - "E:\Setup.exe"
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {42B4BCBF-6DDF-4AF9-9039-5FAC0D6C86A9} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {EA0B3F23-EC28-4D92-907D-7330BC5DC9E8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-10-24] (Google Inc -> Google Inc.)
Task: {F56DA74A-3CAA-4C5D-9582-AA65266E90F4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-10-24] (Google Inc -> Google Inc.)
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
C:\WINDOWS\yacht.xws
C:\DumpStack.log.tmp
C:\Users\f3rn\AppData\Roaming\settings.xml
C:\Users\f3rn\AppData\Roaming\SGFED.ini
C:\Users\f3rn\AppData\Local\14j3k4qh.owv
C:\Users\f3rn\AppData\Local\1hsgdbde.cdz
C:\Users\f3rn\AppData\Local\2dzpcgbq.2un
C:\Users\f3rn\AppData\Local\2knf2y3h.2gn
C:\Users\f3rn\AppData\Local\2qv03mpu.3mp
C:\Users\f3rn\AppData\Local\32l3qhfc.vz4
C:\Users\f3rn\AppData\Local\3fjufy3d.je0
C:\Users\f3rn\AppData\Local\3frneqam.jb4
C:\Users\f3rn\AppData\Local\51vw5ckf.bo2
C:\Users\f3rn\AppData\Local\5vaenvia.wzb
C:\Users\f3rn\AppData\Local\ahgyvyov.n43
C:\Users\f3rn\AppData\Local\ajcfpjtn.zyn
C:\Users\f3rn\AppData\Local\am2eh35d.omj
C:\Users\f3rn\AppData\Local\ct0ne2ak.1za
C:\Users\f3rn\AppData\Local\d1mst4pb.s2w
C:\Users\f3rn\AppData\Local\d315pu5o.u5y
C:\Users\f3rn\AppData\Local\dagxodai.tno
C:\Users\f3rn\AppData\Local\dbollnsr.r5z
C:\Users\f3rn\AppData\Local\degnoga1.0yn
C:\Users\f3rn\AppData\Local\dvu2fpbg.em2
C:\Users\f3rn\AppData\Local\e213v5l3.sea
C:\Users\f3rn\AppData\Local\e5003d3x.av3
C:\Users\f3rn\AppData\Local\evptibua.zx2
C:\Users\f3rn\AppData\Local\fogriyue.rdv
C:\Users\f3rn\AppData\Local\g13dsxra.bvv
C:\Users\f3rn\AppData\Local\ihvm5gcu.dai
C:\Users\f3rn\AppData\Local\jb4lzj25.ren
C:\Users\f3rn\AppData\Local\jbtjwtbf.rxs
C:\Users\f3rn\AppData\Local\k0vlwkvl.tc3
C:\Users\f3rn\AppData\Local\kclj4bnz.vtc
C:\Users\f3rn\AppData\Local\lhln030i.x3z
C:\Users\f3rn\AppData\Local\m1mtxtcg.ber
C:\Users\f3rn\AppData\Local\nooscpyq.rsu
C:\Users\f3rn\AppData\Local\p4gjwute.oas
C:\Users\f3rn\AppData\Local\pcvyplzd.tl5
C:\Users\f3rn\AppData\Local\ratlt5hx.2hu
C:\Users\f3rn\AppData\Local\rbk2p41z.t1n
C:\Users\f3rn\AppData\Local\rjwuoa4n.5qu
C:\Users\f3rn\AppData\Local\sjjqetai.dre
C:\Users\f3rn\AppData\Local\Temptable.xml
C:\Users\f3rn\AppData\Local\tned1wfq.vwc
C:\Users\f3rn\AppData\Local\uiv2rhik.dcz
C:\Users\f3rn\AppData\Local\uziulnl1.bwr
C:\Users\f3rn\AppData\Local\varczkgw.ucp
C:\Users\f3rn\AppData\Local\vd01r3ql.yvk
C:\Users\f3rn\AppData\Local\vmygdhnw.ih3
C:\Users\f3rn\AppData\Local\x5roxcno.2mr
C:\Users\f3rn\AppData\Local\y1oxhud5.qda
C:\Users\f3rn\AppData\Local\z41cqp5g.lc5
C:\Users\f3rn\AppData\Local\{41246F7E-2EE6-4FE1-8D7C-17355C973EC8}
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
HKLM\...\.scr: => <==== ATTENTION
FirewallRules: [{5151605E-1768-4E7D-928C-8523B6F965B6}] => (Allow) C:\Users\f3rn\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{1B3A7B3D-BDAB-42D8-8F3A-7AB50A5826FD}] => (Allow) C:\Users\f3rn\AppData\Roaming\uTorrent\uTorrent.exe => No File

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Prosím o kontrolu.. Někdo se mi dostává na účty google, fb, instagram

Napsal: 03 bře 2022 12:02
od ferneticek
Hezký den, posílám log. děkuji
Fix result of Farbar Recovery Scan Tool (x64) Version: 27-02-2022
Ran by f3rn (03-03-2022 11:58:10) Run:1
Running from C:\Users\f3rn\Desktop
Loaded Profiles: f3rn
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [707256 2021-12-15] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {346dbe04-130a-11eb-a527-f894c23540cf} - "E:\Setup.exe"
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {3bd275bf-92bb-11eb-a54f-f894c23540cf} - "E:\Setup.exe"
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {3bd2761d-92bb-11eb-a54f-f894c23540cf} - "E:\Setup.exe"
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {779ed778-3a22-11eb-a531-f894c23540cf} - "E:\autorun.exe"
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {d6eec80a-1507-11eb-a527-f894c23540cf} - "E:\Setup.exe"
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {f9195cb8-fc81-11eb-a561-f894c23540cf} - "E:\Setup.exe"
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\...\MountPoints2: {f9195cc0-fc81-11eb-a561-f894c23540cf} - "E:\Setup.exe"
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {42B4BCBF-6DDF-4AF9-9039-5FAC0D6C86A9} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {EA0B3F23-EC28-4D92-907D-7330BC5DC9E8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-10-24] (Google Inc -> Google Inc.)
Task: {F56DA74A-3CAA-4C5D-9582-AA65266E90F4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-10-24] (Google Inc -> Google Inc.)
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
C:\WINDOWS\yacht.xws
C:\DumpStack.log.tmp
C:\Users\f3rn\AppData\Roaming\settings.xml
C:\Users\f3rn\AppData\Roaming\SGFED.ini
C:\Users\f3rn\AppData\Local\14j3k4qh.owv
C:\Users\f3rn\AppData\Local\1hsgdbde.cdz
C:\Users\f3rn\AppData\Local\2dzpcgbq.2un
C:\Users\f3rn\AppData\Local\2knf2y3h.2gn
C:\Users\f3rn\AppData\Local\2qv03mpu.3mp
C:\Users\f3rn\AppData\Local\32l3qhfc.vz4
C:\Users\f3rn\AppData\Local\3fjufy3d.je0
C:\Users\f3rn\AppData\Local\3frneqam.jb4
C:\Users\f3rn\AppData\Local\51vw5ckf.bo2
C:\Users\f3rn\AppData\Local\5vaenvia.wzb
C:\Users\f3rn\AppData\Local\ahgyvyov.n43
C:\Users\f3rn\AppData\Local\ajcfpjtn.zyn
C:\Users\f3rn\AppData\Local\am2eh35d.omj
C:\Users\f3rn\AppData\Local\ct0ne2ak.1za
C:\Users\f3rn\AppData\Local\d1mst4pb.s2w
C:\Users\f3rn\AppData\Local\d315pu5o.u5y
C:\Users\f3rn\AppData\Local\dagxodai.tno
C:\Users\f3rn\AppData\Local\dbollnsr.r5z
C:\Users\f3rn\AppData\Local\degnoga1.0yn
C:\Users\f3rn\AppData\Local\dvu2fpbg.em2
C:\Users\f3rn\AppData\Local\e213v5l3.sea
C:\Users\f3rn\AppData\Local\e5003d3x.av3
C:\Users\f3rn\AppData\Local\evptibua.zx2
C:\Users\f3rn\AppData\Local\fogriyue.rdv
C:\Users\f3rn\AppData\Local\g13dsxra.bvv
C:\Users\f3rn\AppData\Local\ihvm5gcu.dai
C:\Users\f3rn\AppData\Local\jb4lzj25.ren
C:\Users\f3rn\AppData\Local\jbtjwtbf.rxs
C:\Users\f3rn\AppData\Local\k0vlwkvl.tc3
C:\Users\f3rn\AppData\Local\kclj4bnz.vtc
C:\Users\f3rn\AppData\Local\lhln030i.x3z
C:\Users\f3rn\AppData\Local\m1mtxtcg.ber
C:\Users\f3rn\AppData\Local\nooscpyq.rsu
C:\Users\f3rn\AppData\Local\p4gjwute.oas
C:\Users\f3rn\AppData\Local\pcvyplzd.tl5
C:\Users\f3rn\AppData\Local\ratlt5hx.2hu
C:\Users\f3rn\AppData\Local\rbk2p41z.t1n
C:\Users\f3rn\AppData\Local\rjwuoa4n.5qu
C:\Users\f3rn\AppData\Local\sjjqetai.dre
C:\Users\f3rn\AppData\Local\Temptable.xml
C:\Users\f3rn\AppData\Local\tned1wfq.vwc
C:\Users\f3rn\AppData\Local\uiv2rhik.dcz
C:\Users\f3rn\AppData\Local\uziulnl1.bwr
C:\Users\f3rn\AppData\Local\varczkgw.ucp
C:\Users\f3rn\AppData\Local\vd01r3ql.yvk
C:\Users\f3rn\AppData\Local\vmygdhnw.ih3
C:\Users\f3rn\AppData\Local\x5roxcno.2mr
C:\Users\f3rn\AppData\Local\y1oxhud5.qda
C:\Users\f3rn\AppData\Local\z41cqp5g.lc5
C:\Users\f3rn\AppData\Local\{41246F7E-2EE6-4FE1-8D7C-17355C973EC8}
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
HKLM\...\.scr: => <==== ATTENTION
FirewallRules: [{5151605E-1768-4E7D-928C-8523B6F965B6}] => (Allow) C:\Users\f3rn\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{1B3A7B3D-BDAB-42D8-8F3A-7AB50A5826FD}] => (Allow) C:\Users\f3rn\AppData\Roaming\uTorrent\uTorrent.exe => No File

EmptyTemp:
End
*****************

Processes closed successfully.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => removed successfully
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{346dbe04-130a-11eb-a527-f894c23540cf} => removed successfully
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3bd275bf-92bb-11eb-a54f-f894c23540cf} => removed successfully
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3bd2761d-92bb-11eb-a54f-f894c23540cf} => removed successfully
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{779ed778-3a22-11eb-a531-f894c23540cf} => removed successfully
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d6eec80a-1507-11eb-a527-f894c23540cf} => removed successfully
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f9195cb8-fc81-11eb-a561-f894c23540cf} => removed successfully
HKU\S-1-5-21-3183132213-805255280-2740908323-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f9195cc0-fc81-11eb-a561-f894c23540cf} => removed successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{42B4BCBF-6DDF-4AF9-9039-5FAC0D6C86A9}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{42B4BCBF-6DDF-4AF9-9039-5FAC0D6C86A9}" => removed successfully
C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EA0B3F23-EC28-4D92-907D-7330BC5DC9E8}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA0B3F23-EC28-4D92-907D-7330BC5DC9E8}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F56DA74A-3CAA-4C5D-9582-AA65266E90F4}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F56DA74A-3CAA-4C5D-9582-AA65266E90F4}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => removed successfully
C:\WINDOWS\yacht.xws => moved successfully
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
C:\Users\f3rn\AppData\Roaming\settings.xml => moved successfully
C:\Users\f3rn\AppData\Roaming\SGFED.ini => moved successfully
C:\Users\f3rn\AppData\Local\14j3k4qh.owv => moved successfully
C:\Users\f3rn\AppData\Local\1hsgdbde.cdz => moved successfully
C:\Users\f3rn\AppData\Local\2dzpcgbq.2un => moved successfully
C:\Users\f3rn\AppData\Local\2knf2y3h.2gn => moved successfully
C:\Users\f3rn\AppData\Local\2qv03mpu.3mp => moved successfully
C:\Users\f3rn\AppData\Local\32l3qhfc.vz4 => moved successfully
C:\Users\f3rn\AppData\Local\3fjufy3d.je0 => moved successfully
C:\Users\f3rn\AppData\Local\3frneqam.jb4 => moved successfully
C:\Users\f3rn\AppData\Local\51vw5ckf.bo2 => moved successfully
C:\Users\f3rn\AppData\Local\5vaenvia.wzb => moved successfully
C:\Users\f3rn\AppData\Local\ahgyvyov.n43 => moved successfully
C:\Users\f3rn\AppData\Local\ajcfpjtn.zyn => moved successfully
C:\Users\f3rn\AppData\Local\am2eh35d.omj => moved successfully
C:\Users\f3rn\AppData\Local\ct0ne2ak.1za => moved successfully
C:\Users\f3rn\AppData\Local\d1mst4pb.s2w => moved successfully
C:\Users\f3rn\AppData\Local\d315pu5o.u5y => moved successfully
C:\Users\f3rn\AppData\Local\dagxodai.tno => moved successfully
C:\Users\f3rn\AppData\Local\dbollnsr.r5z => moved successfully
C:\Users\f3rn\AppData\Local\degnoga1.0yn => moved successfully
C:\Users\f3rn\AppData\Local\dvu2fpbg.em2 => moved successfully
C:\Users\f3rn\AppData\Local\e213v5l3.sea => moved successfully
C:\Users\f3rn\AppData\Local\e5003d3x.av3 => moved successfully
C:\Users\f3rn\AppData\Local\evptibua.zx2 => moved successfully
C:\Users\f3rn\AppData\Local\fogriyue.rdv => moved successfully
C:\Users\f3rn\AppData\Local\g13dsxra.bvv => moved successfully
C:\Users\f3rn\AppData\Local\ihvm5gcu.dai => moved successfully
C:\Users\f3rn\AppData\Local\jb4lzj25.ren => moved successfully
C:\Users\f3rn\AppData\Local\jbtjwtbf.rxs => moved successfully
C:\Users\f3rn\AppData\Local\k0vlwkvl.tc3 => moved successfully
C:\Users\f3rn\AppData\Local\kclj4bnz.vtc => moved successfully
C:\Users\f3rn\AppData\Local\lhln030i.x3z => moved successfully
C:\Users\f3rn\AppData\Local\m1mtxtcg.ber => moved successfully
C:\Users\f3rn\AppData\Local\nooscpyq.rsu => moved successfully
C:\Users\f3rn\AppData\Local\p4gjwute.oas => moved successfully
C:\Users\f3rn\AppData\Local\pcvyplzd.tl5 => moved successfully
C:\Users\f3rn\AppData\Local\ratlt5hx.2hu => moved successfully
C:\Users\f3rn\AppData\Local\rbk2p41z.t1n => moved successfully
C:\Users\f3rn\AppData\Local\rjwuoa4n.5qu => moved successfully
C:\Users\f3rn\AppData\Local\sjjqetai.dre => moved successfully
C:\Users\f3rn\AppData\Local\Temptable.xml => moved successfully
C:\Users\f3rn\AppData\Local\tned1wfq.vwc => moved successfully
C:\Users\f3rn\AppData\Local\uiv2rhik.dcz => moved successfully
C:\Users\f3rn\AppData\Local\uziulnl1.bwr => moved successfully
C:\Users\f3rn\AppData\Local\varczkgw.ucp => moved successfully
C:\Users\f3rn\AppData\Local\vd01r3ql.yvk => moved successfully
C:\Users\f3rn\AppData\Local\vmygdhnw.ih3 => moved successfully
C:\Users\f3rn\AppData\Local\x5roxcno.2mr => moved successfully
C:\Users\f3rn\AppData\Local\y1oxhud5.qda => moved successfully
C:\Users\f3rn\AppData\Local\z41cqp5g.lc5 => moved successfully
C:\Users\f3rn\AppData\Local\{41246F7E-2EE6-4FE1-8D7C-17355C973EC8} => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Classes\.scr\\"Default"="scrfile" => value restored successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5151605E-1768-4E7D-928C-8523B6F965B6}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1B3A7B3D-BDAB-42D8-8F3A-7AB50A5826FD}" => not found

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 208176127 B
Java, Flash, Steam htmlcache => 393984612 B
Windows/system/drivers => 23539454 B
Edge => 132144 B
Chrome => 643004799 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 152800388 B
systemprofile32 => 152812781 B
LocalService => 152831119 B
NetworkService => 152846149 B
f3rn => 1007104989 B

RecycleBin => 0 B
EmptyTemp: => 2.7 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 03-03-2022 12:00:04)

C:\DumpStack.log.tmp => Could not move

==== End of Fixlog 12:00:04 ====

Re: Prosím o kontrolu.. Někdo se mi dostává na účty google, fb, instagram

Napsal: 03 bře 2022 13:14
od Rudy
Smazáno, log by již měl být OK.

Re: Prosím o kontrolu.. Někdo se mi dostává na účty google, fb, instagram

Napsal: 03 bře 2022 13:23
od ferneticek
Mockrát děkuji, znamená to, že by měl být PC čistý? Nebo bych měl ještě udělat nějaké další aktivity?

Re: Prosím o kontrolu.. Někdo se mi dostává na účty google, fb, instagram

Napsal: 03 bře 2022 13:59
od Rudy
Snad ještě změnit všechna hesla. PC by měl být OK.

Re: Prosím o kontrolu.. Někdo se mi dostává na účty google, fb, instagram

Napsal: 03 bře 2022 14:14
od ferneticek
To je skvělé, děkuji příspěvek na chod fóra jsem odeslal.
Děkuji a přeji ať se daří.

Re: Prosím o kontrolu.. Někdo se mi dostává na účty google, fb, instagram

Napsal: 03 bře 2022 14:47
od Rudy
My děkujeme za příspěvek a vy nemáte zač! :)