Stránka 1 z 1

Prosím o kontrolu logu

Napsal: 22 zář 2022 13:38
od petr1a
Prosím o konrolu Logu. Mám podezření, že v mém PC je nějaký malware či trojský kůň, který můj Avast antivirus nenalezl. Potřebuji mít jistotu, že mé PC je čisté. Předem velmi děkuji za pomoc.

Re: Prosím o kontrolu logu

Napsal: 22 zář 2022 16:13
od petr1a
# -------------------------------
# Malwarebytes AdwCleaner 8.4.0.0
# -------------------------------
# Build: 08-30-2022
# Database: 2022-08-22.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 09-22-2022
# Duration: 00:00:02
# OS: Windows 11 (Build 22000.978)
# Cleaned: 5
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\ProgramData\PC Cleaner
Deleted C:\Users\petrz\AppData\Roaming\IObit\Advanced SystemCare

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted C:\Windows\System32\Tasks\PC CLEANER AUTOMATIC SCAN AND NOTIFICATIONS

***** [ Registry ] *****

Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{86DA6DE2-AA8F-4920-AF7D-8AE3F4741BB1}
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC Cleaner automatic scan and notifications

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [3613 octets] - [22/09/2022 17:04:34]
AdwCleaner[S01].txt - [3674 octets] - [22/09/2022 17:07:17]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########

Re: Prosím o kontrolu logu

Napsal: 22 zář 2022 17:00
od Rudy
OK. Dejte nové logy FRST+Addition.

Re: Prosím o kontrolu logu

Napsal: 22 zář 2022 17:34
od petr1a
Slíbené nové logy z FRST + Addition č. 2

Re: Prosím o kontrolu logu

Napsal: 22 zář 2022 18:03
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\...\MountPoints2: {2fe3aec6-e00c-11ec-9720-646c80af6337} - "D:\vs_ultimate.exe"
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\...\MountPoints2: {3ffc9700-e804-11ec-9726-646c80af6337} - "D:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\...\MountPoints2: {b90998a5-4546-11ec-96e3-646c80af6337} - "D:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\...\MountPoints2: {e1bbfd39-67e0-11ec-96f0-646c80af6337} - "D:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\...\MountPoints2: {f47721ee-e801-11ec-9726-646c80af6337} - "D:\HiSuiteDownLoader.exe"
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy-Firefox: Restriction <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {38EE1657-9AB0-466E-AF92-3C81AC312E1C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-05-06] (Google LLC -> Google LLC)
Task: {D3148008-6D4B-4DE6-91BB-55524EA84391} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-05-06] (Google LLC -> Google LLC)
S3 MFE_RR; \??\C:\Users\petrz\AppData\Local\Temp\mfe_rr.sys [X] <==== ATTENTION
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\petrz\AppData\Roaming\Microsoft\c706bd65-3a5c-4ccf-9e3d-35916d2438e5.tmp

EmptyTenp:
End
Uložte do C:\Users\petrz\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Prosím o kontrolu logu

Napsal: 22 zář 2022 18:32
od petr1a
Fix result of Farbar Recovery Scan Tool (x64) Version: 30-08-2022
Ran by petrz (22-09-2022 19:27:55) Run:1
Running from C:\Users\petrz\Downloads
Loaded Profiles: petrz
Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\...\MountPoints2: {2fe3aec6-e00c-11ec-9720-646c80af6337} - "D:\vs_ultimate.exe"
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\...\MountPoints2: {3ffc9700-e804-11ec-9726-646c80af6337} - "D:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\...\MountPoints2: {b90998a5-4546-11ec-96e3-646c80af6337} - "D:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\...\MountPoints2: {e1bbfd39-67e0-11ec-96f0-646c80af6337} - "D:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\...\MountPoints2: {f47721ee-e801-11ec-9726-646c80af6337} - "D:\HiSuiteDownLoader.exe"
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy-Firefox: Restriction <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {38EE1657-9AB0-466E-AF92-3C81AC312E1C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-05-06] (Google LLC -> Google LLC)
Task: {D3148008-6D4B-4DE6-91BB-55524EA84391} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-05-06] (Google LLC -> Google LLC)
S3 MFE_RR; \??\C:\Users\petrz\AppData\Local\Temp\mfe_rr.sys [X] <==== ATTENTION
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\petrz\AppData\Roaming\Microsoft\c706bd65-3a5c-4ccf-9e3d-35916d2438e5.tmp
*****************

Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2fe3aec6-e00c-11ec-9720-646c80af6337} => removed successfully
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ffc9700-e804-11ec-9726-646c80af6337} => removed successfully
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b90998a5-4546-11ec-96e3-646c80af6337} => removed successfully
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e1bbfd39-67e0-11ec-96f0-646c80af6337} => removed successfully
HKU\S-1-5-21-4003014785-1107625205-4150319644-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f47721ee-e801-11ec-9726-646c80af6337} => removed successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
C:\Program Files\Mozilla Firefox\distribution\policies.json => moved successfully
C:\ProgramData\NTUSER.pol => moved successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{38EE1657-9AB0-466E-AF92-3C81AC312E1C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{38EE1657-9AB0-466E-AF92-3C81AC312E1C}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D3148008-6D4B-4DE6-91BB-55524EA84391}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3148008-6D4B-4DE6-91BB-55524EA84391}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
HKLM\System\CurrentControlSet\Services\MFE_RR => removed successfully
MFE_RR => service removed successfully
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA" => not found
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore" => not found
C:\Users\petrz\AppData\Roaming\Microsoft\c706bd65-3a5c-4ccf-9e3d-35916d2438e5.tmp => moved successfully


The system needed a reboot.

==== End of Fixlog 19:28:00 ====

Re: Prosím o kontrolu logu

Napsal: 22 zář 2022 18:58
od Rudy
Smazáno, log je již OK.

Re: Prosím o kontrolu logu

Napsal: 22 zář 2022 20:54
od petr1a
Velmi Vám děkuji za pomoc a mohu Vás prosím poprosit, jestli by jste mi řekl, co v mém pc bylo ?
Jestli nějaký malware, spyware či trojský kůň ?

Re: Prosím o kontrolu logu

Napsal: 23 zář 2022 09:32
od Rudy
Avast zřejmě roho trojáka smazal. To jsme mazali my, už byly jen neškodné zbytečnosti. Takže nevím, jaký trojan, nebo malware to byl.