podozrenie na hack
Napsal: 27 kvě 2026 16:16
Mal som zablokovaný email. Ked som ho odblokoval novým heslom tak som zistil že mi prišiel výhražný email že mam zaplatiť inak budem mat problém atd. Samozrejme som nezaplatil.
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.Start
CloseProcesses:
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [751240 2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {B9B24DD5-5C20-471B-B6FD-AB631238EBAB} - System32\Tasks\CCleanerSkipUAC - maroš => "C:\Users\maroš\Downloads\ccPortable\App\CCleaner\CCleaner.exe" $(Arg0) (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
Task: {7A003965-A297-4DC6-B15B-852D798391E0} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe Reboot (No File)
Task: {E28465B1-9792-4B39-859F-9EFC14B29405} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File)
Task: {CFA58C9E-50F1-4DDF-BD8F-A2154F906CF0} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {EA3F661E-B31C-44A9-B40C-E3D5D56149D4} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display => C:\windows\system32\MusNotification.exe Display (No File)
Task: {848DCC36-520C-4946-BF68-C7EFFEFA2F84} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot => C:\windows\system32\MusNotification.exe ReadyToReboot (No File)
Task: {7DFB30A7-7126-42EA-BDA8-1835C1B5DF9F} - System32\Tasks\OneDrive Startup Task-S-1-5-21-836710197-3910017001-3467480500-1002 => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\OneDriveLauncher.exe /startInstances (No File)
Task: {001C2B6B-FB55-48E7-963F-E35F20F9B055} - System32\Tasks\Opera scheduled Autoupdate 1737984004 => C:\Users\maroš\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe --scheduledtask --bypasslauncher $(Arg0) (No File)
Error reading preferences. Please make sure ESET "Secure Browser" option is disabled. <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\bojobppfploabceghnmlahpoonbcbacn [2026-05-20] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-04-30] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh [2026-05-27] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\hmclfiddnlhfnemdelgodbcmhpobomha [2026-04-14] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\jbkfoedolllekgbhcbcoahefnbanhhlh [2026-05-15] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-04-14] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\kgocmibpdgfgpbmckolcpjoegieclgdj [2026-04-17] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\nkapkmklnmidbbgjaipbgpcnbomnaakc [2026-04-14] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\odfafepnkmbhccpbejgmiehpchacaeak [2026-05-12] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\panammoooggmlehahpcjckcncfeffcoi [2026-05-20] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\pdffkfellgipmhklpdmokmckkkfcopbh [2026-05-14] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 3\Extensions\bojobppfploabceghnmlahpoonbcbacn [2026-04-17] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-04-17] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 3\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-04-17] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 3\Extensions\nkapkmklnmidbbgjaipbgpcnbomnaakc [2026-04-17] [UpdateUrl:0] <==== ATTENTION
Error reading preferences. Please make sure ESET "Secure Browser" option is disabled. <==== ATTENTION
CHR Extension: (No Name) - C:\Users\maroš\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-05-14] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\maroš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-04-20] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\maroš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2026-05-20] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\maroš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-06-16] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\maroš\AppData\Local\Google\Chrome\User Data\Default\Extensions\oombnmpbbhbakfpfgdflaajkhicgfaam [2025-12-13] [UpdateUrl:0] <==== ATTENTION
Error reading preferences. Please make sure ESET "Secure Browser" option is disabled. <==== ATTENTION
BRA Extension: (No Name) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-02-26] [UpdateUrl:0] <==== ATTENTION
BRA Extension: (No Name) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2026-02-26] [UpdateUrl:0] <==== ATTENTION
BRA Extension: (No Name) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\kpiecbcckbofpmkkkdibbllpinceiihk [2026-02-26] [UpdateUrl:0] <==== ATTENTION
BRA Extension: (No Name) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\oombnmpbbhbakfpfgdflaajkhicgfaam [2026-02-26] [UpdateUrl:0] <==== ATTENTION
S1 netfilter2; system32\drivers\netfilter2.sys (No File)
S4 NvModuleTracker; \SystemRoot\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys (No File)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [6684]
EmptyTemp:
Hosts:
End