Prosím o kontrolu Logu HJT

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jerabina
člen Security týmu
Příspěvky: 3647
Registrován: 16 bře 2013 15:08
Bydliště: Litoměřice

Re: Prosím o kontrolu Logu HJT

Příspěvek od jerabina »

Odinstaluj vše od IObit a McAfee

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:

HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7394584 2014-12-12] (Piriform Ltd)
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {02d5e45b-4852-11e6-82c3-8cdcd48d65de} - "F:\Lenovo_Suite.exe" 
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {1cc9439c-a9f3-11e4-828b-1008b1bf986e} - "F:\LG_PC_Programs.exe" 
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {3b299db7-35a0-11e6-82be-8cdcd48d65de} - "F:\Lenovo_Suite.exe" 
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {3b299e3d-35a0-11e6-82be-8cdcd48d65de} - "F:\Lenovo_Suite.exe" 
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {3b3586ed-7537-11e6-82d9-8cdcd48d65de} - "F:\Lenovo_Suite.exe" 
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {95275f61-179b-11e6-82bc-1008b1bf986d} - "F:\Lenovo_Suite.exe" 
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {95276210-179b-11e6-82bc-1008b1bf986d} - "F:\Lenovo_Suite.exe" 
HKU\S-1-5-18\...\Run: [Advanced SystemCare 8] => "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://www.bing.com?pc=HPDTDFJS
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: No Name -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> No File

FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Extension: (No Name) - C:\Users\TomikCR\AppData\Roaming\Mozilla\Firefox\Profiles\d1xemxoz.default\extensions\anttoolbar@ant.com [not found]
FF Extension: (No Name) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [not found]

R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960672 2016-07-20] (IObit)
S2 McAfee SiteAdvisor Service; "C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe" [X]

S3 mfesapsn; \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [X]

C:\Program Files (x86)\IObit
C:\ProgramData\IObit
C:\Users\TomikCR\AppData\Roaming\IObit
C:\Users\Administrator\AppData\LocalLow\IObit
C:\Program Files (x86)\McAfee
C:\ProgramData\McAfee

C:\ProgramData\RogueKiller

C:\Windows\system32\IObitSmartDefragExtension.dll
C:\Windows\system32\Drivers\SmartDefragDriver.sys
C:\Windows\System32\Tasks\SmartDefrag_AutoAnalyze
C:\Windows\System32\Tasks\SmartDefrag_Update
C:\Windows\system32\config\components.iodefrag.bak
C:\Windows\system32\config\SOFTWARE.iodefrag.bak
C:\Windows\system32\config\DEFAULT.iodefrag.bak
C:\Windows\system32\config\SAM.iodefrag.bak
C:\Windows\system32\config\SECURITY.iodefrag.bak
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag

Task: {2220448C-F5C1-4C9F-9165-F8F8C93B7575} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {235FC62B-4FBA-4CDE-9230-FDABA2632E4F} - System32\Tasks\{9D8EF746-B721-44F5-A499-74337197D5DB} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -c -runfromtemp -l0x0005 -removeonly
Task: {60CA173A-343A-436B-A513-1781E4904A2C} - System32\Tasks\SmartDefrag_Update => C:\Program Files (x86)\IObit\Smart Defrag\AutoUpdate.exe [2016-07-22] (IObit)
Task: {68E1C2C8-E605-4F6F-B9E7-4EC1325A88A0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {C60A1A91-54EA-4D60-B06A-A94012A794AE} - System32\Tasks\SmartDefrag_AutoAnalyze => C:\Program Files (x86)\IObit\Smart Defrag\AutoDefrag.exe [2016-06-06] (IObit)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForTomikCR.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

C:\Program Files (x86)\Google\Update

AlternateDataStreams: C:\ProgramData\Temp:4ABA35EE [124]

IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\100sexlinks.com -> 100sexlinks.com

EmptyTemp:
End
(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt

Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.
TomikCR
Level 1
Level 1
Příspěvky: 73
Registrován: 19 srp 2007 18:59

Re: Prosím o kontrolu Logu HJT

Příspěvek od TomikCR »

Fix result of Farbar Recovery Scan Tool (x64) Version: 12-09-2016
Ran by TomikCR (13-09-2016 23:17:26) Run:1
Running from C:\Users\TomikCR\Desktop
Loaded Profiles: TomikCR (Available Profiles: TomikCR & Administrator)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:

HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7394584 2014-12-12] (Piriform Ltd)
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {02d5e45b-4852-11e6-82c3-8cdcd48d65de} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {1cc9439c-a9f3-11e4-828b-1008b1bf986e} - "F:\LG_PC_Programs.exe"
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {3b299db7-35a0-11e6-82be-8cdcd48d65de} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {3b299e3d-35a0-11e6-82be-8cdcd48d65de} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {3b3586ed-7537-11e6-82d9-8cdcd48d65de} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {95275f61-179b-11e6-82bc-1008b1bf986d} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {95276210-179b-11e6-82bc-1008b1bf986d} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-18\...\Run: [Advanced SystemCare 8] => "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://www.bing.com?pc=HPDTDFJS
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: No Name -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> No File

FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Extension: (No Name) - C:\Users\TomikCR\AppData\Roaming\Mozilla\Firefox\Profiles\d1xemxoz.default\extensions\anttoolbar@ant.com [not found]
FF Extension: (No Name) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [not found]

R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960672 2016-07-20] (IObit)
S2 McAfee SiteAdvisor Service; "C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe" [X]

S3 mfesapsn; \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [X]

C:\Program Files (x86)\IObit
C:\ProgramData\IObit
C:\Users\TomikCR\AppData\Roaming\IObit
C:\Users\Administrator\AppData\LocalLow\IObit
C:\Program Files (x86)\McAfee
C:\ProgramData\McAfee

C:\ProgramData\RogueKiller

C:\Windows\system32\IObitSmartDefragExtension.dll
C:\Windows\system32\Drivers\SmartDefragDriver.sys
C:\Windows\System32\Tasks\SmartDefrag_AutoAnalyze
C:\Windows\System32\Tasks\SmartDefrag_Update
C:\Windows\system32\config\components.iodefrag.bak
C:\Windows\system32\config\SOFTWARE.iodefrag.bak
C:\Windows\system32\config\DEFAULT.iodefrag.bak
C:\Windows\system32\config\SAM.iodefrag.bak
C:\Windows\system32\config\SECURITY.iodefrag.bak
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag

Task: {2220448C-F5C1-4C9F-9165-F8F8C93B7575} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {235FC62B-4FBA-4CDE-9230-FDABA2632E4F} - System32\Tasks\{9D8EF746-B721-44F5-A499-74337197D5DB} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -c -runfromtemp -l0x0005 -removeonly
Task: {60CA173A-343A-436B-A513-1781E4904A2C} - System32\Tasks\SmartDefrag_Update => C:\Program Files (x86)\IObit\Smart Defrag\AutoUpdate.exe [2016-07-22] (IObit)
Task: {68E1C2C8-E605-4F6F-B9E7-4EC1325A88A0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {C60A1A91-54EA-4D60-B06A-A94012A794AE} - System32\Tasks\SmartDefrag_AutoAnalyze => C:\Program Files (x86)\IObit\Smart Defrag\AutoDefrag.exe [2016-06-06] (IObit)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForTomikCR.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

C:\Program Files (x86)\Google\Update

AlternateDataStreams: C:\ProgramData\Temp:4ABA35EE [124]

IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\100sexlinks.com -> 100sexlinks.com

EmptyTemp:
End
*****************

Processes closed successfully.
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{02d5e45b-4852-11e6-82c3-8cdcd48d65de}" => key removed successfully
HKCR\CLSID\{02d5e45b-4852-11e6-82c3-8cdcd48d65de} => key not found.
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1cc9439c-a9f3-11e4-828b-1008b1bf986e}" => key removed successfully
HKCR\CLSID\{1cc9439c-a9f3-11e4-828b-1008b1bf986e} => key not found.
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3b299db7-35a0-11e6-82be-8cdcd48d65de}" => key removed successfully
HKCR\CLSID\{3b299db7-35a0-11e6-82be-8cdcd48d65de} => key not found.
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3b299e3d-35a0-11e6-82be-8cdcd48d65de}" => key removed successfully
HKCR\CLSID\{3b299e3d-35a0-11e6-82be-8cdcd48d65de} => key not found.
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3b3586ed-7537-11e6-82d9-8cdcd48d65de}" => key removed successfully
HKCR\CLSID\{3b3586ed-7537-11e6-82d9-8cdcd48d65de} => key not found.
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{95275f61-179b-11e6-82bc-1008b1bf986d}" => key removed successfully
HKCR\CLSID\{95275f61-179b-11e6-82bc-1008b1bf986d} => key not found.
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{95276210-179b-11e6-82bc-1008b1bf986d}" => key removed successfully
HKCR\CLSID\{95276210-179b-11e6-82bc-1008b1bf986d} => key not found.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 8 => value removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page => value removed successfully
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\First Home Page => value removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" => key removed successfully
HKCR\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} => key not found.
Firefox "newtab" removed successfully
Firefox "homepage" removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3" => key removed successfully
C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll => moved successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9" => key removed successfully
C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll => not found.
C:\Users\TomikCR\AppData\Roaming\Mozilla\Firefox\Profiles\d1xemxoz.default\extensions\anttoolbar@ant.com => path removed successfully
C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi => path removed successfully
LiveUpdateSvc => service removed successfully
McAfee SiteAdvisor Service => service removed successfully
mfesapsn => service removed successfully
C:\Program Files (x86)\IObit => moved successfully
C:\ProgramData\IObit => moved successfully
C:\Users\TomikCR\AppData\Roaming\IObit => moved successfully
C:\Users\Administrator\AppData\LocalLow\IObit => moved successfully
"C:\Program Files (x86)\McAfee" => not found.
C:\ProgramData\McAfee => moved successfully
C:\ProgramData\RogueKiller => moved successfully
C:\Windows\system32\IObitSmartDefragExtension.dll => moved successfully
C:\Windows\system32\Drivers\SmartDefragDriver.sys => moved successfully
C:\Windows\System32\Tasks\SmartDefrag_AutoAnalyze => moved successfully
C:\Windows\System32\Tasks\SmartDefrag_Update => moved successfully
C:\Windows\system32\config\components.iodefrag.bak => moved successfully
C:\Windows\system32\config\SOFTWARE.iodefrag.bak => moved successfully
C:\Windows\system32\config\DEFAULT.iodefrag.bak => moved successfully
C:\Windows\system32\config\SAM.iodefrag.bak => moved successfully
C:\Windows\system32\config\SECURITY.iodefrag.bak => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2220448C-F5C1-4C9F-9165-F8F8C93B7575}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2220448C-F5C1-4C9F-9165-F8F8C93B7575}" => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{235FC62B-4FBA-4CDE-9230-FDABA2632E4F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{235FC62B-4FBA-4CDE-9230-FDABA2632E4F}" => key removed successfully
C:\Windows\System32\Tasks\{9D8EF746-B721-44F5-A499-74337197D5DB} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9D8EF746-B721-44F5-A499-74337197D5DB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{60CA173A-343A-436B-A513-1781E4904A2C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{60CA173A-343A-436B-A513-1781E4904A2C}" => key removed successfully
C:\Windows\System32\Tasks\SmartDefrag_Update => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SmartDefrag_Update" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{68E1C2C8-E605-4F6F-B9E7-4EC1325A88A0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68E1C2C8-E605-4F6F-B9E7-4EC1325A88A0}" => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C60A1A91-54EA-4D60-B06A-A94012A794AE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C60A1A91-54EA-4D60-B06A-A94012A794AE}" => key removed successfully
C:\Windows\System32\Tasks\SmartDefrag_AutoAnalyze => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SmartDefrag_AutoAnalyze" => key removed successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\Windows\Tasks\HPCeeScheduleForTomikCR.job => moved successfully
C:\Program Files (x86)\Google\Update => moved successfully
C:\ProgramData\Temp => ":4ABA35EE" ADS removed successfully.
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008i.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008k.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\00hq.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0190-dialers.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\01i.info" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\02pmnzy5eo29bfk4.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\05p.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\07ic5do2myz3vzpk.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\08nigbmwk43i01y6.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\093qpeuqpmz6ebfa.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0calories.net" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0cj.net" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0scan.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-britney-spears-nude.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-domains-registrations.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-se.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1001movie.com" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1001night.biz" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\100gal.net" => key removed successfully
"HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\100sexlinks.com" => key removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 5571276 B
Java, Flash, Steam htmlcache => 39930472 B
Windows/system/drivers => 167885 B
Edge => 0 B
Chrome => 791292315 B
Firefox => 622592 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 560 B
LocalService => 0 B
NetworkService => 21260 B
TomikCR => 23108632 B
Administrator => 18143 B

RecycleBin => 333855 B
EmptyTemp: => 829.2 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 23:17:35 ====
Uživatelský avatar
jaro3
člen Security týmu
Příspěvky: 43412
Registrován: 16 čer 2007 18:58
Bydliště: Jižní Čechy

Re: Prosím o kontrolu Logu HJT

Příspěvek od jaro3 »

Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
TomikCR
Level 1
Level 1
Příspěvky: 73
Registrován: 19 srp 2007 18:59

Re: Prosím o kontrolu Logu HJT

Příspěvek od TomikCR »

Malinko se mi zdá že se to zhoršilo, ventilátorek zase má trochu zvýšené otáčky ale už nekolísá, je to spíš takové stupňovité. Připadá mi to trošku jako něco mezi stupněm jedna a dva. Nicméně celkově to hodnotím jako zlepšení o 70%. Asi toho balastu bylo v PC víc než dost.
Zkusil jsem otevřít asi pět oken, pustit video, a zároven hudbu v přehrávači a serfovat na netu a na fotce je vidět že disk už neskáče na 100% vytíženosti a i procesor se drží v relativní normě.
Přílohy
Bez názvu.jpg
Uživatelský avatar
jaro3
člen Security týmu
Příspěvky: 43412
Registrován: 16 čer 2007 18:58
Bydliště: Jižní Čechy

Re: Prosím o kontrolu Logu HJT

Příspěvek od jaro3 »

byl tam dost binec , takže ještě tohle:
Použij:
Odstraňovač veteše..
http://www.pcdecrapifier.com/

Je váš počítač pomalý? Dokonce i u zbrusu nových počítačů často přicházejí se spoustou předinstalovaného softwaru zbytečný balast , který může způsobit, že nový PC se začne zpomalovat. Nemluvě o všechny otravné pop-up! Jiní mohou mít počítač, který je stár pár let a máme tam nainstalované spoustu haraburdí! Stává se , na spoustu programů v průběhu času zapomeneme a neodstranníme je.
PC Decrapifier je tu pro Vás! Je to bezplatný nástroj pro Vaše použití, který pomáhá odstranit nepotřebné programy, položky Po spuštění a ikony, které zpomalují počítač. Bere vás krok za krokem, doporučuje Vám, co odstranit, z nichž mnohé mohou být odstraněny bez dozoru. Vydejte se na stránku pro stahování!
http://majorgeeks.com/downloadget.php?i ... 81de2b2978
http://www.pcdecrapifier.com/download
http://dl.pcdecrapifier.com/pc-decrapifier-2.2.8.exe
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Odpovědět

Zpět na „HiJackThis“