Kontrola logu - neuvěřitelně zasekaný notebook

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Zombak21
nováček
Příspěvky: 11
Registrován: listopad 20
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu - neuvěřitelně zasekaný notebook

Příspěvekod Zombak21 » 27 bře 2021 14:15

C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a0cb0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a0cd1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a0dbd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a0dee.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a0eea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a0f98.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a10c3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a10d5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a1125.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a11e2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a130d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a134e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a137f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a13ee.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a198d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a199f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a1b57.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a1d6c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a1e29.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a1e4b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a1e7b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a1ebc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a1f89.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a1faa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ebc-22d4-1a201a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c54e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c57f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c590.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c5b2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c5c3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c5d5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c5d7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c5e9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c5fa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c61b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c65c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c65e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c670.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c6c0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c6d1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c6e3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c6f5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c716.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-ee8-b44-32c718.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3c6d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3ccd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3cfe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3d1f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3d40.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3dfe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3e6d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3e7f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3ecf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3ed1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3ee2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3f13.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3f25.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3f37.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3f48.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d3f89.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d4102.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d4123.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f2c-26c4-1d4154.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-c2d7e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-c2ddd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-c2e3d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-c2e4f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-c2ebe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-c2ed0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-c3903.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-c3ec2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-c6065.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-c6549.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-c7d96.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-c8345.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-ca6bd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-cbe5e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-cec65.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-cf466.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d1435.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d283c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d34d1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d37f0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d4465.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d4801.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d4beb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d4d25.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d51ac.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d5567.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d62d6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d64fb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d67cc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d7069.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d74b1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d761a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d785e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d79c8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d7b60.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d7c2d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f78-4f0-d7ff8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-ace49.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-ace5b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-ace6d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-ace7e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-ace80.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-ace92.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-ace94.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-acea5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-acea7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-aceb9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-acebb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-acecd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-acecf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-aced1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-acee2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-acee4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-acef6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-acef8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-f94-1b48-acf0a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a55f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a571.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a573.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a584.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a596.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a5a8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a5b9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a5cb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a5dd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a5df.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a5f0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a5f2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a604.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a606.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a617.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a629.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a62b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a64c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fb0-1040-15a65e.tmp deleted
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Lavasoft\WebCompanion.exe_Url_siq0lwf3tzgxp2khfkllybk3idtbehng deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google deleted
C:\Users\sonin\Downloads\bsplayer275.setup.exe deleted
C:\Users\sonin\AppData\LocalLow\Unity deleted
"C:\DumpStack.log.tmp" not deleted

==== Chromium Look ======================

Google Chrome Version: 89.0.4389.90

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
eofcbnmajmjmplflapaojjnihcjkigck - No path found[]

Chrome Media Router - sonin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

==== Reset Google Chrome ======================

C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\sonin\AppData\Local\Microsoft\Edge\User Data\Default\Preferences was reset successfully
C:\Users\sonin\AppData\Local\Microsoft\Edge\User Data\Default\Secure Preferences was reset successfully
C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Web Data will be reset at reboot
C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal will be reset at reboot
C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Web Data.ReadOnly was reset successfully
C:\Users\sonin\AppData\Local\Microsoft\Edge\User Data\Default\Web Data was reset successfully
C:\Users\sonin\AppData\Local\Microsoft\Edge\User Data\Default\Web Data-journal was reset successfully
C:\Users\sonin\AppData\Local\Microsoft\Edge\User Data\Default\Web Data.ReadOnly was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\sonin\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\sonin\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Edge Cache ======================

Edge Cache Emptied Successfully

==== Empty Chrome Cache ======================

C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Cache will be emptied at reboot
C:\Users\sonin\AppData\Local\Microsoft\Edge\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=1948 folders=2898 326770623 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\sonin\AppData\Local\Temp will be emptied at reboot
C:\Users\TEMP\AppData\Local\Temp emptied successfully
C:\Users\TEMP.DESKTOP-RFATIHM\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\sonin\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\DumpStack.log.tmp" not deleted
"C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Web Data" not found
"C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal" not found
"C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0" deleted
"C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1" deleted
"C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2" deleted
"C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3" deleted
"C:\Users\sonin\AppData\Local\Google\Chrome\User Data\Default\Cache\index" deleted

==== EOF on 27.03.2021 at 13:42:22,08 ======================

Zemana AntiMalware

Informace o kontroly
Název produktu    :  Zemana AntiMalware
Stav kontroly    :  Dokončena
Datum kontroly    :  27.03.2021 13:51:47
Typ kontroly    :  Inteligentní kontrola
Čas trvání    :  00:01:41
Zkontrolované objekty    :  1861
Zjištěné objekty    :  2
Vyloučené objekty    :  0
Automatické odesílání    :  Ano
Operační systém    :  Windows 10 x64
Procesor    :  4X Intel(R) Core(TM) i3-3217U CPU @ 1.80GHz
Režim systému BIOS    :  UEFI
Informace o doméně    :  WORKGROUP,False,NetSetupWorkgroupName
CUID    :  12C1056FAD0A5928230711


Odhalení
MD5    :  
Stav    :  Zkontrolováno
Objekt    :  http://nyx.cz/
Vydavatel    :  
Velikost    :  0
Odhalení    :  Hijack:Browser/ChromeStartupUrl
Akce    :  Vymazat
-----------------------------------------------------------------------
MD5    :  
Stav    :  Zkontrolováno
Objekt    :  http://slevomat.cz/
Vydavatel    :  
Velikost    :  0
Odhalení    :  Hijack:Browser/ChromeStartupUrl
Akce    :  Vymazat
-----------------------------------------------------------------------


HJT Log

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:54:44, on 27.03.2021
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.19041.0001)
Boot mode: Normal

Running processes:
C:\Users\sonin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\WINDOWS\SysWOW64\DllHost.exe
C:\Users\sonin\Downloads\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O1 - Hosts: ::1 localhost
O4 - HKCU\..\Run: [OneDrive] "C:\Users\sonin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype for Desktop] C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Discord] C:\Users\sonin\AppData\Local\Discord\Update.exe --processStart Discord.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Inc. - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\Avast Software\Avast\aswidsagent.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\Avast Software\Avast\AvastSvc.exe
O23 - Service: Avast Tools (avast! Tools) - AVAST Software - C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
O23 - Service: AvastWscReporter - AVAST Software - C:\Program Files\Avast Software\Avast\wsc_proxy.exe
O23 - Service: Avast Cleanup (CleanupPSvc) - AVAST Software - C:\Program Files\Avast Software\Cleanup\TuneupSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_d766e - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\89.0.4389.90\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: RogueKiller RTP (rkrtservice) - Unknown owner - C:\Program Files\RogueKiller\RogueKillerSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8463 bytes


Nejedná se o můj počítač, takže jsem v něm zatím nedělal prakticky nic jiného než postup, který mi tu udáváš, ale nějaké zlepšení stavu asi i vnímám. Nechám na tom chvilku blbnout majitele a zeptám se ho, jestli problém přetrvává.

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu - neuvěřitelně zasekaný notebook

Příspěvekod jaro3 » 27 bře 2021 16:25

Stáhni si zde DelFix
Další odkazy:
https://toolslib.net/downloads/viewdownload/2-delfix/
http://ccm.net/download/download-24087-delfix
https://www.bleepingcomputer.com/download/delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7, 8 a10 musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt

Stáhni si CrystalDiskInfo
https://www.stahuj.cz/utility_a_ostatni ... ldiskinfo/
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.

Pak dej vědět.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Zombak21
nováček
Příspěvky: 11
Registrován: listopad 20
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu - neuvěřitelně zasekaný notebook

Příspěvekod Zombak21 » 03 dub 2021 13:23

ZDravím, omlouvám se se zpožděním, konečně jsem se sem zase dostal.

Takže...


Delfix Log:

# Updated 26/04/2015 by Xplode
# Username : sonin - DESKTOP-RFATIHM
# Operating System : Windows 10 Home (64 bits)

~ Removing disinfection tools ...

Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\zoek-results.log
Deleted : C:\Users\sonin\Desktop\AdwCleaner.exe
Deleted : C:\Users\sonin\Desktop\AdwCleaner[C00].txt
Deleted : C:\Users\sonin\Desktop\JRT.exe
Deleted : C:\Users\sonin\Desktop\JRT.txt
Deleted : C:\Users\sonin\Desktop\hijackthislast.txt
Deleted : C:\Users\sonin\Desktop\roguekiller.txt
Deleted : C:\Users\sonin\Desktop\roguekiller2.txt
Deleted : C:\Users\sonin\Desktop\zoek-results.txt
Deleted : C:\Users\Public\Desktop\RogueKiller.lnk
Deleted : C:\Users\sonin\Downloads\hijackthis.exe
Deleted : C:\Users\sonin\Downloads\hijackthis.log
Deleted : C:\Users\sonin\Downloads\RogueKiller_setup.exe
Deleted : C:\Users\sonin\Downloads\TFC.exe
Deleted : C:\Users\sonin\Downloads\zoek1.rar
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis

~ Cleaning system restore ...

Deleted : RP #53 [JRT Pre-Junkware Removal | 03/26/2021 16:42:16]
Deleted : RP #54 [Installed Sophos Virus Removal Tool. | 03/26/2021 17:41:42]
Deleted : RP #55 [Installed Sophos Virus Removal Tool. | 03/26/2021 17:52:29]

New restore point created !

########## - EOF - ########### DelFix v1.010 - Logfile created 03/04/2021 at 13:08:59
# Updated 26/04/2015 by Xplode
# Username : sonin - DESKTOP-RFATIHM
# Operating System : Windows 10 Home (64 bits)

~ Removing disinfection tools ...

Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\zoek-results.log
Deleted : C:\Users\sonin\Desktop\AdwCleaner.exe
Deleted : C:\Users\sonin\Desktop\AdwCleaner[C00].txt
Deleted : C:\Users\sonin\Desktop\JRT.exe
Deleted : C:\Users\sonin\Desktop\JRT.txt
Deleted : C:\Users\sonin\Desktop\hijackthislast.txt
Deleted : C:\Users\sonin\Desktop\roguekiller.txt
Deleted : C:\Users\sonin\Desktop\roguekiller2.txt
Deleted : C:\Users\sonin\Desktop\zoek-results.txt
Deleted : C:\Users\Public\Desktop\RogueKiller.lnk
Deleted : C:\Users\sonin\Downloads\hijackthis.exe
Deleted : C:\Users\sonin\Downloads\hijackthis.log
Deleted : C:\Users\sonin\Downloads\RogueKiller_setup.exe
Deleted : C:\Users\sonin\Downloads\TFC.exe
Deleted : C:\Users\sonin\Downloads\zoek1.rar
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis

~ Cleaning system restore ...

Deleted : RP #53 [JRT Pre-Junkware Removal | 03/26/2021 16:42:16]
Deleted : RP #54 [Installed Sophos Virus Removal Tool. | 03/26/2021 17:41:42]
Deleted : RP #55 [Installed Sophos Virus Removal Tool. | 03/26/2021 17:52:29]

New restore point created !

########## - EOF - ##########


A Crystal Disk:
----------------------------------------------------------------------------
CrystalDiskInfo 8.12.0 (C) 2008-2021 hiyohiyo
Crystal Dew World: https://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 10 [10.0 Build 19041] (x64)
Date : 2021/04/03 13:21:10

-- Controller Map ----------------------------------------------------------
+ Intel(R) 7 Series Chipset Family SATA AHCI Controller [ATA]
- TOSHIBA MQ01ABD100
- MATSHITA DVD-RAM UJ8E2 S
- Řadič prostorů úložišť [SCSI]
- DAEMON Tools Lite Virtual SCSI Bus [SCSI]

-- Disk List ---------------------------------------------------------------
(01) TOSHIBA MQ01ABD100 : 1000,2 GB [0/0/0, pd1]

----------------------------------------------------------------------------
(01) TOSHIBA MQ01ABD100
----------------------------------------------------------------------------
Model : TOSHIBA MQ01ABD100
Firmware : AX0R2J
Serial Number : Y3F5C0X4T
Disk Size : 1000,2 GB (8,4/137,4/1000,2/----)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 1953525168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : SATA/600 | SATA/600
Power On Hours : 15991 hod.
Power On Count : 5534 krát
Temperature : 41 C (105 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, NCQ
APM Level : 0080h [ON]
AAM Level : ----
Drive Letter : C: D:

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _50 000000000000 Počet chyb čtení
02 100 100 _50 000000000000 Průchodnost disku
03 100 100 __1 0000000006B5 Čas na roztočení ploten
04 100 100 __0 0000000015A0 Počet spuštění/zastavení
05 100 100 _50 000000000000 Počet přemapovaných sektorů
07 100 100 _50 000000000000 Počet chybných hledání
08 100 100 _50 000000000000 Čas potřebný na vyhledání
09 _61 _61 __0 000000003E77 Hodin v činnosti
0A 210 100 _30 000000000000 Počet opakovaných pokusů o roztočení ploten
0C 100 100 __0 00000000159E Počet cyklů zapnutí zařízení
BF 100 100 __0 000000002392 Počet udalostí zaznamenaných otřesovým senzorem
C0 _99 _99 __0 00000000024E Počet vypnutí disku
C1 _99 _99 __0 000000004C73 Počet cyklů načítání/vymazání
C2 100 100 __0 0032000E0029 Teplota
C4 100 100 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 100 100 __0 000000000000 Počet podezřelých sektorů
C6 100 100 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
DC 100 100 __0 000000000000 Posunutí disku vůči ose
DE _65 _65 __0 000000003839 Počet hodin zalažení budoucího mechanismu magnetických hlav
DF 100 100 __0 000000000000 Zatížení budiče magnetických hlav způsobené opakovanými úkony
E0 100 100 __0 000000000000 Zatížení budiče magnetických hlav způsobené napětím mechanických částí
E2 100 100 __0 0000000000BA Celkový čas zatížení budiče magnetických hlav
F0 100 100 __1 000000000000 Čas nastavování hlaviček - v hodinách

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0040 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2020 2020 2020 2059 3346 3543 3058 3454
020: 0000 4000 0000 4158 3052 324A 2020 544F 5348 4942
030: 4120 4D51 3031 4142 4431 3030 2020 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4000 0200 0000 0007 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0007 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F EF0E 0006 004C 0048
080: 01F8 0000 746B 7D09 6163 7469 BC09 6163 203F 006E
090: 006E 0080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6DB0 7470 0000 0000 0000 0000 6003 0000 5000 0395
110: 2350 5399 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 003D 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 103F 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 0080 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 D4A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 0B 00 64 64 00 00 00 00 00 00 00 02 05
010: 00 64 64 00 00 00 00 00 00 00 03 27 00 64 64 B5
020: 06 00 00 00 00 00 04 32 00 64 64 A0 15 00 00 00
030: 00 00 05 33 00 64 64 00 00 00 00 00 00 00 07 0B
040: 00 64 64 00 00 00 00 00 00 00 08 05 00 64 64 00
050: 00 00 00 00 00 00 09 32 00 3D 3D 77 3E 00 00 00
060: 00 00 0A 33 00 D2 64 00 00 00 00 00 00 00 0C 32
070: 00 64 64 9E 15 00 00 00 00 00 BF 32 00 64 64 92
080: 23 00 00 00 00 00 C0 32 00 63 63 4E 02 00 00 00
090: 00 00 C1 32 00 63 63 73 4C 00 00 00 00 00 C2 22
0A0: 00 64 64 29 00 0E 00 32 00 00 C4 32 00 64 64 00
0B0: 00 00 00 00 00 00 C5 32 00 64 64 00 00 00 00 00
0C0: 00 00 C6 30 00 64 64 00 00 00 00 00 00 00 C7 32
0D0: 00 C8 C8 00 00 00 00 00 00 00 DC 02 00 64 64 00
0E0: 00 00 00 00 00 00 DE 32 00 41 41 39 38 00 00 00
0F0: 00 00 DF 32 00 64 64 00 00 00 00 00 00 00 E0 22
100: 00 64 64 00 00 00 00 00 00 00 E2 26 00 64 64 BA
110: 00 00 00 00 00 00 F0 01 00 64 64 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 5B
170: 03 00 01 00 02 EC 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 8D

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 32 00 00 00 00 00 00 00 00 00 00 02 32
010: 00 00 00 00 00 00 00 00 00 00 03 01 00 00 00 00
020: 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00
030: 00 00 05 32 00 00 00 00 00 00 00 00 00 00 07 32
040: 00 00 00 00 00 00 00 00 00 00 08 32 00 00 00 00
050: 00 00 00 00 00 00 09 00 00 00 00 00 00 00 00 00
060: 00 00 0A 1E 00 00 00 00 00 00 00 00 00 00 0C 00
070: 00 00 00 00 00 00 00 00 00 00 BF 00 00 00 00 00
080: 00 00 00 00 00 00 C0 00 00 00 00 00 00 00 00 00
090: 00 00 C1 00 00 00 00 00 00 00 00 00 00 00 C2 00
0A0: 00 00 00 00 00 00 00 00 00 00 C4 00 00 00 00 00
0B0: 00 00 00 00 00 00 C5 00 00 00 00 00 00 00 00 00
0C0: 00 00 C6 00 00 00 00 00 00 00 00 00 00 00 C7 00
0D0: 00 00 00 00 00 00 00 00 00 00 DC 00 00 00 00 00
0E0: 00 00 00 00 00 00 DE 00 00 00 00 00 00 00 00 00
0F0: 00 00 DF 00 00 00 00 00 00 00 00 00 00 00 E0 00
100: 00 00 00 00 00 00 00 00 00 00 E2 00 00 00 00 00
110: 00 00 00 00 00 00 F0 01 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 36



Uživatel popisuje částečné zlepšení, pořád to není úplně top, ale prý to funguje znatelně lépe.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu - neuvěřitelně zasekaný notebook

Příspěvekod jaro3 » 03 dub 2021 18:51

Stáhni si Memtest
http://www.stahuj.cz/utility_a_ostatni/ ... i/memtest/


Políčko , ve kterém je napsáno:
All unused RAM ponech.
-dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.
V případě vyšších kapacit RAM je třeba Memtest spustit několikrát , pro 2GB ( jednotlivá největší kapacita RAM) 2x , pro 4GB 3x , pro 8Gb 4x ap.
poklepej na Memtest , pak znovu a znovu , do políček všech Memtestů napiš 2048 , pak dej u všech Memtestů "Start".

Vypni antivir i firewall.
Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
další odkaz:
http://www.bleepingcomputer.com/downloa ... scan-tool/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 10 hostů