Dobrý den, prosím o kontrolu logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Simisejk
nováček
Příspěvky: 24
Registrován: leden 12
Pohlaví: Muž
Stav:
Offline

Re: Dobrý den, prosím o kontrolu logu

Příspěvekod Simisejk » 07 pro 2020 23:00

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Home Premium x64
Ran by Kateýina (Administrator) on po 07.12.2020 at 22:51:12,88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 45

Successfully deleted: C:\Users\Kateýina\AppData\Local\{0B1AB8B2-F2AF-428E-85C3-121C5039FF3E} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{0BFA0CA0-D832-48D3-BA8D-A33468CD491A} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{0CFB23CF-FF62-4DAC-8221-B751E6A22630} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{19A53D54-2B98-4829-9CA3-4E6CEF82CEA9} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{2C17EE2D-5895-4175-9ECC-87A7506E8845} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{38D0E6C6-BD19-449D-859E-4DF354BA2CED} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{42468F73-6ABD-4A02-819B-CEC41F9AE002} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{514AD24A-C6E7-40CF-AD31-05DE6B4F617F} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{633C8462-0E24-4634-9CBE-46E6945D135C} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{65558C5A-3227-4333-98D2-940C3CC5AF94} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{89C4EAA4-65AF-400F-AEFC-3227557ED6EA} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{8D6D1F0F-CAF7-4584-AE6A-FE481E5D04DA} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{8DC2E3CB-8CE5-45D6-B87E-4FCED7DD2E21} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{97815478-53A0-4F8E-8102-C3F8045D1B1A} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{A4FFED17-C721-4D23-9FCE-7B335EAAC8F1} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{A8A6F455-209A-49B1-9251-5C8C1D8F3E76} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{AD99DC50-FC4F-4E90-BD5F-1B37392934A7} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{B8E27FCA-F368-408F-9EBD-2ECEDE080DCB} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{C4E7DB18-E0A2-4640-B5E3-93F3AF2AB1C6} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{CEF563C2-5AB6-497E-B993-533A79263946} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{DF6577E4-4D5C-4613-A7C7-D37DCCC8F371} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\{EB5CEEDC-7FFA-49C5-A386-41419743AA12} (Empty Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd (Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bgjpfhpjcgdppjbgnpnjllokbmcdllig (Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_olfeabkoenfaoljndfecamgilllcpiak_0.localstorage (File)
Successfully deleted: C:\Users\Kateýina\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage (File)
Successfully deleted: C:\Users\Kateýina\AppData\Local\installer (Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Roaming\nico mak computing (Folder)
Successfully deleted: C:\Users\Kateýina\Documents\add-in express (Folder)
Successfully deleted: C:\Windows\system32\Tasks\4bd3ec58-c42f-443e-8edb-0a5b2d035380-1 (Task)
Successfully deleted: C:\Windows\system32\Tasks\4bd3ec58-c42f-443e-8edb-0a5b2d035380-4 (Task)
Successfully deleted: C:\Windows\system32\Tasks\4bd3ec58-c42f-443e-8edb-0a5b2d035380-5 (Task)
Successfully deleted: C:\Windows\system32\Tasks\RMSmartUpdate (Task)
Successfully deleted: C:\Windows\Tasks\4bd3ec58-c42f-443e-8edb-0a5b2d035380-1.job (Task)
Successfully deleted: C:\Windows\Tasks\4bd3ec58-c42f-443e-8edb-0a5b2d035380-4.job (Task)
Successfully deleted: C:\Windows\Tasks\4bd3ec58-c42f-443e-8edb-0a5b2d035380-5.job (Task)
Successfully deleted: C:\Windows\wininit.ini (File)
Successfully deleted: C:\Users\Kateýina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DCK98MIQ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F6H1EG49 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KRSKQH0L (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Kateýina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M0USJXHY (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DCK98MIQ (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F6H1EG49 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KRSKQH0L (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M0USJXHY (Temporary Internet Files Folder)



Registry: 6

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{41545534-2D56-3700-76A7-7A786E7484D7} (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{495958D9-410D-41C4-B34A-5FA31DDBEF47} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 07.12.2020 at 22:56:12,97
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Reklama
Simisejk
nováček
Příspěvky: 24
Registrován: leden 12
Pohlaví: Muž
Stav:
Offline

Re: Dobrý den, prosím o kontrolu logu

Příspěvekod Simisejk » 07 pro 2020 23:03

Nějak jim to blbne, já to nakonec stáhl musí se na to víckrát kliknout a pak vyskočilo okno, nevdía dam vše do karantény

Simisejk
nováček
Příspěvky: 24
Registrován: leden 12
Pohlaví: Muž
Stav:
Offline

Re: Dobrý den, prosím o kontrolu logu

Příspěvekod Simisejk » 07 pro 2020 23:31

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 07.12.20
Čas skenování: 23:05
Logovací soubor: 49f1ebc6-38d8-11eb-bdd6-386077e92d6a.json

-Informace o softwaru-
Verze: 4.2.3.96
Verze komponentů: 1.0.1122
Aktualizovat verzi balíku komponent: 1.0.34039
Licence: Zkušební

-Systémová informace-
OS: Windows 7 Service Pack 1
CPU: x64
Systém souborů: NTFS
Uživatel: KATERINA-PC\Kate\u00c5\u0099ina

-Shrnutí skenování-
Typ skenování: Skenování hrozeb (Threat Scan)
Spuštění skenování: Ruční
Výsledek: Dokončeno
Skenované objekty: 251623
Zjištěné hrozby: 40
Hrozby umístěné do karantény: 40
Uplynulý čas: 7 min, 30 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Zakázáno
Heuristika: Povoleno
Potenciálně nežádoucí program: Detekovat
Potenciálně nežádoucí modifikace: Detekovat

-Podrobnosti skenování-
Proces: 1
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\RTOP\BIN\RTOP_SVC.EXE, V karanténě, 1035, 823167, , , , , 1E3684D287D5F141087610D5F3120F11, A8B46855E9A2DAE5C11A2AAF1BDE7B7E3BDAA9336E0640A99417103314D85C76

Modul: 1
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\RTOP\BIN\RTOP_SVC.EXE, V karanténě, 1035, 823167, , , , , 1E3684D287D5F141087610D5F3120F11, A8B46855E9A2DAE5C11A2AAF1BDE7B7E3BDAA9336E0640A99417103314D85C76

Klíč registru: 26
PUP.Optional.SecurityProtection, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\NOAJMLKIPCLMEOLFCNFLKJHIJKIGPFJH, V karanténě, 1873, 242841, , , , , ,
PUP.Optional.SecurityProtection, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\noajmlkipclmeolfcnflkjhijkigpfjh, V karanténě, 1873, 242841, 1.0.34039, , ame, , ,
PUP.Optional.ByteFence, HKLM\SOFTWARE\WOW6432NODE\Bytefence, V karanténě, 1035, 388723, 1.0.34039, , ame, , ,
Adware.Elex, HKLM\SOFTWARE\WOW6432NODE\winzipersvc, V karanténě, 205, 444492, 1.0.34039, , ame, , ,
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355555510}, V karanténě, 511, 324197, 1.0.34039, , ame, , ,
PUP.Optional.ByteFence, HKLM\SOFTWARE\ByteFence, V karanténě, 1035, 388723, 1.0.34039, , ame, , ,
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, V karanténě, 3667, 238777, 1.0.34039, , ame, , ,
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, V karanténě, 3667, 238776, 1.0.34039, , ame, , ,
PUP.Optional.ByteFence, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\ByteFenceService, V karanténě, 1035, 389039, 1.0.34039, , ame, , ,
PUP.Optional.Yontoo, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\Update PodoWeb, V karanténě, 27, 254019, 1.0.34039, , ame, , ,
PUP.Optional.Yontoo, HKLM\SOFTWARE\POLICIES\GOOGLE\CHROME, V karanténě, 27, -1, 0.0.0, , action, , ,
PUP.Optional.Yontoo, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\CHROME, V karanténě, 27, -1, 0.0.0, , action, , ,
PUP.Optional.Yontoo, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\Util PodoWeb, V karanténě, 27, 254019, 1.0.34039, , ame, , ,
Adware.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\winzipersvc, V karanténě, 205, 385015, 1.0.34039, , ame, , ,
PUP.Optional.ByteFence, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ByteFence, V karanténě, 1035, 388725, 1.0.34039, , ame, , ,
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreClass.1, V karanténě, 3667, 238771, , , , , ,
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreClass, V karanténě, 3667, 238771, 1.0.34039, , ame, , ,
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc.1.0, V karanténě, 3667, 238771, , , , , ,
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc, V karanténě, 3667, 238771, 1.0.34039, , ame, , ,
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3COMClassService.1.0, V karanténě, 3667, 238771, , , , , ,
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3COMClassService, V karanténě, 3667, 238771, 1.0.34039, , ame, , ,
PUP.Optional.ByteFence, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rtop, V karanténě, 1035, 823167, , , , , ,
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebSvc.1.0, V karanténě, 3667, 238771, , , , , ,
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebSvc, V karanténě, 3667, 238771, 1.0.34039, , ame, , ,
PUP.Optional.CrossRider, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355555510}, V karanténě, 511, 324197, 1.0.34039, , ame, , ,
PUP.Optional.CrossRider, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{55555555-5555-5555-5555-550355555510}, V karanténě, 511, 324197, 1.0.34039, , ame, , ,

Hodnota v registru: 3
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355555510}|, V karanténě, 511, 324197, 1.0.34039, , ame, , ,
PUP.Optional.CrossRider, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355555510}|, V karanténě, 511, 324197, 1.0.34039, , ame, , ,
PUP.Optional.CrossRider, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{55555555-5555-5555-5555-550355555510}|, V karanténě, 511, 324197, 1.0.34039, , ame, , ,

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 4
PUP.Optional.ByteFence, C:\ProgramData\ByteFence\RTOP, V karanténě, 1035, 388718, , , , , ,
PUP.Optional.ByteFence, C:\PROGRAMDATA\BYTEFENCE, V karanténě, 1035, 388718, 1.0.34039, , ame, , ,
PUP.Optional.ByteFence, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\ByteFence Anti-Malware, V karanténě, 1035, 823168, 1.0.34039, , ame, , ,
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE, V karanténě, 1035, 823167, 1.0.34039, , ame, , ,

Soubor: 5
PUP.Optional.ByteFence, C:\ProgramData\ByteFence\RTOP\hosts_backup, V karanténě, 1035, 388718, , , , , A4ECA8014112A13122660B77E6F9ECA2, D311A04D648B6A745F75A8D55D063343BBB8758DFCF0AFFE1DDA9B7617DD4BC6
PUP.Optional.ByteFence, C:\ProgramData\ByteFence\RTOP\uclogfile.bin, V karanténě, 1035, 388718, , , , , ,
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\RTOP\BIN\RTOP_SVC.EXE, V karanténě, 1035, 823167, , , , , 1E3684D287D5F141087610D5F3120F11, A8B46855E9A2DAE5C11A2AAF1BDE7B7E3BDAA9336E0640A99417103314D85C76
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\RTOP\BIN\RTOP_SVC.EXE, V karanténě, 1035, 823167, 1.0.34039, , ame, , 1E3684D287D5F141087610D5F3120F11, A8B46855E9A2DAE5C11A2AAF1BDE7B7E3BDAA9336E0640A99417103314D85C76
PUP.Optional.ASK, C:\USERS\KATEřINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Nahrazen, 281, 454827, 1.0.34039, , ame, , 5F0E00C12371A75AFAD24D006706CE7F, 13D77263EDC6220401DF9D36F62FFC351F00C58364AC7311DB6EFC54BE40B33D

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)

WMI: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Dobrý den, prosím o kontrolu logu

Příspěvekod jaro3 » 08 pro 2020 00:14

OK.

Sophos Virus Removal Tool je praktický softwarový nástroj, který by mohl odstranit infekce, které antivirový program nedetekuje .
Stáhněte si ho zde z některého odkazu:
http://www.majorgeeks.com/files/details ... _tool.html
http://www.majorgeeks.com/mg/get/sophos ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,2.html

Viry mohou zpomalit počítač, nebo se snaží ukrást vaše data, a ani nevíte , že je máte. Co potřebujete, je rychlý a snadný způsob, jak je najít a zbavit se jich, pokud již máte antivirový program v počítači nainstalován , můžete nainstalovat i nástroj Sophos Virus Removal , který identifikuje a vyčistí zbylé infekce, které mohl Váš antivirový program přehlédnout.
K použití Sophos Virus Removal Tool na něj poklepejte a stiskněte tlačítko „Start scanning“ . Pak bude Sophos Virus Removal Tool vyhledávat a odstraňovat viry, které najde. Může být vyžadován restart.
Pokud byly nalezeny viry , tak po skenu klikni na „Details…“ a potom na „View log file“. Zkopíruj celý log a vlož ho sem. Potom zavři „threat detail“ a klikni na „Start cleanup“.
Jinak se log nachází zde:
C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs

Stáhni si RogueKiller by Adlice Software
http://www.adlice.com/download/roguekiller/
http://www.bleepingcomputer.com/download/roguekiller/
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7,8,10 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Open Report “ , v okně pak na „Open TXT“ a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků


další zítra.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Simisejk
nováček
Příspěvky: 24
Registrován: leden 12
Pohlaví: Muž
Stav:
Offline

Re: Dobrý den, prosím o kontrolu logu

Příspěvekod Simisejk » 08 pro 2020 13:12

Sophos Virus Removal Tool v pořádku, čistý, nic nenašel.

RogueKiller Anti-Malware V14.8.0.0 (x64) [Nov 17 2020] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : Kate?ina [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20201208_091743, Driver : Loaded
Mode : Standard Scan, Scan -- Date : 2020/12/08 11:43:52 (Duration : 00:37:02)
Switches : -minimize

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.Gen1 (Potentially Malicious)] \{9F46BAC9-5FA4-4E33-8CC1-30DF82E3696B} -- C:\Windows\system32\pcalua.exe [-a "C:\Program Files (x86)\YouTube Accelerator\YTAUninstall.exe"] -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> XX - Software
[PUP.Gen1 (Potentially Malicious)] (X86) HKEY_LOCAL_MACHINE\Software\simplitec -- N/A -> Found
[PUP.ByteFence|PUP.Gen1 (Potentially Malicious)] (X64) HKEY_USERS\S-1-5-21-1359306060-3591449500-354510066-1001\Software\ByteFence -- N/A -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.InstallCore (Potentially Malicious)] (shortcut) Music Search MP3.lnk -- C:\Users\Public\Desktop\Music Search MP3.lnk => C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\yct.exe [/MP3DOWNLOADER] -> Found
[PUP.InstallCore (Potentially Malicious)] (shortcut) aTube Catcher.lnk -- C:\Users\Kate?ina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\aTube Catcher.lnk => C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\yct.exe -> Found
[PUP.InstallCore (Potentially Malicious)] (shortcut) aTube Catcher.lnk -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher\aTube Catcher.lnk => C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\yct.exe -> Found
[PUP.Gen1 (Potentially Malicious)] (folder) simplitec -- C:\ProgramData\simplitec -> Found
[PUP.InstallCore (Potentially Malicious)] (folder) DsNET Corp -- C:\Program Files (x86)\DsNET Corp -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

Simisejk
nováček
Příspěvky: 24
Registrován: leden 12
Pohlaví: Muž
Stav:
Offline

Re: Dobrý den, prosím o kontrolu logu

Příspěvekod Simisejk » 08 pro 2020 13:16

Po vyčištění

RogueKiller Anti-Malware V14.8.0.0 (x64) [Nov 17 2020] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : Kate?ina [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20201208_091743, Driver : Loaded
Mode : Standard Scan, Delete -- Date : 2020/12/08 13:14:52 (Duration : 00:37:02)
Switches : -minimize

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.Gen1 (Potentially Malicious)] \{9F46BAC9-5FA4-4E33-8CC1-30DF82E3696B} -- C:\Windows\system32\pcalua.exe (-a "C:\Program Files (x86)\YouTube Accelerator\YTAUninstall.exe") -> Deleted
[PUP.Gen1 (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\simplitec -- -> Deleted
[PUP.ByteFence|PUP.Gen1 (Potentially Malicious)] HKEY_USERS\S-1-5-21-1359306060-3591449500-354510066-1001\Software\ByteFence -- -> Deleted
[PUP.InstallCore (Potentially Malicious)] Music Search MP3.lnk -- %SystemDrive%\Users\Public\Desktop\Music Search MP3.lnk (lnk => C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\yct.exe [/MP3DOWNLOADER]) -> Deleted
[PUP.InstallCore (Potentially Malicious)] aTube Catcher.lnk -- %_Kate?ina_appdata%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\aTube Catcher.lnk (lnk => C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\yct.exe []) -> Deleted
[PUP.InstallCore (Potentially Malicious)] aTube Catcher.lnk -- %programdata%\Microsoft\Windows\Start Menu\Programs\aTube Catcher\aTube Catcher.lnk (lnk => C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\yct.exe []) -> Deleted
[PUP.Gen1 (Potentially Malicious)] simplitec -- %programdata%\simplitec -> Deleted
=> News Feed Info -- C:\PROGRA~3\SIMPLI~1\Common\NEWSFE~1 -> Deleted
=> Common -- C:\PROGRA~3\SIMPLI~1\Common -> Deleted
=> RegistryCleanerModule.result -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\CHECKD~1\REGIST~1.RES -> Deleted
=> checkdetails -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\CHECKD~1 -> Deleted
=> 10188.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\10188.png -> Deleted
=> 10299.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\10299.png -> Deleted
=> 11406.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\11406.png -> Deleted
=> 16122.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\16122.png -> Deleted
=> 16973.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\16973.png -> Deleted
=> 17840.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\17840.png -> Deleted
=> 18675.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\18675.png -> Deleted
=> 20103.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\20103.png -> Deleted
=> 20458.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\20458.png -> Deleted
=> 20643.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\20643.png -> Deleted
=> 20859.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\20859.png -> Deleted
=> 21207.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\21207.png -> Deleted
=> 21268.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\21268.png -> Deleted
=> 2465.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\2465.png -> Deleted
=> 4536.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\4536.png -> Deleted
=> 4565.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\4565.png -> Deleted
=> 9876.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\9876.png -> Deleted
=> driverupdate.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\DRIVER~1.LOG -> Deleted
=> dudevices.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1\DUDEVI~1.LOG -> Deleted
=> driverupdate -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\DRIVER~1 -> Deleted
=> 2015-12-08 19-39-06,645 Mini.dmp -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\EXCEPT~1\2015-1~1.DMP -> Deleted
=> Exception.exlog -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\EXCEPT~1\EXCEPT~1.EXL -> Deleted
=> Trace.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\EXCEPT~1\Trace.log -> Deleted
=> ExceptionHandlerDll -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\EXCEPT~1 -> Deleted
=> gahelper.dat -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\gahelper.dat -> Deleted
=> PowerSuite_installation.ini -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\POWERS~1.INI -> Deleted
=> Backups -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\Backups -> Deleted
=> 2015-05-14 22-05-46 RegCleanerDll.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\Log\2015-0~1.LOG -> Deleted
=> 2015-05-19 09-18-11 RegCleanerDll.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\Log\2015-0~2.LOG -> Deleted
=> 2015-06-26 12-21-40 RegCleanerDll.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\Log\2015-0~3.LOG -> Deleted
=> 2015-08-05 15-27-52 RegCleanerDll.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\Log\2015-0~4.LOG -> Deleted
=> 2015-09-15 20-13-06 RegCleanerDll.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\Log\20B062~1.LOG -> Deleted
=> 2015-10-19 19-05-17 RegCleanerDll.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\Log\2015-1~1.LOG -> Deleted
=> 2015-11-20 16-59-18 RegCleanerDll.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\Log\2015-1~2.LOG -> Deleted
=> 2015-12-22 09-52-07 RegCleanerDll.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\Log\2015-1~3.LOG -> Deleted
=> 2015-12-26 16-29-16 RegCleanerDll.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\Log\2015-1~4.LOG -> Deleted
=> 2015-12-26 16-31-29 RegCleanerDll.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\Log\20CB74~1.LOG -> Deleted
=> Log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\Log -> Deleted
=> RegCleanerDll.cfg -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1\REGCLE~1.CFG -> Deleted
=> RegCleanerDll -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGCLE~1 -> Deleted
=> 2015-12-26 16-29-16 RegDefragDll.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGDEF~1\Log\2015-1~1.LOG -> Deleted
=> 2015-12-26 16-31-29 RegDefragDll.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGDEF~1\Log\2015-1~2.LOG -> Deleted
=> Log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGDEF~1\Log -> Deleted
=> RegDefragDll -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\REGDEF~1 -> Deleted
=> scheduler_ignore.dat -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SCHEDU~1.DAT -> Deleted
=> 0e5705b69762b9c04e64ec8b2265c8fe.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\services\0E5705~1.PNG -> Deleted
=> 32ca86a73eb01a7a413d46513f499edd.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\services\32CA86~1.PNG -> Deleted
=> 62d22e8e11759585cee651149e9d3e6b.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\services\62D22E~1.PNG -> Deleted
=> 65d26e9bfe68fe194d6c6d24f8496448.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\services\65D26E~1.PNG -> Deleted
=> 6919118e5331081fee0338835cac22a1.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\services\691911~1.PNG -> Deleted
=> 9d46382aedbba649251caac61bc99f0d.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\services\9D4638~1.PNG -> Deleted
=> a0d239d1abb440fe20b790f08fffba37.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\services\A0D239~1.PNG -> Deleted
=> c240c5b629c54401806335ed7fac512d.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\services\C240C5~1.PNG -> Deleted
=> f9b70b05728f2ee4c8734191c6cb4a47.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\services\F9B70B~1.PNG -> Deleted
=> ffa0e463422f7a8e819d534b62937005.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\services\FFA0E4~1.PNG -> Deleted
=> services.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\services\services.log -> Deleted
=> services -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\services -> Deleted
=> Setup Log 2015-05-14 #002.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SETUPL~1.LOG -> Deleted
=> Setup Log 2015-12-26 #001.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SETUPL~3.LOG -> Deleted
=> Setup Log 2015-12-26 #002.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SETUPL~2.LOG -> Deleted
=> SimpliClean_installation.ini -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SIMPLI~2.INI -> Deleted
=> SimpliFast_installation.ini -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SIMPLI~3.INI -> Deleted
=> SimpliSafe_installation.ini -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SIMPLI~4.INI -> Deleted
=> 0b2887086930390ed09d4f4767bed43e.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\0B2887~1.PNG -> Deleted
=> 16ea31c035167d1272c6c863111166b0.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\16EA31~1.PNG -> Deleted
=> 17308d8319ba2a4ae0ce9cc98029ae84.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\17308D~1.PNG -> Deleted
=> 17f611256bfc835cf93efd62956630af.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\17F611~1.PNG -> Deleted
=> 1a51c418e3ffb7cab83eac12669cdeee.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\1A51C4~1.PNG -> Deleted
=> 1b79814d61b4238caf1e8bb7bbebbad7.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\1B7981~1.PNG -> Deleted
=> 2508e517523c5415e6bcb5ba43b58f32.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\2508E5~1.PNG -> Deleted
=> 305b4b3e45cfeae8f99bfef6a8f0ccb0.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\305B4B~1.PNG -> Deleted
=> 31f7fb166785ff0888ffbe8c6da9c546.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\31F7FB~1.PNG -> Deleted
=> 3bda7c0e8b422c3624b69b4e09ce7a83.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\3BDA7C~1.PNG -> Deleted
=> 45fc2c143d158c566c9f97d5833c3f44.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\45FC2C~1.PNG -> Deleted
=> 479007a78a3255e4605d474750eaecb4.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\479007~1.PNG -> Deleted
=> 4cb3a18ac81617583e87f3e8dc524155.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\4CB3A1~1.PNG -> Deleted
=> 5146e3c3bd54365569566168a041c515.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\5146E3~1.PNG -> Deleted
=> 52a715b060f0f371d9a1e1b32b06ac78.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\52A715~1.PNG -> Deleted
=> 62102bff69d8702e80a43ede935f634e.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\62102B~1.PNG -> Deleted
=> 6270d911c43f39c3a8b273af8f741a55.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\6270D9~1.PNG -> Deleted
=> 6c16626a315e2668de3d55d012172c4a.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\6C1662~1.PNG -> Deleted
=> 6caecf91f0ff6eaf699c0aeedc7f59db.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\6CAECF~1.PNG -> Deleted
=> 6ccab557e232dc61bb8e456e287bde77.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\6CCAB5~1.PNG -> Deleted
=> 851d44d0f758b99436a0c81cd31a5808.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\851D44~1.PNG -> Deleted
=> 8570a95c980388a498ef2d55fbd09390.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\8570A9~1.PNG -> Deleted
=> 8a25881cbc286afd228d9d8ce6fd80a7.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\8A2588~1.PNG -> Deleted
=> 8cc365ff4765b4bfb5b2b319271f4b5f.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\8CC365~1.PNG -> Deleted
=> 928c83083b1bb00748aea259c92e56f2.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\928C83~1.PNG -> Deleted
=> ae0f28c2b7b99a209c399317d6edd762.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\AE0F28~1.PNG -> Deleted
=> b0bec5f8f7f759ac815689306be0d174.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\B0BEC5~1.PNG -> Deleted
=> c1ad641b7533fef1c63d33d738b2809e.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\C1AD64~1.PNG -> Deleted
=> cec2338905b935a5ae473df21323534b.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\CEC233~1.PNG -> Deleted
=> ef38ff25eb4630a799b3ec702a5ca537.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\EF38FF~1.PNG -> Deleted
=> softwareproducts.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1\SOFTWA~1.LOG -> Deleted
=> softwareproducts -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\SOFTWA~1 -> Deleted
=> 2497bad945f03b996a4dcaebc389eabd.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\2497BA~1.PNG -> Deleted
=> 36507bd8d478fb0e99c4c12829de93df.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\36507B~1.PNG -> Deleted
=> 50350dcadda4f427ded193aab220d211.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\50350D~1.PNG -> Deleted
=> 5a1e08e405d4a74282a05bb17c78b6bf.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\5A1E08~1.PNG -> Deleted
=> 68f3fdd237c691e5246afc25c327cee3.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\68F3FD~1.PNG -> Deleted
=> 794deb2f4cbbbe876818c9aadc538417.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\794DEB~1.PNG -> Deleted
=> 88bb79d161dc0770b341fc79fa828953.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\88BB79~1.PNG -> Deleted
=> 9314d87a24b4729eb5f0e39f1fbd21e9.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\9314D8~1.PNG -> Deleted
=> 93ec7a263ddb9d0e57ae183174b9fcc6.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\93EC7A~1.PNG -> Deleted
=> acf37253bf86639c175423cd69228f76.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\ACF372~1.PNG -> Deleted
=> b1e9348de7fecfd6a43a9bfca1b836f2.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\B1E934~1.PNG -> Deleted
=> bc23a49757c996711a13a1fee94aea33.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\BC23A4~1.PNG -> Deleted
=> c7252254ded85b4863ccba52b105238e.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\C72522~1.PNG -> Deleted
=> d983dd28d77e3788c315195abe9424aa.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\D983DD~1.PNG -> Deleted
=> e15b3c720c1a1448c8fb951d4ae4f8df.png -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\E15B3C~1.PNG -> Deleted
=> startup.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup\startup.log -> Deleted
=> startup -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\startup -> Deleted
=> TemperatureMonitoringModule.cfg -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\TEMPER~1\TEMPER~1.CFG -> Deleted
=> TemperatureMonitoringModule.log -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\TEMPER~1\TEMPER~1.LOG -> Deleted
=> TemperatureMonitoringModule -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1\TEMPER~1 -> Deleted
=> simplitec Power Suite -- C:\PROGRA~3\SIMPLI~1\SIMPLI~1 -> Deleted
[PUP.InstallCore (Potentially Malicious)] DsNET Corp -- %programfiles(x86)%\DsNET Corp -> Deleted
=> asfbin.exe -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\asfbin.exe -> Deleted
=> atc.ico -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\atc.ico -> Deleted
=> aTubeRawSocket.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\ATUBER~1.DLL -> Deleted
=> aTubeRec.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\aTubeRec.dll -> Deleted
=> AudioCapture.ocx -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\AUDIOC~1.OCX -> Deleted
=> ChilkatAx-9.5.0-win32.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\CHILKA~1.DLL -> Deleted
=> control.dat -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\control.dat -> Deleted
=> cshtpax8.ocx -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\cshtpax8.ocx -> Deleted
=> cshtpax9.ocx -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\cshtpax9.ocx -> Deleted
=> cswskax8.ocx -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\cswskax8.ocx -> Deleted
=> dsnaic.ocx -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\dsnaic.ocx -> Deleted
=> DSNCLiteTimer.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\DSNCLI~1.DLL -> Deleted
=> DSNTabCtrl.ocx -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\DSNTAB~1.OCX -> Deleted
=> dvdauthor.ocx -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\DVDAUT~1.OCX -> Deleted
=> eWorker.exe -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\eWorker.exe -> Deleted
=> ExButton.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\ExButton.dll -> Deleted
=> ExGrid.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\ExGrid.dll -> Deleted
=> ffmpeg.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\ffmpeg.dll -> Deleted
=> grayPlay.ico -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\grayPlay.ico -> Deleted
=> icon_list.ico -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\ICON_L~1.ICO -> Deleted
=> ImageThumbnailCP.ocx -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\IMAGET~1.OCX -> Deleted
=> lame_enc.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\lame_enc.dll -> Deleted
=> catala.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language\catala.txt -> Deleted
=> czech.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language\czech.txt -> Deleted
=> deutsch.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language\deutsch.txt -> Deleted
=> english.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language\english.txt -> Deleted
=> french.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language\french.txt -> Deleted
=> galician.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language\galician.txt -> Deleted
=> italian.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language\italian.txt -> Deleted
=> polish.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language\polish.txt -> Deleted
=> ptrbrasil.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language\PTRBRA~1.TXT -> Deleted
=> slov.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language\slov.txt -> Deleted
=> spanish.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language\spanish.txt -> Deleted
=> Türkçe.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language\TRKE~1.TXT -> Deleted
=> Language -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Language -> Deleted
=> license.txt -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\license.txt -> Deleted
=> mpf.ico -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\mpf.ico -> Deleted
=> mscomctl.OCX -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\mscomctl.OCX -> Deleted
=> msscript.OCX -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\msscript.OCX -> Deleted
=> PacketX.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\PacketX.dll -> Deleted
=> 3G2.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\3G2.png -> Deleted
=> 3GP.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\3GP.png -> Deleted
=> ASF.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\ASF.png -> Deleted
=> avi.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\avi.png -> Deleted
=> cell.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\cell.png -> Deleted
=> dvd.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\dvd.png -> Deleted
=> flac.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\flac.png -> Deleted
=> FLV.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\FLV.png -> Deleted
=> gif.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\gif.png -> Deleted
=> ipod.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\ipod.png -> Deleted
=> MKV.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\MKV.png -> Deleted
=> MOV.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\MOV.png -> Deleted
=> mp2.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\mp2.png -> Deleted
=> mp3.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\mp3.png -> Deleted
=> mp4.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\mp4.png -> Deleted
=> MPG.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\MPG.png -> Deleted
=> mpg1.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\mpg1.png -> Deleted
=> mpg2.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\mpg2.png -> Deleted
=> nintendo.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\nintendo.png -> Deleted
=> no.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\no.png -> Deleted
=> nokia.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\nokia.png -> Deleted
=> ogg.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\ogg.png -> Deleted
=> psp.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\psp.png -> Deleted
=> RM.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\RM.png -> Deleted
=> svcd.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\svcd.png -> Deleted
=> vcd.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\vcd.png -> Deleted
=> vob.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\vob.png -> Deleted
=> WAV.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\WAV.png -> Deleted
=> WMA.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\WMA.png -> Deleted
=> wmv.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\wmv.png -> Deleted
=> xbox.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\xbox.png -> Deleted
=> zune.png -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF\zune.png -> Deleted
=> pngFF -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\pngFF -> Deleted
=> 3G2352X288.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\3G2352~1.APF -> Deleted
=> 3GP128X96.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\3GP128~1.APF -> Deleted
=> 3GP352X288.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\3GP352~1.APF -> Deleted
=> APPLETV.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\APPLETV.apf -> Deleted
=> AVIDIVX.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\AVIDIVX.apf -> Deleted
=> AVIH264.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\AVIH264.apf -> Deleted
=> AVIMSMPEG42.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\AVIMSM~1.APF -> Deleted
=> AVIMSMPEG421600.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\AVIMSM~2.APF -> Deleted
=> AVIXVID.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\AVIXVID.apf -> Deleted
=> BBCELLH320x240.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\BBCELL~1.APF -> Deleted
=> BD720.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\BD720.apf -> Deleted
=> BD1080.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\BDR\BD1080.apf -> Deleted
=> BD480.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\BDR\BD480.apf -> Deleted
=> BD720.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\BDR\BD720.apf -> Deleted
=> BDR -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\BDR -> Deleted
=> CELLH320x240.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\CELLH3~1.APF -> Deleted
=> CELLM320x240.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\CELLM3~1.APF -> Deleted
=> DVDNTSC.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\DVDNTSC.apf -> Deleted
=> DVDPAL.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\DVDPAL.apf -> Deleted
=> FLAC.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\FLAC.apf -> Deleted
=> FLV.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\FLV.apf -> Deleted
=> GIF.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\GIF.apf -> Deleted
=> GIF2.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\GIF2.apf -> Deleted
=> IPAD.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\IPAD.apf -> Deleted
=> IPHONE320x240.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\IPHONE~1.APF -> Deleted
=> IPOD320x240.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\IPOD32~1.APF -> Deleted
=> MKV.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MKV.apf -> Deleted
=> MOV.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MOV.apf -> Deleted
=> MP2.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MP2.apf -> Deleted
=> 128.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MP3\128.apf -> Deleted
=> 192.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MP3\192.apf -> Deleted
=> 256.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MP3\256.apf -> Deleted
=> 320.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MP3\320.apf -> Deleted
=> 64.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MP3\64.apf -> Deleted
=> MP3 -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MP3 -> Deleted
=> MP3_128.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MP3_128.apf -> Deleted
=> MP3_192.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MP3_192.apf -> Deleted
=> MP3_320.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MP3_320.apf -> Deleted
=> MP4HD1080P.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MP4HD1~1.APF -> Deleted
=> MPEG4HQ.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MPEG4HQ.apf -> Deleted
=> MPEG4HQ720x480.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MPEG4H~1.APF -> Deleted
=> MPEG4HQANDROID.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MPEG4H~2.APF -> Deleted
=> MPEG4HQIOS.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MPEG4H~3.APF -> Deleted
=> MPG1.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MPG1.apf -> Deleted
=> MPG2.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\MPG2.apf -> Deleted
=> N800.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\N800.apf -> Deleted
=> OGG.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\OGG.apf -> Deleted
=> PSP.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\PSP.apf -> Deleted
=> PSVCD.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\PSVCD.apf -> Deleted
=> PVCD.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\PVCD.apf -> Deleted
=> RMVB.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\RMVB.apf -> Deleted
=> SVCDNTSC.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\SVCDNTSC.apf -> Deleted
=> SWF.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\SWF.apf -> Deleted
=> VCDNTSC.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\VCDNTSC.apf -> Deleted
=> VOB.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\VOB.apf -> Deleted
=> WAV.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\WAV.apf -> Deleted
=> WEBM.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\WEBM.apf -> Deleted
=> WIIMJPEG.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\WIIMJPEG.apf -> Deleted
=> WMA.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\WMA.apf -> Deleted
=> WMVV1.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\WMVV1.apf -> Deleted
=> WPMPEG4HQ.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\WPMPEG~1.APF -> Deleted
=> XBOX360.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\XBOX360.apf -> Deleted
=> ZUNEWM8.apf -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles\ZUNEWM8.apf -> Deleted
=> Profiles -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Profiles -> Deleted
=> pthreadGC2.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\PTHREA~1.DLL -> Deleted
=> mundofox -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\req\mundofox -> Deleted
=> myplay -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\req\myplay -> Deleted
=> req -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\req -> Deleted
=> rtmpdump.exe -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\rtmpdump.exe -> Deleted
=> SearchBox.ocx -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\SEARCH~1.OCX -> Deleted
=> Message.wav -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Sounds\Message.wav -> Deleted
=> Sounds -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\Sounds -> Deleted
=> StarBurn.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\StarBurn.dll -> Deleted
=> StarBurnX12.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\STARBU~1.DLL -> Deleted
=> StarBurn_SuperVideoCD.iso -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\STARBU~1.ISO -> Deleted
=> StarBurn_VideoCD.iso -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\STARBU~2.ISO -> Deleted
=> tsmuxer.exe -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\tsmuxer.exe -> Deleted
=> unins000.dat -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\unins000.dat -> Deleted
=> unins000.exe -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\unins000.exe -> Deleted
=> vbzlib1.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\vbzlib1.dll -> Deleted
=> videoplay.exe -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\VIDEOP~1.EXE -> Deleted
=> viscomaudio.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\VISCOM~2.DLL -> Deleted
=> viscomaudiodata.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\VISCOM~3.DLL -> Deleted
=> viscomaudioencoder.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\VISCOM~4.DLL -> Deleted
=> viscomaudioprocess.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\VICC4E~1.DLL -> Deleted
=> viscomdvdimg.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\VISCOM~1.DLL -> Deleted
=> viscomspeaker.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\VI78C4~1.DLL -> Deleted
=> viscomwave.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\VIB61D~1.DLL -> Deleted
=> viscomwaveform.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\VIE633~1.DLL -> Deleted
=> vst.ico -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\vst.ico -> Deleted
=> WnASPI32.dll -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\WnASPI32.dll -> Deleted
=> yct.exe -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0\yct.exe -> Deleted
=> aTube Catcher 2.0 -- C:\PROGRA~2\DSNETC~1\ATUBEC~1.0 -> Deleted

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Dobrý den, prosím o kontrolu logu

Příspěvekod jaro3 » 08 pro 2020 16:42

Vypni antivir i firewall.
Stáhni Zoek.exe
http://download.bleepingcomputer.com/smeenk/zoek.exe
https://uloz.to/file/nFH1LwSrGioP/zoek1-rar

Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;

klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log Zkopíruj sem celý obsah toho logu.
Pokud budou problémy , spusť zoek v nouz. režimu.


Stáhni si Zemana AntiMalware Free z tohoto odkazu:
https://www.zemana.com/Download/AntiMal ... .Setup.exe
a ulož si ho na plochu.
Poklepej na tento soubor na ploše a postupuj podle pokynů k instalaci programu.
Přijmi licenci k používání programu EULA , pokud se nabídne.
Pokud je k dispozici aktualizace programu , klepni na tlačítko „Update now“ ( aktualizovat nyní).
Můžeš si zatrhnout i vytvoření bodu obnovy:
Klikni na ozubené kolečko , poté na „Skenování“ a zatrhni „vytvářet body obnovy“.
Vrať se zpět ( klikni na domeček).
Zavři všechny otevřené soubory, složky a prohlížeče
Neměň žádné nastavení. Klikni na „Skenovat“.
Po skenu lze vidět , zda jsou nějaké nákazy. Klikni na „Další“. Nákazy budou přemístěny do karantény.
Když je skenování dokončeno, objeví se tisková zpráva , zkopíruj sem celý obsah té zprávy.
Jinak můžeš zprávy vidět , když klikneš vpravo nahoře na „ zprávy“.


Vlož nový log z HJT + informuj o problémech.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Simisejk
nováček
Příspěvky: 24
Registrován: leden 12
Pohlaví: Muž
Stav:
Offline

Re: Dobrý den, prosím o kontrolu logu

Příspěvekod Simisejk » 09 pro 2020 02:40

Kouknu na to o vikendu, jsem pracovně pryč...

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Dobrý den, prosím o kontrolu logu

Příspěvekod jaro3 » 09 pro 2020 16:18

OK.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 15 hostů