Prosím o kontrolu PC s podivným chováním Opery Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

VladoR
nováček
Příspěvky: 37
Registrován: říjen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu PC s podivným chováním Opery

Příspěvekod VladoR » 24 zář 2020 00:02

Aha, to se neodeslalo. Dával jsem to do zprávy, le jaksi neodešlo to. Zoek tedy nemám. Mám ho udělat znovu?

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu PC s podivným chováním Opery

Příspěvekod jaro3 » 24 zář 2020 00:24

Jo , ještě jednou zoek.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

VladoR
nováček
Příspěvky: 37
Registrován: říjen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu PC s podivným chováním Opery

Příspěvekod VladoR » 24 zář 2020 00:27

Kurňa, Zoek jsem kopíroval a vkládal a odeslal ale jak vidím neprošel. Tak jsem to udělal znovu.
Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by wov on 24.09.2020 at 0:05:08,93.
Microsoft Windows 10 Pro 10.0.18363 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\wov\AppData\Local\Temp\scoped_dir13876_1466301545\zoek (1).exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2020-09-23-163629.log 263314 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\Users\wov\AppData\Local\GHISLER deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\wov\AppData\Roaming\Mozilla\Firefox\Profiles\zidueetw.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\wov\AppData\Roaming\Mozilla\Firefox\Profiles\zidueetw.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\wov\AppData\Roaming\Thunderbird\Profiles\60qzzmyd.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\wov\AppData\Roaming\Thunderbird\Profiles\60qzzmyd.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd11.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd13.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd25.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd27.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd29.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd4a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd4c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd4e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd50.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd62.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd73.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd75.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd77.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd79.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd8b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10dd8d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10ddae.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10ddb0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3650-3710-10ddb2.tmp deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\wov\AppData\Roaming\Mozilla\Firefox\Profiles\zidueetw.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\wov\AppData\Roaming\Thunderbird\Profiles\60qzzmyd.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

ProfilePath: C:\Users\wov\AppData\Roaming\Mozilla\Firefox\Profiles\zidueetw.default
- Undetermined - %ProfilePath%\extensions\sko-extension@firma.seznam.cz
- short_ passwords - %ProfilePath%\extensions\jid1-r1tDuNiNb4SEww@jetpack.xpi
- short_ __MSG_name__ - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\wov\AppData\Roaming\Thunderbird\Profiles\60qzzmyd.default
- Undetermined - %ProfilePath%\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\wov\AppData\Roaming\Mozilla\Firefox\Profiles\zidueetw.default
- C:\PROGRA1\MICROS1\Office14\NPAUTHZ.DLL - [?]


==== Chromium Look ======================

Google Chrome Version: 85.0.4183.121


Seznam doplněk - Email - wov\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Seznam doplněk - Esko - wov\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak
Chrome Media Router - wov\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/?clid=12454"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/?clid=12454"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{FAEE00BE-14F9-417D-ACFA-D94EBB0230E1}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\SearchScopes\{FAEE00BE-14F9-417D-ACFA-D94EBB0230E1} - http://www.bing.com/search?q={searchTerms}&form=PRFUJ1&src=IE11TR&pc=FSTE
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{FAEE00BE-14F9-417D-ACFA-D94EBB0230E1}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes\{FAEE00BE-14F9-417D-ACFA-D94EBB0230E1} - http://www.bing.com/search?q={searchTerms}&form=PRFUJ1&src=IE11TR&pc=FSTE
HKCU\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
HKCU\SearchScopes\{23A9FB25-AECA-4830-91D8-D41D7445A85C} - http://www.mapy.cz/?query={searchTerms}&sourceid=QuickSearch_12454
HKCU\SearchScopes\{2B0C936F-F84F-4952-BE97-9B3F48C60CA5} - http://www.novinky.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
HKCU\SearchScopes\{42FBDBB6-6455-46DB-ABEC-B55C3426C80E} - http://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
HKCU\SearchScopes\{5B9B0816-E962-4A23-9E69-7A18D154DC59} - http://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454
HKCU\SearchScopes\{9695384D-56F3-481F-B554-67F4287B78BF} - http://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454
HKCU\SearchScopes\{A1E5B629-8E7B-4056-BDAB-F180BDDE4839} - http://www.firmy.cz/?q={searchTerms}&sourceid=QuickSearch_12454
HKCU\SearchScopes\{A612448E-F41B-4B8C-BCA9-24E495C7F34E} - http://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454
HKCU\SearchScopes\{C9FCF2A6-0396-4AC4-AFE0-0B1F187A7F7C} - http://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=QuickSearch_12454

==== Reset Google Chrome ======================

C:\Users\wov\Appdata\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\wov\Appdata\Roaming\Opera Software\Opera Stable\Preferences.backup was reset successfully
C:\Users\wov\Appdata\Roaming\Opera Software\Opera Stable\Secure Preferences was reset successfully
C:\Users\wov\Appdata\Roaming\Opera Software\Opera Stable\Secure Preferences.backup was reset successfully
C:\Users\wov\Appdata\Roaming\Opera Software\Opera Stable\Web Data was reset successfully
C:\Users\wov\Appdata\Roaming\Opera Software\Opera Stable\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\wov\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\wov\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Edge Cache ======================

Edge Cache Emptied Successfully

==== Empty Chrome Cache ======================

C:\Users\wov\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\wov\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache emptied successfully
C:\Users\wov\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\wov\AppData\Local\Microsoft\Edge\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=2814 folders=3674 719838521 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\wov\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\wov\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 24.09.2020 at 0:25:33,34 ======================

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu PC s podivným chováním Opery

Příspěvekod jaro3 » 24 zář 2020 17:40

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O1 - Hosts: ::1 localhost


Stáhni si zde DelFix
Další odkazy:
https://toolslib.net/downloads/viewdownload/2-delfix/
http://ccm.net/download/download-24087-delfix
https://www.bleepingcomputer.com/download/delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7, 8 a10 musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt

Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

VladoR
nováček
Příspěvky: 37
Registrován: říjen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu PC s podivným chováním Opery

Příspěvekod VladoR » 24 zář 2020 21:17

Je divné, že už jsem to dvakrát posílal ale ani jednou to neodešlo. Tak nový pokus Zoek:
Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by wov on 24.09.2020 at 18:07:12,88.
Microsoft Windows 10 Pro 10.0.18363 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\wov\Desktop\zoek (1).exe [Scan all users] [Quick Scan] [Auto Clean]

==== Older Logs ======================

C:\zoek-results2020-09-23-163629.log 263314 bytes
C:\zoek-results2020-09-23-222533.log 11568 bytes

==== Empty Folders Check ======================

C:\Program Files\ModifiableWindowsApps

==== Files Recently Created / Modified ======================

====== C:\WINDOWS ====
2020-09-23 16:41:06 D9D00A30802050031A06F2F24CB9856A 324151 ----a-w- C:\WINDOWS\ZAM.krnl.trace
====== C:\Users\wov\AppData\Local\Temp ====
2020-09-24 16:07:10 8377C99BF813BE986D07730F5C433382 68096 ----a-w- C:\Users\wov\AppData\Local\Temp\ZAScan.exe
2020-09-24 16:07:10 75375C22C72F1BEB76BEA39C22A1ED68 167936 ----a-w- C:\Users\wov\AppData\Local\Temp\unzip.exe
2020-09-24 16:07:10 1A3F82F420340222F13C5633AEB716D6 533851 ----a-w- C:\Users\wov\AppData\Local\Temp\sr.exe
====== Java Cache =====
====== C:\WINDOWS\SysWOW64 =====
====== C:\WINDOWS\SysWOW64\drivers =====
====== C:\WINDOWS\Sysnative =====
2020-09-21 16:03:43 6F29EA44A4F3EDFB75BEDC12FA49E578 338528 ----a-w- C:\WINDOWS\Sysnative\aswBoot.exe
====== C:\WINDOWS\Sysnative\drivers =====
2020-09-24 15:49:49 BF514AA5D5A02EC8EB8D6AD50607A6F3 38032 ----a-w- C:\WINDOWS\Sysnative\drivers\truesight.sys
2020-09-23 16:41:01 A83639773C1BD96A2953EA64A82FF863 232792 ----a-w- C:\WINDOWS\Sysnative\drivers\amsdk.sys
2020-09-21 16:03:37 6F72A2BAD6FEEA867B651274AB9487CA 217328 ----a-w- C:\WINDOWS\Sysnative\drivers\aswStm.sys
2020-09-21 16:03:36 BC2D1E60EB57A7A3CA512F518F4FA294 175192 ----a-w- C:\WINDOWS\Sysnative\drivers\aswMonFlt.sys
2020-09-09 14:36:22 7BAFB78DCBF0C74C1F1453E11DEC841B 56320 ----a-w- C:\WINDOWS\Sysnative\drivers\ndiscap.sys
2020-09-09 14:36:19 5B038AA3F751252D65FB93DC86CA740C 84280 ----a-w- C:\WINDOWS\Sysnative\drivers\hvservice.sys
2020-09-09 14:36:10 A5AB27AAC0413E283C117A5D4B73A90D 244736 ----a-w- C:\WINDOWS\Sysnative\drivers\ndproxy.sys
2020-09-09 14:36:10 9040C7286D3856CF821C9004E3C85E2E 28672 ----a-w- C:\WINDOWS\Sysnative\drivers\ndistapi.sys
2020-09-09 14:36:10 531BDEF1400B022C3AB5A4BAC287E779 92672 ----a-w- C:\WINDOWS\Sysnative\drivers\wanarp.sys
2020-09-09 14:36:09 BB197B109B4C29986BA6E3545BD443F9 291840 ----a-w- C:\WINDOWS\Sysnative\drivers\ahcache.sys
2020-09-09 14:36:03 BDBC4C75FE18B4522368042F94A5CEDA 400696 ----a-w- C:\WINDOWS\Sysnative\drivers\clfs.sys
2020-09-09 14:36:03 B49EDC579AA2E7EB7B1BC11C0A65CAAD 131896 ----a-w- C:\WINDOWS\Sysnative\drivers\mup.sys
2020-09-09 14:36:03 A8A43EEF8C1B7B03750D180D0DFD0D16 457016 ----a-w- C:\WINDOWS\Sysnative\drivers\rdbss.sys
2020-09-09 14:36:03 81D84DA690D6EA929B2B98D4B4B5DEAF 561464 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb.sys
2020-09-09 14:36:03 3C94BCDA2A65E71413D3FEE2B4BE913E 2986808 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys
2020-09-09 14:36:03 3A938538858C3D6C2A7C67484056173B 260408 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb20.sys
2020-09-09 14:36:03 3159B39F8179CA4F57E1A4A0C6AAA243 477496 ----a-w- C:\WINDOWS\Sysnative\drivers\FWPKCLNT.SYS
2020-09-09 14:36:02 9BFEAAD2EFAF678B8BBFC986D94A9757 661832 ----a-w- C:\WINDOWS\Sysnative\drivers\afd.sys
2020-09-09 14:36:02 9906881520CA54C276B4B18B0472FA99 1480520 ----a-w- C:\WINDOWS\Sysnative\drivers\ndis.sys
2020-09-09 14:36:02 699C7DEBA7FBC8A8C4DC0D1491CFA85D 146248 ----a-w- C:\WINDOWS\Sysnative\drivers\ksecdd.sys
2020-09-09 14:36:02 213F8906EE67BB2FE51F152F2880E275 372536 ----a-w- C:\WINDOWS\Sysnative\drivers\msrpc.sys
2020-09-09 14:35:59 0C0E52C66F7F0F0488422559030FC0AA 2697536 ----a-w- C:\WINDOWS\Sysnative\drivers\ntfs.sys
2020-09-09 14:35:58 2AFFEFE2524D32A9B1E248346407660C 179512 ----a-w- C:\WINDOWS\Sysnative\drivers\ksecpkg.sys
2020-09-09 14:35:57 E0736100E41D3FA9B14A8E784B277C68 18432 ----a-w- C:\WINDOWS\Sysnative\drivers\applockerfltr.sys
2020-09-09 14:35:57 93171D02F2CF70E22A0A890B425C34FC 205640 ----a-w- C:\WINDOWS\Sysnative\drivers\appid.sys
2020-09-09 14:35:50 EC5109B80691ED43A7D132EBFD4F6598 874296 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms2.sys
2020-09-09 14:35:50 83C1F910613AF55E9924E3F2A8F1D7BA 3581240 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgkrnl.sys
2020-09-09 14:35:50 306CE105A8B03A93E70BAE351001BFC4 441152 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms1.sys
2020-09-09 14:35:48 68E9DD2B8EC5D537D9610AA4C99686A9 30720 ----a-w- C:\WINDOWS\Sysnative\drivers\KNetPwrDepBroker.sys
2020-09-09 14:35:48 4F25D29A759B4ADFC4C76A3305D878AD 817152 ----a-w- C:\WINDOWS\Sysnative\drivers\PEAuth.sys
2020-09-09 14:35:46 FD957849622BB52DD4FFB8B683E69E4B 59192 ----a-w- C:\WINDOWS\Sysnative\drivers\storufs.sys
2020-09-09 14:35:46 E296DFDCF3B56B57E6D2C5B4945EB295 250680 ----a-w- C:\WINDOWS\Sysnative\drivers\tpm.sys
2020-09-09 14:35:46 DE1BB09C09710E504D925E166A0C3BAF 555320 ----a-w- C:\WINDOWS\Sysnative\drivers\Vid.sys
2020-09-09 14:35:46 D43D39F5A58A553DB0B726F218FB8824 36352 ----a-w- C:\WINDOWS\Sysnative\drivers\BtaMPM.sys
2020-09-09 14:35:46 BF696833734ECF0F5920B5A6B1820EBC 224072 ----a-w- C:\WINDOWS\Sysnative\drivers\intelppm.sys
2020-09-09 14:35:46 882C3A7C2518CA54C0C4CA356AD4152C 208712 ----a-w- C:\WINDOWS\Sysnative\drivers\processr.sys
2020-09-09 14:35:46 6DF64CDECBDF4903145DE05140BA366C 201544 ----a-w- C:\WINDOWS\Sysnative\drivers\amdppm.sys
2020-09-09 14:35:46 55B91062FD88B3D38C7276F56409AF7A 142152 ----a-w- C:\WINDOWS\Sysnative\drivers\stornvme.sys
2020-09-09 14:35:46 538FC7D3EE3985AF28FF51191CC11883 200008 ----a-w- C:\WINDOWS\Sysnative\drivers\amdk8.sys
====== C:\WINDOWS\Tasks ======
2020-09-23 16:41:03 21B632972B93B5469D4CD34560693B25 2518 ----a-w- C:\WINDOWS\Sysnative\Tasks\AMHelper
2020-09-20 07:29:19 -------- d-----w- C:\WINDOWS\Sysnative\Tasks\Mozilla
====== C:\WINDOWS\Temp ======
======= C:\Program Files =====
2020-09-21 16:52:55 -------- d-----w- C:\Program Files\RogueKiller
======= C:\PROGRA~2 =====
2020-09-23 16:41:01 -------- d-----w- C:\PROGRA~2\Zemana
2020-09-21 16:08:02 -------- d-----w- C:\PROGRA~2\Sophos
2020-09-01 17:22:57 -------- d-----w- C:\PROGRA~2\Mozilla Thunderbird
======= C: =====
====== C:\Users\wov\AppData\Roaming ======
2020-09-23 22:24:48 -------- d-----w- C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp
2020-09-23 22:24:48 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp
2020-09-23 22:24:48 -------- d-----w- C:\Users\wov\AppData\Local\Temp
2020-09-23 22:24:48 -------- d-----w- C:\Users\Default\AppData\Local\Temp
2020-09-23 22:24:48 -------- d-----w- C:\Users\Default User\AppData\Local\Temp
2020-09-23 16:49:02 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Zemana
2020-09-23 16:43:45 -------- d-----w- C:\Users\wov\AppData\Local\CrashDumps
2020-09-23 16:41:04 -------- d-----w- C:\Users\wov\AppData\Local\Zemana
2020-09-23 16:40:52 -------- d-----w- C:\Users\wov\AppData\Local\AMSDK
2020-09-20 22:09:08 -------- d-----w- C:\Users\wov\AppData\Local\Adobe
2020-09-20 22:02:34 -------- d-----w- C:\Users\wov\AppData\Locallow\IGDump
====== C:\Users\wov ======
2020-09-23 16:41:02 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2020-09-23 16:39:50 DE4AF67A8A5A388882BDE10A8F9BFCA1 12795472 ----a-w- C:\Users\wov\Desktop\ZemanaAntiMalware_Setup.exe
2020-09-21 16:52:59 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2020-09-21 16:52:38 -------- d-----w- C:\ProgramData\RogueKiller
2020-09-21 16:08:36 -------- d-----w- C:\ProgramData\Sophos
2020-09-21 16:08:04 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2020-09-21 15:47:27 E40542C4CC75E658A4615BFEFB308570 1790024 ----a-w- C:\Users\wov\Desktop\JunkwareRT.exe
2020-09-20 21:54:43 69546BACB4531A9E82D9320817250873 8414384 ----a-w- C:\Users\wov\Desktop\adwcleaner_8.0.7.exe
2020-09-20 21:44:40 0E9A6C238D3725F7DE89A965CFB8BA58 2040904 ----a-w- C:\Users\wov\Desktop\MBSetup.exe
2020-09-20 21:44:20 69546BACB4531A9E82D9320817250873 8414384 ----a-w- C:\Users\wov\Desktop\AdwCleaner (1).exe
2020-09-20 21:43:52 788FCDDD88240A85039F7F561093B118 448512 ----a-w- C:\Users\wov\Desktop\TFC.exe
2020-09-20 21:43:12 D9DE89F0FAF18019BC9595F0F47BCA61 50688 ----a-w- C:\Users\wov\Desktop\ATF-Cleaner.exe

====== C: exe-files ==
2020-09-24 16:07:10 8377C99BF813BE986D07730F5C433382 68096 ----a-w- C:\Users\wov\AppData\Local\Temp\ZAScan.exe
2020-09-24 16:07:10 75375C22C72F1BEB76BEA39C22A1ED68 167936 ----a-w- C:\Users\wov\AppData\Local\Temp\unzip.exe
2020-09-24 16:07:10 1A3F82F420340222F13C5633AEB716D6 533851 ----a-w- C:\Users\wov\AppData\Local\Temp\sr.exe
2020-09-23 20:51:38 A5843BD951F148E99B7265E5BD159FB7 1967360 ----a-w- C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\85.0.4183.121\85.0.4183.121_85.0.4183.102_chrome_updater.exe
2020-09-23 16:41:02 61446FDD76788229D3EBAEABE84DF38C 887896 ----a-w- C:\Program Files (x86)\Zemana\AntiMalware\dotNetFx40_Client_setup.exe
2020-09-23 16:41:01 DE4AF67A8A5A388882BDE10A8F9BFCA1 12795472 ----a-w- C:\Program Files (x86)\Zemana\AntiMalware\Setup.exe
2020-09-23 16:41:01 D95D2576455B9F7BAA0251EF9D35F880 1199992 ----a-w- C:\Program Files (x86)\Zemana\AntiMalware\unins000.exe
2020-09-23 16:41:01 C91ACDB6B0AAC6B7F6A291E81EDE3C30 658808 ----a-w- C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe
2020-09-23 16:39:50 DE4AF67A8A5A388882BDE10A8F9BFCA1 12795472 ----a-w- C:\Users\wov\Desktop\ZemanaAntiMalware_Setup.exe
2020-09-23 16:38:53 5F2E39FBBBD504D38D1256C8BA2A725F 2353320 ----a-w- C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\85.1.14.84\Installer\setup.exe
2020-09-23 16:38:53 5F2E39FBBBD504D38D1256C8BA2A725F 2353320 ----a-w- C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\85.1.14.84\Installer\chrmstp.exe
2020-09-23 16:38:52 4B27293A39BBC7778E1F4C181E95F7BE 892584 ----a-w- C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\85.1.14.84\notification_helper.exe
2020-09-23 16:38:52 1D100E2B9316543C9988FAD3AD1679AC 1212584 ----a-w- C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\85.1.14.84\chrome_pwa_launcher.exe
2020-09-23 16:38:40 231743D9FF2C79DD4D00FEB47F540377 69826728 ----a-w- C:\Program Files (x86)\BraveSoftware\Update\Install\{D03BADAE-ACE1-4558-BAEE-8B4DD6CB1A03}\brave_installer-x64.exe
2020-09-23 16:38:38 231743D9FF2C79DD4D00FEB47F540377 69826728 ----a-w- C:\Program Files (x86)\BraveSoftware\Update\Download\{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}\85.1.14.84\brave_installer-x64.exe
2020-09-21 16:52:57 15DB9E800636057FF4444C529B19C479 30745656 ----a-w- C:\Program Files\RogueKiller\RogueKiller64.exe
2020-09-21 16:52:56 82F808615833B1D392E40F47A4A0A211 25532472 ----a-w- C:\Program Files\RogueKiller\RogueKiller.exe
2020-09-21 16:52:56 5DD085B466BF53C4F98C3D5E6FD41456 14539832 ----a-w- C:\Program Files\RogueKiller\Updater.exe
2020-09-21 16:52:55 49CB6FB4A852798582A36DBB31D36E92 13610040 ----a-w- C:\Program Files\RogueKiller\RogueKillerSvc.exe
2020-09-21 16:52:55 0F26AC82C5EE1B7D7102C5764C990E42 799288 ----a-w- C:\Program Files\RogueKiller\unins000.exe
2020-09-21 16:03:43 6F29EA44A4F3EDFB75BEDC12FA49E578 338528 ----a-w- C:\Windows\System32\aswBoot.exe
2020-09-21 15:47:27 E40542C4CC75E658A4615BFEFB308570 1790024 ----a-w- C:\Users\wov\Desktop\JunkwareRT.exe
2020-09-20 21:54:43 69546BACB4531A9E82D9320817250873 8414384 ----a-w- C:\Users\wov\Desktop\adwcleaner_8.0.7.exe
2020-09-20 21:44:40 0E9A6C238D3725F7DE89A965CFB8BA58 2040904 ----a-w- C:\Users\wov\Desktop\MBSetup.exe
2020-09-20 21:44:20 69546BACB4531A9E82D9320817250873 8414384 ----a-w- C:\Users\wov\Desktop\AdwCleaner (1).exe
2020-09-20 21:43:52 788FCDDD88240A85039F7F561093B118 448512 ----a-w- C:\Users\wov\Desktop\TFC.exe
2020-09-20 21:43:12 D9DE89F0FAF18019BC9595F0F47BCA61 50688 ----a-w- C:\Users\wov\Desktop\ATF-Cleaner.exe
2020-09-18 14:10:02 634A26997BF9FE9A98C58ADC303E30D2 386584 ----a-w- C:\Program Files\Opera\71.0.3770.148\installer_helper_64.exe
2020-09-18 14:10:01 DB96FEAF7A179183A49B46707E8BF01A 1718808 ----a-w- C:\Program Files\Opera\71.0.3770.148\opera_crashreporter.exe
2020-09-18 14:10:01 CB01B1A49D5949F53BCF6A9736D9DAD9 4584984 ----a-w- C:\Program Files\Opera\71.0.3770.148\installer.exe
2020-09-18 14:10:01 80D427F8971BDB5841B7E48321742763 896536 ----a-w- C:\Program Files\Opera\71.0.3770.148\notification_helper.exe
2020-09-18 14:10:01 54EEE8B98AA46CE2672537B48F2AC5B9 3861528 ----a-w- C:\Program Files\Opera\71.0.3770.148\opera_autoupdate.exe
2020-09-18 14:10:01 33C1464470B12463D87CF0DF1BD5F983 1149976 ----a-w- C:\Program Files\Opera\71.0.3770.148\opera.exe
2020-09-18 14:03:11 6026C33BBEBF574A64E36F2B07BBA6FE 375832 ----a-w- C:\Program Files\Opera\70.0.3728.189\installer_helper_64.exe
2020-09-18 14:03:11 074C0051A1AB5A18E0DC3EAAD5EB1B38 1506840 ----a-w- C:\Program Files\Opera\70.0.3728.189\opera_crashreporter.exe
2020-09-18 14:03:10 E1725C6D4A469A73D9B7536E269F9FE4 1127448 ----a-w- C:\Program Files\Opera\70.0.3728.189\opera.exe
2020-09-18 14:03:10 D9E7C4536CA20F68F7F7E501D1ECCD42 3720216 ----a-w- C:\Program Files\Opera\70.0.3728.189\opera_autoupdate.exe
2020-09-18 14:03:10 B2C0BDF3063372EFFB2C8E2306C1FB06 876568 ----a-w- C:\Program Files\Opera\70.0.3728.189\notification_helper.exe
2020-09-18 14:03:10 94EB5A4D523FFF16AFF6534860743815 4609560 ----a-w- C:\Program Files\Opera\70.0.3728.189\installer.exe
=== C: other files ==
2020-09-24 15:49:49 BF514AA5D5A02EC8EB8D6AD50607A6F3 38032 ----a-w- C:\Windows\System32\drivers\truesight.sys
2020-09-23 16:41:01 A83639773C1BD96A2953EA64A82FF863 232792 ----a-w- C:\Windows\System32\drivers\amsdk.sys
2020-09-21 16:03:43 E9D0CD563EE5C71687357107538D2BD7 16824 ----a-w- C:\Windows\ELAMBKUP\aswElam.sys
2020-09-21 16:03:37 6F72A2BAD6FEEA867B651274AB9487CA 217328 ----a-w- C:\Windows\System32\drivers\aswStm.sys
2020-09-21 16:03:36 BC2D1E60EB57A7A3CA512F518F4FA294 175192 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2020-09-18 14:10:02 CB4529AE45B4C9002E3ECA25971BEA02 2250 ----a-w- C:\Program Files\Opera\71.0.3770.148\resources\standard_themes\default_theme.zip
2020-09-18 14:10:02 2450B6917322168E02DE2073889E94DB 2240 ----a-w- C:\Program Files\Opera\71.0.3770.148\resources\standard_themes\default_dark_theme.zip
2020-09-18 14:03:11 CB4529AE45B4C9002E3ECA25971BEA02 2250 ----a-w- C:\Program Files\Opera\70.0.3728.189\resources\standard_themes\default_theme.zip
2020-09-18 14:03:11 2450B6917322168E02DE2073889E94DB 2240 ----a-w- C:\Program Files\Opera\70.0.3728.189\resources\standard_themes\default_dark_theme.zip

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup"

[HKEY_USERS\S-1-5-21-4258622689-1388004505-547537832-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"="C:\Users\wov\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background"
"CCleaner Smart Cleaning"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Opera Browser Assistant"="C:\Program Files\Opera\assistant\browser_assistant.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"="C:\Users\wov\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background"
"CCleaner Smart Cleaning"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR"

==== Startup Registry Enabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvLaunch.exe /gui"
"TuneupUI.exe"="C:\Program Files\Avast Software\Cleanup\TuneupUI.exe /nogui"
"SecurityHealth"="%windir%\system32\SecurityHealthSystray.exe "

==== Other Scheduled Tasks ======================

"C:\WINDOWS\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe]
"C:\WINDOWS\SysNative\tasks\Adobe Flash Player NPAPI Notifier" [C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_433_Plugin.exe]
"C:\WINDOWS\SysNative\tasks\Adobe Flash Player PPAPI Notifier" [C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_433_pepper.exe]
"C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\WINDOWS\SysNative\tasks\AMHelper" ["C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe"]
"C:\WINDOWS\SysNative\tasks\Avast Emergency Update" [C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe]
"C:\WINDOWS\SysNative\tasks\BraveSoftwareUpdateTaskMachineCore" [C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe]
"C:\WINDOWS\SysNative\tasks\BraveSoftwareUpdateTaskMachineUA" [C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe]
"C:\WINDOWS\SysNative\tasks\CCleaner Update" [C:\Program Files\CCleaner\CCUpdate.exe]
"C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\WINDOWS\SysNative\tasks\OneDrive Standalone Update Task v2" [%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe]
"C:\WINDOWS\SysNative\tasks\OneDrive Standalone Update Task-S-1-5-21-4258622689-1388004505-547537832-1001" [%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe]
"C:\WINDOWS\SysNative\tasks\Opera scheduled assistant Autoupdate 1547137929" [C:\Program Files\Opera\launcher.exe]
"C:\WINDOWS\SysNative\tasks\Opera scheduled Autoupdate 1514415525" [C:\Program Files\Opera\launcher.exe]
"C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{F9336EBF-DA5B-4A78-9288-7676B717BD01}" [C:\WINDOWS\system32\msfeedssync.exe]
"C:\WINDOWS\SysNative\tasks\Avast Software\Avast Cleanup Update" [C:\Program Files\Common Files\Avast Software\Icarus\avast-tu\icarus.exe]
"C:\WINDOWS\SysNative\tasks\Avast Software\Avast Cleanup Update BugReport" [C:\Program Files\Avast Software\Cleanup\AvBugReport.exe]
"C:\WINDOWS\SysNative\tasks\Avast Software\Overseer" [C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe]
"C:\WINDOWS\SysNative\tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB" [C:\Program Files\Mozilla Firefox\default-browser-agent.exe]
"C:\WINDOWS\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\wov\AppData\Roaming\Mozilla\Firefox\Profiles\zidueetw.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\wov\AppData\Roaming\Thunderbird\Profiles\60qzzmyd.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

ProfilePath: C:\Users\wov\AppData\Roaming\Mozilla\Firefox\Profiles\zidueetw.default
- Undetermined - %ProfilePath%\extensions\sko-extension@firma.seznam.cz
- short_ passwords - %ProfilePath%\extensions\jid1-r1tDuNiNb4SEww@jetpack.xpi
- short_ __MSG_name__ - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\wov\AppData\Roaming\Thunderbird\Profiles\60qzzmyd.default
- Undetermined - %ProfilePath%\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\wov\AppData\Roaming\Mozilla\Firefox\Profiles\zidueetw.default
- C:\PROGRA1\MICROS1\Office14\NPAUTHZ.DLL - [?]


==== Chromium Look ======================

Google Chrome Version: 85.0.4183.121


Seznam doplněk - Email - wov\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Avast SafePrice Price comparison deals and coupons on safe shopping sites - Save Money - wov\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Seznam doplněk - Esko - wov\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak
Slides - wov\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
Docs - wov\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - wov\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - wov\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Avast SafePrice Price comparison deals and coupons on safe shopping sites - Save Money - wov\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Sheets - wov\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap
Google Docs Offline - wov\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi
Chrome Web Store Payments - wov\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - wov\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
Chrome Media Router - wov\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\wov\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\wov\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Edge Cache ======================

Edge Cache Emptied Successfully

==== Empty Chrome Cache ======================

C:\Users\wov\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\wov\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache emptied successfully
C:\Users\wov\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\wov\AppData\Local\Microsoft\Edge\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=2814 folders=3674 719838521 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\wov\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\wov\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 24.09.2020 at 20:53:30,50 ======================

VladoR
nováček
Příspěvky: 37
Registrován: říjen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu PC s podivným chováním Opery

Příspěvekod VladoR » 24 zář 2020 21:31

Fixnul jsem HJT, potíže PC už jsem nepozoroval. Zdá se být v kondici. Takže poslední Delfix napsal:
# DelFix v1.013 - Logfile created 24/09/2020 at 21:29:04
# Updated 17/04/2016 by Xplode
# Username : wov - DESKTOP-JF9340H
# Operating System : Windows 10 Enterprise (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\zoek-results.log
Deleted : C:\zoek-results2020-09-23-163629.log
Deleted : C:\zoek-results2020-09-23-222533.log
Deleted : C:\Users\wov\Desktop\AdwCleaner (1).exe
Deleted : C:\Users\wov\Desktop\AdwCleaner.exe
Deleted : C:\Users\wov\Desktop\adwcleaner_8.0.7.exe
Deleted : C:\Users\wov\Desktop\JRT.txt
Deleted : C:\Users\wov\Desktop\TFC.exe
Deleted : C:\Users\wov\Desktop\zoek (1).exe
Deleted : C:\Users\Public\Desktop\RogueKiller.lnk

########## - EOF - ##########

VladoR
nováček
Příspěvky: 37
Registrován: říjen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu PC s podivným chováním Opery

Příspěvekod VladoR » 24 zář 2020 21:32

Fixnul jsem HJT, potíže PC už jsem nepozoroval. Zdá se být v kondici. Takže poslední Delfix napsal:
# DelFix v1.013 - Logfile created 24/09/2020 at 21:29:04
# Updated 17/04/2016 by Xplode
# Username : wov - DESKTOP-JF9340H
# Operating System : Windows 10 Enterprise (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\zoek-results.log
Deleted : C:\zoek-results2020-09-23-163629.log
Deleted : C:\zoek-results2020-09-23-222533.log
Deleted : C:\Users\wov\Desktop\AdwCleaner (1).exe
Deleted : C:\Users\wov\Desktop\AdwCleaner.exe
Deleted : C:\Users\wov\Desktop\adwcleaner_8.0.7.exe
Deleted : C:\Users\wov\Desktop\JRT.txt
Deleted : C:\Users\wov\Desktop\TFC.exe
Deleted : C:\Users\wov\Desktop\zoek (1).exe
Deleted : C:\Users\Public\Desktop\RogueKiller.lnk

########## - EOF - ##########

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu PC s podivným chováním Opery  Vyřešeno

Příspěvekod jaro3 » 24 zář 2020 22:42

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 6 hostů