Prosím o kontrolu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Luk4579
Level 1
Level 1
Příspěvky: 84
Registrován: červen 23
Pohlaví: Muž
Stav:
Offline

Prosím o kontrolu

Příspěvekod Luk4579 » 31 srp 2023 11:54

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 11:53:26, on 31.08.2023
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.22621.0001)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
C:\Users\lukin\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\116.0.1938.62\BHO\ie_to_edge_bho.dll
O4 - HKCU\..\Run: [MicrosoftEdgeAutoLaunch_C2A946453535DAC8E26670192D3842C0] "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5
O4 - HKCU\..\Run: [EpicGamesLauncher] "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent -launchcontext=boot
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlansp_c.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AsusUpdateCheck - Unknown owner - C:\Windows\System32\AsusUpdateCheck.exe (file missing)
O23 - Service: CMigrationService - Clonix & CottonCandy - C:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\Windows\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_9d722 - Unknown owner - C:\Windows\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Epic Online Services (EpicOnlineServices) - Epic Games, Inc. - C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) (GoogleChromeElevationService) - Google LLC - C:\Program Files\Google\Chrome\Application\116.0.5845.141\elevation_service.exe
O23 - Service: Slu ba Aktualizace Google (gupdate) (gupdate) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Slu ba Aktualizace Google (gupdatem) (gupdatem) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_d3828c822366e497\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\Windows\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Universal Service (RtkAudioUniversalService) - Realtek Semiconductor - C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_31adae5d99f8cd09\RtkAudUService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SamsungMagicianSVC - Samsung Electronics Co., Ltd. - C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001 (Sense) - Unknown owner - C:\Program Files (x86)\Windows Defender Advanced Threat Protection\MsSense.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\Sgrm\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\Windows\system32\Sgrm\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTrap) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7717 bytes

Reklama
Uživatelský avatar
Luk4579
Level 1
Level 1
Příspěvky: 84
Registrován: červen 23
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod Luk4579 » 31 srp 2023 11:57

# -------------------------------
# Malwarebytes AdwCleaner 8.4.0.0
# -------------------------------
# Build: 08-30-2022
# Database: 2023-07-19.3 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 08-31-2023
# Duration: 00:00:02
# OS: Windows 11 (Build 22621.2215)
# Scanned: 32105
# Detected: 0


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.



########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########

Uživatelský avatar
Luk4579
Level 1
Level 1
Příspěvky: 84
Registrován: červen 23
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod Luk4579 » 31 srp 2023 12:00

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 8/31/23
Scan Time: 11:59 AM
Log File: 0d439ca1-47e5-11ee-b7d9-581122c741b8.json

-Software Information-
Version: 4.6.1.280
Components Version: 1.0.2117
Update Package Version: 1.0.74691
License: Free

-System Information-
OS: Windows 11 (Build 22621.2215)
CPU: x64
File System: NTFS
User: LUKAS\lukin

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 236294
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 0 min, 26 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0
(No malicious items detected)

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

Uživatelský avatar
Luk4579
Level 1
Level 1
Příspěvky: 84
Registrován: červen 23
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod Luk4579 » 31 srp 2023 12:04

----------------------------------------------------------------------------
CrystalDiskInfo 9.1.1 (C) 2008-2023 hiyohiyo
Crystal Dew World: https://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 11 Professional [10.0 Build 22621] (x64)
Date : 2023/08/31 12:03:23

-- Controller Map ----------------------------------------------------------
+ Standardní řadič SATA AHCI [ATA]
- Samsung SSD 860 EVO 250GB
- WDC WD5000AZLX-60K2TA0
- HL-DT-ST DVDRAM GH22NS70
- Řadič prostorů úložišť [SCSI]

-- Disk List ---------------------------------------------------------------
(01) Samsung SSD 860 EVO 250GB : 250,0 GB [0/0/0, pd1] - sg
(02) WDC WD5000AZLX-60K2TA0 : 500,1 GB [1/0/0, pd1]

----------------------------------------------------------------------------
(01) Samsung SSD 860 EVO 250GB
----------------------------------------------------------------------------
Model : Samsung SSD 860 EVO 250GB
Firmware : RVT04B6Q
Serial Number : S4CJNF0MB23271H
Disk Size : 250,0 GB (8,4/137,4/250,0/250,0)
Buffer Size : Neznámy údaj
Queue Depth : 32
# of Sectors : 488397168
Rotation Rate : ---- (SSD)
Interface : Serial ATA
Major Version : ACS-4
Minor Version : ACS-4 Revision 5
Transfer Mode : SATA/600 | SATA/600
Power On Hours : 8229 hodin
Power On Count : 1638 krát
Host Writes : 14611 GB
Wear Level Count : 80
Temperature : 34 C (93 F)
Health Status : Dobrý (95 %)
Features : S.M.A.R.T., NCQ, TRIM, DevSleep, GPL
APM Level : ----
AAM Level : ----
Drive Letter : C:

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
05 100 100 _10 000000000000 Počet přerozdělených sektorů
09 _98 _98 __0 000000002025 Hodiny zapnutí
0C _98 _98 __0 000000000666 Počet zapnutí
B1 _95 _95 __0 000000000050 Počet opotřebení
B3 100 100 _10 000000000000 Počet použitých rezervovaných bloků (celkem)
B5 100 100 _10 000000000000 Počet selhání programu (celkem)
B6 100 100 _10 000000000000 Počet chyb při mazání (celkem)
B7 100 100 _10 000000000000 Chybný běhový blok (celkem)
BB 100 100 __0 000000000000 Počet neopravitelných chyb
BE _66 _58 __0 000000000022 Teplota proudění vzduchu
C3 200 200 __0 000000000000 ECC míra chyb
C7 _96 _96 __0 000000000C90 Počet chyb CRC
EB _99 _99 __0 00000000000F Počet obnovení POR
F1 _99 _99 __0 00072262CB57 Celkem zapsáno LBA

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0040 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 5334 434A 4E46 304D 4232 3332 3731 4820 2020 2020
020: 0000 0000 0000 5256 5430 3442 3651 5361 6D73 756E
030: 6720 5353 4420 3836 3020 4556 4F20 3235 3047 4220
040: 2020 2020 2020 2020 2020 2020 2020 8001 4001 2F00
050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB 0101
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 4F30
070: 0000 0000 0000 0000 0000 001F 850E 00C6 016C 0060
080: 09FC 005E 746B 7D01 4163 7469 BC01 4163 407F 0002
090: 0004 0000 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 5970 1D1C 0000 0000 0000 0008 4000 0000 5002 538E
110: 49B3 BDF4 0000 0000 0000 0000 0000 0000 0000 401E
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0001
170: 2020 2020 2020 2020 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 003D 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 0001 0000 0000
220: 0000 0000 10FF 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0000 1400 0000 0000 0000 0000
240: 0000 0000 0000 4000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 66A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 01 00 05 33 00 64 64 00 00 00 00 00 00 00 09 32
010: 00 62 62 25 20 00 00 00 00 00 0C 32 00 62 62 66
020: 06 00 00 00 00 00 B1 13 00 5F 5F 50 00 00 00 00
030: 00 00 B3 13 00 64 64 00 00 00 00 00 00 00 B5 32
040: 00 64 64 00 00 00 00 00 00 00 B6 32 00 64 64 00
050: 00 00 00 00 00 00 B7 13 00 64 64 00 00 00 00 00
060: 00 00 BB 32 00 64 64 00 00 00 00 00 00 00 BE 32
070: 00 42 3A 22 00 00 00 00 00 00 C3 1A 00 C8 C8 00
080: 00 00 00 00 00 00 C7 3E 00 60 60 90 0C 00 00 00
090: 00 00 EB 12 00 63 63 0F 00 00 00 00 00 00 F1 32
0A0: 00 63 63 57 CB 62 22 07 00 00 00 00 00 00 00 00
0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 53
170: 03 00 01 00 02 55 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D5

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 01 00 05 0A 00 00 00 00 00 00 00 00 00 00 09 00
010: 00 00 00 00 00 00 00 00 00 00 0C 00 00 00 00 00
020: 00 00 00 00 00 00 B1 00 00 00 00 00 00 00 00 00
030: 00 00 B3 0A 00 00 00 00 00 00 00 00 00 00 B5 0A
040: 00 00 00 00 00 00 00 00 00 00 B6 0A 00 00 00 00
050: 00 00 00 00 00 00 B7 0A 00 00 00 00 00 00 00 00
060: 00 00 BB 00 00 00 00 00 00 00 00 00 00 00 BE 00
070: 00 00 00 00 00 00 00 00 00 00 C3 00 00 00 00 00
080: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
090: 00 00 EB 00 00 00 00 00 00 00 00 00 00 00 F1 00
0A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4E

----------------------------------------------------------------------------
(02) WDC WD5000AZLX-60K2TA0
----------------------------------------------------------------------------
Model : WDC WD5000AZLX-60K2TA0
Firmware : 01.01A01
Serial Number : WD-WCC6Z5CEYNFK
Disk Size : 500,1 GB (8,4/137,4/500,1/500,1)
Buffer Size : 32767 KB
Queue Depth : 32
# of Sectors : 976773168
Rotation Rate : 7200 RPM
Interface : Serial ATA
Major Version : ACS-3
Minor Version : ACS-3 Revision 5
Transfer Mode : SATA/600 | SATA/600
Power On Hours : 8669 hodin
Power On Count : 1828 krát
Temperature : 32 C (89 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, NCQ, GPL
APM Level : 0080h [ON]
AAM Level : ----
Drive Letter : D:

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Počet chyb čtení
03 173 172 _21 000000000915 Čas na roztočení ploten
04 _94 _94 __0 000000001ADF Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 100 253 _51 000000000000 Počet chybných hledání
09 _89 _89 __0 0000000021DD Hodin v činnosti
0A 100 100 _51 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C _99 _99 __0 000000000724 Počet cyklů zapnutí zařízení
B7 100 100 __0 000000000000 Specifický pro výrobce
B8 100 100 _97 000000000000 Ukončovacích chyb
BB 100 100 __0 000000000000 Ohlášeno neopravitelných chyb
BC 100 100 __0 000000000000 Časový limit příkazu
BE _68 _59 _40 000020170020 Teplota toku vzduchu
C0 200 200 __0 000000000046 Počet vypnutí disku
C1 194 194 __0 000000004E6A Počet cyklů načítání/vymazání
C2 111 102 __0 000000000020 Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 200 200 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 200 200 __0 000000000000 Počet chyb při zápisu sektorů

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5743 4336 5A35 4345 594E 464B
020: 0000 FFFF 0000 3031 2E30 3141 3031 5744 4320 5744
030: 3530 3030 415A 4C58 2D36 304B 3254 4130 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4001 0000 0000 0006 3FFF 0010 003F FC10 00FB 5110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 2D08
070: 0000 0000 0000 0000 0000 001F 850E 0006 00CC 0040
080: 07FE 006D 706B 7C29 6123 7069 BC09 6123 203F 8020
090: 8020 0080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6030 3A38 0000 0000 0000 0000 6003 0000 5001 4EE2
110: 113F BD5D 0000 0000 0000 0000 0000 0000 0000 40DC
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0002 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 303D 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 1C20 0000 0000
220: 0000 0000 107E 0000 0000 0000 0000 0000 0000 0000
230: 6030 3A38 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 E8A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 AD AC 15 09 00 00 00 00 00 04 32 00 5E 5E DF
020: 1A 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2F 00 64 FD 00 00 00 00 00 00 00 09 32
040: 00 59 59 DD 21 00 00 00 00 00 0A 33 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 63 63 24 07 00 00 00 00 00 B7 32
070: 00 64 64 00 00 00 00 00 00 00 B8 33 00 64 64 00
080: 00 00 00 00 00 00 BB 32 00 64 64 00 00 00 00 00
090: 00 00 BC 32 00 64 64 00 00 00 00 00 00 00 BE 22
0A0: 00 44 3B 20 00 17 20 00 00 00 C0 32 00 C8 C8 46
0B0: 00 00 00 00 00 00 C1 32 00 C2 C2 6A 4E 00 00 00
0C0: 00 00 C2 22 00 6F 66 20 00 00 00 00 00 00 C4 32
0D0: 00 C8 C8 00 00 00 00 00 00 00 C5 32 00 C8 C8 00
0E0: 00 00 00 00 00 00 C6 30 00 C8 C8 00 00 00 00 00
0F0: 00 00 C7 32 00 C8 C8 00 00 00 00 00 00 00 C8 08
100: 00 C8 C8 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 82 00 80 16 01 5B
170: 03 00 01 00 02 3E 00 00 00 00 00 00 00 00 00 00
180: 00 00 01 01 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 96

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 00 00 00 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 33 64 00 00 00 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 33 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 B7 00
070: 00 00 00 00 00 00 00 00 00 00 B8 61 00 00 00 00
080: 00 00 00 00 00 00 BB 00 00 00 00 00 00 00 00 00
090: 00 00 BC 00 00 00 00 00 00 00 00 00 00 00 BE 28
0A0: 00 00 00 00 00 00 00 00 00 00 C0 00 00 00 00 00
0B0: 00 00 00 00 00 00 C1 00 00 00 00 00 00 00 00 00
0C0: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C4 00
0D0: 00 00 00 00 00 00 00 00 00 00 C5 00 00 00 00 00
0E0: 00 00 00 00 00 00 C6 00 00 00 00 00 00 00 00 00
0F0: 00 00 C7 00 00 00 00 00 00 00 00 00 00 00 C8 00
100: C8 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 82 00 80 16 01 5B
170: 03 00 01 00 02 3E 00 00 00 00 00 00 00 00 00 00
180: 00 00 01 01 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 7C

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod jaro3 » 31 srp 2023 14:56

Jsou problémy?

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
https://downloads.malwarebytes.com/file/JRT-EOL
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dlouho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si ATF Cleaner
https://www.majorgeeks.com/mg/getmirror ... ner,2.html
Poklepej na ATF Cleaner.exe, klikni na select all, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome ,Edge , tak ATF nemusíš použít.


Stáhni si TFC
http://www.geekstogo.com/forum/files/fi ... -oldtimer/
https://www.bleepingcomputer.com/download/tfc/
https://www.majorgeeks.com/files/detail ... eaner.html
https://www.majorgeeks.com/mg/get/temp_ ... ner,1.html

Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni si RogueKiller by Adlice Software
http://www.adlice.com/download/roguekiller/
http://www.bleepingcomputer.com/download/roguekiller/
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- - klikni na „Scan“. V novém okně nic neměň a klikni dole na „Start“ ve sloupci „Quick Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Results “ , v dalším okně pak levým t. na „Report“ a vyber : „Text File“ , log nazvi třeba RK a ulož do dokumentů nebo na plochu. Otevři soubor a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Luk4579
Level 1
Level 1
Příspěvky: 84
Registrován: červen 23
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod Luk4579 » 31 srp 2023 14:59

Někdy se stránky načítají pomalu, restart modemu proběhl.

Uživatelský avatar
Luk4579
Level 1
Level 1
Příspěvky: 84
Registrován: červen 23
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod Luk4579 » 31 srp 2023 15:15

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Enterprise x64
Ran by lukin (Administrator) on 31.08.2023 at 15:01:48,58
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 1

Successfully deleted: C:\Users\lukin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\facebook.lnk (Shortcut)



Registry: 2

Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 31.08.2023 at 15:02:37,26
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
Luk4579
Level 1
Level 1
Příspěvky: 84
Registrován: červen 23
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod Luk4579 » 31 srp 2023 15:21

r o g r a m : R o g u e K i l l e r A n t i - M a l w a r e

V e r s i o n : 1 5 . 1 2 . 0 . 0

x 6 4 : Y e s

P r o g r a m D a t e : A u g 2 9 2 0 2 3

L o c a t i o n : C : \ P r o g r a m F i l e s \ R o g u e K i l l e r \ R o g u e K i l l e r 6 4 . e x e

P r e m i u m : N o

C o m p a n y : A d l i c e S o f t w a r e

W e b s i t e : h t t p s : / / w w w . a d l i c e . c o m /

C o n t a c t : h t t p s : / / a d l i c e . c o m / c o n t a c t /

W e b s i t e : h t t p s : / / a d l i c e . c o m / d o w n l o a d / r o g u e k i l l e r /

O p e r a t i n g S y s t e m : W i n d o w s 1 1 ( 1 0 . 0 . 2 2 6 2 1 ) 6 4 - b i t

6 4 - b i t O S : Y e s

S t a r t u p : 0

W i n d o w s P E : N o

U s e r : l u k i n

U s e r i s A d m i n : Y e s

D a t e : 2 0 2 3 / 0 8 / 3 1 1 3 : 2 0 : 0 1

T y p e : S c a n

A b o r t e d : N o

S c a n M o d e : Q u i c k

D u r a t i o n : 6

F o u n d i t e m s : 0

T o t a l s c a n n e d : 9 2 0

S i g n a t u r e s V e r s i o n : 2 0 2 3 0 8 2 8 _ 0 7 3 9 1 3

T r u e s i g h t D r i v e r : Y e s

U p d a t e s C o u n t : 0

A r g u m e n t s : - m i n i m i z e



* * * * * * * * * * * * * * * * * * * * * * * * * W a r n i n g s * * * * * * * * * * * * * * * * * * * * * * * * *



* * * * * * * * * * * * * * * * * * * * * * * * * P r o c e s s e s * * * * * * * * * * * * * * * * * * * * * * * * *



* * * * * * * * * * * * * * * * * * * * * * * * * M o d u l e s * * * * * * * * * * * * * * * * * * * * * * * * *



* * * * * * * * * * * * * * * * * * * * * * * * * S e r v i c e s * * * * * * * * * * * * * * * * * * * * * * * * *



* * * * * * * * * * * * * * * * * * * * * * * * * S c h e d u l e d T a s k s * * * * * * * * * * * * * * * * * * * * * * * * *



* * * * * * * * * * * * * * * * * * * * * * * * * R e g i s t r y * * * * * * * * * * * * * * * * * * * * * * * * *



* * * * * * * * * * * * * * * * * * * * * * * * * W M I * * * * * * * * * * * * * * * * * * * * * * * * *



* * * * * * * * * * * * * * * * * * * * * * * * * H o s t s F i l e * * * * * * * * * * * * * * * * * * * * * * * * *

i s _ t o o _ b i g : N o

h o s t s _ f i l e _ p a t h : N / A





* * * * * * * * * * * * * * * * * * * * * * * * * F i l e s y s t e m * * * * * * * * * * * * * * * * * * * * * * * * *



* * * * * * * * * * * * * * * * * * * * * * * * * W e b B r o w s e r s * * * * * * * * * * * * * * * * * * * * * * * * *



* * * * * * * * * * * * * * * * * * * * * * * * * A n t i r o o t k i t * * * * * * * * * * * * * * * * * * * * * * * * *

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod jaro3 » 31 srp 2023 17:07

ATF a TFC provedeny?

Vypni antivir i firewall, RogueKiller, Malwarebytes Antimalware, windowsDefender
Stáhni zoek:
https://uloz.to/file/nFH1LwSrGioP/zoek1-rar

Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;

klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log Zkopíruj sem celý obsah toho logu.
Pokud budou problémy , spusť zoek v nouz. režimu.

Stáhni si Zemana AntiMalware Free z tohoto odkazu:
https://www.zemana.com/Download/AntiMal ... .Setup.exe

(posuvník dolu na download)
a ulož si ho na plochu.
Poklepej na tento soubor na ploše a postupuj podle pokynů k instalaci programu.
Přijmi licenci k používání programu EULA , pokud se nabídne.
Pokud je k dispozici aktualizace programu , klepni na tlačítko „Update now“ ( aktualizovat nyní).
Zavři všechny otevřené soubory, složky a prohlížeče
Neměň žádné nastavení. Klikni na „Skenovat nyní“.
Po skenu lze vidět , zda jsou nějaké nákazy. Klikni na „Vykonat“ ( vymazat). Nákazy budou přemístěny do karantény.
Když je skenování dokončeno, klikni vlevo na „zprávy“ a pak na „otevři zprávu“ a zkopíruj sem celý obsah té zprávy.

Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Luk4579
Level 1
Level 1
Příspěvky: 84
Registrován: červen 23
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod Luk4579 » 31 srp 2023 19:42

Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by lukin on 31.08.2023 at 19:33:09,57.
Microsoft Windows 11 Pro 10.0.22621 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\lukin\Downloads\zoek1\zoek1\zoek (1).exe [Scan all users] [Script inserted]

===== Runcheck 19:33:27,02 =====

--- Create Environment Variables 19:33:27,74
--- Create System Restore Point 19:33:41,86
--- Checking Input 19:33:47,68
--- Reset Hosts File 19:34:02,28
--- AU AppData Check 19:34:02,65
--- Remove From Windows Installer 19:34:03,76
--- Empty Folders Check 19:35:06,54
--- Registry HKLM Software Check 19:35:06,55
--- Quick Launch Shortcut Check 19:35:13,90
--- IE Startpage Check 19:35:16,75
--- Program Files DB Check 19:35:32,15
--- C:\Users\Default\AppData\Roaming DB Check 19:36:02,14
--- C:\Users\Default User\AppData\Roaming DB Check 19:36:02,14
--- C:\Users\lukin\AppData\Roaming DB Check 19:36:02,14
--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 19:36:02,14
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 19:36:02,14
--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 19:36:02,14
--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 19:36:02,14
--- C:\Users\lukin DB Check 19:37:33,85
--- C:\PROGRA~3 DB Check 19:37:45,12

Uživatelský avatar
Luk4579
Level 1
Level 1
Příspěvky: 84
Registrován: červen 23
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod Luk4579 » 31 srp 2023 19:43

ATF a TFC, provedeny

Uživatelský avatar
Luk4579
Level 1
Level 1
Příspěvky: 84
Registrován: červen 23
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod Luk4579 » 31 srp 2023 20:12

Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by lukin on 31.08.2023 at 19:33:09,57.
Microsoft Windows 11 Pro 10.0.22621 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\lukin\Downloads\zoek1\zoek1\zoek (1).exe [Scan all users] [Script inserted]

==== System Restore Info ======================

31.08.2023 19:33:47 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\Users\lukin\AppData\Local\DBG deleted successfully
C:\Users\lukin\AppData\Local\PeerDistRepub deleted successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\PeerDistPub deleted successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\PeerDistRepub deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~3\Package Cache deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\CM2D483.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd12e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd130.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd132.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd134.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd146.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd148.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd14a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd14c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd14e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd15f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd161.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd163.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd165.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd167.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd169.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd17b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd17d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd17f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd181.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd183.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd185.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd197.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1084-2910-cd199.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35ae.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35b0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35c2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35c4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35c6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35c8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35ca.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35dc.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35de.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35e0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35e2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35e4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35e6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35f7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35f9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35fb.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35fd.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b35ff.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b3601.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b3613.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b3615.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b3617.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-128c-2e78-b3619.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe6cd.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe6df.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe6e1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe6e3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe6e5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe6e7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe6f8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe6fa.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe6fc.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe6fe.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe700.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe702.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe714.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe735.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe737.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe739.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe73b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe74d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe74f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe751.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe753.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe755.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1390-2358-1fe757.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b866e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b8680.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b8682.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b8684.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86a5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86a7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86a9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86ab.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86ad.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86ce.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86d0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86d2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86d4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86d6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86d8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86ea.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86ec.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86ee.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86f0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86f2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b86f4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b8706.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1398-21a4-b8708.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4de7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4de9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4deb.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4ded.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4dff.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e01.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e03.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e14.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e16.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e28.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e39.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e3b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e3d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e3f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e41.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e53.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e55.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e57.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e59.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e5b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e6d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e6f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1430-d5c-1c4e71.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-28172d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-28172f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281731.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281733.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281744.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281746.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281748.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-28174a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-28174c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-28174e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281760.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281762.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281764.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281766.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281768.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-28176a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-28177c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-28177e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281780.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281782.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281784.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281786.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-148-3540-281797.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb312.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb323.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb325.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb327.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb329.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb32b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb32d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb34f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb351.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb353.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb355.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb357.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb368.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-14a0-343c-2eb36a.tmp deleted


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 26 hostů