Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

kontrola pc

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
zail
Návštěvník
Návštěvník
Příspěvky: 118
Registrován: 19 pro 2005 15:28

Re: kontrola pc

#16 Příspěvek od zail »

Fix result of Farbar Recovery Scan Tool (x64) Version: 17.02.2018
Ran by lukas_000 (19-02-2018 15:47:43) Run:2
Running from C:\Users\lukas_000\Desktop
Loaded Profiles: lukas_000 (Available Profiles: lukas_000)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\lukas_000\AppData\Local\Temp
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
IFEO\backitup.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\cdspeed.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\coverdes.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\drivespeed.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\dtagent.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\dtlauncher.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\epsdnavi.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\excel.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\infotool.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\msaccess.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\msouc.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\mspub.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\nero.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\neroburnrights.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\nerohome.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\neromediahome.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\neroscoutoptions.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\nerostartsmart.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\nerovision.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\onenote.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\onenotem.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\outlook.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\photosnap.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\photosnapviewer.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\powerpnt.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\recode.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\setlang.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\setupneromobile.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\setupx.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\showtime.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\soundtrax.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\teamviewer.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\waveedit.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\wbfsmanager.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\winword.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
Toolbar: HKLM - No Name - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - No File
Toolbar: HKLM-x32 - No Name - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - No File
Task: {30F5F149-5E0F-426C-BECF-102524B7DD2D} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {4D592FEF-CC54-4D03-A34D-D580186879CB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-03] (Google Inc.)
Task: {81CAE846-613E-4644-B550-7E037E3C3697} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {85E5B9C8-12C5-40D5-8FA2-7F196B52472F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {A5D637BA-6F37-4B8F-ABD0-78D93F933F10} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION

EmptyTemp:
End
*****************

Processes closed successfully.
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
C:\Users\lukas_000\AppData\Local\Temp => moved successfully
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\backitup.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cdspeed.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\coverdes.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\drivespeed.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dtagent.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dtlauncher.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\epsdnavi.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\excel.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\infotool.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msaccess.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msouc.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mspub.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\nero.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\neroburnrights.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\nerohome.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\neromediahome.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\neroscoutoptions.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\nerostartsmart.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\nerovision.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\onenote.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\onenotem.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\outlook.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\photosnap.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\photosnapviewer.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\powerpnt.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\recode.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\setlang.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\setupneromobile.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\setupx.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\showtime.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\soundtrax.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\teamviewer.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\waveedit.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wbfsmanager.exe" => removed successfully
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\winword.exe" => removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{4BAAC1B8-0800-42C9-8FA6-08B211F356B8}" => removed successfully
HKLM\Software\Classes\CLSID\{4BAAC1B8-0800-42C9-8FA6-08B211F356B8} => key not found
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{4BAAC1B8-0800-42C9-8FA6-08B211F356B8}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{4BAAC1B8-0800-42C9-8FA6-08B211F356B8} => key not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{30F5F149-5E0F-426C-BECF-102524B7DD2D} => could not remove key. ErrorCode1: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{30F5F149-5E0F-426C-BECF-102524B7DD2D} => could not remove key. ErrorCode1: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => could not remove key. ErrorCode1: 0x00000001
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4D592FEF-CC54-4D03-A34D-D580186879CB}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4D592FEF-CC54-4D03-A34D-D580186879CB}" => removed successfully
"C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{81CAE846-613E-4644-B550-7E037E3C3697}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81CAE846-613E-4644-B550-7E037E3C3697}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{85E5B9C8-12C5-40D5-8FA2-7F196B52472F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85E5B9C8-12C5-40D5-8FA2-7F196B52472F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A5D637BA-6F37-4B8F-ABD0-78D93F933F10}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A5D637BA-6F37-4B8F-ABD0-78D93F933F10}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 35155341 B
Java, Flash, Steam htmlcache => 12699099 B
Windows/system/drivers => 46808301 B
Edge => 9719 B
Chrome => 756143956 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 4898 B
NetworkService => 0 B
lukas_000 => 6688064 B

RecycleBin => 9880326 B
EmptyTemp: => 837.2 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 19-02-2018 15:48:47)


Result of scheduled keys to remove after reboot:

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{30F5F149-5E0F-426C-BECF-102524B7DD2D}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{30F5F149-5E0F-426C-BECF-102524B7DD2D}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => key removed successfully

==== End of Fixlog 15:48:47 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118270
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: kontrola pc

#17 Příspěvek od Rudy »

Smazáno, log je již OK. Nastala nějaká zmněa?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

zail
Návštěvník
Návštěvník
Příspěvky: 118
Registrován: 19 pro 2005 15:28

Re: kontrola pc

#18 Příspěvek od zail »

dekuji, vypada to ze je vse v poradku.
Co tam byl za problem

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118270
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: kontrola pc

#19 Příspěvek od Rudy »

Převážně zbytečnosti.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět