

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Extréemne pomalé vypínanie
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Extréemne pomalé vypínanie
Já Vám napíšu skript zítra, dnes už na to nevidím 

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Extréemne pomalé vypínanie
Jasné, v phoode : ďakujem... ps dala som fix, a tu je log z fixu
Error: Unable to interpret <HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s> in the current context!
Error: Unable to interpret </md5start> in the current context!
Error: Unable to interpret <cngaudit.dll> in the current context!
Error: Unable to interpret <cryptsvc.dll> in the current context!
Error: Unable to interpret <eNetHook.dll> in the current context!
Error: Unable to interpret <eventlog.dll> in the current context!
Error: Unable to interpret <hal.dll> in the current context!
Error: Unable to interpret <logevent.dll> in the current context!
Error: Unable to interpret <netlogon.dll> in the current context!
Error: Unable to interpret <ntelogon.dll> in the current context!
Error: Unable to interpret <scecli.dll> in the current context!
Error: Unable to interpret <sceclt.dll> in the current context!
Error: Unable to interpret <ws2_32.dll> in the current context!
Error: Unable to interpret <autochk.exe> in the current context!
Error: Unable to interpret <csrss.exe> in the current context!
Error: Unable to interpret <explorer.exe> in the current context!
Error: Unable to interpret <lsass.exe> in the current context!
Error: Unable to interpret <services.exe> in the current context!
Error: Unable to interpret <smss.exe> in the current context!
Error: Unable to interpret <spoolsv.exe> in the current context!
Error: Unable to interpret <svchost.exe> in the current context!
Error: Unable to interpret <userinit.exe> in the current context!
Error: Unable to interpret <winlogon.exe> in the current context!
Error: Unable to interpret <adp3132.sys> in the current context!
Error: Unable to interpret <AGP440.sys> in the current context!
Error: Unable to interpret <ahcix86.sys> in the current context!
Error: Unable to interpret <ahcix86s.sys> in the current context!
Error: Unable to interpret <atapi.sys> in the current context!
Error: Unable to interpret <cdrom.sys> in the current context!
Error: Unable to interpret <Changer.sys> in the current context!
Error: Unable to interpret <fastfat.sys> in the current context!
Error: Unable to interpret <iaStor.sys> in the current context!
Error: Unable to interpret <iastorv.sys> in the current context!
Error: Unable to interpret <IdeChnDr.sys> in the current context!
Error: Unable to interpret <isapnp.sys> in the current context!
Error: Unable to interpret <JakNDis.sys> in the current context!
Error: Unable to interpret <KR10N.sys> in the current context!
Error: Unable to interpret <mv61xx.sys> in the current context!
Error: Unable to interpret <ndis.sys> in the current context!
Error: Unable to interpret <ntfs.sys> in the current context!
Error: Unable to interpret <nvata.sys> in the current context!
Error: Unable to interpret <nvatabus.sys> in the current context!
Error: Unable to interpret <nvgts.sys> in the current context!
Error: Unable to interpret <nvraid.sys> in the current context!
Error: Unable to interpret <nvrd32.sys> in the current context!
Error: Unable to interpret <nvstor.sys> in the current context!
Error: Unable to interpret <nvstor32.sys> in the current context!
Error: Unable to interpret <symmpi.sys> in the current context!
Error: Unable to interpret <tcpip.sys> in the current context!
Error: Unable to interpret <vaxscsi.sys> in the current context!
Error: Unable to interpret <viamraid.sys> in the current context!
Error: Unable to interpret <viasraid.sys> in the current context!
Error: Unable to interpret <ViPrt.sys> in the current context!
Error: Unable to interpret </md5stop> in the current context!
Error: Unable to interpret <C:\windows\system32\spool\prtprocs|dll;true;true;true /FP> in the current context!
Error: Unable to interpret <%systemroot%\system32\drivers\*.sys /5> in the current context!
Error: Unable to interpret <%systemroot%\system32\drivers\*.sys /X> in the current context!
Error: Unable to interpret <%systemroot%\system32\drivers\*.sys /lockedfiles> in the current context!
Error: Unable to interpret <%systemroot%\system32\*.* /5> in the current context!
Error: Unable to interpret <%systemroot%\system32\*.dll /lockedfiles> in the current context!
Error: Unable to interpret <%systemroot%\system32\config\*.sav> in the current context!
Error: Unable to interpret <%systemroot%\Tasks\*.job /lockedfiles> in the current context!
Error: Unable to interpret <%systemroot%\*.* /U /s> in the current context!
Error: Unable to interpret <%systemroot%\*. /mp /s> in the current context!
Error: Unable to interpret <%ALLUSERSPROFILE%\Data Aplikací\*.*> in the current context!
Error: Unable to interpret <%ALLUSERSPROFILE%\Data Aplikací\*.exe /s> in the current context!
Error: Unable to interpret <%ALLUSERSPROFILE%\Dáta aplikácií\*.*> in the current context!
Error: Unable to interpret <%ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s> in the current context!
Error: Unable to interpret <%APPDATA%\*.> in the current context!
Error: Unable to interpret <%APPDATA%\*.*> in the current context!
Error: Unable to interpret <%APPDATA%\*.exe /s> in the current context!
Error: Unable to interpret <%SYSTEMDRIVE%\*.exe> in the current context!
Error: Unable to interpret <HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s> in the current context!
Error: Unable to interpret <HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs> in the current context!
Error: Unable to interpret <HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS /s> in the current context!
Error: Unable to interpret <reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c> in the current context!
Error: Unable to interpret <reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c> in the current context!
Error: Unable to interpret <reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c> in the current context!
Error: Unable to interpret <reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c> in the current context!
Error: Unable to interpret <reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c> in the current context!
Error: Unable to interpret <type c:\boot.ini >> test.txt /c> in the current context!
Error: Unable to interpret <%SystemDrive%\PhysicalMBR.bin /md5 > in the current context!
OTL by OldTimer - Version 3.2.26.1 log created on 07212011_233240
Error: Unable to interpret <HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s> in the current context!
Error: Unable to interpret </md5start> in the current context!
Error: Unable to interpret <cngaudit.dll> in the current context!
Error: Unable to interpret <cryptsvc.dll> in the current context!
Error: Unable to interpret <eNetHook.dll> in the current context!
Error: Unable to interpret <eventlog.dll> in the current context!
Error: Unable to interpret <hal.dll> in the current context!
Error: Unable to interpret <logevent.dll> in the current context!
Error: Unable to interpret <netlogon.dll> in the current context!
Error: Unable to interpret <ntelogon.dll> in the current context!
Error: Unable to interpret <scecli.dll> in the current context!
Error: Unable to interpret <sceclt.dll> in the current context!
Error: Unable to interpret <ws2_32.dll> in the current context!
Error: Unable to interpret <autochk.exe> in the current context!
Error: Unable to interpret <csrss.exe> in the current context!
Error: Unable to interpret <explorer.exe> in the current context!
Error: Unable to interpret <lsass.exe> in the current context!
Error: Unable to interpret <services.exe> in the current context!
Error: Unable to interpret <smss.exe> in the current context!
Error: Unable to interpret <spoolsv.exe> in the current context!
Error: Unable to interpret <svchost.exe> in the current context!
Error: Unable to interpret <userinit.exe> in the current context!
Error: Unable to interpret <winlogon.exe> in the current context!
Error: Unable to interpret <adp3132.sys> in the current context!
Error: Unable to interpret <AGP440.sys> in the current context!
Error: Unable to interpret <ahcix86.sys> in the current context!
Error: Unable to interpret <ahcix86s.sys> in the current context!
Error: Unable to interpret <atapi.sys> in the current context!
Error: Unable to interpret <cdrom.sys> in the current context!
Error: Unable to interpret <Changer.sys> in the current context!
Error: Unable to interpret <fastfat.sys> in the current context!
Error: Unable to interpret <iaStor.sys> in the current context!
Error: Unable to interpret <iastorv.sys> in the current context!
Error: Unable to interpret <IdeChnDr.sys> in the current context!
Error: Unable to interpret <isapnp.sys> in the current context!
Error: Unable to interpret <JakNDis.sys> in the current context!
Error: Unable to interpret <KR10N.sys> in the current context!
Error: Unable to interpret <mv61xx.sys> in the current context!
Error: Unable to interpret <ndis.sys> in the current context!
Error: Unable to interpret <ntfs.sys> in the current context!
Error: Unable to interpret <nvata.sys> in the current context!
Error: Unable to interpret <nvatabus.sys> in the current context!
Error: Unable to interpret <nvgts.sys> in the current context!
Error: Unable to interpret <nvraid.sys> in the current context!
Error: Unable to interpret <nvrd32.sys> in the current context!
Error: Unable to interpret <nvstor.sys> in the current context!
Error: Unable to interpret <nvstor32.sys> in the current context!
Error: Unable to interpret <symmpi.sys> in the current context!
Error: Unable to interpret <tcpip.sys> in the current context!
Error: Unable to interpret <vaxscsi.sys> in the current context!
Error: Unable to interpret <viamraid.sys> in the current context!
Error: Unable to interpret <viasraid.sys> in the current context!
Error: Unable to interpret <ViPrt.sys> in the current context!
Error: Unable to interpret </md5stop> in the current context!
Error: Unable to interpret <C:\windows\system32\spool\prtprocs|dll;true;true;true /FP> in the current context!
Error: Unable to interpret <%systemroot%\system32\drivers\*.sys /5> in the current context!
Error: Unable to interpret <%systemroot%\system32\drivers\*.sys /X> in the current context!
Error: Unable to interpret <%systemroot%\system32\drivers\*.sys /lockedfiles> in the current context!
Error: Unable to interpret <%systemroot%\system32\*.* /5> in the current context!
Error: Unable to interpret <%systemroot%\system32\*.dll /lockedfiles> in the current context!
Error: Unable to interpret <%systemroot%\system32\config\*.sav> in the current context!
Error: Unable to interpret <%systemroot%\Tasks\*.job /lockedfiles> in the current context!
Error: Unable to interpret <%systemroot%\*.* /U /s> in the current context!
Error: Unable to interpret <%systemroot%\*. /mp /s> in the current context!
Error: Unable to interpret <%ALLUSERSPROFILE%\Data Aplikací\*.*> in the current context!
Error: Unable to interpret <%ALLUSERSPROFILE%\Data Aplikací\*.exe /s> in the current context!
Error: Unable to interpret <%ALLUSERSPROFILE%\Dáta aplikácií\*.*> in the current context!
Error: Unable to interpret <%ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s> in the current context!
Error: Unable to interpret <%APPDATA%\*.> in the current context!
Error: Unable to interpret <%APPDATA%\*.*> in the current context!
Error: Unable to interpret <%APPDATA%\*.exe /s> in the current context!
Error: Unable to interpret <%SYSTEMDRIVE%\*.exe> in the current context!
Error: Unable to interpret <HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s> in the current context!
Error: Unable to interpret <HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs> in the current context!
Error: Unable to interpret <HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS /s> in the current context!
Error: Unable to interpret <reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c> in the current context!
Error: Unable to interpret <reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c> in the current context!
Error: Unable to interpret <reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c> in the current context!
Error: Unable to interpret <reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c> in the current context!
Error: Unable to interpret <reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c> in the current context!
Error: Unable to interpret <type c:\boot.ini >> test.txt /c> in the current context!
Error: Unable to interpret <%SystemDrive%\PhysicalMBR.bin /md5 > in the current context!
OTL by OldTimer - Version 3.2.26.1 log created on 07212011_233240
Re: Extréemne pomalé vypínanie


Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Extréemne pomalé vypínanie
hups...
) dá sa to napravit? 


Re: Extréemne pomalé vypínanie
Ono se nic neprovedlo, takže teď jdeme teprve mazat
Spustte OTL
-do bílého okna dole skopírujte tento skript:
-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde


-do bílého okna dole skopírujte tento skript:
Kód: Vybrat vše
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
@Alternate Data Stream - 232 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 184 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:A8ADE5D8
:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\ProgramData\ezsidmv.dat
C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
C:\ProgramData\AVG10
:commands
[resethosts]
[emptytemp]
[EMPTYFLASH]
[clearallrestorepoints]
[Reboot]
-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Extréemne pomalé vypínanie
A kde nájdem ten script? na céčku? a neviete mi povedať aký má názov? 

Re: Extréemne pomalé vypínanie
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
ADS C:\ProgramData\Temp:0B4227B4 deleted successfully.
ADS C:\ProgramData\Temp:DFC5A2B2 deleted successfully.
ADS C:\ProgramData\Temp:430C6D84 deleted successfully.
ADS C:\ProgramData\Temp:A8ADE5D8 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9202.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9D9.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9E41.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPAADF.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAP1248.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAPA562.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAPB405.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAPCA04.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE291.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE56E.tmp folder moved successfully.
C:\WINDOWS\Installer\MSID8F5.tmp moved successfully.
C:\WINDOWS\temp\Cab32B3.tmp moved successfully.
C:\WINDOWS\temp\CabC8CA.tmp moved successfully.
C:\WINDOWS\temp\Tar32C3.tmp moved successfully.
C:\WINDOWS\temp\TarC8EA.tmp moved successfully.
C:\WINDOWS\temp\~DF68D7974CCBD81FEA.TMP moved successfully.
C:\ProgramData\ezsidmv.dat moved successfully.
C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 moved successfully.
C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 moved successfully.
C:\ProgramData\AVG10\Cfg folder moved successfully.
C:\ProgramData\AVG10 folder moved successfully.
========== COMMANDS ==========
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes
User: Default User
User: katka
->Temp folder emptied: 2352 bytes
->Temporary Internet Files folder emptied: 336138 bytes
->Google Chrome cache emptied: 8592248 bytes
->Flash cache emptied: 343 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 109737997 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50520 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 113.00 mb
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: katka
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0.00 mb
Restore point Set: OTL Restore Point
OTL by OldTimer - Version 3.2.26.1 log created on 07222011_122013
Files\Folders moved on Reboot...
C:\Users\katka\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot...
========== OTL ==========
No active process named explorer.exe was found!
ADS C:\ProgramData\Temp:0B4227B4 deleted successfully.
ADS C:\ProgramData\Temp:DFC5A2B2 deleted successfully.
ADS C:\ProgramData\Temp:430C6D84 deleted successfully.
ADS C:\ProgramData\Temp:A8ADE5D8 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9202.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9D9.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9E41.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPAADF.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAP1248.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAPA562.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAPB405.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAPCA04.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE291.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE56E.tmp folder moved successfully.
C:\WINDOWS\Installer\MSID8F5.tmp moved successfully.
C:\WINDOWS\temp\Cab32B3.tmp moved successfully.
C:\WINDOWS\temp\CabC8CA.tmp moved successfully.
C:\WINDOWS\temp\Tar32C3.tmp moved successfully.
C:\WINDOWS\temp\TarC8EA.tmp moved successfully.
C:\WINDOWS\temp\~DF68D7974CCBD81FEA.TMP moved successfully.
C:\ProgramData\ezsidmv.dat moved successfully.
C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 moved successfully.
C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 moved successfully.
C:\ProgramData\AVG10\Cfg folder moved successfully.
C:\ProgramData\AVG10 folder moved successfully.
========== COMMANDS ==========
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes
User: Default User
User: katka
->Temp folder emptied: 2352 bytes
->Temporary Internet Files folder emptied: 336138 bytes
->Google Chrome cache emptied: 8592248 bytes
->Flash cache emptied: 343 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 109737997 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50520 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 113.00 mb
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: katka
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0.00 mb
Restore point Set: OTL Restore Point
OTL by OldTimer - Version 3.2.26.1 log created on 07222011_122013
Files\Folders moved on Reboot...
C:\Users\katka\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot...
Re: Extréemne pomalé vypínanie
Copak dělá počítač? 

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Extréemne pomalé vypínanie
Zase sekal...a ešte k tomu mi napísalo že mám nelegálny windows ( počítač som kupoval z alzy aj s windowsom tak já neviem xD)
vičistím ho combofixom nech zmaže aspoň ten jeden vírus a zanesiem do servisu u nás v meste
vičistím ho combofixom nech zmaže aspoň ten jeden vírus a zanesiem do servisu u nás v meste

Re: Extréemne pomalé vypínanie
Tak ho reklamujte, určitě bych se v Alze na tu legálnost zeptala
Tak sem hodte ještě ten combofix,ale tím to asi nebude.

Tak sem hodte ještě ten combofix,ale tím to asi nebude.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Extréemne pomalé vypínanie
ComboFix 11-07-20.02 - katka . 07. 2011 13:28:53.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.4091.2761 [GMT 2:00]
Running from: c:\users\katka\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Outdated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Outdated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\s.bat
.
.
((((((((((((((((((((((((( Files Created from 2011-06-22 to 2011-07-22 )))))))))))))))))))))))))))))))
.
.
2011-07-22 11:40 . 2011-07-22 11:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-20 18:57 . 2011-07-21 14:13 -------- d-----w- c:\program files (x86)\CrystalDiskInfo
2011-07-20 15:57 . 2011-07-20 15:57 -------- d-----w- c:\users\katka\AppData\Roaming\Malwarebytes
2011-07-20 15:57 . 2011-07-20 15:57 -------- d-----w- c:\programdata\Malwarebytes
2011-07-20 15:57 . 2010-11-29 15:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-20 13:45 . 2011-07-20 13:50 -------- d-----w- c:\users\katka\AppData\Roaming\PCStitch Pro
2011-07-19 22:27 . 2011-07-19 22:27 -------- d-----w- c:\program files\trend micro
2011-07-18 19:12 . 2011-07-18 19:13 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2011-07-15 11:27 . 2011-07-15 11:27 -------- d-----w- c:\users\katka\AppData\Roaming\Atari
2011-07-15 11:09 . 2011-07-15 11:09 -------- d-----w- c:\program files (x86)\Atari
2011-07-15 11:09 . 2005-04-03 21:00 184320 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2011-07-15 11:09 . 2005-04-03 21:00 63488 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2011-07-15 11:08 . 2011-07-15 11:08 200836 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2011-07-15 11:08 . 2005-04-03 21:02 753664 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2011-07-15 11:08 . 2005-04-03 21:02 69714 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2011-07-15 11:08 . 2005-04-03 21:01 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2011-07-15 11:08 . 2005-04-03 20:59 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2011-07-15 11:08 . 2011-07-15 11:08 331908 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2011-07-07 23:39 . 2011-07-07 23:39 -------- d-----w- c:\programdata\Microsoft Help
2011-07-07 23:39 . 2011-07-07 23:39 -------- d-----w- c:\users\katka\AppData\Local\Microsoft Help
2011-07-07 22:17 . 2011-07-07 22:17 458048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-07-02 21:07 . 2011-07-02 21:07 -------- d--h--w- c:\programdata\Common Files
2011-07-02 21:06 . 2011-07-22 10:45 -------- d-----w- c:\programdata\AVG10
2011-07-02 07:39 . 2011-07-02 07:39 233488 ----a-w- c:\windows\system32\drivers\PCTCore64.sys
2011-07-02 07:33 . 2010-01-22 07:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-07-02 07:33 . 2010-01-22 07:55 767952 ----a-w- c:\windows\BDTSupport.dll
2011-07-02 07:33 . 2010-01-22 07:56 165840 ----a-w- c:\windows\PCTBDRes.dll
2011-07-02 07:33 . 2010-01-22 07:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
2011-07-02 07:24 . 2010-02-05 07:18 133072 ----a-w- c:\windows\system32\drivers\pctwfpfilter64.sys
2011-07-02 07:24 . 2010-02-05 07:17 306648 ----a-w- c:\windows\system32\drivers\pctgntdi64.sys
2011-07-02 07:23 . 2011-07-02 07:39 92896 ----a-w- c:\windows\system32\drivers\pctplsg64.sys
2011-07-02 07:23 . 2011-07-03 17:07 -------- d-----w- c:\program files (x86)\Spyware Doctor
2011-07-01 20:28 . 2011-07-03 11:45 -------- d-----w- c:\program files (x86)\Common Files\PC Tools
2011-07-01 20:28 . 2011-07-01 20:43 -------- d-----w- c:\programdata\PC Tools
2011-07-01 20:28 . 2011-07-01 20:28 -------- d-----w- c:\users\katka\AppData\Roaming\PC Tools
2011-06-30 12:25 . 2011-06-30 12:25 -------- d-----w- C:\output
2011-06-28 21:18 . 2011-07-14 08:25 -------- d-----w- c:\users\katka\AppData\Roaming\QuickScan
2011-06-28 08:10 . 2011-07-03 11:44 -------- d-----w- C:\676a689354ac6d7d82a6486bd7ce4f75
2011-06-24 18:41 . 2011-07-03 11:44 -------- d-----w- c:\program files (x86)\ESET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-07 22:17 . 2011-06-04 09:40 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2011-06-25 13:57 . 2010-08-27 23:37 655360 ----a-w- c:\windows\SysWow64\vmprp331.ax
2011-06-25 13:57 . 2010-08-28 00:12 1171456 ----a-w- c:\windows\SysWow64\PicNotify.dll
2011-06-25 13:57 . 2010-08-27 23:21 274432 ----a-w- c:\windows\SysWow64\Oemdspif.dll
2011-06-25 13:57 . 2010-08-28 00:12 77824 ----a-w- c:\windows\SysWow64\ILU.dll
2011-06-25 13:57 . 2010-08-28 00:12 32768 ----a-w- c:\windows\SysWow64\ILUT.dll
2011-06-25 13:57 . 2009-07-13 21:59 2531328 ----a-w- c:\windows\SysWow64\igd10umd32.dll
2011-06-25 13:57 . 2009-07-13 21:59 3805184 ----a-w- c:\windows\SysWow64\igdumd32.dll
2011-06-25 13:57 . 2010-11-12 00:44 94208 ----a-w- c:\windows\SysWow64\dpl100.dll
2011-06-25 13:57 . 2010-02-19 19:27 843776 ----a-w- c:\windows\SysWow64\divx_xx16.dll
2011-06-25 13:57 . 2010-02-19 19:27 839680 ----a-w- c:\windows\SysWow64\divx_xx11.dll
2011-06-25 13:57 . 2010-02-19 19:27 856064 ----a-w- c:\windows\SysWow64\divx_xx0c.dll
2011-06-25 13:57 . 2010-02-19 19:27 856064 ----a-w- c:\windows\SysWow64\divx_xx07.dll
2011-06-25 13:57 . 2010-02-19 19:27 847872 ----a-w- c:\windows\SysWow64\divx_xx0a.dll
2011-06-25 13:57 . 2010-08-27 23:21 356352 ----a-w- c:\windows\SysWow64\atipdlxx.dll
2011-06-25 13:57 . 2010-08-27 23:21 53248 ----a-w- c:\windows\SysWow64\aticalrt.dll
2011-06-25 13:57 . 2010-08-27 23:21 53248 ----a-w- c:\windows\SysWow64\aticalcl.dll
2011-06-25 13:57 . 2010-08-27 23:21 446464 ----a-w- c:\windows\SysWow64\aticfx32.dll
2011-06-25 13:57 . 2010-08-27 23:21 3657728 ----a-w- c:\windows\SysWow64\aticaldd.dll
2011-06-25 13:57 . 2010-08-27 23:21 237568 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2011-06-25 13:56 . 2010-08-28 00:12 1044480 ----a-w- c:\windows\SysWow64\3DImageRenderer.dll
2011-06-25 13:49 . 2010-08-27 23:37 208896 ----a-w- c:\windows\Reg331Unstal.dll
2011-06-12 09:13 . 2011-06-12 09:13 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2011-06-04 09:40 . 2011-06-04 09:40 458048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-06-03 05:57 . 2011-07-14 13:13 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-24 17:14 . 2011-04-18 19:34 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-14 12:20 . 2011-05-14 12:20 33344 ----a-w- c:\windows\system32\drivers\hamachi.sys
2011-05-03 05:29 . 2011-06-17 15:02 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-03 04:30 . 2011-06-17 15:02 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-05-02 08:45 . 2011-05-02 08:45 254528 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-05-01 17:18 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-05-01 17:18 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-05-01 17:03 . 2011-05-01 17:03 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-05-01 17:03 . 2011-05-01 17:03 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-05-01 17:03 . 2011-05-01 17:03 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-05-01 17:03 . 2011-05-01 17:03 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-01 17:03 . 2011-05-01 17:03 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-01 17:03 . 2011-05-01 17:03 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-05-01 17:03 . 2011-05-01 17:03 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-05-01 17:03 . 2011-05-01 17:03 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-05-01 17:03 . 2011-05-01 17:03 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-05-01 17:03 . 2011-05-01 17:03 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-05-01 17:03 . 2011-05-01 17:03 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-05-01 17:03 . 2011-05-01 17:03 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-05-01 17:03 . 2011-05-01 17:03 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-05-01 17:03 . 2011-05-01 17:03 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-05-01 17:03 . 2011-05-01 17:03 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-01 17:03 . 2011-05-01 17:03 448512 ----a-w- c:\windows\system32\html.iec
2011-05-01 17:03 . 2011-05-01 17:03 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-05-01 17:03 . 2011-05-01 17:03 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-05-01 17:03 . 2011-05-01 17:03 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-05-01 17:03 . 2011-05-01 17:03 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-01 17:03 . 2011-05-01 17:03 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-05-01 17:03 . 2011-05-01 17:03 222208 ----a-w- c:\windows\system32\msls31.dll
2011-05-01 17:03 . 2011-05-01 17:03 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-01 17:03 . 2011-05-01 17:03 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-05-01 17:03 . 2011-05-01 17:03 160256 ----a-w- c:\windows\system32\wextract.exe
2011-05-01 17:03 . 2011-05-01 17:03 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-05-01 17:03 . 2011-05-01 17:03 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-05-01 17:03 . 2011-05-01 17:03 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-01 17:03 . 2011-05-01 17:03 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-05-01 17:03 . 2011-05-01 17:03 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-05-01 17:03 . 2011-05-01 17:03 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-05-01 17:03 . 2011-05-01 17:03 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-01 17:03 . 2011-05-01 17:03 12288 ----a-w- c:\windows\system32\mshta.exe
2011-05-01 17:03 . 2011-05-01 17:03 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-05-01 17:03 . 2011-05-01 17:03 114176 ----a-w- c:\windows\system32\admparse.dll
2011-05-01 17:03 . 2011-05-01 17:03 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-01 17:03 . 2011-05-01 17:03 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-05-01 17:03 . 2011-05-01 17:03 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-04-29 03:06 . 2011-06-17 15:02 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 03:05 . 2011-06-17 15:02 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 03:05 . 2011-06-17 15:02 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-27 02:40 . 2011-06-17 15:02 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-27 02:39 . 2011-06-17 15:02 289280 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-27 02:39 . 2011-06-17 15:02 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-25 05:33 . 2011-06-17 15:03 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-04-25 02:34 . 2011-06-17 15:03 499200 ----a-w- c:\windows\system32\drivers\afd.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 4"="c:\program files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-05-28 412560]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-06-25 98304]
"331BigDog"="c:\program files (x86)\USB Camera\VM331_STI.EXE" [2009-09-15 536576]
"VeriFaceManager"="c:\program files (x86)\Lenovo\VeriFace\PManage.exe" [2010-08-28 3122528]
"UCam_Menu"="c:\program files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"YouCam Mirror Tray icon"="c:\program files (x86)\Lenovo\YouCam\YouCamTray.exe" [2010-03-02 171104]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-04-05 1486392]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2009-8-11 1080608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoThumbnailCache"= 1 (0x1)
"DisableThumbnailsOnNetworkFolders"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 0039021310639213mcinstcleanup;McAfee Application Installer Cleanup (0039021310639213); [x]
R2 0069921305984216mcinstcleanup;McAfee Application Installer Cleanup (0069921305984216); [x]
R2 0191871304422590mcinstcleanup;McAfee Application Installer Cleanup (0191871304422590); [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-14 136176]
R3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [x]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-14 136176]
R3 IGRS;IGRS;c:\program files (x86)\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
R3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192]
R3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2010-08-30 220528]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x]
R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys [x]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-04-14 245352]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 vm331avs;Digital Camera 1;c:\windows\system32\Drivers\vm331avs.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
S3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
IgrsSvcs REG_MULTI_SZ ReadyComm.DirectRouter PS_MDP
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-14 13:56]
.
2011-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-14 13:56]
.
2011-07-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1067309388-1185033214-2816805062-1000Core.job
- c:\users\katka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-22 08:06]
.
2011-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1067309388-1185033214-2816805062-1000UA.job
- c:\users\katka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-22 08:06]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2010-08-28 00:12 1502720 ----a-w- c:\windows\System32\IcnOvrly.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-27 10775584]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-04-27 2040352]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\utility.exe" [2010-04-12 4462496]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2010-03-18 7056800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uLocal Page = c:\windows\system32\blank.htm
IE: Send image to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1067309388-1185033214-2816805062-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-1067309388-1185033214-2816805062-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-07-22 13:43:31
ComboFix-quarantined-files.txt 2011-07-22 11:43
.
Pre-Run: 411 621 216 256 bytes free
Post-Run: 411 129 233 408 bytes free
.
- - End Of File - - 1A71D06B9F4B113C1FE963F5FB22D55A
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.4091.2761 [GMT 2:00]
Running from: c:\users\katka\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Outdated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Outdated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\s.bat
.
.
((((((((((((((((((((((((( Files Created from 2011-06-22 to 2011-07-22 )))))))))))))))))))))))))))))))
.
.
2011-07-22 11:40 . 2011-07-22 11:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-20 18:57 . 2011-07-21 14:13 -------- d-----w- c:\program files (x86)\CrystalDiskInfo
2011-07-20 15:57 . 2011-07-20 15:57 -------- d-----w- c:\users\katka\AppData\Roaming\Malwarebytes
2011-07-20 15:57 . 2011-07-20 15:57 -------- d-----w- c:\programdata\Malwarebytes
2011-07-20 15:57 . 2010-11-29 15:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-20 13:45 . 2011-07-20 13:50 -------- d-----w- c:\users\katka\AppData\Roaming\PCStitch Pro
2011-07-19 22:27 . 2011-07-19 22:27 -------- d-----w- c:\program files\trend micro
2011-07-18 19:12 . 2011-07-18 19:13 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2011-07-15 11:27 . 2011-07-15 11:27 -------- d-----w- c:\users\katka\AppData\Roaming\Atari
2011-07-15 11:09 . 2011-07-15 11:09 -------- d-----w- c:\program files (x86)\Atari
2011-07-15 11:09 . 2005-04-03 21:00 184320 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2011-07-15 11:09 . 2005-04-03 21:00 63488 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2011-07-15 11:08 . 2011-07-15 11:08 200836 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2011-07-15 11:08 . 2005-04-03 21:02 753664 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2011-07-15 11:08 . 2005-04-03 21:02 69714 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2011-07-15 11:08 . 2005-04-03 21:01 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2011-07-15 11:08 . 2005-04-03 20:59 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2011-07-15 11:08 . 2011-07-15 11:08 331908 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2011-07-07 23:39 . 2011-07-07 23:39 -------- d-----w- c:\programdata\Microsoft Help
2011-07-07 23:39 . 2011-07-07 23:39 -------- d-----w- c:\users\katka\AppData\Local\Microsoft Help
2011-07-07 22:17 . 2011-07-07 22:17 458048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-07-02 21:07 . 2011-07-02 21:07 -------- d--h--w- c:\programdata\Common Files
2011-07-02 21:06 . 2011-07-22 10:45 -------- d-----w- c:\programdata\AVG10
2011-07-02 07:39 . 2011-07-02 07:39 233488 ----a-w- c:\windows\system32\drivers\PCTCore64.sys
2011-07-02 07:33 . 2010-01-22 07:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-07-02 07:33 . 2010-01-22 07:55 767952 ----a-w- c:\windows\BDTSupport.dll
2011-07-02 07:33 . 2010-01-22 07:56 165840 ----a-w- c:\windows\PCTBDRes.dll
2011-07-02 07:33 . 2010-01-22 07:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
2011-07-02 07:24 . 2010-02-05 07:18 133072 ----a-w- c:\windows\system32\drivers\pctwfpfilter64.sys
2011-07-02 07:24 . 2010-02-05 07:17 306648 ----a-w- c:\windows\system32\drivers\pctgntdi64.sys
2011-07-02 07:23 . 2011-07-02 07:39 92896 ----a-w- c:\windows\system32\drivers\pctplsg64.sys
2011-07-02 07:23 . 2011-07-03 17:07 -------- d-----w- c:\program files (x86)\Spyware Doctor
2011-07-01 20:28 . 2011-07-03 11:45 -------- d-----w- c:\program files (x86)\Common Files\PC Tools
2011-07-01 20:28 . 2011-07-01 20:43 -------- d-----w- c:\programdata\PC Tools
2011-07-01 20:28 . 2011-07-01 20:28 -------- d-----w- c:\users\katka\AppData\Roaming\PC Tools
2011-06-30 12:25 . 2011-06-30 12:25 -------- d-----w- C:\output
2011-06-28 21:18 . 2011-07-14 08:25 -------- d-----w- c:\users\katka\AppData\Roaming\QuickScan
2011-06-28 08:10 . 2011-07-03 11:44 -------- d-----w- C:\676a689354ac6d7d82a6486bd7ce4f75
2011-06-24 18:41 . 2011-07-03 11:44 -------- d-----w- c:\program files (x86)\ESET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-07 22:17 . 2011-06-04 09:40 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2011-06-25 13:57 . 2010-08-27 23:37 655360 ----a-w- c:\windows\SysWow64\vmprp331.ax
2011-06-25 13:57 . 2010-08-28 00:12 1171456 ----a-w- c:\windows\SysWow64\PicNotify.dll
2011-06-25 13:57 . 2010-08-27 23:21 274432 ----a-w- c:\windows\SysWow64\Oemdspif.dll
2011-06-25 13:57 . 2010-08-28 00:12 77824 ----a-w- c:\windows\SysWow64\ILU.dll
2011-06-25 13:57 . 2010-08-28 00:12 32768 ----a-w- c:\windows\SysWow64\ILUT.dll
2011-06-25 13:57 . 2009-07-13 21:59 2531328 ----a-w- c:\windows\SysWow64\igd10umd32.dll
2011-06-25 13:57 . 2009-07-13 21:59 3805184 ----a-w- c:\windows\SysWow64\igdumd32.dll
2011-06-25 13:57 . 2010-11-12 00:44 94208 ----a-w- c:\windows\SysWow64\dpl100.dll
2011-06-25 13:57 . 2010-02-19 19:27 843776 ----a-w- c:\windows\SysWow64\divx_xx16.dll
2011-06-25 13:57 . 2010-02-19 19:27 839680 ----a-w- c:\windows\SysWow64\divx_xx11.dll
2011-06-25 13:57 . 2010-02-19 19:27 856064 ----a-w- c:\windows\SysWow64\divx_xx0c.dll
2011-06-25 13:57 . 2010-02-19 19:27 856064 ----a-w- c:\windows\SysWow64\divx_xx07.dll
2011-06-25 13:57 . 2010-02-19 19:27 847872 ----a-w- c:\windows\SysWow64\divx_xx0a.dll
2011-06-25 13:57 . 2010-08-27 23:21 356352 ----a-w- c:\windows\SysWow64\atipdlxx.dll
2011-06-25 13:57 . 2010-08-27 23:21 53248 ----a-w- c:\windows\SysWow64\aticalrt.dll
2011-06-25 13:57 . 2010-08-27 23:21 53248 ----a-w- c:\windows\SysWow64\aticalcl.dll
2011-06-25 13:57 . 2010-08-27 23:21 446464 ----a-w- c:\windows\SysWow64\aticfx32.dll
2011-06-25 13:57 . 2010-08-27 23:21 3657728 ----a-w- c:\windows\SysWow64\aticaldd.dll
2011-06-25 13:57 . 2010-08-27 23:21 237568 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2011-06-25 13:56 . 2010-08-28 00:12 1044480 ----a-w- c:\windows\SysWow64\3DImageRenderer.dll
2011-06-25 13:49 . 2010-08-27 23:37 208896 ----a-w- c:\windows\Reg331Unstal.dll
2011-06-12 09:13 . 2011-06-12 09:13 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2011-06-04 09:40 . 2011-06-04 09:40 458048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-06-03 05:57 . 2011-07-14 13:13 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-24 17:14 . 2011-04-18 19:34 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-14 12:20 . 2011-05-14 12:20 33344 ----a-w- c:\windows\system32\drivers\hamachi.sys
2011-05-03 05:29 . 2011-06-17 15:02 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-03 04:30 . 2011-06-17 15:02 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-05-02 08:45 . 2011-05-02 08:45 254528 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-05-01 17:18 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-05-01 17:18 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-05-01 17:03 . 2011-05-01 17:03 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-05-01 17:03 . 2011-05-01 17:03 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-05-01 17:03 . 2011-05-01 17:03 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-05-01 17:03 . 2011-05-01 17:03 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-01 17:03 . 2011-05-01 17:03 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-01 17:03 . 2011-05-01 17:03 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-05-01 17:03 . 2011-05-01 17:03 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-05-01 17:03 . 2011-05-01 17:03 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-05-01 17:03 . 2011-05-01 17:03 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-05-01 17:03 . 2011-05-01 17:03 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-05-01 17:03 . 2011-05-01 17:03 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-05-01 17:03 . 2011-05-01 17:03 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-05-01 17:03 . 2011-05-01 17:03 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-05-01 17:03 . 2011-05-01 17:03 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-05-01 17:03 . 2011-05-01 17:03 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-01 17:03 . 2011-05-01 17:03 448512 ----a-w- c:\windows\system32\html.iec
2011-05-01 17:03 . 2011-05-01 17:03 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-05-01 17:03 . 2011-05-01 17:03 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-05-01 17:03 . 2011-05-01 17:03 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-05-01 17:03 . 2011-05-01 17:03 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-01 17:03 . 2011-05-01 17:03 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-05-01 17:03 . 2011-05-01 17:03 222208 ----a-w- c:\windows\system32\msls31.dll
2011-05-01 17:03 . 2011-05-01 17:03 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-01 17:03 . 2011-05-01 17:03 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-05-01 17:03 . 2011-05-01 17:03 160256 ----a-w- c:\windows\system32\wextract.exe
2011-05-01 17:03 . 2011-05-01 17:03 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-05-01 17:03 . 2011-05-01 17:03 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-05-01 17:03 . 2011-05-01 17:03 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-01 17:03 . 2011-05-01 17:03 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-05-01 17:03 . 2011-05-01 17:03 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-05-01 17:03 . 2011-05-01 17:03 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-05-01 17:03 . 2011-05-01 17:03 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-01 17:03 . 2011-05-01 17:03 12288 ----a-w- c:\windows\system32\mshta.exe
2011-05-01 17:03 . 2011-05-01 17:03 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-05-01 17:03 . 2011-05-01 17:03 114176 ----a-w- c:\windows\system32\admparse.dll
2011-05-01 17:03 . 2011-05-01 17:03 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-01 17:03 . 2011-05-01 17:03 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-05-01 17:03 . 2011-05-01 17:03 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-04-29 03:06 . 2011-06-17 15:02 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 03:05 . 2011-06-17 15:02 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 03:05 . 2011-06-17 15:02 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-27 02:40 . 2011-06-17 15:02 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-27 02:39 . 2011-06-17 15:02 289280 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-27 02:39 . 2011-06-17 15:02 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-25 05:33 . 2011-06-17 15:03 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-04-25 02:34 . 2011-06-17 15:03 499200 ----a-w- c:\windows\system32\drivers\afd.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 4"="c:\program files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-05-28 412560]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-06-25 98304]
"331BigDog"="c:\program files (x86)\USB Camera\VM331_STI.EXE" [2009-09-15 536576]
"VeriFaceManager"="c:\program files (x86)\Lenovo\VeriFace\PManage.exe" [2010-08-28 3122528]
"UCam_Menu"="c:\program files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"YouCam Mirror Tray icon"="c:\program files (x86)\Lenovo\YouCam\YouCamTray.exe" [2010-03-02 171104]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-04-05 1486392]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2009-8-11 1080608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoThumbnailCache"= 1 (0x1)
"DisableThumbnailsOnNetworkFolders"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 0039021310639213mcinstcleanup;McAfee Application Installer Cleanup (0039021310639213); [x]
R2 0069921305984216mcinstcleanup;McAfee Application Installer Cleanup (0069921305984216); [x]
R2 0191871304422590mcinstcleanup;McAfee Application Installer Cleanup (0191871304422590); [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-14 136176]
R3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [x]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-14 136176]
R3 IGRS;IGRS;c:\program files (x86)\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
R3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192]
R3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2010-08-30 220528]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x]
R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys [x]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-04-14 245352]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 vm331avs;Digital Camera 1;c:\windows\system32\Drivers\vm331avs.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
S3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
IgrsSvcs REG_MULTI_SZ ReadyComm.DirectRouter PS_MDP
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-14 13:56]
.
2011-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-14 13:56]
.
2011-07-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1067309388-1185033214-2816805062-1000Core.job
- c:\users\katka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-22 08:06]
.
2011-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1067309388-1185033214-2816805062-1000UA.job
- c:\users\katka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-22 08:06]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2010-08-28 00:12 1502720 ----a-w- c:\windows\System32\IcnOvrly.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-27 10775584]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-04-27 2040352]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\utility.exe" [2010-04-12 4462496]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2010-03-18 7056800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uLocal Page = c:\windows\system32\blank.htm
IE: Send image to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1067309388-1185033214-2816805062-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-1067309388-1185033214-2816805062-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-07-22 13:43:31
ComboFix-quarantined-files.txt 2011-07-22 11:43
.
Pre-Run: 411 621 216 256 bytes free
Post-Run: 411 129 233 408 bytes free
.
- - End Of File - - 1A71D06B9F4B113C1FE963F5FB22D55A
Re: Extréemne pomalé vypínanie
Pořád zasekaný?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Extréemne pomalé vypínanie
Už nie tak, ale iba keď sťahuje databázu mcaffee 

Re: Extréemne pomalé vypínanie
Tak to se mi děje při stahování aktualizací Avastu také
Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********
Stáhněte T-Cleaner
http://tharifas.sweb.cz/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********
Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru
záložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner
záložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy
ok
zavřít
Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********
Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********
Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?


- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********

http://tharifas.sweb.cz/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********

- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy



- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********

http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.