Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

win32 neshta dokoncit odstraneni

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Jezevec2104
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 pro 2011 11:10

win32 neshta dokoncit odstraneni

#1 Příspěvek od Jezevec2104 »

Dobry den, snazil jsem se cist a hledat abych zjednodusil komunikaci, ovsem nejsem si jisty zda tomu plne rozumim tak me prosim hned neukamenujte. Pri nostalgickem pocinu jsem si stahl hru diabloII a natahl jsem si vir win32 nestha. Pri odstranovani jsem pouzil postup:
Odstránenie:
1:Opravíme pridružení exe súborov
2:Spustíme exehelper src
3: Spustíme Malwarebytes.
4:Vyčistíte temp TFC CCleaner
5:Vypneme obnovu systému, win7 XP po reštarte zapnúť spät.
6: Vyliečime počítač s AVPTOOL.
Bod jedna se nepovedlo uplne dokoncit ani v nouzovem rezimu s prikazovym radkem :( zbytek probehl celkem ok prikladam log z Avptool:

Status: Detected (events: 4)
17.12.2011 2:01:32 Detected virus Virus.Win32.Neshta.a D:\Install\Diablo\diablo_2-lod_cz-part1-nahrano-pres-MULTILOAD-CZ.rar//CD Key/D2LODCDKeygen.exe High
17.12.2011 2:01:33 Detected virus Virus.Win32.Neshta.a D:\Install\Diablo\diablo_2-lod_cz-part1-nahrano-pres-MULTILOAD-CZ.rar//źeçtina/D2czSlovnik.exe High
17.12.2011 2:03:45 Detected virus Virus.Win32.Neshta.a D:\Install\Diablo\diablo_2-lod_cz-part1-nahrano-pres-MULTILOAD-CZ.rar//źeçtina/Diablo 2 CZ.exe High
17.12.2011 2:03:45 Detected virus Virus.Win32.Neshta.a D:\Install\Diablo\diablo_2-lod_cz-part1-nahrano-pres-MULTILOAD-CZ.rar//Update Patch/LODPatch_113c.exe High

pote nekolik uplnych testu Avastem po startu jiz bez nalezenych hrozeb. Proveden scan pomoci RSIT prikladam log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Smisek at 2011-12-17 11:22:14
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 13 GB (25%) free of 50 GB
Total RAM: 3583 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:22:32, on 17.12.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\vsnpstd3.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
C:\Program Files (x86)\ASUS\EPU\EPU.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\iPScan5x.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\ASUS\GPU Boost Driver\GpuBoostServer.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files\trend micro\Smisek.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Six Engine] "C:\Program Files (x86)\ASUS\EPU\EPU.exe" -b
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iPScan5x] C:\Windows\iPScan5x.EXE
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
O4 - HKCU\..\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://www.impuls.cz
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11578 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Microsoft IntelliType Pro\itype.exe"
"C:\Windows\vsnpstd3.exe"
"C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE" /logon
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
"C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe" -tray
"C:\Program Files (x86)\ASUS\EPU\EPU.exe" -b
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Windows\iPScan5x.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" /logon
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe"
taskeng.exe {D6041D63-7DB9-4406-B847-29F138866769}
taskeng.exe {B88DCC53-3DF5-4BF7-8EEF-CD1E5A4F4A5C}
"C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
"C:\Program Files\ASUS\GPU Boost Driver\GpuBoostServer.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2756
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
{D53135A7-8471-4928-83EF-9AFB2837193E}
{E989F2EF-F60C-444F-AF75-F1450D4FF9B8}
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-40a439dc-3433-473a-a027-674acc7a8856 -SystemEventPortName:HostProcess-4a245b06-ffd0-4482-b0ca-2579e2236c47 -IoCancelEventPortName:HostProcess-2f2a5c9f-5e79-4737-9496-70a283d1dfcd -NonStateChangingEventPortName:HostProcess-e7b83760-a215-4165-8984-232cb97ac74f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:8b2f4c88-755b-473f-902a-b75827eadc6b
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-2135631886-2993492131-3194471246-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-2135631886-2993492131-3194471246-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Users\Smisek\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2135631886-2993492131-3194471246-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2135631886-2993492131-3194471246-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Smisek\AppData\Roaming\Mozilla\Firefox\Profiles\8l54pyh0.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=1.1.11]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-11-28 963064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-12-02 458416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08 202144]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28 809040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-12-02 342192]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-11-28 963064]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2010-03-25 1548096]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-12-02 458416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28 809040]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-12-02 342192]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08 1619352]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-07-06 11057768]
"itype"=C:\Program Files\Microsoft IntelliType Pro\itype.exe [2009-11-11 2345848]
"snpstd3"=C:\Windows\vsnpstd3.exe [2006-09-18 843776]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2011-03-15 2779024]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2011-04-24 39408]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"OscarEditor"=C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [2010-07-22 2636800]
""= []
"NokiaSuite.exe"=C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2011-11-01 1053056]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 98304]
"Six Engine"=C:\Program Files (x86)\ASUS\EPU\EPU.exe [2010-06-14 5309056]
"BCU"=C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2010-03-05 411864]
"NUSB3MON"=C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-04-27 113288]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-11-28 3744552]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"iPScan5x"=C:\Windows\iPScan5x.EXE [2008-09-06 94208]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-11-01 59240]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"CanonSolutionMenuEx"=C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [2011-03-28 1611160]
"Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 449608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=0
"DisableTaskMgr"=0
"DisableCMD"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=0
"ForceActiveDesktopOn"=0
"NoSetActiveDesktop"=0
"NoFolderOptions"=0
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-12-17 11:22:14 ----D---- C:\rsit
2011-12-17 11:22:14 ----D---- C:\Program Files\trend micro
2011-12-16 23:47:48 ----D---- C:\ProgramData\Kaspersky Lab
2011-12-16 23:33:45 ----D---- C:\Program Files\CCleaner
2011-12-16 22:18:04 ----D---- C:\Users\Smisek\AppData\Roaming\Malwarebytes
2011-12-16 22:17:57 ----D---- C:\ProgramData\Malwarebytes
2011-12-16 22:17:53 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-12-16 22:17:53 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-12-16 17:10:09 ----A---- C:\Windows\SYSWOW64\BnetLog.txt
2011-12-16 16:59:37 ----A---- C:\Windows\directx.sys
2011-12-16 16:54:24 ----A---- C:\Windows\DIIUnin.dat
2011-12-16 16:54:23 ----A---- C:\Windows\DIIUnin.pif
2011-12-16 16:54:23 ----A---- C:\Windows\DIIUnin.exe
2011-12-14 16:22:15 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-12-14 16:22:15 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-12-14 16:22:15 ----A---- C:\Windows\system32\mshtmled.dll
2011-12-14 16:22:15 ----A---- C:\Windows\system32\iertutil.dll
2011-12-14 16:22:14 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-12-14 16:22:14 ----A---- C:\Windows\SYSWOW64\url.dll
2011-12-14 16:22:14 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-12-14 16:22:14 ----A---- C:\Windows\system32\urlmon.dll
2011-12-14 16:22:14 ----A---- C:\Windows\system32\url.dll
2011-12-14 16:22:14 ----A---- C:\Windows\system32\ieui.dll
2011-12-14 16:22:13 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-12-14 16:22:13 ----A---- C:\Windows\system32\wininet.dll
2011-12-14 16:22:13 ----A---- C:\Windows\system32\jsproxy.dll
2011-12-14 16:22:12 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-12-14 16:22:12 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-12-14 16:22:12 ----A---- C:\Windows\system32\jscript9.dll
2011-12-14 16:22:12 ----A---- C:\Windows\system32\jscript.dll
2011-12-14 16:22:11 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-12-14 16:22:11 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-12-14 16:22:09 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-12-14 16:22:09 ----A---- C:\Windows\system32\mshtml.dll
2011-12-14 16:22:08 ----A---- C:\Windows\system32\ieframe.dll
2011-12-14 16:17:03 ----A---- C:\Windows\system32\csrsrv.dll
2011-12-14 16:17:02 ----A---- C:\Windows\system32\win32k.sys
2011-12-14 16:17:01 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-12-14 16:17:01 ----A---- C:\Windows\system32\EncDec.dll
2011-12-14 16:16:58 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-12-14 16:16:58 ----A---- C:\Windows\system32\tzres.dll
2011-12-13 21:03:55 ----HD---- C:\ProgramData\CanonIJEGV
2011-12-13 21:02:39 ----D---- C:\Program Files\VibrateGameDeviceDriver
2011-12-13 21:02:39 ----D---- C:\Program Files (x86)\VibrateGameDeviceDriver
2011-12-13 20:56:57 ----HD---- C:\ProgramData\CanonIJEPPEX2
2011-12-13 20:56:57 ----HD---- C:\ProgramData\CanonEPP
2011-12-13 20:56:56 ----D---- C:\Users\Smisek\AppData\Roaming\Canon
2011-12-13 20:52:08 ----A---- C:\Windows\system32\CNMXLMAW.DLL
2011-12-13 20:45:59 ----D---- C:\Program Files\Common Files\CANON
2011-12-13 20:45:49 ----D---- C:\ProgramData\CanonIJWSpt
2011-12-13 20:44:39 ----D---- C:\Program Files\Canon
2011-12-13 20:43:52 ----HD---- C:\ProgramData\CanonBJ
2011-12-13 20:43:41 ----HD---- C:\Windows\system32\CanonIJ Uninstaller Information
2011-12-13 20:43:26 ----A---- C:\Windows\system32\CNMLMAW.DLL
2011-12-13 20:43:17 ----A---- C:\Windows\system32\CNMIUAW.DLL
2011-12-13 20:43:07 ----HD---- C:\Program Files\CanonBJ
2011-12-13 20:40:18 ----D---- C:\Program Files (x86)\Canon
2011-12-12 19:02:01 ----AT---- C:\Windows\SYSWOW64\SIntfNT.dll
2011-12-12 19:02:01 ----AT---- C:\Windows\SYSWOW64\SIntf32.dll
2011-12-12 19:02:01 ----AT---- C:\Windows\SYSWOW64\SIntf16.dll
2011-12-11 22:34:10 ----D---- C:\ProgramData\McAfee
2011-11-21 17:17:44 ----D---- C:\Windows\system32\Macromed
2011-11-19 14:56:13 ----D---- C:\ProgramData\Nokia
2011-11-19 14:55:00 ----D---- C:\Program Files (x86)\PC Connectivity Solution
2011-11-18 18:17:13 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-11-18 18:17:13 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-11-18 18:17:13 ----A---- C:\Windows\SYSWOW64\java.exe
2011-11-18 00:52:43 ----D---- C:\Windows\Minidump

======List of files/folders modified in the last 1 month======

2011-12-17 11:22:29 ----D---- C:\Windows\Temp
2011-12-17 11:22:14 ----RD---- C:\Program Files
2011-12-17 10:40:39 ----D---- C:\Windows\system32\config
2011-12-17 10:36:49 ----D---- C:\Windows\System32
2011-12-17 10:36:49 ----D---- C:\Windows\inf
2011-12-17 10:36:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-12-17 02:19:29 ----D---- C:\Windows\system32\drivers
2011-12-17 01:00:16 ----D---- C:\Windows\system32\wdi
2011-12-16 23:47:51 ----SHD---- C:\System Volume Information
2011-12-16 23:47:48 ----HD---- C:\ProgramData
2011-12-16 23:43:36 ----D---- C:\Windows
2011-12-16 23:36:04 ----D---- C:\Windows\SoftwareDistribution
2011-12-16 23:35:42 ----D---- C:\Users\Smisek\AppData\Roaming\Skype
2011-12-16 23:35:42 ----D---- C:\Users\Smisek\AppData\Roaming\DAEMON Tools Lite
2011-12-16 23:35:38 ----D---- C:\Windows\Panther
2011-12-16 23:35:38 ----D---- C:\Windows\Logs
2011-12-16 23:35:38 ----D---- C:\Windows\debug
2011-12-16 22:18:26 ----D---- C:\Windows\SYSWOW64\drivers
2011-12-16 22:17:53 ----RD---- C:\Program Files (x86)
2011-12-16 22:00:55 ----D---- C:\Windows\system32\catroot2
2011-12-16 21:26:04 ----D---- C:\Windows\system32\LogFiles
2011-12-16 19:23:39 ----D---- C:\Windows\system32\Tasks
2011-12-16 19:20:23 ----D---- C:\Program Files (x86)\OSCAR Editor X7
2011-12-16 17:10:09 ----D---- C:\Windows\SysWOW64
2011-12-15 23:16:26 ----D---- C:\Windows\system
2011-12-15 22:33:59 ----SD---- C:\Users\Smisek\AppData\Roaming\Microsoft
2011-12-14 22:27:39 ----D---- C:\Windows\winsxs
2011-12-14 22:25:29 ----D---- C:\Program Files\Internet Explorer
2011-12-14 22:25:29 ----D---- C:\Program Files (x86)\Internet Explorer
2011-12-14 22:25:28 ----D---- C:\Windows\SYSWOW64\migration
2011-12-14 22:25:28 ----D---- C:\Windows\system32\migration
2011-12-14 16:28:10 ----SHD---- C:\Windows\Installer
2011-12-14 16:28:08 ----RSD---- C:\Windows\assembly
2011-12-14 16:28:08 ----D---- C:\ProgramData\Microsoft Help
2011-12-14 16:27:50 ----D---- C:\Windows\system32\catroot
2011-12-14 16:23:34 ----A---- C:\Windows\system32\MRT.exe
2011-12-14 16:21:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-12-14 16:21:30 ----D---- C:\Windows\system32\cs-CZ
2011-12-13 21:02:57 ----D---- C:\Windows\system32\DriverStore
2011-12-13 20:45:59 ----D---- C:\Program Files\Common Files
2011-12-13 20:40:27 ----D---- C:\Windows\Prefetch
2011-12-13 16:37:11 ----D---- C:\Program Files (x86)\Alawarhry.cz
2011-12-13 16:36:16 ----D---- C:\Program Files (x86)\Full Tilt Poker
2011-12-11 22:28:57 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-12-01 22:18:03 ----D---- C:\Program Files (x86)\Safari
2011-11-28 19:01:23 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-11-28 19:01:14 ----A---- C:\Windows\system32\aswBoot.exe
2011-11-19 14:56:13 ----D---- C:\Program Files (x86)\Nokia
2011-11-19 14:55:05 ----DC---- C:\Windows\system32\DRVSTORE
2011-11-18 21:02:54 ----D---- C:\Program Files (x86)\Common Files
2011-11-18 18:17:10 ----D---- C:\Program Files (x86)\Java

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-08-23 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-04-24 834544]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-08-04 13440]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-11-28 42328]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-11-28 591192]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-11-28 304472]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-11-28 58712]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-11-28 24408]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-11-28 66904]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-03-09 9258496]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-03-09 300544]
R3 AODDriver;AODDriver; \??\C:\Program Files\ASUS\GPU Boost Driver\amd64\AODDriver.sys [2010-03-12 52280]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-01-28 116736]
R3 BthAvrcp;Bluetooth AVRCP Profile; C:\Windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 29184]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-07-06 2419176]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-04-27 83080]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-04-27 184968]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
R3 SNPSTD3;USB PC Camera (SNPSTD3); C:\Windows\system32\DRIVERS\snpstd3.sys [2007-04-03 10535040]
R3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 aelpbiuv;aelpbiuv; C:\Windows\system32\drivers\aelpbiuv.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-22 48488]
S3 IPUSBCam95;iP295x Plug; C:\Windows\System32\Drivers\iP295x.sys [2008-08-15 75776]
S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-08-31 25416]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-08-17 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2011-08-17 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-08-17 9216]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-08-17 9216]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-03-09 203776]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-11-28 44768]
R2 BCUService;Browser Configuration Utility Service; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2008-07-10 40999448]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 157720]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2011-10-27 718384]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-04-22 136176]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-22 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-04-22 136176]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-04-24 182768]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-04-24 1255736]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128]
S4 msvsmon90;Visual Studio 2008 Remote Debugger; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [2008-07-29 4737024]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-07-10 258072]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

Prosim o kontrolu zda je vse uz OK a mohu preinstalovat system. Dekuji

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: win32 neshta dokoncit odstraneni

#2 Příspěvek od vyosek »

Zdravim a pekne poledne preji :)

:arrow: Proc chcete kontrolovat log kdyz chcete preinstalovavat system :roll: Nejak mi unika smysl

:arrow: Jinak bych rad videl logy z MBAMu (zalozka Protokoly) a log z exehelperu

:arrow: A jste jen dalsim dukazem, ze cracky jsou plne bordelu :boxed:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jezevec2104
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 pro 2011 11:10

Re: win32 neshta dokoncit odstraneni

#3 Příspěvek od Jezevec2104 »

Zdravim.
Preinstalovat system chci proto, ze byly smazany .exe ze slozky graficke karty a jinych zarizeni, tak si nejsem jist, zda by vse pracovalo tak jak ma.
Zaroven jsem se docetl, ze pouha preinstalace systemu nestaci k odstraneni Neshta a on byl nalezen nejen na systemovem disku. To k tomu proc bych chtel prekontrolovat logy.

Log z Mbam:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Verze databáze: 8382

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

16.12.2011 23:19:15
mbam-log-2011-12-16 (23-19-15).txt

Typ: Úplná kontrola (C:\|D:\|E:\|)
Kontrolované objekty: 318977
Uplynulý čas: 32 minut, 26 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 1
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 78

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Death Rally (Trojan.Agent) -> Quarantined and deleted successfully.

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
d:\$RECYCLE.BIN\s-1-5-21-2135631886-2993492131-3194471246-1000\$RJSILQ7.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\$RECYCLE.BIN\s-1-5-21-2135631886-2993492131-3194471246-1000\$RQWWQ8Z.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\$RECYCLE.BIN\s-1-5-21-2135631886-2993492131-3194471246-1000\$R1YU8WV\winrar 370 full cz\winrar 3.70 cz.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\$RECYCLE.BIN\s-1-5-21-2135631886-2993492131-3194471246-1000\$R1YU8WV\winrar 370 full cz\wrar370.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\$RECYCLE.BIN\s-1-5-21-2135631886-2993492131-3194471246-1000\$R1YU8WV\winrar 370 full cz\wrar370_full_reg.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\abe's exoddus\Exoddus.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\death rally\dr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\death rally\uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\Diablo 2\Install\diablo 2 full game + datadisk cz (pc hra).part1\diablo 2 full game + datadisk cz (pc hra)\D2Editor.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\Diablo 2\Install\diablo 2 full game + datadisk cz (pc hra).part1\diablo 2 full game + datadisk cz (pc hra)\diablo 2 cd key generator.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\Diablo 2\Install\diablo 2 full game + datadisk cz (pc hra).part1\diablo 2 full game + datadisk cz (pc hra)\diablo 2 expansion key gen.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\Diablo 2\Install\diablo 2 lord of destruction (čeština)\D2instcz.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\nwconfig.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\nwloader.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\nwmain.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\nwn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\nwserver.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\nwtoolset.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\nwupdate.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\cestina\data\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\ereg\ATR1.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\utils\clcompile.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\utils\convertlangid.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\utils\DataPack.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\utils\debugserver.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\utils\nwcontbuild.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\utils\nwcontinst.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\utils\nwhak.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\neverwinternights\NWN\utils\nwsfx.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\operationflashpoint\flashpointpreferences.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\operationflashpoint\flashpointresistance.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\operationflashpoint\operationflashpoint.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\operationflashpoint\opflashpreferences.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\operationflashpoint\uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\Sniper\protect.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\Sniper\sniperelite.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\Sniper\Graphics\specialfx\dxtex.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\Sniper\Patches\fpupdate.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Hry\záchranný tým\Crack\rescueteam.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Install\7zip.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Install\Keygen.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Install\klavesnice.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Install\papiiiclock.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Install\Diablo\CD Key\d2lodcdkeygen.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Install\Diablo\update patch\lodpatch_113c.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Install\Diablo\utility\atma_installer.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Install\Diablo\čeština\d2czslovnik.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Install\winrar 3.80 cz\wrar380cz.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\moje zalohy\SD_Nokia\mmc_ovisuite_2.2.0.245_europe\install_nokia_ovi_suite.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\moje zalohy\SD_Nokia\mmc_ovisuite_2.2.0.245_europe\nokia_ovi_suite_install_files\nokiainstaller.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\C#\Csharp\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\Databaze\databaze111\databaze111\bin\Debug\databaze111.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\Databaze\databaze111\databaze111\bin\Release\databaze111.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\Databaze\databaze111\databaze111\obj\Debug\databaze111.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\Databaze\databaze111\databaze111\obj\Release\databaze111.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\Databaze\databazelinq\bin\Debug\databazelinq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\Databaze\databazelinq\bin\Release\databazelinq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\Databaze\databazelinq\obj\Debug\databazelinq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\Databaze\databazelinq\obj\Release\databazelinq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\Databaze\Stefkova\databazelinq\bin\Debug\databazelinq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\Databaze\Stefkova\databazelinq\bin\Release\databazelinq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\Databaze\Stefkova\databazelinq\obj\Debug\databazelinq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\Databaze\Stefkova\databazelinq\obj\Release\databazelinq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\nove ccko\C\poznáváme c#\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\stefkova_zk\bin\Debug\stefkova_zk.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\bordel z flasky\stefkova_zk\obj\Debug\stefkova_zk.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\visual basic\formular2\bin\Debug\formular2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\visual basic\formular2\obj\Debug\formular2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\visual basic\formular_msgbox\bin\Debug\formular_msgbox.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\visual basic\formular_msgbox\obj\Debug\formular_msgbox.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\visual basic\stefkova_zk\bin\Debug\stefkova_zk.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\programovani\visual basic\stefkova_zk\obj\Debug\stefkova_zk.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\sprava site\Windows\mcp testy\mcp tester n¦µ 210 otázek - povinn8 pro rk\mcptester.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\sprava site\Windows\mcp testy\mcp tester náš 210 otázek - povinný pro rk\mcptester.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\sprava site\Windows\mcp testy\visual certexam suite\designer.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\sprava site\Windows\mcp testy\visual certexam suite\manager.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\sprava site\Windows\mcp testy\visual certexam suite\unins000.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\VSB\sprava site\Windows\mcp testy\visual certexam suite\visual_certexam_suite_setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.



log z Exehelper-u:

exeHelper by Raktor
Build 20100414
Run at 22:10:42 on 12/16/11
Now searching...
Checking for numerical processes...
Checking for sysguard processes...
Checking for bad processes...
Checking for bad files...
Checking for bad registry entries...
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values...
Resetting policies...
--Finished--

exeHelper by Raktor
Build 20100414
Run at 12:33:14 on 12/17/11
Now searching...
Checking for numerical processes...
Checking for sysguard processes...
Checking for bad processes...
Checking for bad files...
Checking for bad registry entries...
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values...
Resetting policies...
--Finished--

Rozumim, mate naprostou pravdu, ale kupovat vsechny programy a hry neni pro me financne unosne :((
Dekuji za pomoc.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: win32 neshta dokoncit odstraneni

#4 Příspěvek od vyosek »

:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Utilitu spustte a prikazte ji, at skenuje - klik na Start Scan
  • Pokud utilita najde infikekci, bude ji chtit lecit (Cure), povolte leceni kliknutim na Continue
  • Pokud utilita najde podezrely soubor (suspicious), bude jej chtit preskocit (Skip), povolte preskoceni kliknutim na Continue
  • Po dokonceni skenu bude mozna nutny restart PC, povolte jej kliknutim na Reboot now
  • Po restartu na Vas vyskoci log, pokud se tak nestane, najdete jej primo na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt - jeho obsah sem vlozte
  • Pokud restart nebude vyzadovan, kliknete na Close a nasledne na Report - vytvori se log - jeho obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jezevec2104
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 pro 2011 11:10

Re: win32 neshta dokoncit odstraneni

#5 Příspěvek od Jezevec2104 »

Provedl jsem scan dle instrukci, prikladam log:


13:13:33.0457 3832 TDSS rootkit removing tool 2.6.23.0 Dec 13 2011 10:39:31
13:13:34.0802 3832 ============================================================
13:13:34.0802 3832 Current date / time: 2011/12/17 13:13:34.0802
13:13:34.0802 3832 SystemInfo:
13:13:34.0802 3832
13:13:34.0802 3832 OS Version: 6.1.7601 ServicePack: 1.0
13:13:34.0802 3832 Product type: Workstation
13:13:34.0802 3832 ComputerName: SMISKOV
13:13:34.0802 3832 UserName: Smisek
13:13:34.0802 3832 Windows directory: C:\Windows
13:13:34.0802 3832 System windows directory: C:\Windows
13:13:34.0802 3832 Running under WOW64
13:13:34.0802 3832 Processor architecture: Intel x64
13:13:34.0802 3832 Number of processors: 2
13:13:34.0802 3832 Page size: 0x1000
13:13:34.0802 3832 Boot type: Normal boot
13:13:34.0802 3832 ============================================================
13:13:36.0130 3832 Initialize success
13:14:01.0449 4280 ============================================================
13:14:01.0449 4280 Scan started
13:14:01.0449 4280 Mode: Manual;
13:14:01.0449 4280 ============================================================
13:14:01.0747 4280 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
13:14:01.0751 4280 1394ohci - ok
13:14:01.0789 4280 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
13:14:01.0795 4280 ACPI - ok
13:14:01.0824 4280 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
13:14:01.0826 4280 AcpiPmi - ok
13:14:01.0883 4280 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
13:14:01.0888 4280 adp94xx - ok
13:14:01.0908 4280 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
13:14:01.0911 4280 adpahci - ok
13:14:01.0928 4280 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
13:14:01.0929 4280 adpu320 - ok
13:14:01.0997 4280 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
13:14:02.0005 4280 AFD - ok
13:14:02.0034 4280 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
13:14:02.0035 4280 agp440 - ok
13:14:02.0055 4280 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
13:14:02.0056 4280 aliide - ok
13:14:02.0085 4280 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
13:14:02.0086 4280 amdide - ok
13:14:02.0132 4280 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
13:14:02.0134 4280 AmdK8 - ok
13:14:02.0307 4280 amdkmdag (bfa9657adf7ddc29242a6e0e88de36fa) C:\Windows\system32\DRIVERS\atikmdag.sys
13:14:02.0346 4280 amdkmdag - ok
13:14:02.0363 4280 amdkmdap (8c493027d9b2399283e724e9862ebb42) C:\Windows\system32\DRIVERS\atikmpag.sys
13:14:02.0365 4280 amdkmdap - ok
13:14:02.0407 4280 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
13:14:02.0409 4280 AmdPPM - ok
13:14:02.0453 4280 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
13:14:02.0454 4280 amdsata - ok
13:14:02.0483 4280 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
13:14:02.0485 4280 amdsbs - ok
13:14:02.0501 4280 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
13:14:02.0502 4280 amdxata - ok
13:14:02.0587 4280 AODDriver (b934322c68c30dceca96c0274a51f7b0) C:\Program Files\ASUS\GPU Boost Driver\amd64\AODDriver.sys
13:14:02.0590 4280 AODDriver - ok
13:14:02.0699 4280 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
13:14:02.0702 4280 AppID - ok
13:14:02.0759 4280 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
13:14:02.0760 4280 arc - ok
13:14:02.0775 4280 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
13:14:02.0777 4280 arcsas - ok
13:14:02.0784 4280 AsIO - ok
13:14:02.0812 4280 aswFsBlk (ce6d8bcc4787704ea4feeb92b0d0caf8) C:\Windows\system32\drivers\aswFsBlk.sys
13:14:02.0812 4280 aswFsBlk - ok
13:14:02.0829 4280 aswMonFlt (0debeb2e3fbd0bf5343125cce617f105) C:\Windows\system32\drivers\aswMonFlt.sys
13:14:02.0830 4280 aswMonFlt - ok
13:14:02.0841 4280 aswRdr (952edc2e81f85d1781958d4128bf59f8) C:\Windows\system32\drivers\aswRdr.sys
13:14:02.0842 4280 aswRdr - ok
13:14:02.0862 4280 aswSnx (dd383e2ac941c545a85ab72503da6c12) C:\Windows\system32\drivers\aswSnx.sys
13:14:02.0865 4280 aswSnx - ok
13:14:02.0884 4280 aswSP (ef5403fb8b2dcb791ec365fdf6040a4a) C:\Windows\system32\drivers\aswSP.sys
13:14:02.0885 4280 aswSP - ok
13:14:02.0895 4280 aswTdi (34165da5c6b30c0f9d61246bf8a28040) C:\Windows\system32\drivers\aswTdi.sys
13:14:02.0896 4280 aswTdi - ok
13:14:02.0938 4280 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
13:14:02.0940 4280 AsyncMac - ok
13:14:02.0973 4280 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
13:14:02.0973 4280 atapi - ok
13:14:03.0020 4280 AtiHdmiService (77c149e6d702737b2e372dee166faef8) C:\Windows\system32\drivers\AtiHdmi.sys
13:14:03.0021 4280 AtiHdmiService - ok
13:14:03.0071 4280 AtiPcie (c07a040d6b5a42dd41ee386cf90974c8) C:\Windows\system32\DRIVERS\AtiPcie.sys
13:14:03.0073 4280 AtiPcie - ok
13:14:03.0119 4280 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
13:14:03.0122 4280 b06bdrv - ok
13:14:03.0142 4280 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
13:14:03.0144 4280 b57nd60a - ok
13:14:03.0194 4280 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
13:14:03.0195 4280 Beep - ok
13:14:03.0242 4280 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
13:14:03.0243 4280 blbdrive - ok
13:14:03.0280 4280 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
13:14:03.0282 4280 bowser - ok
13:14:03.0302 4280 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:14:03.0303 4280 BrFiltLo - ok
13:14:03.0310 4280 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:14:03.0311 4280 BrFiltUp - ok
13:14:03.0325 4280 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
13:14:03.0326 4280 Brserid - ok
13:14:03.0332 4280 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
13:14:03.0333 4280 BrSerWdm - ok
13:14:03.0340 4280 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
13:14:03.0340 4280 BrUsbMdm - ok
13:14:03.0347 4280 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
13:14:03.0348 4280 BrUsbSer - ok
13:14:03.0388 4280 BthAvrcp (832b121e4532919cc49f2438f1dcaa21) C:\Windows\system32\DRIVERS\BthAvrcp.sys
13:14:03.0390 4280 BthAvrcp - ok
13:14:03.0447 4280 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys
13:14:03.0449 4280 BthEnum - ok
13:14:03.0469 4280 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
13:14:03.0471 4280 BTHMODEM - ok
13:14:03.0501 4280 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
13:14:03.0502 4280 BthPan - ok
13:14:03.0541 4280 BTHPORT (64c198198501f7560ee41d8d1efa7952) C:\Windows\System32\Drivers\BTHport.sys
13:14:03.0545 4280 BTHPORT - ok
13:14:03.0580 4280 BTHUSB (f188b7394d81010767b6df3178519a37) C:\Windows\System32\Drivers\BTHUSB.sys
13:14:03.0581 4280 BTHUSB - ok
13:14:03.0599 4280 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
13:14:03.0600 4280 cdfs - ok
13:14:03.0624 4280 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
13:14:03.0626 4280 cdrom - ok
13:14:03.0663 4280 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
13:14:03.0664 4280 circlass - ok
13:14:03.0705 4280 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
13:14:03.0708 4280 CLFS - ok
13:14:03.0744 4280 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
13:14:03.0745 4280 CmBatt - ok
13:14:03.0764 4280 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
13:14:03.0765 4280 cmdide - ok
13:14:03.0809 4280 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
13:14:03.0812 4280 CNG - ok
13:14:03.0832 4280 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
13:14:03.0832 4280 Compbatt - ok
13:14:03.0869 4280 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
13:14:03.0870 4280 CompositeBus - ok
13:14:03.0899 4280 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
13:14:03.0899 4280 crcdisk - ok
13:14:03.0949 4280 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
13:14:03.0953 4280 CSC - ok
13:14:04.0016 4280 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
13:14:04.0019 4280 DfsC - ok
13:14:04.0045 4280 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
13:14:04.0046 4280 discache - ok
13:14:04.0081 4280 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
13:14:04.0082 4280 Disk - ok
13:14:04.0131 4280 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
13:14:04.0131 4280 drmkaud - ok
13:14:04.0179 4280 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
13:14:04.0194 4280 DXGKrnl - ok
13:14:04.0264 4280 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
13:14:04.0285 4280 ebdrv - ok
13:14:04.0311 4280 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
13:14:04.0313 4280 elxstor - ok
13:14:04.0339 4280 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
13:14:04.0339 4280 ErrDev - ok
13:14:04.0375 4280 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
13:14:04.0376 4280 exfat - ok
13:14:04.0395 4280 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
13:14:04.0397 4280 fastfat - ok
13:14:04.0418 4280 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
13:14:04.0419 4280 fdc - ok
13:14:04.0438 4280 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
13:14:04.0439 4280 FileInfo - ok
13:14:04.0453 4280 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
13:14:04.0454 4280 Filetrace - ok
13:14:04.0461 4280 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
13:14:04.0462 4280 flpydisk - ok
13:14:04.0491 4280 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
13:14:04.0493 4280 FltMgr - ok
13:14:04.0504 4280 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
13:14:04.0505 4280 FsDepends - ok
13:14:04.0539 4280 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\Windows\system32\DRIVERS\fssfltr.sys
13:14:04.0540 4280 fssfltr - ok
13:14:04.0567 4280 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
13:14:04.0567 4280 Fs_Rec - ok
13:14:04.0608 4280 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
13:14:04.0609 4280 fvevol - ok
13:14:04.0624 4280 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
13:14:04.0625 4280 gagp30kx - ok
13:14:04.0654 4280 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
13:14:04.0655 4280 hcw85cir - ok
13:14:04.0684 4280 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
13:14:04.0686 4280 HdAudAddService - ok
13:14:04.0709 4280 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
13:14:04.0710 4280 HDAudBus - ok
13:14:04.0716 4280 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
13:14:04.0717 4280 HidBatt - ok
13:14:04.0724 4280 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
13:14:04.0725 4280 HidBth - ok
13:14:04.0732 4280 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
13:14:04.0732 4280 HidIr - ok
13:14:04.0768 4280 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
13:14:04.0768 4280 HidUsb - ok
13:14:04.0791 4280 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
13:14:04.0791 4280 HpSAMD - ok
13:14:04.0836 4280 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
13:14:04.0850 4280 HTTP - ok
13:14:04.0880 4280 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
13:14:04.0881 4280 hwpolicy - ok
13:14:04.0906 4280 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
13:14:04.0907 4280 i8042prt - ok
13:14:04.0949 4280 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
13:14:04.0952 4280 iaStorV - ok
13:14:04.0988 4280 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
13:14:04.0989 4280 iirsp - ok
13:14:05.0058 4280 IntcAzAudAddService (f5872a11eb4f6db170d636cd4e53ca9f) C:\Windows\system32\drivers\RTKVHD64.sys
13:14:05.0071 4280 IntcAzAudAddService - ok
13:14:05.0089 4280 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
13:14:05.0090 4280 intelide - ok
13:14:05.0115 4280 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
13:14:05.0116 4280 intelppm - ok
13:14:05.0145 4280 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:14:05.0146 4280 IpFilterDriver - ok
13:14:05.0162 4280 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
13:14:05.0163 4280 IPMIDRV - ok
13:14:05.0170 4280 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
13:14:05.0171 4280 IPNAT - ok
13:14:05.0223 4280 IPUSBCam95 (ce05db218b0fa002cbeedd365751dbf6) C:\Windows\system32\Drivers\iP295x.sys
13:14:05.0223 4280 IPUSBCam95 - ok
13:14:05.0253 4280 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
13:14:05.0254 4280 IRENUM - ok
13:14:05.0288 4280 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
13:14:05.0288 4280 isapnp - ok
13:14:05.0323 4280 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
13:14:05.0328 4280 iScsiPrt - ok
13:14:05.0359 4280 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
13:14:05.0361 4280 kbdclass - ok
13:14:05.0412 4280 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
13:14:05.0414 4280 kbdhid - ok
13:14:05.0467 4280 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
13:14:05.0470 4280 KSecDD - ok
13:14:05.0505 4280 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
13:14:05.0506 4280 KSecPkg - ok
13:14:05.0529 4280 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
13:14:05.0530 4280 ksthunk - ok
13:14:05.0575 4280 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
13:14:05.0577 4280 lltdio - ok
13:14:05.0616 4280 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
13:14:05.0617 4280 LSI_FC - ok
13:14:05.0635 4280 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
13:14:05.0636 4280 LSI_SAS - ok
13:14:05.0650 4280 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:14:05.0651 4280 LSI_SAS2 - ok
13:14:05.0660 4280 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:14:05.0661 4280 LSI_SCSI - ok
13:14:05.0680 4280 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
13:14:05.0681 4280 luafv - ok
13:14:05.0722 4280 MBAMProtector (23a854450dab5c9b7a42ab9be6f2e4bd) C:\Windows\system32\drivers\mbam.sys
13:14:05.0723 4280 MBAMProtector - ok
13:14:05.0750 4280 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
13:14:05.0750 4280 megasas - ok
13:14:05.0766 4280 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
13:14:05.0768 4280 MegaSR - ok
13:14:05.0798 4280 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
13:14:05.0799 4280 Modem - ok
13:14:05.0837 4280 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
13:14:05.0838 4280 monitor - ok
13:14:05.0888 4280 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
13:14:05.0890 4280 mouclass - ok
13:14:05.0921 4280 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
13:14:05.0923 4280 mouhid - ok
13:14:05.0964 4280 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
13:14:05.0966 4280 mountmgr - ok
13:14:05.0991 4280 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
13:14:05.0992 4280 mpio - ok
13:14:06.0007 4280 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
13:14:06.0008 4280 mpsdrv - ok
13:14:06.0039 4280 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
13:14:06.0041 4280 MRxDAV - ok
13:14:06.0071 4280 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:14:06.0072 4280 mrxsmb - ok
13:14:06.0106 4280 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:14:06.0109 4280 mrxsmb10 - ok
13:14:06.0128 4280 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:14:06.0130 4280 mrxsmb20 - ok
13:14:06.0167 4280 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
13:14:06.0168 4280 msahci - ok
13:14:06.0203 4280 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
13:14:06.0204 4280 msdsm - ok
13:14:06.0249 4280 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
13:14:06.0250 4280 Msfs - ok
13:14:06.0281 4280 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
13:14:06.0282 4280 mshidkmdf - ok
13:14:06.0297 4280 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
13:14:06.0298 4280 msisadrv - ok
13:14:06.0338 4280 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
13:14:06.0339 4280 MSKSSRV - ok
13:14:06.0346 4280 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
13:14:06.0347 4280 MSPCLOCK - ok
13:14:06.0357 4280 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
13:14:06.0358 4280 MSPQM - ok
13:14:06.0393 4280 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
13:14:06.0396 4280 MsRPC - ok
13:14:06.0414 4280 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
13:14:06.0415 4280 mssmbios - ok
13:14:06.0452 4280 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
13:14:06.0453 4280 MSTEE - ok
13:14:06.0472 4280 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
13:14:06.0473 4280 MTConfig - ok
13:14:06.0505 4280 MTsensor (19b006b181e3875fd254f7b67acf1e7c) C:\Windows\system32\DRIVERS\ASACPI.sys
13:14:06.0505 4280 MTsensor - ok
13:14:06.0522 4280 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
13:14:06.0523 4280 Mup - ok
13:14:06.0573 4280 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
13:14:06.0579 4280 NativeWifiP - ok
13:14:06.0642 4280 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
13:14:06.0656 4280 NDIS - ok
13:14:06.0677 4280 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
13:14:06.0678 4280 NdisCap - ok
13:14:06.0703 4280 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
13:14:06.0704 4280 NdisTapi - ok
13:14:06.0731 4280 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
13:14:06.0732 4280 Ndisuio - ok
13:14:06.0764 4280 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
13:14:06.0766 4280 NdisWan - ok
13:14:06.0795 4280 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
13:14:06.0796 4280 NDProxy - ok
13:14:06.0826 4280 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
13:14:06.0827 4280 NetBIOS - ok
13:14:06.0865 4280 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
13:14:06.0868 4280 NetBT - ok
13:14:06.0903 4280 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
13:14:06.0904 4280 nfrd960 - ok
13:14:06.0943 4280 nmwcd (907b5e1e4a592e5edc5e4ccbde4863c2) C:\Windows\system32\drivers\ccdcmbx64.sys
13:14:06.0944 4280 nmwcd - ok
13:14:06.0981 4280 nmwcdc (41c1ac1f3613435eb32d67bcb80a5fa5) C:\Windows\system32\drivers\ccdcmbox64.sys
13:14:06.0981 4280 nmwcdc - ok
13:14:06.0994 4280 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
13:14:06.0995 4280 Npfs - ok
13:14:07.0006 4280 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
13:14:07.0007 4280 nsiproxy - ok
13:14:07.0068 4280 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
13:14:07.0083 4280 Ntfs - ok
13:14:07.0098 4280 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
13:14:07.0099 4280 Null - ok
13:14:07.0124 4280 nusb3hub (285acec1b13a15ba520aae06bacb9cff) C:\Windows\system32\DRIVERS\nusb3hub.sys
13:14:07.0125 4280 nusb3hub - ok
13:14:07.0139 4280 nusb3xhc (f6d625ff7b56bb6ea063f0d3a5bbc996) C:\Windows\system32\DRIVERS\nusb3xhc.sys
13:14:07.0140 4280 nusb3xhc - ok
13:14:07.0177 4280 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
13:14:07.0178 4280 nvraid - ok
13:14:07.0198 4280 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
13:14:07.0199 4280 nvstor - ok
13:14:07.0230 4280 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
13:14:07.0231 4280 nv_agp - ok
13:14:07.0261 4280 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
13:14:07.0262 4280 ohci1394 - ok
13:14:07.0324 4280 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
13:14:07.0325 4280 Parport - ok
13:14:07.0355 4280 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
13:14:07.0356 4280 partmgr - ok
13:14:07.0393 4280 pccsmcfd (bc0018c2d29f655188a0ed3fa94fdb24) C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
13:14:07.0394 4280 pccsmcfd - ok
13:14:07.0423 4280 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
13:14:07.0424 4280 pci - ok
13:14:07.0452 4280 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
13:14:07.0453 4280 pciide - ok
13:14:07.0474 4280 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
13:14:07.0476 4280 pcmcia - ok
13:14:07.0494 4280 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
13:14:07.0495 4280 pcw - ok
13:14:07.0517 4280 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
13:14:07.0520 4280 PEAUTH - ok
13:14:07.0591 4280 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
13:14:07.0594 4280 PptpMiniport - ok
13:14:07.0608 4280 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
13:14:07.0610 4280 Processor - ok
13:14:07.0649 4280 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
13:14:07.0650 4280 Psched - ok
13:14:07.0697 4280 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
13:14:07.0708 4280 ql2300 - ok
13:14:07.0724 4280 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
13:14:07.0725 4280 ql40xx - ok
13:14:07.0748 4280 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
13:14:07.0749 4280 QWAVEdrv - ok
13:14:07.0764 4280 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
13:14:07.0764 4280 RasAcd - ok
13:14:07.0801 4280 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
13:14:07.0801 4280 RasAgileVpn - ok
13:14:07.0830 4280 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
13:14:07.0832 4280 Rasl2tp - ok
13:14:07.0851 4280 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
13:14:07.0852 4280 RasPppoe - ok
13:14:07.0888 4280 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
13:14:07.0889 4280 RasSstp - ok
13:14:07.0921 4280 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
13:14:07.0923 4280 rdbss - ok
13:14:07.0933 4280 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
13:14:07.0933 4280 rdpbus - ok
13:14:07.0941 4280 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
13:14:07.0942 4280 RDPCDD - ok
13:14:07.0970 4280 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
13:14:07.0972 4280 RDPDR - ok
13:14:07.0995 4280 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
13:14:07.0995 4280 RDPENCDD - ok
13:14:08.0009 4280 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
13:14:08.0010 4280 RDPREFMP - ok
13:14:08.0044 4280 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
13:14:08.0045 4280 RDPWD - ok
13:14:08.0086 4280 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
13:14:08.0088 4280 rdyboost - ok
13:14:08.0143 4280 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
13:14:08.0147 4280 RFCOMM - ok
13:14:08.0215 4280 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
13:14:08.0216 4280 rspndr - ok
13:14:08.0259 4280 RTL8167 (4b42bc58294e83a6a92ec8b88c14c4a3) C:\Windows\system32\DRIVERS\Rt64win7.sys
13:14:08.0262 4280 RTL8167 - ok
13:14:08.0294 4280 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
13:14:08.0295 4280 s3cap - ok
13:14:08.0321 4280 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
13:14:08.0323 4280 sbp2port - ok
13:14:08.0361 4280 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
13:14:08.0362 4280 scfilter - ok
13:14:08.0406 4280 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
13:14:08.0407 4280 secdrv - ok
13:14:08.0441 4280 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
13:14:08.0442 4280 Serenum - ok
13:14:08.0455 4280 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
13:14:08.0456 4280 Serial - ok
13:14:08.0480 4280 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
13:14:08.0481 4280 sermouse - ok
13:14:08.0539 4280 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
13:14:08.0540 4280 sffdisk - ok
13:14:08.0558 4280 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
13:14:08.0559 4280 sffp_mmc - ok
13:14:08.0571 4280 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
13:14:08.0572 4280 sffp_sd - ok
13:14:08.0598 4280 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
13:14:08.0599 4280 sfloppy - ok
13:14:08.0621 4280 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:14:08.0622 4280 SiSRaid2 - ok
13:14:08.0640 4280 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
13:14:08.0641 4280 SiSRaid4 - ok
13:14:08.0658 4280 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
13:14:08.0659 4280 Smb - ok
13:14:08.0969 4280 SNPSTD3 (b8b6b14ee7b2e9806e4373a7dc61b592) C:\Windows\system32\DRIVERS\snpstd3.sys
13:14:09.0013 4280 SNPSTD3 - ok
13:14:09.0038 4280 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
13:14:09.0039 4280 spldr - ok
13:14:09.0091 4280 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
13:14:09.0091 4280 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
13:14:09.0096 4280 sptd ( LockedFile.Multi.Generic ) - warning
13:14:09.0096 4280 sptd - detected LockedFile.Multi.Generic (1)
13:14:09.0158 4280 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
13:14:09.0162 4280 srv - ok
13:14:09.0203 4280 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
13:14:09.0210 4280 srv2 - ok
13:14:09.0233 4280 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
13:14:09.0236 4280 srvnet - ok
13:14:09.0280 4280 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
13:14:09.0281 4280 stexstor - ok
13:14:09.0324 4280 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
13:14:09.0325 4280 storflt - ok
13:14:09.0347 4280 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
13:14:09.0348 4280 storvsc - ok
13:14:09.0369 4280 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
13:14:09.0370 4280 swenum - ok
13:14:09.0443 4280 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
13:14:09.0456 4280 Tcpip - ok
13:14:09.0510 4280 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
13:14:09.0523 4280 TCPIP6 - ok
13:14:09.0556 4280 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
13:14:09.0557 4280 tcpipreg - ok
13:14:09.0582 4280 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
13:14:09.0583 4280 TDPIPE - ok
13:14:09.0589 4280 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
13:14:09.0590 4280 TDTCP - ok
13:14:09.0633 4280 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
13:14:09.0637 4280 tdx - ok
13:14:09.0672 4280 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
13:14:09.0675 4280 TermDD - ok
13:14:09.0743 4280 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
13:14:09.0744 4280 tssecsrv - ok
13:14:09.0794 4280 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
13:14:09.0797 4280 TsUsbFlt - ok
13:14:09.0835 4280 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
13:14:09.0837 4280 tunnel - ok
13:14:09.0871 4280 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
13:14:09.0872 4280 uagp35 - ok
13:14:09.0899 4280 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
13:14:09.0902 4280 udfs - ok
13:14:09.0949 4280 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
13:14:09.0950 4280 uliagpkx - ok
13:14:09.0991 4280 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
13:14:09.0992 4280 umbus - ok
13:14:10.0012 4280 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
13:14:10.0013 4280 UmPass - ok
13:14:10.0052 4280 upperdev (4e93c8496359e97830c75ac36393654d) C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
13:14:10.0053 4280 upperdev - ok
13:14:10.0093 4280 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
13:14:10.0095 4280 usbaudio - ok
13:14:10.0124 4280 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
13:14:10.0126 4280 usbccgp - ok
13:14:10.0153 4280 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
13:14:10.0154 4280 usbcir - ok
13:14:10.0178 4280 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
13:14:10.0179 4280 usbehci - ok
13:14:10.0209 4280 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
13:14:10.0212 4280 usbhub - ok
13:14:10.0248 4280 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\DRIVERS\usbohci.sys
13:14:10.0249 4280 usbohci - ok
13:14:10.0267 4280 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
13:14:10.0268 4280 usbprint - ok
13:14:10.0313 4280 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
13:14:10.0314 4280 usbscan - ok
13:14:10.0369 4280 usbser (4acee387fa8fd39f83564fcd2fc234f2) C:\Windows\system32\drivers\usbser.sys
13:14:10.0372 4280 usbser - ok
13:14:10.0409 4280 UsbserFilt (8844cb19a37b65e27049d4a7786726a9) C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
13:14:10.0411 4280 UsbserFilt - ok
13:14:10.0441 4280 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:14:10.0444 4280 USBSTOR - ok
13:14:10.0480 4280 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
13:14:10.0483 4280 usbuhci - ok
13:14:10.0531 4280 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
13:14:10.0532 4280 vdrvroot - ok
13:14:10.0543 4280 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
13:14:10.0545 4280 vga - ok
13:14:10.0563 4280 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
13:14:10.0564 4280 VgaSave - ok
13:14:10.0596 4280 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
13:14:10.0598 4280 vhdmp - ok
13:14:10.0618 4280 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
13:14:10.0619 4280 viaide - ok
13:14:10.0639 4280 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
13:14:10.0642 4280 vmbus - ok
13:14:10.0664 4280 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
13:14:10.0665 4280 VMBusHID - ok
13:14:10.0681 4280 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
13:14:10.0683 4280 volmgr - ok
13:14:10.0720 4280 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
13:14:10.0723 4280 volmgrx - ok
13:14:10.0741 4280 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
13:14:10.0743 4280 volsnap - ok
13:14:10.0784 4280 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
13:14:10.0786 4280 vsmraid - ok
13:14:10.0804 4280 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
13:14:10.0806 4280 vwifibus - ok
13:14:10.0843 4280 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
13:14:10.0844 4280 WacomPen - ok
13:14:10.0888 4280 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
13:14:10.0892 4280 WANARP - ok
13:14:10.0901 4280 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
13:14:10.0905 4280 Wanarpv6 - ok
13:14:10.0942 4280 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
13:14:10.0943 4280 Wd - ok
13:14:10.0968 4280 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
13:14:10.0972 4280 Wdf01000 - ok
13:14:10.0999 4280 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
13:14:11.0000 4280 WfpLwf - ok
13:14:11.0018 4280 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
13:14:11.0019 4280 WIMMount - ok
13:14:11.0087 4280 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
13:14:11.0087 4280 WinUsb - ok
13:14:11.0142 4280 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
13:14:11.0143 4280 WmiAcpi - ok
13:14:11.0171 4280 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
13:14:11.0172 4280 ws2ifsl - ok
13:14:11.0207 4280 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
13:14:11.0208 4280 WudfPf - ok
13:14:11.0223 4280 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
13:14:11.0224 4280 WUDFRd - ok
13:14:11.0254 4280 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
13:14:11.0261 4280 \Device\Harddisk0\DR0 - ok
13:14:11.0264 4280 Boot (0x1200) (1e107c8b0de50b894188897a22a31d41) \Device\Harddisk0\DR0\Partition0
13:14:11.0265 4280 \Device\Harddisk0\DR0\Partition0 - ok
13:14:11.0279 4280 Boot (0x1200) (81367fc490c40b67ebd4958869995edd) \Device\Harddisk0\DR0\Partition1
13:14:11.0280 4280 \Device\Harddisk0\DR0\Partition1 - ok
13:14:11.0299 4280 Boot (0x1200) (8b1e90a83474cde5b031fcf81c0f9b9b) \Device\Harddisk0\DR0\Partition2
13:14:11.0300 4280 \Device\Harddisk0\DR0\Partition2 - ok
13:14:11.0300 4280 ============================================================
13:14:11.0300 4280 Scan finished
13:14:11.0300 4280 ============================================================
13:14:11.0309 4744 Detected object count: 1
13:14:11.0309 4744 Actual detected object count: 1
13:14:15.0000 4744 sptd ( LockedFile.Multi.Generic ) - skipped by user
13:14:15.0000 4744 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

Logum nerozumim, jak to dopadlo? Dekuji

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: win32 neshta dokoncit odstraneni

#6 Příspěvek od vyosek »

:arrow: Log TDSS Killeru je cisty

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jezevec2104
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 pro 2011 11:10

Re: win32 neshta dokoncit odstraneni

#7 Příspěvek od Jezevec2104 »

Dobry den.
Provedl jsem scan v ComboFix-u a tady je log:


ComboFix 11-12-17.05 - Smisek 18.12.2011 9:16.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3583.2175 [GMT 1:00]
Spuštěný z: c:\users\Smisek\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\directx.sys
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-18 do 2011-12-18 )))))))))))))))))))))))))))))))
.
.
2011-12-18 08:42 . 2011-12-18 08:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-17 10:22 . 2011-12-17 10:22 -------- d-----w- C:\rsit
2011-12-17 10:22 . 2011-12-17 10:22 -------- d-----w- c:\program files\trend micro
2011-12-16 22:47 . 2011-12-16 22:47 -------- d-----w- c:\programdata\Kaspersky Lab
2011-12-16 22:33 . 2011-12-16 22:33 -------- d-----w- c:\program files\CCleaner
2011-12-16 21:18 . 2011-12-16 21:18 -------- d-----w- c:\users\Smisek\AppData\Roaming\Malwarebytes
2011-12-16 21:17 . 2011-12-16 21:17 -------- d-----w- c:\programdata\Malwarebytes
2011-12-16 21:17 . 2011-12-16 21:17 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-12-16 21:17 . 2011-08-31 16:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-16 15:54 . 2011-12-16 15:54 94208 ----a-w- c:\windows\DIIUnin.exe
2011-12-16 15:54 . 2011-12-16 15:54 2829 ----a-w- c:\windows\DIIUnin.pif
2011-12-16 15:25 . 2011-11-21 11:40 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9A029B4C-987A-4EBA-B4F7-A284A888CE31}\mpengine.dll
2011-12-15 22:16 . 1997-08-21 17:44 345600 ----a-w- c:\windows\system\qtim32.dll
2011-12-15 21:34 . 2011-12-15 21:34 -------- d-----w- c:\users\Smisek\Tracing
2011-12-14 15:17 . 2011-10-26 05:21 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 15:17 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-14 15:17 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-14 15:17 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-14 15:16 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-14 15:16 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-12-13 20:03 . 2011-12-13 20:03 -------- d--h--w- c:\programdata\CanonIJEGV
2011-12-13 20:02 . 2011-12-13 20:02 -------- d-----w- c:\program files\VibrateGameDeviceDriver
2011-12-13 20:02 . 2011-12-13 20:02 -------- d-----w- c:\program files (x86)\VibrateGameDeviceDriver
2011-12-13 19:56 . 2011-12-13 19:56 -------- d--h--w- c:\programdata\CanonIJEPPEX2
2011-12-13 19:56 . 2011-12-13 19:56 -------- d--h--w- c:\programdata\CanonEPP
2011-12-13 19:56 . 2011-12-13 19:56 -------- d-----w- c:\users\Smisek\AppData\Roaming\Canon
2011-12-13 19:52 . 2011-05-23 04:00 385536 ----a-w- c:\windows\system32\CNMXLMAW.DLL
2011-12-13 19:45 . 2011-12-13 19:45 -------- d-----w- c:\program files\Common Files\CANON
2011-12-13 19:45 . 2011-12-13 19:45 -------- d-----w- c:\programdata\CanonIJWSpt
2011-12-13 19:44 . 2011-12-13 19:44 -------- d-----w- c:\program files\Canon
2011-12-13 19:43 . 2011-12-13 19:43 -------- d--h--w- c:\programdata\CanonBJ
2011-12-13 19:43 . 2011-05-23 04:00 98816 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPPAW.DLL
2011-12-13 19:43 . 2011-05-23 04:00 30208 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPDAW.DLL
2011-12-13 19:43 . 2011-12-13 19:43 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2011-12-13 19:43 . 2011-05-23 04:00 385536 ----a-w- c:\windows\system32\CNMLMAW.DLL
2011-12-13 19:43 . 2011-02-03 09:20 256000 ----a-w- c:\windows\system32\CNMIUAW.DLL
2011-12-13 19:40 . 2011-12-13 19:49 -------- d-----w- c:\program files (x86)\Canon
2011-12-12 18:02 . 2011-12-15 22:17 21840 ----atw- c:\windows\SysWow64\SIntfNT.dll
2011-12-12 18:02 . 2011-12-15 22:17 17212 ----atw- c:\windows\SysWow64\SIntf32.dll
2011-12-12 18:02 . 2011-12-15 22:17 12067 ----atw- c:\windows\SysWow64\SIntf16.dll
2011-12-11 21:34 . 2011-12-11 21:34 -------- d-----w- c:\programdata\McAfee
2011-11-21 16:17 . 2011-11-21 16:17 -------- d-----w- c:\windows\system32\Macromed
2011-11-19 13:59 . 2011-11-19 13:59 -------- d-----w- c:\users\Smisek\AppData\Local\NokiaAccount
2011-11-19 13:56 . 2011-11-19 13:56 -------- d-----w- c:\programdata\Nokia
2011-11-19 13:55 . 2011-11-19 13:55 -------- d-----w- c:\program files (x86)\PC Connectivity Solution
2011-11-18 20:02 . 2011-11-18 20:02 -------- d-----w- c:\program files (x86)\Common Files\Java
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-11 21:34 . 2011-05-21 20:03 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-28 18:01 . 2011-04-22 21:10 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-04-22 21:10 199816 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-11-28 18:01 . 2011-04-22 21:10 256960 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:54 . 2011-04-22 21:10 591192 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-04-22 21:10 304472 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-04-22 21:10 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-04-22 21:10 58712 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-04-22 21:10 66904 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-11-28 17:51 . 2011-04-22 21:10 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-10-03 04:06 . 2011-06-29 11:40 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-09-29 16:29 . 2011-11-09 18:14 1923952 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-04-24 39408]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"OscarEditor"="c:\program files (x86)\OSCAR Editor X7\OscarEditor.exe" [2010-07-22 2636800]
"NokiaSuite.exe"="c:\program files (x86)\Nokia\Nokia Suite\NokiaSuite.exe" [2011-11-01 1053056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 98304]
"Six Engine"="c:\program files (x86)\ASUS\EPU\EPU.exe" [2010-06-14 5309056]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2010-03-05 411864]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"iPScan5x"="c:\windows\iPScan5x.EXE" [2008-09-06 94208]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2011-03-28 1611160]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-22 136176]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-22 136176]
R3 IPUSBCam95;iP295x Plug;c:\windows\system32\Drivers\iP295x.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AODDriver;AODDriver;c:\program files\ASUS\GPU Boost Driver\amd64\AODDriver.sys [2010-03-12 52280]
S3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - AODDRIVER
.
Obsah adresáře 'Naplánované úlohy'
.
2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-22 21:10]
.
2011-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-22 21:10]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-11-11 2345848]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-15 2779024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://seznam.cz/
mLocal Page = c:\windows\SysWOW64\blank.htm
Trusted Zone: impuls.cz\www
TCP: DhcpNameServer = 11.168.55.1
FF - ProfilePath - c:\users\Smisek\AppData\Roaming\Mozilla\Firefox\Profiles\8l54pyh0.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Google Chrome - c:\users\Smisek\AppData\Local\Google\Chrome\Application\16.0.912.63\Installer\setup.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-12-18 09:44:03
ComboFix-quarantined-files.txt 2011-12-18 08:44
.
Před spuštěním: Volných bajtů: 12 821 286 912
Po spuštění: Volných bajtů: 12 547 538 944
.
- - End Of File - - 532CB723C912D66BFC6ACEB275A32D32

Prosim o radu co dale. Diky

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: win32 neshta dokoncit odstraneni

#8 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    "DAEMON Tools Lite"=-
    "OscarEditor"=-
    "NokiaSuite.exe"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"=-
    "BCU"=-
    "Adobe ARM"=-
    "SunJavaUpdateSched"=-
    "Malwarebytes' Anti-Malware"=-
    
    Driver::
    gupdate
    gupdatem
    
    File::
    c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    AtJob::
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jezevec2104
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 pro 2011 11:10

Re: win32 neshta dokoncit odstraneni

#9 Příspěvek od Jezevec2104 »

Provedl jsem, musel jsem jeste jednou restartovat, nefungovaly prohlizece.

ComboFix 11-12-17.05 - Smisek 18.12.2011 11:08:11.2.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3583.2671 [GMT 1:00]
Spuštěný z: c:\users\Smisek\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Smisek\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-18 do 2011-12-18 )))))))))))))))))))))))))))))))
.
.
2011-12-17 10:22 . 2011-12-17 10:22 -------- d-----w- C:\rsit
2011-12-17 10:22 . 2011-12-17 10:22 -------- d-----w- c:\program files\trend micro
2011-12-16 22:47 . 2011-12-16 22:47 -------- d-----w- c:\programdata\Kaspersky Lab
2011-12-16 22:33 . 2011-12-16 22:33 -------- d-----w- c:\program files\CCleaner
2011-12-16 21:18 . 2011-12-16 21:18 -------- d-----w- c:\users\Smisek\AppData\Roaming\Malwarebytes
2011-12-16 21:17 . 2011-12-16 21:17 -------- d-----w- c:\programdata\Malwarebytes
2011-12-16 21:17 . 2011-12-16 21:17 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-12-16 21:17 . 2011-08-31 16:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-16 15:54 . 2011-12-16 15:54 94208 ----a-w- c:\windows\DIIUnin.exe
2011-12-16 15:54 . 2011-12-16 15:54 2829 ----a-w- c:\windows\DIIUnin.pif
2011-12-16 15:25 . 2011-11-21 11:40 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9A029B4C-987A-4EBA-B4F7-A284A888CE31}\mpengine.dll
2011-12-15 22:16 . 1997-08-21 17:44 345600 ----a-w- c:\windows\system\qtim32.dll
2011-12-15 21:34 . 2011-12-15 21:34 -------- d-----w- c:\users\Smisek\Tracing
2011-12-14 15:17 . 2011-10-26 05:21 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 15:17 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-14 15:17 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-14 15:17 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-14 15:16 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-14 15:16 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-12-13 20:03 . 2011-12-13 20:03 -------- d--h--w- c:\programdata\CanonIJEGV
2011-12-13 20:02 . 2011-12-13 20:02 -------- d-----w- c:\program files\VibrateGameDeviceDriver
2011-12-13 20:02 . 2011-12-13 20:02 -------- d-----w- c:\program files (x86)\VibrateGameDeviceDriver
2011-12-13 19:56 . 2011-12-13 19:56 -------- d--h--w- c:\programdata\CanonIJEPPEX2
2011-12-13 19:56 . 2011-12-13 19:56 -------- d--h--w- c:\programdata\CanonEPP
2011-12-13 19:56 . 2011-12-13 19:56 -------- d-----w- c:\users\Smisek\AppData\Roaming\Canon
2011-12-13 19:52 . 2011-05-23 04:00 385536 ----a-w- c:\windows\system32\CNMXLMAW.DLL
2011-12-13 19:45 . 2011-12-13 19:45 -------- d-----w- c:\program files\Common Files\CANON
2011-12-13 19:45 . 2011-12-13 19:45 -------- d-----w- c:\programdata\CanonIJWSpt
2011-12-13 19:44 . 2011-12-13 19:44 -------- d-----w- c:\program files\Canon
2011-12-13 19:43 . 2011-12-13 19:43 -------- d--h--w- c:\programdata\CanonBJ
2011-12-13 19:43 . 2011-05-23 04:00 98816 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPPAW.DLL
2011-12-13 19:43 . 2011-05-23 04:00 30208 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPDAW.DLL
2011-12-13 19:43 . 2011-12-13 19:43 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2011-12-13 19:43 . 2011-05-23 04:00 385536 ----a-w- c:\windows\system32\CNMLMAW.DLL
2011-12-13 19:43 . 2011-02-03 09:20 256000 ----a-w- c:\windows\system32\CNMIUAW.DLL
2011-12-13 19:40 . 2011-12-13 19:49 -------- d-----w- c:\program files (x86)\Canon
2011-12-12 18:02 . 2011-12-15 22:17 21840 ----atw- c:\windows\SysWow64\SIntfNT.dll
2011-12-12 18:02 . 2011-12-15 22:17 17212 ----atw- c:\windows\SysWow64\SIntf32.dll
2011-12-12 18:02 . 2011-12-15 22:17 12067 ----atw- c:\windows\SysWow64\SIntf16.dll
2011-12-11 21:34 . 2011-12-11 21:34 -------- d-----w- c:\programdata\McAfee
2011-11-21 16:17 . 2011-11-21 16:17 -------- d-----w- c:\windows\system32\Macromed
2011-11-19 13:59 . 2011-11-19 13:59 -------- d-----w- c:\users\Smisek\AppData\Local\NokiaAccount
2011-11-19 13:56 . 2011-11-19 13:56 -------- d-----w- c:\programdata\Nokia
2011-11-19 13:55 . 2011-11-19 13:55 -------- d-----w- c:\program files (x86)\PC Connectivity Solution
2011-11-18 20:02 . 2011-11-18 20:02 -------- d-----w- c:\program files (x86)\Common Files\Java
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-11 21:34 . 2011-05-21 20:03 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-28 18:01 . 2011-04-22 21:10 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-04-22 21:10 199816 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-11-28 18:01 . 2011-04-22 21:10 256960 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:54 . 2011-04-22 21:10 591192 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-04-22 21:10 304472 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-04-22 21:10 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-04-22 21:10 58712 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-04-22 21:10 66904 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-11-28 17:51 . 2011-04-22 21:10 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-10-03 04:06 . 2011-06-29 11:40 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-09-29 16:29 . 2011-11-09 18:14 1923952 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-18_08.42.20 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2011-12-18 08:12 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-12-18 10:14 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-12-18 10:14 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-12-18 08:12 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-12-18 08:12 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-12-18 10:14 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-04-22 18:53 . 2011-12-17 12:41 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-04-22 18:53 . 2011-12-18 09:59 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-12-16 22:33 . 2011-12-18 09:59 49152 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-12-17 12:41 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-12-18 09:59 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-06-10 19:31 . 2011-12-18 10:12 5155 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat
- 2011-06-10 19:31 . 2011-12-17 23:01 5155 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat
+ 2011-12-18 10:13 . 2011-12-18 10:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-12-18 08:10 . 2011-12-18 08:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-12-18 10:13 . 2011-12-18 10:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-12-18 08:10 . 2011-12-18 08:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-04-24 10:54 . 2011-12-18 09:58 408152 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2009-07-14 05:01 . 2011-12-18 10:12 814600 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-12-17 23:01 814600 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Six Engine"="c:\program files (x86)\ASUS\EPU\EPU.exe" [2010-06-14 5309056]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"iPScan5x"="c:\windows\iPScan5x.EXE" [2008-09-06 94208]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2011-03-28 1611160]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 IPUSBCam95;iP295x Plug;c:\windows\system32\Drivers\iP295x.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AODDriver;AODDriver;c:\program files\ASUS\GPU Boost Driver\amd64\AODDriver.sys [2010-03-12 52280]
S3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-11-11 2345848]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-15 2779024]
"combofix"="c:\combofix\CF26671.3XE" [2010-11-20 345088]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://seznam.cz/
mLocal Page = c:\windows\SysWOW64\blank.htm
Trusted Zone: impuls.cz\www
TCP: DhcpNameServer = 11.168.55.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\shell32.dll
FF - ProfilePath - c:\users\Smisek\AppData\Roaming\Mozilla\Firefox\Profiles\8l54pyh0.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files\ASUS\GPU Boost Driver\GpuBoostServer.exe
.
**************************************************************************
.
Celkový čas: 2011-12-18 11:19:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-12-18 10:19
ComboFix2.txt 2011-12-18 08:44
.
Před spuštěním: Volných bajtů: 12 590 997 504
Po spuštění: Volných bajtů: 12 316 471 296
.
- - End Of File - - 10D95D9C26964187B1EB762D577C822A

Prosim o kontrolu, dekuji.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: win32 neshta dokoncit odstraneni

#10 Příspěvek od vyosek »

Log jiz vypada OK, jak se chova PC :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jezevec2104
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 pro 2011 11:10

Re: win32 neshta dokoncit odstraneni

#11 Příspěvek od Jezevec2104 »

No nefunguje kolecko mysi, nacitani slozek je subjektivne pomale. Zobrazeni vypada ok. Jeste se pokusim vysledovat. Jake navrhujete dalsi reseni? Mam provest reinstal nebo jen odstranovat chyby? Dekuji za spostu casu venovaneho me blbosti :oops: Musim opravdu hodne podekovat.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: win32 neshta dokoncit odstraneni

#12 Příspěvek od vyosek »

:arrow: A kdyz pripojite jinou mys tak funguje, tohle bych spise videl na chybu samotne mysi nez ucinek haveti...

:arrow: Se slozkami zkusime neco udelat

:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :files
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Kliknete na cervene tlacitko MoveIt!
  • Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jezevec2104
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 pro 2011 11:10

Re: win32 neshta dokoncit odstraneni

#13 Příspěvek od Jezevec2104 »

Provedeno, zda se to byt v poradku:
All processes killed
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Smisek
->Temp folder emptied: 3756 bytes
->Temporary Internet Files folder emptied: 2378068 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 22282417 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 637 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 49621 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 24,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: Smisek
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.19.0 log created on 12182011_115014

Files moved on Reboot...
C:\Users\Smisek\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Windows\temp\_avast_\unp238762403.tmp moved successfully.
File C:\Windows\temp\_avast_\Webshlock.txt not found!

Registry entries deleted on Reboot...

Ted to vypada celkem vporedku, myslite ze je to vse?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: win32 neshta dokoncit odstraneni

#14 Příspěvek od vyosek »

:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Doporucuji provest defragmentaci disku
  • Nejjednodussi (ale nejmene ucinny) zpusob je pomoci utility ve windowsech
    • Kliknete na Tento pocitac, dale na disk kliknete pravym tlacitkem, vyberte Vlastnosti
    • prepnete se do zalozky Nastroje
    • Nyni vidite pomucky Defragmentace - spustte ji kliknutim na Defragmentovat
    • Toto provedte se vsemi disky
  • Dalsi moznosti (a mnou doporucenou) je pres programek Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
    • Program stahnete, nainstalujte (dejte fajfku pryc u yahoo toolbaru) a spustte
    • Kliknete na Analyzovat
    • Pokud je ve sloupci Fragmentováno vice jak 5%, doporucuji provest defragmentaci (klik na Defragmentovat)
    • Postup provedte se vsemi disky
  • Posledni moznost je pres jednoduchy programek JKDefrag http://www.stahuj.centrum.cz/utility_a_ ... /jkdefrag/
    • Vyhodou programku je, ze se neinstaluje
    • Staci tedy jen stahnout dle verze vaseho OS a rozbalit
    • Nasledne spustit pomoci souboru JKDefrag pripadne JKDefrag64
    • Probehne analyza disku a nasledne i defragmentace
:arrow: Poprosim o novy log z RSIT a napiste co PC
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jezevec2104
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 pro 2011 11:10

Re: win32 neshta dokoncit odstraneni

#15 Příspěvek od Jezevec2104 »

Uz mam skoro vse jen cekam na dokonceni defragmentace vsech disku coz dnes asi nebude. :cry:
Pocitac se chova temer normalne jen treba na strance stahuj.cz musim nekolikrat obnovovat nez se mi zobrazi obsah...
Take bych se rad zeptal co znamenaji takove male stity u ikon. Toto se mi zobrazuje asi od doby co jsem zjistil vir viz priloha
Přílohy
ikony.jpg
ikony.jpg (22.78 KiB) Zobrazeno 2419 x

Odpovědět