
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
pro vyosek (externí disk - data - ztráta?)
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: pro vyosek (externí disk - data - ztráta?)
Ano disk je samozřejmě celou dobu zapnutý a jede.. ve složkách se dá normálně projíždět, vše je na svém místě a např. hudba jde normálně otevřít a spustit.
Výsledek z OTL:
========== FILES ==========
Folder move failed. F:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665 scheduled to be moved on reboot.
Folder move failed. F:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665 scheduled to be moved on reboot.
Folder move failed. F:\RECYCLER scheduled to be moved on reboot.
File move failed. F:\Autorun.V00inf scheduled to be moved on reboot.
File move failed. F:\Autorun.Vinf scheduled to be moved on reboot.
========== COMMANDS ==========
OTL by OldTimer - Version 3.2.54.0 log created on 07202012_212450
Files\Folders moved on Reboot...
Folder move failed. F:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665 scheduled to be moved on reboot.
Folder move failed. F:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665 scheduled to be moved on reboot.
Folder move failed. F:\RECYCLER scheduled to be moved on reboot.
File move failed. F:\Autorun.V00inf scheduled to be moved on reboot.
File move failed. F:\Autorun.Vinf scheduled to be moved on reboot.
PendingFileRenameOperations files...
File F:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665 not found!
File F:\RECYCLER not found!
[2008.04.14 08:51:46 | 000,095,034 | RHS- | M] () F:\Autorun.V00inf : Unable to obtain MD5
[2008.04.14 08:51:46 | 000,095,034 | RHS- | M] () F:\Autorun.Vinf : Unable to obtain MD5
Registry entries deleted on Reboot...
Výsledek z OTL:
========== FILES ==========
Folder move failed. F:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665 scheduled to be moved on reboot.
Folder move failed. F:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665 scheduled to be moved on reboot.
Folder move failed. F:\RECYCLER scheduled to be moved on reboot.
File move failed. F:\Autorun.V00inf scheduled to be moved on reboot.
File move failed. F:\Autorun.Vinf scheduled to be moved on reboot.
========== COMMANDS ==========
OTL by OldTimer - Version 3.2.54.0 log created on 07202012_212450
Files\Folders moved on Reboot...
Folder move failed. F:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665 scheduled to be moved on reboot.
Folder move failed. F:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665 scheduled to be moved on reboot.
Folder move failed. F:\RECYCLER scheduled to be moved on reboot.
File move failed. F:\Autorun.V00inf scheduled to be moved on reboot.
File move failed. F:\Autorun.Vinf scheduled to be moved on reboot.
PendingFileRenameOperations files...
File F:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665 not found!
File F:\RECYCLER not found!
[2008.04.14 08:51:46 | 000,095,034 | RHS- | M] () F:\Autorun.V00inf : Unable to obtain MD5
[2008.04.14 08:51:46 | 000,095,034 | RHS- | M] () F:\Autorun.Vinf : Unable to obtain MD5
Registry entries deleted on Reboot...
Re: pro vyosek (externí disk - data - ztráta?)



- Rozbalte stazeny rar, tak aby byla jen jedna slozka avz4 a spustte avz.exe
- Kliknete nahore na File a nasledne vyberte Custom scripts
- Do okenka nakopirujte skript, ktery mate nize
Kód: Vybrat vše
begin SetAVZGuardStatus(True); SearchRootkit(true, true); ClearQuarantine; DeleteFile('F:\Autorun.V00inf'); DeleteFile('F:\Autorun.Vinf'); DeleteDirectory('F:\RECYCLER'); RebootWindows(true); end.
- Nyni kliknete na Run cimz akci spustite
- po restartu PC je mozne, ze se nacte pruvodce hardwarem, s klidem stornujte (klik na STORNO)

- Do okna vlozte skript nize
Kód: Vybrat vše
:dir f:\
- Kliknete na Look
- Tlacitko Look se zmeni na Scanning a zsedne
- Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
- Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
Re: pro vyosek (externí disk - data - ztráta?)
SystemLook 30.07.11 by jpshortstuff
Log created at 21:44 on 20/07/2012 by Luk
Administrator - Elevation successful
========== dir ==========
f: - Parameters: "(none)"
---Files---
None found.
---Folders---
$RECYCLE.BIN d--hs-- [06:45 20/07/2012]
Autorun.inf drahs-- [17:00 20/07/2012]
FRIGO d------ [16:19 09/08/2010]
KŮČA d------ [17:26 28/10/2011]
NOVÁ SLOŽKA d------ [13:35 12/12/2011]
RECYCLER d--h--- [19:48 08/07/2010]
specops d------ [10:16 10/07/2012]
System Volume Information d--hs-- [19:48 08/07/2010]
tom d------ [14:34 18/07/2012]
ZÁLOHA 2011 transformation HP on MSI d------ [14:36 17/06/2011]
ZÁLOHA 2012 d------ [16:51 08/04/2012]
ZÁLOHA EVA 2012 d------ [20:12 22/06/2012]
-= EOF =-
Log created at 21:44 on 20/07/2012 by Luk
Administrator - Elevation successful
========== dir ==========
f: - Parameters: "(none)"
---Files---
None found.
---Folders---
$RECYCLE.BIN d--hs-- [06:45 20/07/2012]
Autorun.inf drahs-- [17:00 20/07/2012]
FRIGO d------ [16:19 09/08/2010]
KŮČA d------ [17:26 28/10/2011]
NOVÁ SLOŽKA d------ [13:35 12/12/2011]
RECYCLER d--h--- [19:48 08/07/2010]
specops d------ [10:16 10/07/2012]
System Volume Information d--hs-- [19:48 08/07/2010]
tom d------ [14:34 18/07/2012]
ZÁLOHA 2011 transformation HP on MSI d------ [14:36 17/06/2011]
ZÁLOHA 2012 d------ [16:51 08/04/2012]
ZÁLOHA EVA 2012 d------ [20:12 22/06/2012]
-= EOF =-
Re: pro vyosek (externí disk - data - ztráta?)
Co se týká antiviru, tak NOD32 má v karanténě uloženo pár nějaký červů a infiltrací právě z toho F - z externího disku. Tak to jen kdyby to mělou nějakou váhu tato informace. Jinak složky jsou stále všechny pohromadě a soubory vypadají že jsou komplet.
Re: pro vyosek (externí disk - data - ztráta?)
Tak jeste uklidime
T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
Karantenu NODu muzete s klidem vyprazdnit
Poprosim o novy log z RSIT a napiste ci jsou nejake problemy


- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy



Re: pro vyosek (externí disk - data - ztráta?)
LOG Z RSIT:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Luk at 2012-07-20 22:25:58
Microsoft Windows 7 Professional
System drive C: has 22 GB (28%) free of 76 GB
Total RAM: 1535 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:26:19, on 20.7.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\SOUNDMAN.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Luk\Desktop\RSIT.exe
C:\Program Files\trend micro\Luk.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Luk\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Network LookOut Agent (NetworkLookOutAgent) - Unknown owner - C:\Program Files\Network LookOut Administrator Pro\bin\NLAgentProSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
--
End of file - 5251 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17 3855520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\Windows\SOUNDMAN.EXE [2009-04-14 604704]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-07-02 2202704]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-07-20 22:25:58 ----D---- C:\rsit
2012-07-20 22:17:35 ----D---- C:\Program Files\CCleaner
2012-07-20 21:40:09 ----A---- C:\Windows\system32\drivers\uti3ndu1.sys
2012-07-20 21:39:57 ----A---- C:\Windows\system32\drivers\uji3ndu1.sys
2012-07-20 19:00:47 ----RASHD---- C:\Autorun.inf
2012-07-19 23:27:15 ----D---- C:\Program Files\trend micro
2012-07-19 23:02:42 ----D---- C:\totalcmd
2012-07-05 11:35:49 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2012-07-05 10:26:52 ----D---- C:\Program Files\Batman Arkham City
======List of files/folders modified in the last 1 month======
2012-07-20 22:26:09 ----D---- C:\Windows\Prefetch
2012-07-20 22:25:59 ----D---- C:\Windows\Temp
2012-07-20 22:19:32 ----D---- C:\Windows\System32
2012-07-20 22:19:32 ----D---- C:\Windows\inf
2012-07-20 22:19:32 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-07-20 22:18:59 ----D---- C:\Windows\Panther
2012-07-20 22:18:59 ----D---- C:\Users\Luk\AppData\Roaming\uTorrent
2012-07-20 22:18:59 ----D---- C:\Users\Luk\AppData\Roaming\Skype
2012-07-20 22:18:59 ----D---- C:\Users\Luk\AppData\Roaming\DAEMON Tools Lite
2012-07-20 22:18:58 ----D---- C:\Windows\Logs
2012-07-20 22:18:58 ----D---- C:\Windows\debug
2012-07-20 22:18:58 ----D---- C:\Windows
2012-07-20 22:17:37 ----D---- C:\Windows\system32\Tasks
2012-07-20 22:17:35 ----D---- C:\Program Files
2012-07-20 21:57:30 ----D---- C:\Windows\system32\config
2012-07-20 21:40:09 ----D---- C:\Windows\system32\drivers
2012-07-20 18:59:29 ----SHD---- C:\$Recycle.Bin
2012-07-20 08:45:13 ----D---- C:\Windows\system32\drivers\etc
2012-07-19 23:14:45 ----D---- C:\Users\Luk\AppData\Roaming\ICQ
2012-07-19 23:10:20 ----D---- C:\Windows\Tasks
2012-07-19 23:10:20 ----D---- C:\Windows\system32\wfp
2012-07-19 23:10:18 ----D---- C:\Windows\system32\wbem
2012-07-19 23:10:06 ----D---- C:\Windows\system32\DriverStore
2012-07-19 23:10:06 ----D---- C:\Windows\system32\CodeIntegrity
2012-07-19 23:10:06 ----D---- C:\Windows\system32\catroot2
2012-07-19 23:10:05 ----D---- C:\Windows\AppCompat
2012-07-19 23:10:05 ----D---- C:\Users\Luk\AppData\Roaming\vlc
2012-07-19 23:10:05 ----D---- C:\Users\Luk\AppData\Roaming\PhotoFiltre 7
2012-07-19 23:10:02 ----D---- C:\Program Files\TeamViewer
2012-07-19 23:09:59 ----D---- C:\Windows\registration
2012-07-19 23:09:54 ----D---- C:\Users\Luk\AppData\Roaming\TeamViewer
2012-07-19 23:09:53 ----SD---- C:\Users\Luk\AppData\Roaming\Microsoft
2012-07-19 23:08:17 ----SHD---- C:\System Volume Information
2012-07-05 11:35:53 ----SHD---- C:\Windows\Installer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-07-25 218688]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-04-28 114984]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-06-24 136120]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-04-28 96896]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\Windows\system32\drivers\RTKVAC.SYS [2009-06-18 4172832]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 uji3ndu1;AVZ-SG Kernel Driver; \??\C:\Windows\system32\Drivers\uji3ndu1.sys [2012-07-20 10240]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 uti3ndu1;AVZ Kernel Driver; \??\C:\Windows\system32\Drivers\uti3ndu1.sys [2012-07-20 7168]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-07-02 810144]
R2 NetworkLookOutAgent;Network LookOut Agent; C:\Program Files\Network LookOut Administrator Pro\bin\NLAgentProSvc.exe [2012-04-07 1322592]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 129640]
R2 TeamViewer7;TeamViewer 7; C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-02-15 158856]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-07-02 33584]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-07-25 1343400]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Luk at 2012-07-20 22:25:58
Microsoft Windows 7 Professional
System drive C: has 22 GB (28%) free of 76 GB
Total RAM: 1535 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:26:19, on 20.7.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\SOUNDMAN.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Luk\Desktop\RSIT.exe
C:\Program Files\trend micro\Luk.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Luk\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Network LookOut Agent (NetworkLookOutAgent) - Unknown owner - C:\Program Files\Network LookOut Administrator Pro\bin\NLAgentProSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
--
End of file - 5251 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17 3855520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\Windows\SOUNDMAN.EXE [2009-04-14 604704]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-07-02 2202704]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-07-20 22:25:58 ----D---- C:\rsit
2012-07-20 22:17:35 ----D---- C:\Program Files\CCleaner
2012-07-20 21:40:09 ----A---- C:\Windows\system32\drivers\uti3ndu1.sys
2012-07-20 21:39:57 ----A---- C:\Windows\system32\drivers\uji3ndu1.sys
2012-07-20 19:00:47 ----RASHD---- C:\Autorun.inf
2012-07-19 23:27:15 ----D---- C:\Program Files\trend micro
2012-07-19 23:02:42 ----D---- C:\totalcmd
2012-07-05 11:35:49 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2012-07-05 10:26:52 ----D---- C:\Program Files\Batman Arkham City
======List of files/folders modified in the last 1 month======
2012-07-20 22:26:09 ----D---- C:\Windows\Prefetch
2012-07-20 22:25:59 ----D---- C:\Windows\Temp
2012-07-20 22:19:32 ----D---- C:\Windows\System32
2012-07-20 22:19:32 ----D---- C:\Windows\inf
2012-07-20 22:19:32 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-07-20 22:18:59 ----D---- C:\Windows\Panther
2012-07-20 22:18:59 ----D---- C:\Users\Luk\AppData\Roaming\uTorrent
2012-07-20 22:18:59 ----D---- C:\Users\Luk\AppData\Roaming\Skype
2012-07-20 22:18:59 ----D---- C:\Users\Luk\AppData\Roaming\DAEMON Tools Lite
2012-07-20 22:18:58 ----D---- C:\Windows\Logs
2012-07-20 22:18:58 ----D---- C:\Windows\debug
2012-07-20 22:18:58 ----D---- C:\Windows
2012-07-20 22:17:37 ----D---- C:\Windows\system32\Tasks
2012-07-20 22:17:35 ----D---- C:\Program Files
2012-07-20 21:57:30 ----D---- C:\Windows\system32\config
2012-07-20 21:40:09 ----D---- C:\Windows\system32\drivers
2012-07-20 18:59:29 ----SHD---- C:\$Recycle.Bin
2012-07-20 08:45:13 ----D---- C:\Windows\system32\drivers\etc
2012-07-19 23:14:45 ----D---- C:\Users\Luk\AppData\Roaming\ICQ
2012-07-19 23:10:20 ----D---- C:\Windows\Tasks
2012-07-19 23:10:20 ----D---- C:\Windows\system32\wfp
2012-07-19 23:10:18 ----D---- C:\Windows\system32\wbem
2012-07-19 23:10:06 ----D---- C:\Windows\system32\DriverStore
2012-07-19 23:10:06 ----D---- C:\Windows\system32\CodeIntegrity
2012-07-19 23:10:06 ----D---- C:\Windows\system32\catroot2
2012-07-19 23:10:05 ----D---- C:\Windows\AppCompat
2012-07-19 23:10:05 ----D---- C:\Users\Luk\AppData\Roaming\vlc
2012-07-19 23:10:05 ----D---- C:\Users\Luk\AppData\Roaming\PhotoFiltre 7
2012-07-19 23:10:02 ----D---- C:\Program Files\TeamViewer
2012-07-19 23:09:59 ----D---- C:\Windows\registration
2012-07-19 23:09:54 ----D---- C:\Users\Luk\AppData\Roaming\TeamViewer
2012-07-19 23:09:53 ----SD---- C:\Users\Luk\AppData\Roaming\Microsoft
2012-07-19 23:08:17 ----SHD---- C:\System Volume Information
2012-07-05 11:35:53 ----SHD---- C:\Windows\Installer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-07-25 218688]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-04-28 114984]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-06-24 136120]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-04-28 96896]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\Windows\system32\drivers\RTKVAC.SYS [2009-06-18 4172832]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 uji3ndu1;AVZ-SG Kernel Driver; \??\C:\Windows\system32\Drivers\uji3ndu1.sys [2012-07-20 10240]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 uti3ndu1;AVZ Kernel Driver; \??\C:\Windows\system32\Drivers\uti3ndu1.sys [2012-07-20 7168]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-07-02 810144]
R2 NetworkLookOutAgent;Network LookOut Agent; C:\Program Files\Network LookOut Administrator Pro\bin\NLAgentProSvc.exe [2012-04-07 1322592]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 129640]
R2 TeamViewer7;TeamViewer 7; C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-02-15 158856]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-07-02 33584]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-07-25 1343400]
-----------------EOF-----------------
Re: pro vyosek (externí disk - data - ztráta?)
Log se zda OK, co nas pacient 

Re: pro vyosek (externí disk - data - ztráta?)
Zkouším vše co mě napadá, všechny data zdají se být tam kde byly, hudba hraje, foto se otevřou, další dokumenty atd. taktéž. Zeptám se asi blbě, ale je tedy jako úplně po všem?
Všechno se chová tak jako dřív, tak budu věřit že je to ok.
Musím říct, že to pro mě byla taková škola, že všechno už budu zálohovat min. na 3x a pravidelně. Když napišu, že jste mi prakticky zachránil život, tak nepřehánim, protože některé ty věci, které tam na externím disku jsou, potřebuji i k práci a brigádě a zrovna hned zítra.
Opravdu ještě jednou největší díky. Ani tomu nemůžu uvěřit. Sice si nemůžu moc vyskakovat, ale vyhledam tady na foru info abych věděl co a kam, a přispěju buď přes paysec nebo normálně přes BÚ alespoň na provoz fóra, nebo Vám. Nenapadlo by mě asi už ani ve snu, že se v dnešní době bude zabývat někdo mým problém, natolik intenzivně a ještě navíc bude všemožně zkoušet najít řešení a pomoc.
Díky ještě jednou za naprosto profesionální přístup a pomoc, za naprosto srozumitelný postup a řešení i pro někoho, kdo slyšel LOG poprvé v životě. Mějte se hezky a ať se daří.. Zatím Nashle a dobrou noc.

Musím říct, že to pro mě byla taková škola, že všechno už budu zálohovat min. na 3x a pravidelně. Když napišu, že jste mi prakticky zachránil život, tak nepřehánim, protože některé ty věci, které tam na externím disku jsou, potřebuji i k práci a brigádě a zrovna hned zítra.
Opravdu ještě jednou největší díky. Ani tomu nemůžu uvěřit. Sice si nemůžu moc vyskakovat, ale vyhledam tady na foru info abych věděl co a kam, a přispěju buď přes paysec nebo normálně přes BÚ alespoň na provoz fóra, nebo Vám. Nenapadlo by mě asi už ani ve snu, že se v dnešní době bude zabývat někdo mým problém, natolik intenzivně a ještě navíc bude všemožně zkoušet najít řešení a pomoc.
Díky ještě jednou za naprosto profesionální přístup a pomoc, za naprosto srozumitelný postup a řešení i pro někoho, kdo slyšel LOG poprvé v životě. Mějte se hezky a ať se daří.. Zatím Nashle a dobrou noc.
Re: pro vyosek (externí disk - data - ztráta?)



Nemate zac, rad jsem pomohl

