Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

policie vir velky problem

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Lokhys
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 19 bře 2013 09:01

Re: policie vir velky problem

#61 Příspěvek od Lokhys »

aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-03-19 20:05:36
-----------------------------
20:05:36.062 OS Version: Windows 5.1.2600 Service Pack 3
20:05:36.062 Number of processors: 1 586 0x209
20:05:36.078 ComputerName: LUKASEK-31FF2A8 UserName: Lukasek
20:05:37.968 Initialize success
20:05:38.218 AVAST engine defs: 13031900
20:05:46.578 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
20:05:46.578 Disk 0 Vendor: WDC_WD1200BB-00DWA0 15.05R15 Size: 111427MB BusType: 3
20:05:46.671 Disk 0 MBR read successfully
20:05:46.671 Disk 0 MBR scan
20:05:46.671 Disk 0 Windows XP default MBR code
20:05:46.687 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 111419 MB offset 63
20:05:46.687 Disk 0 scanning sectors +228187260
20:05:46.828 Disk 0 scanning C:\WINDOWS\system32\drivers
20:06:02.218 Service scanning
20:06:23.140 Modules scanning
20:06:33.703 Disk 0 trace - called modules:
20:06:33.734 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys viaide.sys PCIIDEX.SYS
20:06:33.734 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89e85ab8]
20:06:33.734 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\00000067[0x89ec29e8]
20:06:33.734 5 ACPI.sys[f75ae620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x89ea9d98]
20:06:34.484 AVAST engine scan C:\WINDOWS
20:06:42.140 AVAST engine scan C:\WINDOWS\system32
20:13:33.578 AVAST engine scan C:\WINDOWS\system32\drivers
20:14:10.421 AVAST engine scan C:\Documents and Settings\Lukasek
20:22:56.625 AVAST engine scan C:\Documents and Settings\All Users
20:24:13.093 Scan finished successfully
20:37:21.718 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Lukasek\Plocha\MBR.dat"
20:37:21.734 The log file has been saved successfully to "C:\Documents and Settings\Lukasek\Plocha\aswMBR.txt"

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: policie vir velky problem

#62 Příspěvek od vyosek »

:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Kliknete na volbu Change parametrs
  • V okne Additional Option zakliknete vsechny moznosti
  • Kliknete na OK
  • Utilite prikazte, at skenuje - klik na Start Scan
  • Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
  • Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
  • Pokud mate vsude Skip, kliknete na Continue
  • Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Lokhys
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 19 bře 2013 09:01

Re: policie vir velky problem

#63 Příspěvek od Lokhys »

21:21:07.0734 2956 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
21:21:07.0890 2956 ============================================================
21:21:07.0890 2956 Current date / time: 2013/03/19 21:21:07.0890
21:21:07.0890 2956 SystemInfo:
21:21:07.0890 2956
21:21:07.0890 2956 OS Version: 5.1.2600 ServicePack: 3.0
21:21:07.0890 2956 Product type: Workstation
21:21:07.0890 2956 ComputerName: LUKASEK-31FF2A8
21:21:07.0890 2956 UserName: Lukasek
21:21:07.0890 2956 Windows directory: C:\WINDOWS
21:21:07.0890 2956 System windows directory: C:\WINDOWS
21:21:07.0890 2956 Processor architecture: Intel x86
21:21:07.0890 2956 Number of processors: 1
21:21:07.0890 2956 Page size: 0x1000
21:21:07.0890 2956 Boot type: Normal boot
21:21:07.0890 2956 ============================================================
21:21:09.0687 2956 Drive \Device\Harddisk0\DR0 - Size: 0x1B34367A00 (108.82 Gb), SectorSize: 0x200, Cylinders: 0x377D, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
21:21:09.0703 2956 Drive \Device\Harddisk1\DR2 - Size: 0x1EF3FE00 (0.48 Gb), SectorSize: 0x200, Cylinders: 0x3F, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
21:21:09.0703 2956 ============================================================
21:21:09.0703 2956 \Device\Harddisk0\DR0:
21:21:09.0703 2956 MBR partitions:
21:21:09.0703 2956 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xD99DC3D
21:21:09.0703 2956 \Device\Harddisk1\DR2:
21:21:09.0703 2956 MBR partitions:
21:21:09.0703 2956 \Device\Harddisk1\DR2\Partition1: MBR, Type 0xE, StartLBA 0x3F, BlocksNum 0xF79C0
21:21:09.0703 2956 ============================================================
21:21:09.0734 2956 C: <-> \Device\Harddisk0\DR0\Partition1
21:21:09.0734 2956 ============================================================
21:21:09.0734 2956 Initialize success
21:21:09.0734 2956 ============================================================
21:21:43.0031 1176 ============================================================
21:21:43.0031 1176 Scan started
21:21:43.0031 1176 Mode: Manual; SigCheck; TDLFS;
21:21:43.0031 1176 ============================================================
21:21:44.0000 1176 ================ Scan system memory ========================
21:21:44.0000 1176 System memory - ok
21:21:44.0000 1176 ================ Scan services =============================
21:21:44.0218 1176 [ 149A8F7ADF9742554DC323E290551E3E ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys
21:21:44.0578 1176 Aavmker4 - ok
21:21:44.0593 1176 Abiosdsk - ok
21:21:44.0609 1176 abp480n5 - ok
21:21:44.0671 1176 [ 4FE34F1F3126B61FCC6B2043AA8112C9 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
21:21:45.0031 1176 ACPI - ok
21:21:45.0078 1176 [ AFDFF022A01F0B11C776F0860C3B282F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
21:21:45.0343 1176 ACPIEC - ok
21:21:45.0437 1176 [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
21:21:45.0484 1176 AdobeFlashPlayerUpdateSvc - ok
21:21:45.0500 1176 adpu160m - ok
21:21:45.0546 1176 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
21:21:45.0796 1176 aec - ok
21:21:45.0843 1176 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
21:21:45.0906 1176 AFD - ok
21:21:45.0921 1176 Aha154x - ok
21:21:45.0937 1176 aic78u2 - ok
21:21:45.0953 1176 aic78xx - ok
21:21:45.0984 1176 [ E0A6FA244B8624D78FE5FF6F56A33BAE ] Alerter C:\WINDOWS\system32\alrsvc.dll
21:21:46.0281 1176 Alerter - ok
21:21:46.0328 1176 [ 88842DE939A827577BF24243699AC80A ] ALG C:\WINDOWS\System32\alg.exe
21:21:46.0468 1176 ALG - ok
21:21:46.0484 1176 AliIde - ok
21:21:46.0500 1176 amsint - ok
21:21:46.0515 1176 AppMgmt - ok
21:21:46.0531 1176 asc - ok
21:21:46.0546 1176 asc3350p - ok
21:21:46.0562 1176 asc3550 - ok
21:21:46.0671 1176 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
21:21:46.0703 1176 aspnet_state - ok
21:21:46.0750 1176 [ DE6ED95AEF259979B2830450072A627B ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
21:21:46.0781 1176 aswFsBlk - ok
21:21:46.0812 1176 [ 31E0D16EB06D09A248AFF20C76F9091B ] aswKbd C:\WINDOWS\system32\drivers\aswKbd.sys
21:21:46.0843 1176 aswKbd - ok
21:21:46.0875 1176 [ 84F0BE324EE111338589F448C3E8BAB2 ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys
21:21:46.0906 1176 aswMon2 - ok
21:21:46.0937 1176 [ 7C9F0A2AB17D52261A9252A2EB320884 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr.sys
21:21:46.0968 1176 aswRdr - ok
21:21:47.0046 1176 [ B32E9AD44A1DBB3E8095E80F8DF32B03 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
21:21:47.0218 1176 aswSnx - ok
21:21:47.0296 1176 [ 67B558895695545FB0568B7541F3BCA7 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
21:21:47.0390 1176 aswSP - ok
21:21:47.0421 1176 [ E3E73B2B73A4DFADFDDF557192C4B08A ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
21:21:47.0453 1176 aswTdi - ok
21:21:47.0500 1176 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
21:21:47.0718 1176 AsyncMac - ok
21:21:47.0750 1176 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
21:21:48.0015 1176 atapi - ok
21:21:48.0031 1176 Atdisk - ok
21:21:48.0156 1176 [ 55C017C4E1AD9E2FB08CFA1568F50B6F ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
21:21:48.0218 1176 Ati HotKey Poller ( UnsignedFile.Multi.Generic ) - warning
21:21:48.0234 1176 Ati HotKey Poller - detected UnsignedFile.Multi.Generic (1)
21:21:48.0328 1176 [ 8C6A9FE81268A57D363C4B0CBDA58CB1 ] ATI Smart C:\WINDOWS\system32\ati2sgag.exe
21:21:48.0468 1176 ATI Smart ( UnsignedFile.Multi.Generic ) - warning
21:21:48.0484 1176 ATI Smart - detected UnsignedFile.Multi.Generic (1)
21:21:48.0734 1176 [ F942E79994B3751501C478BF9713D221 ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
21:21:49.0281 1176 ati2mtag ( UnsignedFile.Multi.Generic ) - warning
21:21:49.0281 1176 ati2mtag - detected UnsignedFile.Multi.Generic (1)
21:21:49.0328 1176 [ 0E4BB35C5305099AC82053AC992E3E0E ] ATITool C:\WINDOWS\system32\DRIVERS\ATITool.sys
21:21:49.0390 1176 ATITool ( UnsignedFile.Multi.Generic ) - warning
21:21:49.0390 1176 ATITool - detected UnsignedFile.Multi.Generic (1)
21:21:49.0468 1176 [ F0D933B42CD0594048E4D5200AE9E417 ] atksgt C:\WINDOWS\system32\DRIVERS\atksgt.sys
21:21:49.0546 1176 atksgt - ok
21:21:49.0593 1176 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
21:21:49.0890 1176 Atmarpc - ok
21:21:49.0937 1176 [ DE31B88962A8645DBA5A37B993E7B0F1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
21:21:50.0187 1176 AudioSrv - ok
21:21:50.0234 1176 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
21:21:50.0484 1176 audstub - ok
21:21:50.0562 1176 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
21:21:50.0593 1176 avast! Antivirus - ok
21:21:50.0640 1176 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
21:21:50.0906 1176 Beep - ok
21:21:50.0968 1176 [ 19395D092FD85DDC2D9C7729CF5A2AC8 ] BITS C:\WINDOWS\system32\qmgr.dll
21:21:51.0265 1176 BITS - ok
21:21:51.0312 1176 [ 89E739BBA5F636297EA5B5F811189E06 ] Browser C:\WINDOWS\System32\browser.dll
21:21:51.0375 1176 Browser - ok
21:21:51.0390 1176 catchme - ok
21:21:51.0421 1176 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
21:21:51.0671 1176 cbidf2k - ok
21:21:51.0687 1176 cd20xrnt - ok
21:21:51.0718 1176 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
21:21:51.0984 1176 Cdaudio - ok
21:21:52.0015 1176 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
21:21:52.0328 1176 Cdfs - ok
21:21:52.0359 1176 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
21:21:52.0640 1176 Cdrom - ok
21:21:52.0656 1176 Changer - ok
21:21:52.0687 1176 [ E390DC1D7C461D7D56EC53402F329928 ] CiSvc C:\WINDOWS\system32\cisvc.exe
21:21:52.0937 1176 CiSvc - ok
21:21:52.0968 1176 [ 064507A8DFA8C5C7E2FFDDD3E6F424FA ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
21:21:53.0296 1176 ClipSrv - ok
21:21:53.0328 1176 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:21:53.0375 1176 clr_optimization_v2.0.50727_32 - ok
21:21:53.0390 1176 CmdIde - ok
21:21:53.0406 1176 COMSysApp - ok
21:21:53.0421 1176 Cpqarray - ok
21:21:53.0484 1176 [ F3AB0933CBD166D271992F411C27CCAF ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
21:21:53.0765 1176 CryptSvc - ok
21:21:53.0781 1176 dac2w2k - ok
21:21:53.0796 1176 dac960nt - ok
21:21:53.0875 1176 [ BE27674D1CBC3214AEC84B4336A38BBF ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
21:21:53.0968 1176 DcomLaunch - ok
21:21:54.0031 1176 [ 8C9A53E285AC5E6704844D0459EC85BE ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
21:21:54.0281 1176 Dhcp - ok
21:21:54.0328 1176 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
21:21:54.0593 1176 Disk - ok
21:21:54.0609 1176 dmadmin - ok
21:21:54.0703 1176 [ DB5FD2BF5B07DC54BFCB3664FF05BD7C ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
21:21:55.0031 1176 dmboot - ok
21:21:55.0125 1176 [ FFF1720AF51171F32F1EAD5CF71F2810 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
21:21:55.0406 1176 dmio - ok
21:21:55.0453 1176 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
21:21:55.0687 1176 dmload - ok
21:21:55.0734 1176 [ 2BFEFE9E865655A76982F050450B9591 ] dmserver C:\WINDOWS\System32\dmserver.dll
21:21:56.0015 1176 dmserver - ok
21:21:56.0046 1176 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
21:21:56.0312 1176 DMusic - ok
21:21:56.0359 1176 [ DFAA406BF19F4EE806A6F8D4342137F7 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
21:21:56.0421 1176 Dnscache - ok
21:21:56.0468 1176 [ 4A3E2BD20157A0946751229E92EB8621 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
21:21:56.0718 1176 Dot3svc - ok
21:21:56.0734 1176 dpti2o - ok
21:21:56.0765 1176 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
21:21:57.0000 1176 drmkaud - ok
21:21:57.0062 1176 [ 687AF6BB383885FF6A64071B189A7F3E ] dtsoftbus01 C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys
21:21:57.0109 1176 dtsoftbus01 - ok
21:21:57.0156 1176 [ 0887D9C2BE8D940778CAD1E3B85F2A41 ] EapHost C:\WINDOWS\System32\eapsvc.dll
21:21:57.0453 1176 EapHost - ok
21:21:57.0484 1176 [ A2A4912798F2BE706ABADD3D30800D16 ] ERSvc C:\WINDOWS\System32\ersvc.dll
21:21:57.0718 1176 ERSvc - ok
21:21:57.0750 1176 [ A55DD7D8CED5D2624A9EE2DDA7BE0319 ] es1371 C:\WINDOWS\system32\drivers\es1371mp.sys
21:21:58.0015 1176 es1371 - ok
21:21:58.0078 1176 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] Eventlog C:\WINDOWS\system32\services.exe
21:21:58.0156 1176 Eventlog - ok
21:21:58.0218 1176 [ A371F11EF07653591C8DE26AFB13CE7F ] EventSystem C:\WINDOWS\system32\es.dll
21:21:58.0312 1176 EventSystem - ok
21:21:58.0359 1176 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
21:21:58.0578 1176 Fastfat - ok
21:21:58.0625 1176 [ EE9A2B9EA968A792A053C9D1A86BF870 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
21:21:58.0687 1176 FastUserSwitchingCompatibility - ok
21:21:58.0718 1176 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
21:21:58.0984 1176 Fdc - ok
21:21:59.0015 1176 [ E9648254056BCE81A85380C0C3647DC4 ] FETNDIS C:\WINDOWS\system32\DRIVERS\fetnd5.sys
21:21:59.0312 1176 FETNDIS - ok
21:21:59.0343 1176 [ AC366695A0796560AA37215AD5762AAF ] Fips C:\WINDOWS\system32\drivers\Fips.sys
21:21:59.0609 1176 Fips - ok
21:21:59.0640 1176 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
21:21:59.0921 1176 Flpydisk - ok
21:21:59.0953 1176 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
21:22:00.0234 1176 FltMgr - ok
21:22:00.0328 1176 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
21:22:00.0359 1176 FontCache3.0.0.0 - ok
21:22:00.0406 1176 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
21:22:00.0640 1176 Fs_Rec - ok
21:22:00.0687 1176 [ 4E664D8541DB4A66B73A24257E322E1F ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
21:22:00.0937 1176 Ftdisk - ok
21:22:00.0968 1176 [ 065639773D8B03F33577F6CDAEA21063 ] gameenum C:\WINDOWS\system32\DRIVERS\gameenum.sys
21:22:01.0265 1176 gameenum - ok
21:22:01.0312 1176 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
21:22:01.0640 1176 Gpc - ok
21:22:01.0703 1176 [ FCFE31FB75F8A6295B6B0AF87A626282 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
21:22:01.0968 1176 helpsvc - ok
21:22:01.0984 1176 HidServ - ok
21:22:02.0031 1176 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
21:22:02.0359 1176 HidUsb - ok
21:22:02.0406 1176 [ 7A6B320928F86BC851530D63C82965D9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
21:22:02.0703 1176 hkmsvc - ok
21:22:02.0718 1176 hpn - ok
21:22:02.0796 1176 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
21:22:02.0875 1176 HTTP - ok
21:22:02.0937 1176 [ 58FE2F2DA3BC5573F4A35B3760D3125F ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
21:22:03.0250 1176 HTTPFilter - ok
21:22:03.0265 1176 i2omgmt - ok
21:22:03.0296 1176 i2omp - ok
21:22:03.0343 1176 [ C528E27945367191E7BAE364930B6932 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
21:22:03.0609 1176 i8042prt - ok
21:22:03.0718 1176 [ DAF66902F08796F9C694901660E5A64A ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
21:22:03.0750 1176 IDriverT ( UnsignedFile.Multi.Generic ) - warning
21:22:03.0750 1176 IDriverT - detected UnsignedFile.Multi.Generic (1)
21:22:03.0859 1176 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
21:22:04.0093 1176 idsvc - ok
21:22:04.0140 1176 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
21:22:04.0437 1176 Imapi - ok
21:22:04.0484 1176 [ F7B93AAFAD33B2320954C17E26C8D361 ] ImapiService C:\WINDOWS\system32\imapi.exe
21:22:04.0765 1176 ImapiService - ok
21:22:04.0796 1176 ini910u - ok
21:22:04.0828 1176 IntelIde - ok
21:22:04.0890 1176 [ 27B290D632AF2CF3CF40BFDDB7370985 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
21:22:05.0203 1176 intelppm - ok
21:22:05.0234 1176 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
21:22:05.0515 1176 Ip6Fw - ok
21:22:05.0562 1176 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
21:22:05.0828 1176 IpFilterDriver - ok
21:22:05.0859 1176 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
21:22:06.0125 1176 IpInIp - ok
21:22:06.0187 1176 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
21:22:06.0453 1176 IpNat - ok
21:22:06.0500 1176 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
21:22:06.0765 1176 IPSec - ok
21:22:06.0796 1176 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
21:22:06.0890 1176 IRENUM - ok
21:22:06.0937 1176 [ CC9F8A2D60AED1A51A3AC34C59B987AE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
21:22:07.0171 1176 isapnp - ok
21:22:07.0218 1176 [ 4AC11B2250106774F694DF2DB4FFED61 ] Iviaspi C:\WINDOWS\system32\drivers\iviaspi.sys
21:22:07.0265 1176 Iviaspi ( UnsignedFile.Multi.Generic ) - warning
21:22:07.0265 1176 Iviaspi - detected UnsignedFile.Multi.Generic (1)
21:22:07.0359 1176 [ B591E761161D1EF547D76EF236EAA6A5 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
21:22:07.0390 1176 JavaQuickStarterService - ok
21:22:07.0437 1176 [ 1B6162FE7F66B1A71A4B70F941C4AA9B ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
21:22:07.0703 1176 Kbdclass - ok
21:22:07.0765 1176 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
21:22:08.0031 1176 kmixer - ok
21:22:08.0093 1176 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
21:22:08.0218 1176 KSecDD - ok
21:22:08.0265 1176 [ 3428E8F86F8ADD36B42FB23542C7B3E4 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
21:22:08.0328 1176 lanmanserver - ok
21:22:08.0390 1176 [ 936C1D110232D23B621CB0196E4F80F0 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
21:22:08.0453 1176 lanmanworkstation - ok
21:22:08.0484 1176 lbrtfdc - ok
21:22:08.0562 1176 [ F8A7212D0864EF5E9185FB95E6623F4D ] lirsgt C:\WINDOWS\system32\DRIVERS\lirsgt.sys
21:22:08.0593 1176 lirsgt - ok
21:22:08.0640 1176 [ 0AB159F536E3E8F7F07113702A07CCA5 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
21:22:08.0890 1176 LmHosts - ok
21:22:08.0937 1176 [ 221CD1C815B8A6B79389C3F5D1018DE8 ] Messenger C:\WINDOWS\System32\msgsvc.dll
21:22:09.0218 1176 Messenger - ok
21:22:09.0281 1176 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
21:22:09.0531 1176 mnmdd - ok
21:22:09.0562 1176 [ 9A57D046F88F4B69751B11FD40088A61 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
21:22:09.0859 1176 mnmsrvc - ok
21:22:09.0921 1176 [ 44032B0C6D9954D3FD26438330B99EE7 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
21:22:10.0171 1176 Modem - ok
21:22:10.0218 1176 [ 4CB582831DBDE63CE43B45D771218374 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
21:22:10.0484 1176 Mouclass - ok
21:22:10.0531 1176 [ BB269EBA740737AB749B214D568B6812 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
21:22:10.0796 1176 mouhid - ok
21:22:10.0828 1176 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
21:22:11.0093 1176 MountMgr - ok
21:22:11.0171 1176 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
21:22:11.0234 1176 MozillaMaintenance - ok
21:22:11.0250 1176 mraid35x - ok
21:22:11.0312 1176 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
21:22:11.0578 1176 MRxDAV - ok
21:22:11.0859 1176 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
21:22:12.0828 1176 MRxSmb - ok
21:22:12.0875 1176 [ 6DB4D1521CABA9A5FFAB54ADE0AE867D ] MSDTC C:\WINDOWS\system32\msdtc.exe
21:22:13.0171 1176 MSDTC - ok
21:22:13.0218 1176 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
21:22:13.0453 1176 Msfs - ok
21:22:13.0484 1176 MSIServer - ok
21:22:13.0531 1176 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
21:22:13.0796 1176 MSKSSRV - ok
21:22:13.0843 1176 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
21:22:14.0093 1176 MSPCLOCK - ok
21:22:14.0125 1176 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
21:22:14.0390 1176 MSPQM - ok
21:22:14.0421 1176 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
21:22:14.0656 1176 mssmbios - ok
21:22:14.0718 1176 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
21:22:14.0765 1176 Mup - ok
21:22:14.0828 1176 [ 6EA362E9DB03D44F6B996F4D8BE237E9 ] napagent C:\WINDOWS\System32\qagentrt.dll
21:22:15.0109 1176 napagent - ok
21:22:15.0140 1176 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
21:22:15.0390 1176 NDIS - ok
21:22:15.0437 1176 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
21:22:15.0484 1176 NdisTapi - ok
21:22:15.0531 1176 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
21:22:15.0843 1176 Ndisuio - ok
21:22:15.0875 1176 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
21:22:16.0125 1176 NdisWan - ok
21:22:16.0187 1176 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
21:22:16.0234 1176 NDProxy - ok
21:22:16.0281 1176 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
21:22:16.0546 1176 NetBIOS - ok
21:22:16.0593 1176 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
21:22:16.0859 1176 NetBT - ok
21:22:16.0906 1176 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDE C:\WINDOWS\system32\netdde.exe
21:22:17.0156 1176 NetDDE - ok
21:22:17.0187 1176 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
21:22:17.0500 1176 NetDDEdsdm - ok
21:22:17.0546 1176 [ ED0A176354487CEED65B80A7148AB739 ] Netlogon C:\WINDOWS\system32\lsass.exe
21:22:17.0796 1176 Netlogon - ok
21:22:17.0843 1176 [ 72E1E9E2977BE08BDEEDB6D8FD9D4D40 ] Netman C:\WINDOWS\System32\netman.dll
21:22:18.0109 1176 Netman - ok
21:22:18.0171 1176 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
21:22:18.0218 1176 NetTcpPortSharing - ok
21:22:18.0281 1176 [ 39EE7C3BFBC64BA87CC8CF67386E814C ] Nla C:\WINDOWS\System32\mswsock.dll
21:22:18.0343 1176 Nla - ok
21:22:18.0390 1176 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
21:22:18.0656 1176 Npfs - ok
21:22:18.0671 1176 npggsvc - ok
21:22:18.0750 1176 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
21:22:19.0078 1176 Ntfs - ok
21:22:19.0125 1176 [ ED0A176354487CEED65B80A7148AB739 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
21:22:19.0421 1176 NtLmSsp - ok
21:22:19.0515 1176 [ 023DD70573D644F3D9C8B1258A7BFD08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
21:22:19.0812 1176 NtmsSvc - ok
21:22:19.0843 1176 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
21:22:20.0093 1176 Null - ok
21:22:20.0156 1176 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
21:22:20.0421 1176 NwlnkFlt - ok
21:22:20.0437 1176 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
21:22:20.0703 1176 NwlnkFwd - ok
21:22:20.0796 1176 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
21:22:20.0890 1176 odserv - ok
21:22:20.0937 1176 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:22:20.0968 1176 ose - ok
21:22:21.0031 1176 [ 46F8DB73B4A53E543F8E371DC7C75BAE ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
21:22:21.0296 1176 Parport - ok
21:22:21.0328 1176 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
21:22:21.0593 1176 PartMgr - ok
21:22:21.0640 1176 [ 1FAE19D0457176318BBA4A8795656EBC ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
21:22:21.0875 1176 ParVdm - ok
21:22:21.0890 1176 [ 6CE351D149CB4BEFC702951E471E1730 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
21:22:22.0187 1176 PCI - ok
21:22:22.0203 1176 PCIDump - ok
21:22:22.0234 1176 PCIIde - ok
21:22:22.0281 1176 [ 4FC31E6C19A5CE5198B1ABFF94CAE758 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
21:22:22.0531 1176 Pcmcia - ok
21:22:22.0562 1176 PDCOMP - ok
21:22:22.0578 1176 PDFRAME - ok
21:22:22.0593 1176 PDRELI - ok
21:22:22.0609 1176 PDRFRAME - ok
21:22:22.0625 1176 perc2 - ok
21:22:22.0656 1176 perc2hib - ok
21:22:22.0734 1176 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] PlugPlay C:\WINDOWS\system32\services.exe
21:22:22.0781 1176 PlugPlay - ok
21:22:22.0828 1176 [ 831883B107684301F48ACE752C963984 ] PnkBstrA C:\WINDOWS\system32\PnkBstrA.exe
21:22:22.0875 1176 PnkBstrA - ok
21:22:22.0921 1176 [ ED0A176354487CEED65B80A7148AB739 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
21:22:23.0187 1176 PolicyAgent - ok
21:22:23.0234 1176 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
21:22:23.0500 1176 PptpMiniport - ok
21:22:23.0515 1176 [ ED0A176354487CEED65B80A7148AB739 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
21:22:23.0796 1176 ProtectedStorage - ok
21:22:23.0812 1176 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
21:22:24.0078 1176 PSched - ok
21:22:24.0140 1176 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
21:22:24.0421 1176 Ptilink - ok
21:22:24.0468 1176 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
21:22:24.0500 1176 PxHelp20 - ok
21:22:24.0515 1176 ql1080 - ok
21:22:24.0546 1176 Ql10wnt - ok
21:22:24.0562 1176 ql12160 - ok
21:22:24.0593 1176 ql1240 - ok
21:22:24.0609 1176 ql1280 - ok
21:22:24.0640 1176 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
21:22:24.0906 1176 RasAcd - ok
21:22:24.0953 1176 [ 2B5E44EA009F2F374B980E1E9A70635D ] RasAuto C:\WINDOWS\System32\rasauto.dll
21:22:25.0218 1176 RasAuto - ok
21:22:25.0265 1176 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
21:22:25.0546 1176 Rasl2tp - ok
21:22:25.0609 1176 [ D57554C664B64604BD1EE13EA2C07E77 ] RasMan C:\WINDOWS\System32\rasmans.dll
21:22:25.0859 1176 RasMan - ok
21:22:25.0890 1176 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
21:22:26.0140 1176 RasPppoe - ok
21:22:26.0171 1176 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
21:22:26.0421 1176 Raspti - ok
21:22:26.0484 1176 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
21:22:26.0796 1176 Rdbss - ok
21:22:26.0828 1176 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
21:22:27.0109 1176 RDPCDD - ok
21:22:27.0187 1176 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
21:22:27.0265 1176 RDPWD - ok
21:22:27.0312 1176 [ C0D9D9711CB74EE9BC66353D8CBDAB0E ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
21:22:27.0593 1176 RDSessMgr - ok
21:22:27.0625 1176 [ 611BFD220305BE3A85AE876EA47D4AA5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
21:22:27.0875 1176 redbook - ok
21:22:27.0921 1176 [ 127C26B5371651043450E52542099ABA ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
21:22:28.0203 1176 RemoteAccess - ok
21:22:28.0265 1176 [ 718B3BDC0BC3C2F7D065A53D26202AF9 ] RpcLocator C:\WINDOWS\system32\locator.exe
21:22:28.0515 1176 RpcLocator - ok
21:22:28.0578 1176 [ BE27674D1CBC3214AEC84B4336A38BBF ] RpcSs C:\WINDOWS\System32\rpcss.dll
21:22:28.0640 1176 RpcSs - ok
21:22:28.0718 1176 [ 09AB2E71E58B078038E3BFDBA7FFC984 ] RSVP C:\WINDOWS\system32\rsvp.exe
21:22:28.0968 1176 RSVP - ok
21:22:29.0000 1176 [ ED0A176354487CEED65B80A7148AB739 ] SamSs C:\WINDOWS\system32\lsass.exe
21:22:29.0265 1176 SamSs - ok
21:22:29.0312 1176 [ 410046E401EB11E1E6749E9DEEA41D4A ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
21:22:29.0578 1176 SCardSvr - ok
21:22:29.0640 1176 [ 20B2751CD4C8F3FD989739CA661B9F30 ] SCDEmu C:\WINDOWS\system32\drivers\SCDEmu.sys
21:22:29.0671 1176 SCDEmu ( UnsignedFile.Multi.Generic ) - warning
21:22:29.0671 1176 SCDEmu - detected UnsignedFile.Multi.Generic (1)
21:22:29.0734 1176 [ 3FF232A7731621B8902D81D42418C93C ] Schedule C:\WINDOWS\system32\schedsvc.dll
21:22:29.0984 1176 Schedule - ok
21:22:30.0046 1176 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
21:22:30.0171 1176 Secdrv - ok
21:22:30.0234 1176 [ 477E2C3CC5E4A0D635BCB0EA8DCAC3C6 ] seclogon C:\WINDOWS\System32\seclogon.dll
21:22:30.0546 1176 seclogon - ok
21:22:30.0578 1176 [ A530B75C10C23C9AB28FDB6CE719E21F ] SENS C:\WINDOWS\system32\sens.dll
21:22:30.0859 1176 SENS - ok
21:22:30.0921 1176 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
21:22:31.0140 1176 serenum - ok
21:22:31.0187 1176 [ B842729337C9B921615C40D3C1A1AF96 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
21:22:31.0468 1176 Serial - ok
21:22:31.0546 1176 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
21:22:31.0781 1176 Sfloppy - ok
21:22:31.0906 1176 [ F58FACA9621D2DB01BD0927D9A0A208E ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
21:22:32.0203 1176 SharedAccess - ok
21:22:32.0250 1176 [ EE9A2B9EA968A792A053C9D1A86BF870 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
21:22:32.0296 1176 ShellHWDetection - ok
21:22:32.0312 1176 Simbad - ok
21:22:32.0375 1176 [ 6128E98EAAED364ED1A32708D2FD22CB ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
21:22:32.0421 1176 SkypeUpdate - ok
21:22:32.0453 1176 Sparrow - ok
21:22:32.0500 1176 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
21:22:32.0718 1176 splitter - ok
21:22:32.0765 1176 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
21:22:32.0828 1176 Spooler - ok
21:22:32.0859 1176 [ 94610C8653635E4459316A0050D55CE7 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
21:22:32.0984 1176 sr - ok
21:22:33.0046 1176 [ 35B91147124F64AC8081A2EDB9EA4DEE ] srservice C:\WINDOWS\system32\srsvc.dll
21:22:33.0171 1176 srservice - ok
21:22:33.0250 1176 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
21:22:33.0375 1176 Srv - ok
21:22:33.0421 1176 [ BECD5271DC4E3B7C3D035F790FCBC1E5 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
21:22:33.0546 1176 SSDPSRV - ok
21:22:33.0593 1176 Steam Client Service - ok
21:22:33.0671 1176 [ C1CDD9275F6A115BB0AE1D55D8D27BA6 ] stisvc C:\WINDOWS\system32\wiaservc.dll
21:22:34.0000 1176 stisvc - ok
21:22:34.0046 1176 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
21:22:34.0296 1176 swenum - ok
21:22:34.0343 1176 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
21:22:34.0625 1176 swmidi - ok
21:22:34.0640 1176 SwPrv - ok
21:22:34.0671 1176 symc810 - ok
21:22:34.0703 1176 symc8xx - ok
21:22:34.0734 1176 sym_hi - ok
21:22:34.0750 1176 sym_u3 - ok
21:22:34.0796 1176 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
21:22:35.0062 1176 sysaudio - ok
21:22:35.0156 1176 [ CE06F01B88ACE199A1BF460CAC29C110 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
21:22:35.0468 1176 SysmonLog - ok
21:22:35.0531 1176 [ C2546CD7A398476F9DF5614B2AE160E8 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
21:22:35.0828 1176 TapiSrv - ok
21:22:35.0937 1176 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
21:22:36.0031 1176 Tcpip - ok
21:22:36.0078 1176 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
21:22:36.0390 1176 TDPIPE - ok
21:22:36.0437 1176 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
21:22:36.0687 1176 TDTCP - ok
21:22:36.0718 1176 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
21:22:36.0968 1176 TermDD - ok
21:22:37.0046 1176 [ A75DD6FC3DBEE4FFF5EBC9F2C28BB66E ] TermService C:\WINDOWS\System32\termsrv.dll
21:22:37.0343 1176 TermService - ok
21:22:37.0390 1176 [ EE9A2B9EA968A792A053C9D1A86BF870 ] Themes C:\WINDOWS\System32\shsvcs.dll
21:22:37.0421 1176 Themes - ok
21:22:37.0468 1176 TosIde - ok
21:22:37.0515 1176 [ 38853304CCB938D30E0C4CDE8D2C2A8A ] TrkWks C:\WINDOWS\system32\trkwks.dll
21:22:37.0781 1176 TrkWks - ok
21:22:37.0859 1176 [ D85938F272D1BCF3DB3A31FC0A048928 ] uagp35 C:\WINDOWS\system32\DRIVERS\uagp35.sys
21:22:38.0156 1176 uagp35 - ok
21:22:38.0203 1176 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
21:22:38.0484 1176 Udfs - ok
21:22:38.0500 1176 ultra - ok
21:22:38.0546 1176 [ AB0A7CA90D9E3D6A193905DC1715DED0 ] UMWdf C:\WINDOWS\system32\wdfmgr.exe
21:22:38.0609 1176 UMWdf - ok
21:22:38.0687 1176 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
21:22:38.0984 1176 Update - ok
21:22:39.0046 1176 [ 651BD90DCEE5B7BDC74A2EB7C9266F9E ] upnphost C:\WINDOWS\System32\upnphost.dll
21:22:39.0187 1176 upnphost - ok
21:22:39.0218 1176 [ 20A0F6A11959E92908717D09E87D670D ] UPS C:\WINDOWS\System32\ups.exe
21:22:39.0500 1176 UPS - ok
21:22:39.0531 1176 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
21:22:39.0765 1176 usbehci - ok
21:22:39.0812 1176 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
21:22:40.0078 1176 usbhub - ok
21:22:40.0156 1176 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
21:22:40.0406 1176 usbscan - ok
21:22:40.0437 1176 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
21:22:40.0703 1176 USBSTOR - ok
21:22:40.0734 1176 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
21:22:40.0953 1176 usbuhci - ok
21:22:40.0984 1176 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
21:22:41.0281 1176 VgaSave - ok
21:22:41.0343 1176 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
21:22:41.0625 1176 ViaIde - ok
21:22:41.0656 1176 [ 28A4B296B47782173C346E376CB374D1 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
21:22:42.0000 1176 VolSnap - ok
21:22:42.0078 1176 [ D6BA1A63D9E00933F1CD2A885573AFB2 ] VSS C:\WINDOWS\System32\vssvc.exe
21:22:42.0234 1176 VSS - ok
21:22:42.0296 1176 [ FA4E1CDBA256787F2149F4AAD07BC91F ] W32Time C:\WINDOWS\system32\w32time.dll
21:22:42.0562 1176 W32Time - ok
21:22:42.0609 1176 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
21:22:42.0875 1176 Wanarp - ok
21:22:42.0906 1176 WDICA - ok
21:22:42.0953 1176 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
21:22:43.0187 1176 wdmaud - ok
21:22:43.0250 1176 [ 47AE51048A82DFA1CD6B51D369F7E169 ] WebClient C:\WINDOWS\System32\webclnt.dll
21:22:43.0515 1176 WebClient - ok
21:22:43.0609 1176 [ E488332126E3B1182D2B8A0C35408EC6 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
21:22:43.0875 1176 winmgmt - ok
21:22:44.0265 1176 [ 4D34CEDD74BDBF2B6A935EAE3BF80543 ] WinRM C:\WINDOWS\system32\WsmSvc.dll
21:22:44.0515 1176 WinRM - ok
21:22:44.0609 1176 [ 140EF97B64F560FD78643CAE2CDAD838 ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
21:22:44.0687 1176 WmdmPmSN - ok
21:22:44.0765 1176 [ 23F6F03272F7E5679F1F050AED5ACEE6 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
21:22:45.0296 1176 WmiApSrv - ok
21:22:45.0359 1176 [ 1385E5AA9C9821790D33A9563B8D2DD0 ] WpdUsb C:\WINDOWS\system32\Drivers\wpdusb.sys
21:22:45.0406 1176 WpdUsb - ok
21:22:45.0468 1176 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
21:22:45.0703 1176 WS2IFSL - ok
21:22:45.0750 1176 [ 4C86D5FAF78194995AF9CC1075F65DD3 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
21:22:46.0015 1176 wscsvc - ok
21:22:46.0062 1176 [ C1364564800EE9784192145324A23308 ] wuauserv C:\WINDOWS\system32\wuauserv.dll
21:22:46.0343 1176 wuauserv - ok
21:22:46.0437 1176 [ A27D4BA7264C0BF52F32D10405BEA1D4 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
21:22:46.0765 1176 WZCSVC - ok
21:22:46.0812 1176 [ EAA4BB9EDB3FB10CF8979FE65E63658F ] xmlprov C:\WINDOWS\System32\xmlprov.dll
21:22:47.0125 1176 xmlprov - ok
21:22:47.0140 1176 ================ Scan global ===============================
21:22:47.0187 1176 [ F36278E42C8C5DF03CE17DAC8231C91C ] C:\WINDOWS\system32\basesrv.dll
21:22:47.0265 1176 [ F3FA14A297BC687D0B51289D034033C9 ] C:\WINDOWS\system32\winsrv.dll
21:22:47.0359 1176 [ F3FA14A297BC687D0B51289D034033C9 ] C:\WINDOWS\system32\winsrv.dll
21:22:47.0406 1176 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] C:\WINDOWS\system32\services.exe
21:22:47.0421 1176 [Global] - ok
21:22:47.0421 1176 ================ Scan MBR ==================================
21:22:47.0453 1176 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
21:22:47.0734 1176 \Device\Harddisk0\DR0 - ok
21:22:47.0765 1176 [ 54F5CF4F39FF21175E9898037BDC5451 ] \Device\Harddisk1\DR2
21:22:49.0000 1176 \Device\Harddisk1\DR2 - ok
21:22:49.0000 1176 ================ Scan VBR ==================================
21:22:49.0015 1176 [ FC77DEF437768F299C8AE31CC2428D4E ] \Device\Harddisk0\DR0\Partition1
21:22:49.0015 1176 \Device\Harddisk0\DR0\Partition1 - ok
21:22:49.0031 1176 [ 3616EAD18958304D58463638E63FC816 ] \Device\Harddisk1\DR2\Partition1
21:22:49.0031 1176 \Device\Harddisk1\DR2\Partition1 - ok
21:22:49.0046 1176 ============================================================
21:22:49.0046 1176 Scan finished
21:22:49.0046 1176 ============================================================
21:22:49.0203 2224 Detected object count: 7
21:22:49.0203 2224 Actual detected object count: 7
21:22:56.0578 2224 Ati HotKey Poller ( UnsignedFile.Multi.Generic ) - skipped by user
21:22:56.0578 2224 Ati HotKey Poller ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:22:56.0578 2224 ATI Smart ( UnsignedFile.Multi.Generic ) - skipped by user
21:22:56.0578 2224 ATI Smart ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:22:56.0593 2224 ati2mtag ( UnsignedFile.Multi.Generic ) - skipped by user
21:22:56.0593 2224 ati2mtag ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:22:56.0593 2224 ATITool ( UnsignedFile.Multi.Generic ) - skipped by user
21:22:56.0593 2224 ATITool ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:22:56.0593 2224 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
21:22:56.0593 2224 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:22:56.0609 2224 Iviaspi ( UnsignedFile.Multi.Generic ) - skipped by user
21:22:56.0609 2224 Iviaspi ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:22:56.0609 2224 SCDEmu ( UnsignedFile.Multi.Generic ) - skipped by user
21:22:56.0609 2224 SCDEmu ( UnsignedFile.Multi.Generic ) - User select action: Skip

Lokhys
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 19 bře 2013 09:01

Re: policie vir velky problem

#64 Příspěvek od Lokhys »

KDyžtak zítra tu budu tak od pul 1. Teď už jdu spát tak děkuji za spolupráci a za pomoc a kdybyste byl tak hodný tak zítra kdyby sme pokračovali ? :)

Lokhys
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 19 bře 2013 09:01

Re: policie vir velky problem

#65 Příspěvek od Lokhys »

Nebo šak vlastně je to forum tak to sem mužete šak hazet a ja to budu postupně dělat když tu budu když ne tak až přidu a tak uplně sem zapoměl že je to forko :D ....

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: policie vir velky problem

#66 Příspěvek od vyosek »

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    :reg
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Advanced SystemCare 5"=-
    "Facebook Update"=-
    "BitTorrent"=-
    [-HKLM\~\startupfolder\C:^Documents and Settings^Lukasek^Nabídka Start^Programy^Po spuštění^Registrace FIFA 10.lnk]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5985:TCP"=-
    "57128:TCP"=-
    "57128:UDP"=-
    
    :files
    c:\documents and settings\All Users\Data aplikací\{*}
    c:\program files\IObit
    c:\documents and settings\All Users\Data aplikací\8723465.js
    c:\windows\system32\ealregsnapshot1.reg
    c:\documents and settings\Lukasek\Nabídka Start\Programy\Po spuštění\FIFA 10 Registration.lnk
    c:\windows\Tasks\Adobe Flash Player Updater.job
    c:\windows\Tasks\avast! Emergency Update.job
    c:\windows\Tasks\Game_Booster_AutoUpdate.job
    c:\windows\Tasks\Norton Security Scan for Lukasek.job
    c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
    
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [EMPTYJAVA]
  • Nasledne kliknete na Opravit
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Lokhys
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 19 bře 2013 09:01

Re: policie vir velky problem

#67 Příspěvek od Lokhys »

All processes killed
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 5 not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Facebook Update not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\BitTorrent not found.
Registry key HKEY_LOCAL_MACHINE\~\startupfolder\C:^Documents and Settings^Lukasek^Nabídka Start^Programy^Po spuštění^Registrace FIFA 10.lnk\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched\ not found.
Registry key HKEY_LOCAL_MACHINE\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List not found.
Registry key HKEY_LOCAL_MACHINE\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List not found.
Registry key HKEY_LOCAL_MACHINE\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List not found.
========== FILES ==========
c:\documents and settings\All Users\Data aplikací\{0691F710-1ECA-4B5A-9727-25554F1BFDC6} folder moved successfully.
File\Folder c:\program files\IObit not found.
File\Folder c:\documents and settings\All Users\Data aplikací\8723465.js not found.
c:\windows\system32\ealregsnapshot1.reg moved successfully.
c:\documents and settings\Lukasek\Nabídka Start\Programy\Po spuštění\FIFA 10 Registration.lnk moved successfully.
c:\windows\Tasks\Adobe Flash Player Updater.job moved successfully.
c:\windows\Tasks\avast! Emergency Update.job moved successfully.
File\Folder c:\windows\Tasks\Game_Booster_AutoUpdate.job not found.
File\Folder c:\windows\Tasks\Norton Security Scan for Lukasek.job not found.
File\Folder c:\windows\Tasks\Scheduled Update for Ask Toolbar.job not found.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\002783_.tmp moved successfully.
C:\WINDOWS\1C4551A64743409391E41477CD655043.TMP folder moved successfully.
C:\WINDOWS\85EBB28365AF4C539EBE7C0A232762F7.TMP folder moved successfully.
C:\WINDOWS\msdownld.tmp folder moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Administrator.LUKASEK-31FF2A8
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: All Users.WINDOWS.0

User: All Users.WINDOWS.2

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User.WINDOWS.0

User: Default User.WINDOWS.2

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: Lukasek
->Temp folder emptied: 22629980 bytes
->Temporary Internet Files folder emptied: 1319915 bytes
->FireFox cache emptied: 144801857 bytes
->Google Chrome cache emptied: 0 bytes
->Opera cache emptied: 13404620 bytes
->Flash cache emptied: 17514 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 410 bytes

Total Files Cleaned = 174,00 mb


[EMPTYFLASH]

User: Administrator

User: Administrator.LUKASEK-31FF2A8

User: All Users

User: All Users.WINDOWS.0

User: All Users.WINDOWS.2

User: Default User

User: Default User.WINDOWS.0

User: Default User.WINDOWS.2

User: LocalService

User: Lukasek
->Flash cache emptied: 0 bytes

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


[EMPTYJAVA]

User: Administrator

User: Administrator.LUKASEK-31FF2A8

User: All Users

User: All Users.WINDOWS.0

User: All Users.WINDOWS.2

User: Default User

User: Default User.WINDOWS.0

User: Default User.WINDOWS.2

User: LocalService

User: Lukasek

User: NetworkService

Total Java Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 03202013_124348

Files\Folders moved on Reboot...
File\Folder C:\WINDOWS\temp\_avast_\Webshlock.txt not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: policie vir velky problem

#68 Příspěvek od vyosek »

Fajn, jak se chova nas pacient?
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Lokhys
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 19 bře 2013 09:01

Re: policie vir velky problem

#69 Příspěvek od Lokhys »

tak rozhodně lěpe jak před tím ale trošku je to ještě pomalé ale to bude možná windowsem ktery sem tam nainstaloval navíc musím ho smazat ...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: policie vir velky problem

#70 Příspěvek od vyosek »

:arrow: Ano, ty dalsi winy odmaznete

Tak jeste uklidime :James008:

:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Dejte novy log z RSIT a napiste co PC
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Lokhys
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 19 bře 2013 09:01

Re: policie vir velky problem

#71 Příspěvek od Lokhys »

Jak zjistim prosím vás ten log z RSIT ? :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: policie vir velky problem

#72 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Lokhys
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 19 bře 2013 09:01

Re: policie vir velky problem

#73 Příspěvek od Lokhys »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Lukasek at 2013-03-20 14:28:03
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 30 GB (27%) free of 111 GB
Total RAM: 2559 MB (79% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:28:56, on 20.3.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\program files\divx\divx update\divxupdate.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\program files\nero\nero backitup & burn\nero backitup\nbagent.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\program files\common files\java\java update\jusched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\Lukasek\Plocha\RSIT.exe
C:\Program Files\trend micro\Lukasek.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://badoo.com/startpage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\clistart.exe" msrun
O4 - HKLM\..\Run: [PWRISOVM.EXE] c:\program files\poweriso\pwrisovm.exe
O4 - HKLM\..\Run: [DivXUpdate] "c:\program files\divx\divx update\divxupdate.exe" /checknow
O4 - HKLM\..\Run: [NBAgent] "c:\program files\nero\nero backitup & burn\nero backitup\nbagent.exe" /winstart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] c:\program files\adobe\reader 9.0\reader\reader_sl.exe
O4 - HKLM\..\Run: [Adobe ARM] c:\program files\common files\adobe\arm\1.0\adobearm.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] c:\program files\common files\java\java update\jusched.exe
O4 - HKCU\..\Run: [Badoo Desktop] C:\Documents and Settings\All Users\Data aplikací\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\program files\daemon tools lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "c:\program files\skype\phone\skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [EA Core] "c:\program files\electronic arts\eadm\core.exe" -silent
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 6620 bytes

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Lukasek\Data aplikací\Mozilla\Firefox\Profiles\bikzwcbj.default

prefs.js - "browser.startup.homepage" - "https://www.google.cz/"

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.6.602.180 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.9.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=1.1.11]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Lukasek\Data aplikací\Mozilla\Firefox\Profiles\bikzwcbj.default\searchplugins\
badoo.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 77576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-12-12 194432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-11-25 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-11-25 155384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-30 4297136]
"StartCCC"=c:\program files\ati technologies\ati.ace\core-static\clistart.exe [2006-11-10 90112]
"PWRISOVM.EXE"=c:\program files\poweriso\pwrisovm.exe [2010-04-12 180224]
"DivXUpdate"=c:\program files\divx\divx update\divxupdate.exe [2011-07-29 1259376]
"NBAgent"=c:\program files\nero\nero backitup & burn\nero backitup\nbagent.exe [2010-03-14 1086760]
"Adobe Reader Speed Launcher"=c:\program files\adobe\reader 9.0\reader\reader_sl.exe [2012-12-19 41208]
"Adobe ARM"=c:\program files\common files\adobe\arm\1.0\adobearm.exe [2012-12-03 946352]
"SunJavaUpdateSched"=c:\program files\common files\java\java update\jusched.exe [2012-07-03 252848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Badoo Desktop"=C:\Documents and Settings\All Users\Data aplikací\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [2012-12-24 1067232]
"DAEMON Tools Lite"=C:\program files\daemon tools lite\DTLite.exe [2012-02-13 3481408]
"Skype"=c:\program files\skype\phone\skype.exe [2012-02-29 17148552]
"EA Core"=c:\program files\electronic arts\eadm\core.exe [2008-07-22 2772992]
"Steam"=c:\program files\steam\steam.exe [2013-02-15 1597864]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-09-14 122880]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\WINDOWS\system32\msiexec.exe"="C:\WINDOWS\system32\msiexec.exe:*:Enabled:UpdateManagerSetup"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\BitTorrent\BitTorrent.exe"="C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.1040\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.1040\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.1544\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.1544\Agent.exe:*:Enabled:Battle.net Update Agent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"VIDC.WMV3"=wmv9vcm.dll

======List of files/folders created in the last 1 month======

2013-03-20 14:28:04 ----D---- C:\Program Files\trend micro
2013-03-20 14:28:03 ----D---- C:\rsit
2013-03-20 14:11:31 ----D---- C:\Program Files\CCleaner
2013-03-20 13:10:56 ----SHD---- C:\RECYCLER
2013-03-19 15:15:06 ----D---- C:\WINDOWS.2
2013-03-19 15:07:49 ----ASH---- C:\pagefile.sys
2013-03-19 15:03:21 ----D---- C:\WINDOWS.1
2013-03-16 07:55:31 ----A---- C:\Boot.bak
2013-03-16 07:55:21 ----RASHD---- C:\cmdcons
2013-03-15 10:23:32 ----D---- C:\WINDOWS\CTQNKHQJG9IF81UN
2013-03-15 10:05:17 ----D---- C:\WINDOWS.0
2013-03-15 10:01:01 ----D---- C:\Program Files\Common Files\Adobe
2013-03-15 10:01:01 ----D---- C:\Program Files\Adobe
2013-03-15 06:54:30 ----DC---- C:\WINDOWS\$NtUninstallKB2807986$
2013-03-14 11:17:32 ----D---- C:\Program Files\Common Files\Adobe(2)
2013-03-14 11:17:32 ----D---- C:\Program Files\Adobe(2)
2013-03-11 13:11:02 ----D---- C:\Program Files\GameSpy
2013-03-09 16:00:16 ----D---- C:\Program Files\Mozilla Firefox
2013-02-22 18:13:36 ----D---- C:\Documents and Settings\Lukasek\Data aplikací\Wargaming.net
2013-02-21 12:47:25 ----D---- C:\Program Files\EA Sports

======List of files/folders modified in the last 1 month======

2013-03-20 14:28:04 ----RD---- C:\Program Files
2013-03-20 14:28:00 ----D---- C:\WINDOWS\Prefetch
2013-03-20 14:13:05 ----D---- C:\WINDOWS\Temp
2013-03-20 14:12:12 ----D---- C:\WINDOWS\Debug
2013-03-20 14:12:12 ----D---- C:\WINDOWS
2013-03-20 14:09:39 ----D---- C:\Program Files\Steam
2013-03-20 14:09:00 ----D---- C:\Documents and Settings\Lukasek\Data aplikací\Skype
2013-03-20 14:02:14 ----N---- C:\WINDOWS\SchedLgU.Txt
2013-03-20 13:05:09 ----SHD---- C:\System Volume Information
2013-03-20 13:03:11 ----D---- C:\WINDOWS\system32\drivers
2013-03-20 12:44:40 ----D---- C:\WINDOWS\system32
2013-03-20 12:43:53 ----D---- C:\WINDOWS\system32\drivers\etc
2013-03-20 12:43:50 ----SD---- C:\WINDOWS\Tasks
2013-03-19 22:08:59 ----D---- C:\WINDOWS\system32\CatRoot2
2013-03-19 19:03:26 ----A---- C:\WINDOWS\system.ini
2013-03-19 19:00:06 ----D---- C:\WINDOWS\system32\config
2013-03-19 18:55:41 ----D---- C:\WINDOWS\AppPatch
2013-03-19 18:55:33 ----D---- C:\Program Files\Common Files
2013-03-19 18:28:54 ----D---- C:\Documents and Settings\Lukasek\Data aplikací\BitTorrent
2013-03-19 17:12:09 ----SHD---- C:\WINDOWS\Installer
2013-03-19 15:23:16 ----RASH---- C:\boot.ini
2013-03-19 10:39:55 ----D---- C:\Documents and Settings
2013-03-18 12:37:03 ----HD---- C:\WINDOWS\inf
2013-03-16 09:03:06 ----A---- C:\WINDOWS\system32\MRT.exe
2013-03-16 09:02:36 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-03-16 09:02:31 ----D---- C:\Program Files\Internet Explorer
2013-03-16 09:01:19 ----D---- C:\WINDOWS\system32\CatRoot
2013-03-16 08:14:24 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2013-03-15 10:22:59 ----D---- C:\Config.Msi
2013-03-15 10:21:07 ----D---- C:\WINDOWS\system32\DirectX
2013-03-15 10:20:54 ----D---- C:\Games
2013-03-15 10:07:38 ----D---- C:\WINDOWS\system32\wbem
2013-03-15 10:07:37 ----D---- C:\WINDOWS\Registration
2013-03-15 10:00:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2013-03-15 06:54:57 ----D---- C:\WINDOWS\ie8updates
2013-03-15 06:54:43 ----HD---- C:\WINDOWS\$hf_mig$
2013-03-12 07:16:12 ----D---- C:\Documents and Settings\Lukasek\Data aplikací\DAEMON Tools Lite
2013-03-11 15:45:27 ----HD---- C:\Program Files\InstallShield Installation Information
2013-03-11 13:09:03 ----RSD---- C:\WINDOWS\assembly
2013-03-11 13:05:36 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2013-03-11 13:05:31 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2013-03-11 13:05:29 ----A---- C:\WINDOWS\system32\pbsvc.exe
2013-03-11 12:40:24 ----D---- C:\Program Files\Electronic Arts
2013-03-10 11:32:46 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-03-01 03:27:55 ----A---- C:\WINDOWS\system32\mshtml.dll
2013-02-28 07:20:03 ----D---- C:\Program Files\Common Files\Symantec Shared
2013-02-26 11:50:45 ----D---- C:\WINDOWS\Minidump
2013-02-22 11:20:12 ----D---- C:\WINDOWS\WinSxS
2013-02-22 11:09:44 ----D---- C:\Program Files\Paradox Interactive

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2011-11-29 45648]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-13 44672]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2012-10-30 25256]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2012-08-21 18544]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2012-10-30 35928]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2012-10-30 738504]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2012-10-30 361032]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2012-10-30 54232]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2012-02-25 242240]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2010-04-12 59388]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-10-30 21256]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2012-10-30 97608]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2012-09-25 281760]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2012-09-25 25888]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-09-14 2455040]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2005-09-20 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 ATITool;ATITool Overclocking Utility; C:\WINDOWS\system32\DRIVERS\ATITool.sys [2006-11-10 24064]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2005-01-28 18944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-09-14 483328]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-30 44808]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2012-11-25 161768]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2013-03-11 66872]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2007-09-14 593920]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-02-29 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-16 253656]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-03-09 115608]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2012-05-09 3975544]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Lokhys
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 19 bře 2013 09:01

Re: policie vir velky problem

#74 Příspěvek od Lokhys »

Jo a ještě když zapnu hru třeba FIfu 2010 tak po nějakych 5 minutach hraní semi vypne monitor asi kvuli grafarně to mi nedělalo :) když sem to hral předtím... a trochu pomali pc ještě je

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: policie vir velky problem

#75 Příspěvek od vyosek »

:arrow: Spustte HJT a provedeme fixnuti polozek
  • HJT najdete zde C:\Program Files\trend micro\Lukasek.exe
  • Otevre se Vam okno, kliknete na Do a system scan only
  • V dalsim okne najdete radky které jsem Vam vypsal nize, vedle nich je ctverecek, do ktereho udelate zatrzitko
  • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://badoo.com/startpage/
    O4 - HKLM\..\Run: [PWRISOVM.EXE] c:\program files\poweriso\pwrisovm.exe
    O4 - HKLM\..\Run: [DivXUpdate] "c:\program files\divx\divx update\divxupdate.exe" /checknow
    O4 - HKLM\..\Run: [NBAgent] "c:\program files\nero\nero backitup & burn\nero backitup\nbagent.exe" /winstart
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] c:\program files\adobe\reader 9.0\reader\reader_sl.exe
    O4 - HKLM\..\Run: [Adobe ARM] c:\program files\common files\adobe\arm\1.0\adobearm.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] c:\program files\common files\java\java update\jusched.exe
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\program files\daemon tools lite\DTLite.exe" -autorun
    O4 - HKCU\..\Run: [Skype] "c:\program files\skype\phone\skype.exe" /minimized /regrun
    O4 - HKCU\..\Run: [EA Core] "c:\program files\electronic arts\eadm\core.exe" -silent
    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
  • Kliknete na Fix checked (vlevo dole)
  • HJT se Vas zepta zda opravdu ANO, s tim souhlasite a je hotovo Obrázek
:arrow: Mrknete, jetsli nejsou ventilatory a vetraci pruduchy zanesene prachem

:arrow: Aktualizujte ovladac ke GK

:arrow: Napiste co PC
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno