Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pomalý notebook - Podezření na vir

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pomalý notebook - Podezření na vir

#16 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Majkl55
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 15 kvě 2008 12:20

Re: Pomalý notebook - Podezření na vir

#17 Příspěvek od Majkl55 »

Pořád se to dost seká. Co byste poradil jako další krok? Díky
Majkl55

Majkl55
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 15 kvě 2008 12:20

Re: Pomalý notebook - Podezření na vir

#18 Příspěvek od Majkl55 »

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-02-2014
Ran by Ondra (administrator) on ONDRA-PC on 17-02-2014 22:12:50
Running from C:\Users\Ondra\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(ASUS) C:\Program Files\ASUS\SmartLogon\smartlogon.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
() C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
(ATK) C:\Program files\P4G\BatteryLife.exe
(ASUS) C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe
() C:\Program Files\ASUS\ASUS Live Update\ALU.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControl.exe
() C:\Program Files\Wireless Console 2\wcourier.exe
(ATK) C:\Program Files\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\WDC.exe
(ASUSTeK) C:\Windows\System32\ACEngSvr.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(CyberLink) C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files\ASUS\ATK Media\DMedia.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ASUS) C:\Windows\AsScrPro.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(SMART Technologies ULC) C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTSNMPAgent.exe
(SMART Technologies) C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardService.exe
(Apple Inc.) C:\Program Files\QuickTime\qttask.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(SMART Technologies ULC) C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardTools.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(SMART Technologies ULC) C:\Program Files\SMART Technologies\SMART Board Drivers\Aware.exe
(SMART Technologies ULC) C:\Program Files\SMART Technologies\SMART Board Drivers\Marker.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_12_0_0_44_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [CLMLServer] - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [104936 2008-07-19] (CyberLink)
HKLM\...\Run: [P2Go_Menu] - C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [210216 2008-06-14] (CyberLink Corp.)
HKLM\...\Run: [HControlUser] - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [98304 2008-08-18] (ASUS)
HKLM\...\Run: [ATKOSD2] - C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [8105984 2008-09-03] (ASUS)
HKLM\...\Run: [ATKMEDIA] - C:\Program Files\ASUS\ATK Media\DMedia.exe [159744 2008-12-29] (ASUS)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6711840 2009-02-11] (Realtek Semiconductor)
HKLM\...\Run: [ADSMTray] - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [266240 2008-04-01] (ASUSTek Computer Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.)
HKLM\...\Run: [ACMON] - C:\Program Files\ASUS\Splendid\ACMON.exe [851968 2008-10-01] (ATK)
HKLM\...\Run: [ASUS Screen Saver Protector] - C:\Windows\AsScrPro.exe [3054136 2009-06-10] (ASUS)
HKLM\...\Run: [ASUS Camera ScreenSaver] - C:\Windows\AsScrProlog.exe [47672 2009-06-10] ()
HKLM\...\Run: [MobileConnect] - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe [2086912 2008-10-09] (Vodafone)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [13789728 2009-07-02] (NVIDIA Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [] - [X]
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [3076144 2011-08-09] (ESET)
HKLM\...\Run: [SMART SNMP Agent] - C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTSNMPAgent.exe [1037608 2008-07-31] (SMART Technologies ULC)
HKLM\...\Run: [SMART Board Service] - C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardService.exe [2123048 2008-08-08] (SMART Technologies)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2011-06-15] (Apple Inc.)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SRS Premium Sound] - C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe [3257592 2009-03-05] (SRS Labs, Inc.)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-06-10] (Google Inc.)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SearchProtection] - "C:\Users\Ondra\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: J - J:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {03e3fcdf-b50e-11de-bcf2-806e6f6e6963} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {2fb50ba3-8de1-11df-9dc1-002618369cd6} - K:\InstallTomTomHOME.exe
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {548139f8-994d-11de-a75b-806e6f6e6963} - J:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {66748417-6c0d-11de-9f97-002618369cd6} - H:\SETUP.EXE
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {74c29eba-a09b-11de-bdb7-002618369cd6} - I:\LiteAuto.exe
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3017-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3019-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216d1-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216ef-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d21722-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d2172a-7bc1-11de-9bef-002618369cd6} - J:\setup_vmc_lite.exe /checkApplicationPresence
AppInit_DLLs: c:\progra~1\gse7cc~1.ena => File Not Found
Lsa: [Notification Packages] scecli C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT
Startup: C:\Users\Ondra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://startsear.ch/?aff=1&q={searchTerms}
SearchScopes: HKLM - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... lz=1I7ASUS
SearchScopes: HKCU - DefaultScope {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... US_csCZ333
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co.uk/search?sourceid ... US_csCZ333
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... US_csCZ333
BHO: CIEDownload Object - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\Program Files\SMART Technologies\Notebook Software\NotebookPlugin.dll (SMART Technologies ULC.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {44990B00-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsup ... gctlcm.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{400211BB-8E7D-476A-B18B-BADBBB9EDD13}: [NameServer]10.255.255.10,10.255.255.20

FireFox:
========
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/OfficeLive,version=1.4 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013-01-01]

========================== Services (Whitelisted) =================

R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.)
R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [100920 2008-08-14] ()
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] ()
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [974944 2011-08-09] (ESET)
S2 gupdate1ca06351bc16190; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-07-16] (Google Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-10-09] (Vodafone)
S2 916e5338; "C:\Windows\system32\rundll32.exe" "c:\progra~1\GSSvc.dll",service

==================== Drivers (Whitelisted) ====================

R0 AsDsm; C:\Windows\system32\Drivers\AsDsm.sys [30264 2009-06-10] (ASUSTek Computer Inc)
R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2012-10-07] (DT Soft Ltd)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [163424 2011-08-09] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [118104 2011-08-04] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [147480 2011-08-04] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [33656 2011-08-04] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50624 2011-08-04] (ESET)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( )
R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1083880 2009-04-11] (Společnost Microsoft)
R3 SMARTMouseFilterx86; C:\Windows\System32\DRIVERS\SMARTMouseFilterx86.sys [11048 2008-07-30] (SMART Technologies ULC)
R3 SMARTVHidMini2000x86; C:\Windows\System32\DRIVERS\SMARTVHidMini2000x86.sys [14120 2008-07-30] (SMART Technologies ULC)
R3 SMARTVTabletPCx86; C:\Windows\System32\DRIVERS\SMARTVTabletPCx86.sys [16808 2008-07-30] (SMART Technologies ULC)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1753984 2009-03-16] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2009-07-08] ()
R3 SRS_PremiumSound_Service; C:\Windows\System32\drivers\srs_PremiumSound_i386.sys [230952 2009-01-14] ()
U3 a3qff9o1; C:\Windows\system32\Drivers\a3qff9o1.sys [0 ] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-17 22:12 - 2014-02-17 22:13 - 00019477 _____ () C:\Users\Ondra\Desktop\FRST.txt
2014-02-17 22:11 - 2014-02-17 22:11 - 00015327 _____ () C:\Users\Ondra\AppData\Local\LM.bat
2014-02-17 22:09 - 2014-02-17 22:11 - 00029696 _____ () C:\Users\Ondra\AppData\Local\MSGBOX.EXE
2014-02-17 22:09 - 2014-02-17 22:09 - 00112640 _____ (forum.viry.cz) C:\Users\Ondra\Desktop\FRSTLauncher.exe
2014-02-17 22:09 - 2014-02-17 22:09 - 00015327 _____ () C:\Users\Ondra\Desktop\LM.bat
2014-02-17 22:08 - 2014-02-17 22:12 - 00000000 ____D () C:\FRST
2014-02-17 22:08 - 2014-02-17 22:08 - 01141248 _____ (Farbar) C:\Users\Ondra\Desktop\FRST.exe
2014-02-17 21:56 - 2014-02-17 21:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-17 21:33 - 2014-02-16 12:24 - 00008093 _____ () C:\zoek-results2014-02-16-122447.log
2014-02-16 12:07 - 2014-02-16 03:18 - 00020694 _____ () C:\zoek-results2014-02-16-031835.log
2014-02-15 18:07 - 2014-02-17 22:00 - 00008594 _____ () C:\zoek-results.log
2014-02-15 18:00 - 2014-02-15 18:01 - 01283584 _____ () C:\Users\Ondra\Desktop\zoek.exe
2014-02-11 21:02 - 2014-02-11 21:02 - 00000000 ____D () C:\ProgramData\WindowsSearch
2014-02-09 22:52 - 2014-02-09 22:13 - 00000419 _____ () C:\zoek-results2014-02-09-221302.log
2014-02-09 22:09 - 2014-02-16 00:01 - 00000000 ____D () C:\zoek_backup
2014-02-09 13:10 - 2014-02-17 21:59 - 00006218 _____ () C:\Windows\PFRO.log
2014-02-08 19:49 - 2014-02-09 13:39 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-02-08 19:49 - 2014-02-09 13:37 - 00000913 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-08 19:49 - 2014-02-08 19:49 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Malwarebytes
2014-02-08 19:49 - 2014-02-08 19:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-08 19:49 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-08 19:48 - 2014-02-08 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe
2014-02-08 17:36 - 2014-02-08 17:36 - 00000000 ____D () C:\rsit
2014-02-08 17:21 - 2014-02-16 17:37 - 00000000 ____D () C:\AdwCleaner
2014-02-08 17:09 - 2014-02-08 17:20 - 01166132 _____ () C:\Users\Ondra\Desktop\adwcleaner.exe
2014-02-06 20:58 - 2014-02-06 20:58 - 00000000 ____D () C:\ProgramData\UTubeNooAds
2014-02-02 16:24 - 2014-02-02 16:27 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\UTiubeAdBlock
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl
2014-01-19 18:32 - 2014-02-09 15:23 - 00000000 ____D () C:\ProgramData\YoutubeAdblocker
2014-01-19 18:32 - 2014-02-09 15:23 - 00000000 ____D () C:\ProgramData\greAttsaver
2014-01-19 18:32 - 2014-02-06 20:58 - 00000000 ____D () C:\ProgramData\dfbcdfee34f10b72
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Ondra\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\House Of Soft
2014-01-19 18:30 - 2014-01-19 18:36 - 00000000 ____D () C:\ProgramData\InstallMate

==================== One Month Modified Files and Folders =======

2014-02-17 22:13 - 2014-02-17 22:12 - 00019477 _____ () C:\Users\Ondra\Desktop\FRST.txt
2014-02-17 22:12 - 2014-02-17 22:08 - 00000000 ____D () C:\FRST
2014-02-17 22:11 - 2014-02-17 22:11 - 00015327 _____ () C:\Users\Ondra\AppData\Local\LM.bat
2014-02-17 22:11 - 2014-02-17 22:09 - 00029696 _____ () C:\Users\Ondra\AppData\Local\MSGBOX.EXE
2014-02-17 22:09 - 2014-02-17 22:09 - 00112640 _____ (forum.viry.cz) C:\Users\Ondra\Desktop\FRSTLauncher.exe
2014-02-17 22:09 - 2014-02-17 22:09 - 00015327 _____ () C:\Users\Ondra\Desktop\LM.bat
2014-02-17 22:08 - 2014-02-17 22:08 - 01141248 _____ (Farbar) C:\Users\Ondra\Desktop\FRST.exe
2014-02-17 22:06 - 2006-11-02 10:33 - 01393902 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-17 22:01 - 2009-06-25 20:54 - 00031871 _____ () C:\ProgramData\nvModes.001
2014-02-17 22:01 - 2009-06-10 04:39 - 00000000 ___HD () C:\ASUS.DAT
2014-02-17 22:00 - 2014-02-15 18:07 - 00008594 _____ () C:\zoek-results.log
2014-02-17 21:59 - 2014-02-09 13:10 - 00006218 _____ () C:\Windows\PFRO.log
2014-02-17 21:59 - 2013-02-19 10:13 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-17 21:59 - 2013-01-04 01:11 - 00045056 _____ () C:\Windows\system32\acovcnt.exe
2014-02-17 21:59 - 2009-06-25 20:53 - 00031871 _____ () C:\ProgramData\nvModes.dat
2014-02-17 21:59 - 2006-11-02 13:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-17 21:59 - 2006-11-02 12:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-17 21:59 - 2006-11-02 12:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-17 21:58 - 2006-11-02 13:01 - 00032566 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-17 21:57 - 2009-06-10 04:09 - 00000012 _____ () C:\Windows\bthservsdp.dat
2014-02-17 21:57 - 2009-06-10 03:37 - 01980783 _____ () C:\Windows\WindowsUpdate.log
2014-02-17 21:52 - 2009-07-31 14:13 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Skype
2014-02-17 21:45 - 2013-02-19 10:13 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-17 21:17 - 2013-03-31 19:13 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-17 21:16 - 2014-02-17 21:56 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-16 17:37 - 2014-02-08 17:21 - 00000000 ____D () C:\AdwCleaner
2014-02-16 14:44 - 2013-01-03 21:21 - 00000924 _____ () C:\Windows\Tasks\Google Software Updater.job
2014-02-16 12:24 - 2014-02-17 21:33 - 00008093 _____ () C:\zoek-results2014-02-16-122447.log
2014-02-16 03:18 - 2014-02-16 12:07 - 00020694 _____ () C:\zoek-results2014-02-16-031835.log
2014-02-16 00:01 - 2014-02-09 22:09 - 00000000 ____D () C:\zoek_backup
2014-02-15 18:01 - 2014-02-15 18:00 - 01283584 _____ () C:\Users\Ondra\Desktop\zoek.exe
2014-02-11 21:02 - 2014-02-11 21:02 - 00000000 ____D () C:\ProgramData\WindowsSearch
2014-02-09 22:13 - 2014-02-09 22:52 - 00000419 _____ () C:\zoek-results2014-02-09-221302.log
2014-02-09 15:23 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\YoutubeAdblocker
2014-02-09 15:23 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\greAttsaver
2014-02-09 15:23 - 2012-09-30 14:01 - 00000000 ____D () C:\ProgramData\YTD YouTube Downloader & Converter
2014-02-09 13:39 - 2014-02-08 19:49 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-02-09 13:37 - 2014-02-08 19:49 - 00000913 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-08 19:49 - 2014-02-08 19:49 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Malwarebytes
2014-02-08 19:49 - 2014-02-08 19:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-08 19:48 - 2014-02-08 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe
2014-02-08 18:40 - 2009-08-15 18:43 - 00000000 ____D () C:\Windows\Minidump
2014-02-08 18:40 - 2009-07-04 20:55 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\uTorrent
2014-02-08 17:36 - 2014-02-08 17:36 - 00000000 ____D () C:\rsit
2014-02-08 17:36 - 2012-12-09 12:48 - 00000000 ____D () C:\Program Files\trend micro
2014-02-08 17:20 - 2014-02-08 17:09 - 01166132 _____ () C:\Users\Ondra\Desktop\adwcleaner.exe
2014-02-06 21:17 - 2012-04-03 18:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-02-06 21:17 - 2011-09-14 19:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-02-06 21:06 - 2009-07-16 16:49 - 00001978 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-06 20:58 - 2014-02-06 20:58 - 00000000 ____D () C:\ProgramData\UTubeNooAds
2014-02-06 20:58 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\dfbcdfee34f10b72
2014-02-06 20:58 - 2009-09-15 19:17 - 00000270 __RSH () C:\ProgramData\ntuser.pol
2014-02-06 20:30 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\system32\Msdtc
2014-02-06 20:29 - 2009-06-25 17:16 - 00000000 ____D () C:\Users\Ondra
2014-02-06 20:29 - 2006-11-02 10:22 - 51642368 _____ () C:\Windows\system32\config\software_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 45875200 _____ () C:\Windows\system32\config\system_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 44302336 _____ () C:\Windows\system32\config\components_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 00262144 _____ () C:\Windows\system32\config\security_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous
2014-02-06 20:29 - 2006-11-02 10:22 - 00262144 _____ () C:\Windows\system32\config\default_previous
2014-02-06 20:28 - 2009-06-10 04:41 - 00000000 ____D () C:\ProgramData\P4G
2014-02-06 20:28 - 2009-06-10 04:18 - 00000000 ____D () C:\Windows\system32\RTCOM
2014-02-06 20:28 - 2009-06-10 03:44 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-06 20:28 - 2006-11-02 12:37 - 00000000 ____D () C:\Windows\ShellNew
2014-02-06 20:28 - 2006-11-02 11:18 - 00000000 __RSD () C:\Windows\Media
2014-02-06 20:28 - 2006-11-02 11:18 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-02-06 20:28 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\system32\spool
2014-02-06 20:28 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\rescache
2014-02-06 20:27 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\registration
2014-02-03 20:50 - 2006-11-02 11:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-02 16:39 - 2009-06-10 03:49 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-02-02 16:27 - 2014-02-02 16:24 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\UTiubeAdBlock
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl
2014-01-19 21:08 - 2009-06-25 17:55 - 00009728 _____ () C:\Users\Ondra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-19 18:36 - 2014-01-19 18:30 - 00000000 ____D () C:\ProgramData\InstallMate
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Ondra\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Guest
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\Users\Administrator
2014-01-19 18:32 - 2014-01-19 18:32 - 00000000 ____D () C:\ProgramData\House Of Soft
2014-01-19 18:32 - 2009-06-25 17:34 - 00000000 ____D () C:\Users\Ondra\AppData\Local\Google

Files to move or delete:
====================
C:\Users\Ondra\AppData\Roaming\desktop.ini


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-02-17 22:05

==================== End Of Log ============================
Majkl55

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pomalý notebook - Podezření na vir

#19 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
    HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
    HKLM\...\Run: [] - [X]
    HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2011-06-15] (Apple Inc.)
    HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
    HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd)
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SRS Premium Sound] - C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe [3257592 2009-03-05] (SRS Labs, Inc.)
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-06-10] (Google Inc.)
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SearchProtection] - "C:\Users\Ondra\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: J - J:\setup_vmc_lite.exe /checkApplicationPresence
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {03e3fcdf-b50e-11de-bcf2-806e6f6e6963} - I:\setup_vmc_lite.exe /checkApplicationPresence
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {2fb50ba3-8de1-11df-9dc1-002618369cd6} - K:\InstallTomTomHOME.exe
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {548139f8-994d-11de-a75b-806e6f6e6963} - J:\setup_vmc_lite.exe /checkApplicationPresence
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {66748417-6c0d-11de-9f97-002618369cd6} - H:\SETUP.EXE
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {74c29eba-a09b-11de-bdb7-002618369cd6} - I:\LiteAuto.exe
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3017-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3019-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216d1-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216ef-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d21722-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
    HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d2172a-7bc1-11de-9bef-002618369cd6} - J:\setup_vmc_lite.exe /checkApplicationPresence
    AppInit_DLLs: c:\progra~1\gse7cc~1.ena => File Not Found
    GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
    
    SearchScopes: HKLM - DefaultScope value is missing.
    SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://startsear.ch/?aff=1&q={searchTerms}
    SearchScopes: HKLM - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS
    SearchScopes: HKCU - DefaultScope {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_csCZ333
    SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co.uk/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_csCZ333
    SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
    SearchScopes: HKCU - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_csCZ333
    
    S2 916e5338; "C:\Windows\system32\rundll32.exe" "c:\progra~1\GSSvc.dll",service
    U3 a3qff9o1; C:\Windows\system32\Drivers\a3qff9o1.sys [0 ] (Microsoft Corporation)
    S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
    S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
    S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
    
    2014-02-17 22:11 - 2014-02-17 22:11 - 00015327 _____ () C:\Users\Ondra\AppData\Local\LM.bat
    2014-02-17 22:09 - 2014-02-17 22:11 - 00029696 _____ () C:\Users\Ondra\AppData\Local\MSGBOX.EXE
    2014-02-17 22:09 - 2014-02-17 22:09 - 00112640 _____ (forum.viry.cz) C:\Users\Ondra\Desktop\FRSTLauncher.exe
    2014-02-17 22:09 - 2014-02-17 22:09 - 00015327 _____ () C:\Users\Ondra\Desktop\LM.bat
    2014-02-17 21:56 - 2014-02-17 21:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
    2014-02-17 21:33 - 2014-02-16 12:24 - 00008093 _____ () C:\zoek-results2014-02-16-122447.log
    2014-02-16 12:07 - 2014-02-16 03:18 - 00020694 _____ () C:\zoek-results2014-02-16-031835.log
    2014-02-15 18:07 - 2014-02-17 22:00 - 00008594 _____ () C:\zoek-results.log
    2014-02-15 18:00 - 2014-02-15 18:01 - 01283584 _____ () C:\Users\Ondra\Desktop\zoek.exe
    2014-02-09 22:52 - 2014-02-09 22:13 - 00000419 _____ () C:\zoek-results2014-02-09-221302.log
    2014-02-09 22:09 - 2014-02-16 00:01 - 00000000 ____D () C:\zoek_backup
    2014-02-08 19:48 - 2014-02-08 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe
    2014-02-08 17:09 - 2014-02-08 17:20 - 01166132 _____ () C:\Users\Ondra\Desktop\adwcleaner.exe
    2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl
    C:\Users\Ondra\AppData\Roaming\desktop.ini
    c:\progra~1\GSSvc.dll
    C:\Users\Ondra\AppData\Roaming\Search Protection
    
    Hosts:
    CMD: shutdown /r /f /t 2
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Majkl55
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 15 kvě 2008 12:20

Re: Pomalý notebook - Podezření na vir

#20 Příspěvek od Majkl55 »

tady to je...

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 22-02-2014 01
Ran by Ondra at 2014-02-23 14:52:02 Run:1
Running from C:\Users\Ondra\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [] - [X]
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2011-06-15] (Apple Inc.)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SRS Premium Sound] - C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe [3257592 2009-03-05] (SRS Labs, Inc.)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-06-10] (Google Inc.)
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\Run: [SearchProtection] - "C:\Users\Ondra\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: J - J:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {03e3fcdf-b50e-11de-bcf2-806e6f6e6963} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {2fb50ba3-8de1-11df-9dc1-002618369cd6} - K:\InstallTomTomHOME.exe
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {548139f8-994d-11de-a75b-806e6f6e6963} - J:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {66748417-6c0d-11de-9f97-002618369cd6} - H:\SETUP.EXE
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {74c29eba-a09b-11de-bdb7-002618369cd6} - I:\LiteAuto.exe
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3017-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {a8ee3019-2733-11e0-93f0-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216d1-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d216ef-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d21722-7bc1-11de-9bef-002618369cd6} - I:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\...\MountPoints2: {d4d2172a-7bc1-11de-9bef-002618369cd6} - J:\setup_vmc_lite.exe /checkApplicationPresence
AppInit_DLLs: c:\progra~1\gse7cc~1.ena => File Not Found
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://startsear.ch/?aff=1&q={searchTerms}
SearchScopes: HKLM - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... lz=1I7ASUS
SearchScopes: HKCU - DefaultScope {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... US_csCZ333
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co.uk/search?sourceid ... US_csCZ333
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} URL = http://www.google.com/search?sourceid=i ... US_csCZ333

S2 916e5338; "C:\Windows\system32\rundll32.exe" "c:\progra~1\GSSvc.dll",service
U3 a3qff9o1; C:\Windows\system32\Drivers\a3qff9o1.sys [0 ] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

2014-02-17 22:11 - 2014-02-17 22:11 - 00015327 _____ () C:\Users\Ondra\AppData\Local\LM.bat
2014-02-17 22:09 - 2014-02-17 22:11 - 00029696 _____ () C:\Users\Ondra\AppData\Local\MSGBOX.EXE
2014-02-17 22:09 - 2014-02-17 22:09 - 00112640 _____ (forum.viry.cz) C:\Users\Ondra\Desktop\FRSTLauncher.exe
2014-02-17 22:09 - 2014-02-17 22:09 - 00015327 _____ () C:\Users\Ondra\Desktop\LM.bat
2014-02-17 21:56 - 2014-02-17 21:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-17 21:33 - 2014-02-16 12:24 - 00008093 _____ () C:\zoek-results2014-02-16-122447.log
2014-02-16 12:07 - 2014-02-16 03:18 - 00020694 _____ () C:\zoek-results2014-02-16-031835.log
2014-02-15 18:07 - 2014-02-17 22:00 - 00008594 _____ () C:\zoek-results.log
2014-02-15 18:00 - 2014-02-15 18:01 - 01283584 _____ () C:\Users\Ondra\Desktop\zoek.exe
2014-02-09 22:52 - 2014-02-09 22:13 - 00000419 _____ () C:\zoek-results2014-02-09-221302.log
2014-02-09 22:09 - 2014-02-16 00:01 - 00000000 ____D () C:\zoek_backup
2014-02-08 19:48 - 2014-02-08 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe
2014-02-08 17:09 - 2014-02-08 17:20 - 01166132 _____ () C:\Users\Ondra\Desktop\adwcleaner.exe
2014-01-31 20:40 - 2014-01-31 20:40 - 00000000 ____D () C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl
C:\Users\Ondra\AppData\Roaming\desktop.ini
c:\progra~1\GSSvc.dll
C:\Users\Ondra\AppData\Roaming\Search Protection

Hosts:
CMD: shutdown /r /f /t 2

End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => Value deleted successfully.
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ehTray.exe => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SRS Premium Sound => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\swg => Value deleted successfully.
HKU\S-1-5-21-3134179490-1787442154-2696964708-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtection => Value deleted successfully.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-3134179490-1787442154-2696964708-1000 => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{03e3fcdf-b50e-11de-bcf2-806e6f6e6963} => Key not found.
HKCR\CLSID\{03e3fcdf-b50e-11de-bcf2-806e6f6e6963} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2fb50ba3-8de1-11df-9dc1-002618369cd6} => Key not found.
HKCR\CLSID\{2fb50ba3-8de1-11df-9dc1-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{548139f8-994d-11de-a75b-806e6f6e6963} => Key not found.
HKCR\CLSID\{548139f8-994d-11de-a75b-806e6f6e6963} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{66748417-6c0d-11de-9f97-002618369cd6} => Key not found.
HKCR\CLSID\{66748417-6c0d-11de-9f97-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74c29eba-a09b-11de-bdb7-002618369cd6} => Key not found.
HKCR\CLSID\{74c29eba-a09b-11de-bdb7-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a8ee3017-2733-11e0-93f0-002618369cd6} => Key not found.
HKCR\CLSID\{a8ee3017-2733-11e0-93f0-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a8ee3019-2733-11e0-93f0-002618369cd6} => Key not found.
HKCR\CLSID\{a8ee3019-2733-11e0-93f0-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4d216d1-7bc1-11de-9bef-002618369cd6} => Key not found.
HKCR\CLSID\{d4d216d1-7bc1-11de-9bef-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4d216ef-7bc1-11de-9bef-002618369cd6} => Key not found.
HKCR\CLSID\{d4d216ef-7bc1-11de-9bef-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4d21722-7bc1-11de-9bef-002618369cd6} => Key not found.
HKCR\CLSID\{d4d21722-7bc1-11de-9bef-002618369cd6} => Key not found.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4d2172a-7bc1-11de-9bef-002618369cd6} => Key not found.
HKCR\CLSID\{d4d2172a-7bc1-11de-9bef-002618369cd6} => Key not found.
"c:\\progra~1\\gse7cc~1.ena" => Value Data removed successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{A8BD5B79-93F2-41E5-8180-A5EB5B5F5A08} => Key not found.
916e5338 => Service deleted successfully.
a3qff9o1 => Service not found.
IpInIp => Service deleted successfully.
NwlnkFlt => Service deleted successfully.
NwlnkFwd => Service deleted successfully.
"C:\Users\Ondra\AppData\Local\LM.bat" => File/Directory not found.
"C:\Users\Ondra\AppData\Local\MSGBOX.EXE" => File/Directory not found.
"C:\Users\Ondra\Desktop\FRSTLauncher.exe" => File/Directory not found.
C:\Users\Ondra\Desktop\LM.bat => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results2014-02-16-122447.log => Moved successfully.
C:\zoek-results2014-02-16-031835.log => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\Users\Ondra\Desktop\zoek.exe => Moved successfully.
C:\zoek-results2014-02-09-221302.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Ondra\Desktop\mbam-setup-1.75.0.1300.exe => Moved successfully.
C:\Users\Ondra\Desktop\adwcleaner.exe => Moved successfully.
C:\ProgramData\ggcmfjgbkdpknngfcdeedaoomenlenkl => Moved successfully.
C:\Users\Ondra\AppData\Roaming\desktop.ini => Moved successfully.
"c:\progra~1\GSSvc.dll" => File/Directory not found.
"C:\Users\Ondra\AppData\Roaming\Search Protection" => File/Directory not found.
Hosts was reset successfully.

========= shutdown /r /f /t 2 =========


========= End of CMD: =========



The system needs a manual reboot.

==== End of Fixlog ====
Majkl55

Majkl55
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 15 kvě 2008 12:20

Re: Pomalý notebook - Podezření na vir

#21 Příspěvek od Majkl55 »

Notebook se nerestartoval. Fixlist.txt jsem vytvoril. Co mate na mysli: "presunte vytvoreny fixlist vedle FRST"? Oba mam na plose vedle sebe. Mam fixlist presunout do adresare FRST?
Majkl55

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pomalý notebook - Podezření na vir

#22 Příspěvek od vyosek »

Provedl jste to dobre :thumbsup:

Jak se chova PC??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Majkl55
Návštěvník
Návštěvník
Příspěvky: 70
Registrován: 15 kvě 2008 12:20

Re: Pomalý notebook - Podezření na vir

#23 Příspěvek od Majkl55 »

PC je lepší než minulý týden, ale stále pomalé. Hlavně Explorer jde dost pomalu.
Majkl55

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pomalý notebook - Podezření na vir

#24 Příspěvek od vyosek »

:arrow: T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Doporucuji provest defragmentaci disku
  • Nejjednodussi (ale nejmene ucinny) zpusob je pomoci utility ve windowsech
    • Kliknete na Tento pocitac, dale na disk kliknete pravym tlacitkem, vyberte Vlastnosti
    • prepnete se do zalozky Nastroje
    • Nyni vidite pomucky Defragmentace - spustte ji kliknutim na Defragmentovat
    • Toto provedte se vsemi disky
  • Dalsi moznosti (a mnou doporucenou) je pres programek Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
    • Program stahnete, nainstalujte (dejte fajfku pryc u yahoo toolbaru) a spustte
    • Kliknete na Analyzovat
    • Pokud je ve sloupci Fragmentováno vice jak 5%, doporucuji provest defragmentaci (klik na Defragmentovat)
    • Postup provedte se vsemi disky
  • Posledni moznost je pres jednoduchy programek JKDefrag http://www.stahuj.centrum.cz/utility_a_ ... /jkdefrag/
    • Vyhodou programku je, ze se neinstaluje
    • Staci tedy jen stahnout dle verze vaseho OS a rozbalit
    • Nasledne spustit pomoci souboru JKDefrag pripadne JKDefrag64
    • Probehne analyza disku a nasledne i defragmentace
:arrow: Dejte novy log z RSIT a napiste co PC
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět