Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pre STELL

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
misel5
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 15 dub 2014 19:40

Pre STELL

#1 Příspěvek od misel5 »

Je to známeho počítač, neviem prečo tam nemá poriadny antivírus ale Pandu. Potom sa čuduje že chytá vírusy :-D

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-04-2014 01
Ran by SYSTEM on MININT-CR2D3KB on 15-04-2014 20:02:52
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.


The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [168216 2011-05-10] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] => C:\Windows\system32\hkcmd.exe [392472 2011-05-10] (Intel Corporation)
HKLM\...\Run: [Persistence] => C:\Windows\system32\igfxpers.exe [416024 2011-05-10] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912 2011-06-09] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-06-07] (IDT, Inc.)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [932000 2011-06-14] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [795808 2011-06-14] (Atheros Commnucations)
HKLM\...\Run: [SetDefault] => C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [42808 2011-06-27] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-04-29] (Intel Corporation)
HKLM-x32\...\Run: [HPQuickWebProxy] => C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [168504 2011-06-28] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586808 2011-04-08] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2011-01-27] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-05-17] (EasyBits Software AS)
HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAMain.exe [37152 2012-08-26] (Panda Security, S.L.)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
HKLM\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe,
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\Default\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-20] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-20] (Microsoft Corporation)
HKU\hellmaster66\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [15146376 2011-04-18] (Skype Technologies S.A.)
HKU\hellmaster66\...\Run: [uTorrent] => C:\Program Files (x86)\uTorrent\uTorrent.exe [802136 2013-05-26] (BitTorrent Inc.)
Startup: C:\Users\hellmaster66\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wlvd7ta0.lnk
ShortcutTarget: wlvd7ta0.lnk -> C:\ProgramData\0at7dvlw.gsa (Microsoft Corporation)

==================== Services (Whitelisted) =================

S2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-06-14] (Atheros)
S2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe [140064 2012-08-26] (Panda Security, S.L.)
S2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAService.exe [36640 2012-08-26] (Panda Security, S.L.)
S2 Winmgmt; C:\ProgramData\wlvd7ta0.faa [332020 2014-03-29] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

S1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [89128 2012-06-27] (Panda Security, S.L.)
S1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [116776 2012-06-27] (Panda Security, S.L.)
S1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [113192 2012-06-27] (Panda Security, S.L.)
S1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [33320 2012-06-27] (Panda Security, S.L.)
S1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [93224 2012-06-27] (Panda Security, S.L.)
S4 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [68648 2012-06-27] (Panda Security, S.L.)
S1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [116776 2012-06-27] (Panda Security, S.L.)
S1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [304680 2012-06-27] (Panda Security, S.L.)
S1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [109096 2012-06-27] (Panda Security, S.L.)
S1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [112680 2012-06-27] (Panda Security, S.L.)
S1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [219688 2012-07-12] (Panda Security, S.L.)
S1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [105000 2012-06-27] (Panda Security, S.L.)
S2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [168488 2012-08-26] (Panda Security, S.L.)
S2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [120872 2012-08-26] (Panda Security, S.L.)
S1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [205352 2012-08-26] (Panda Security, S.L.)
S2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [124456 2012-08-26] (Panda Security, S.L.)
S2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [130088 2012-08-26] (Panda Security, S.L.)
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [57928 2011-03-10] ()

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-14 20:21 - 2014-04-15 20:02 - 00000000 ____D () C:\FRST
2014-04-09 10:34 - 2011-03-10 08:05 - 00057928 _____ () C:\Windows\System32\Drivers\PSKMAD.sys
2014-03-29 11:22 - 2014-03-29 11:22 - 95027928 ____T () C:\ProgramData\wlvd7ta0.bbr
2014-03-29 11:22 - 2014-03-29 11:22 - 00332020 ____T (Microsoft Corporation) C:\ProgramData\wlvd7ta0.faa
2014-03-29 11:22 - 2014-03-29 11:22 - 00192265 _____ (Microsoft Corporation) C:\ProgramData\0at7dvlw.gsa
2014-03-29 11:17 - 2014-03-29 11:24 - 00000000 ____D () C:\Users\hellmaster66\Downloads\Babovresky 2[2014]DVDRip.XviD[Česko]
2014-03-29 11:17 - 2014-03-29 11:17 - 00015072 _____ () C:\Users\hellmaster66\Downloads\Babovresky_2[2014]DVDRip.XviD[ÄŚesko].torrent
2014-03-23 08:59 - 2014-03-23 08:59 - 01954663 _____ () C:\Users\hellmaster66\Downloads\Vychodiskove_statisticke_udaje_a_podiel_obci_na_vynose_DPFO_pre_rok_2011.htm
2014-03-23 08:57 - 2014-03-23 08:57 - 00022154 _____ () C:\Users\hellmaster66\Downloads\Vychodiskove_statis_udaje_r2008_podiel_vynoseDPFO_VUC.htm
2014-03-17 00:06 - 2014-03-17 00:06 - 00000000 ____D () C:\Users\hellmaster66\Downloads\Walking with Dinosaurs 3D (2013) [1080p]
2014-03-17 00:05 - 2014-03-17 00:05 - 00013384 _____ () C:\Users\hellmaster66\Downloads\Walking_with_Dinosaurs_3D_2013_1080p_BluRay_x264_YIFY_mp4.torrent

==================== One Month Modified Files and Folders =======

2014-04-15 20:02 - 2014-04-14 20:21 - 00000000 ____D () C:\FRST
2014-04-15 07:59 - 2014-03-01 08:07 - 00000944 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-15 07:59 - 2012-12-29 06:41 - 00000000 ____D () C:\Users\hellmaster66\AppData\Roaming\uTorrent
2014-04-15 07:59 - 2009-07-13 21:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-15 07:59 - 2009-07-13 20:51 - 00095358 _____ () C:\Windows\setupact.log
2014-04-14 10:06 - 2011-09-22 15:45 - 01161367 _____ () C:\Windows\WindowsUpdate.log
2014-04-14 10:04 - 2012-09-05 04:29 - 00000000 ____D () C:\Users\hellmaster66\Documents\Bluetooth Folder
2014-04-14 09:59 - 2009-07-13 20:45 - 00032064 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-14 09:59 - 2009-07-13 20:45 - 00032064 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-14 09:25 - 2013-03-20 08:29 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-14 09:21 - 2014-03-01 08:07 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-14 09:21 - 2012-09-07 03:25 - 00000166 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-04-10 11:16 - 2012-09-05 11:25 - 00000000 ____D () C:\Users\hellmaster66\AppData\Roaming\Skype
2014-04-09 10:29 - 2013-08-25 23:17 - 00002019 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-03-29 11:24 - 2014-03-29 11:17 - 00000000 ____D () C:\Users\hellmaster66\Downloads\Babovresky 2[2014]DVDRip.XviD[Česko]
2014-03-29 11:24 - 2012-09-05 04:17 - 00000000 ____D () C:\Users\hellmaster66\AppData\Local\VirtualStore
2014-03-29 11:22 - 2014-03-29 11:22 - 95027928 ____T () C:\ProgramData\wlvd7ta0.bbr
2014-03-29 11:22 - 2014-03-29 11:22 - 00332020 ____T (Microsoft Corporation) C:\ProgramData\wlvd7ta0.faa
2014-03-29 11:22 - 2014-03-29 11:22 - 00192265 _____ (Microsoft Corporation) C:\ProgramData\0at7dvlw.gsa
2014-03-29 11:17 - 2014-03-29 11:17 - 00015072 _____ () C:\Users\hellmaster66\Downloads\Babovresky_2[2014]DVDRip.XviD[ÄŚesko].torrent
2014-03-29 09:37 - 2009-07-13 21:13 - 00006426 _____ () C:\Windows\System32\PerfStringBackup.INI
2014-03-27 13:42 - 2012-12-09 08:05 - 00006080 _____ () C:\ProgramData\NanoRepository.bin
2014-03-27 13:41 - 2014-03-01 08:07 - 00000000 ____D () C:\Users\hellmaster66\AppData\Local\Google
2014-03-23 08:59 - 2014-03-23 08:59 - 01954663 _____ () C:\Users\hellmaster66\Downloads\Vychodiskove_statisticke_udaje_a_podiel_obci_na_vynose_DPFO_pre_rok_2011.htm
2014-03-23 08:57 - 2014-03-23 08:57 - 00022154 _____ () C:\Users\hellmaster66\Downloads\Vychodiskove_statis_udaje_r2008_podiel_vynoseDPFO_VUC.htm
2014-03-20 12:09 - 2013-07-14 10:45 - 00000000 ____D () C:\Windows\System32\MRT
2014-03-20 12:07 - 2013-02-06 11:33 - 90015360 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2014-03-19 12:53 - 2012-12-09 08:05 - 00006080 _____ () C:\ProgramData\NanoRepository.bin.bak
2014-03-19 11:08 - 2013-09-01 02:11 - 00050688 ___SH () C:\Users\hellmaster66\Downloads\Thumbs.db
2014-03-17 12:44 - 2013-06-12 23:40 - 00000000 ____D () C:\Users\hellmaster66\Desktop\face
2014-03-17 00:06 - 2014-03-17 00:06 - 00000000 ____D () C:\Users\hellmaster66\Downloads\Walking with Dinosaurs 3D (2013) [1080p]
2014-03-17 00:05 - 2014-03-17 00:05 - 00013384 _____ () C:\Users\hellmaster66\Downloads\Walking_with_Dinosaurs_3D_2013_1080p_BluRay_x264_YIFY_mp4.torrent

Some content of TEMP:
====================
C:\Users\hellmaster66\AppData\Local\Temp\jjxuc-cs.dll
C:\Users\hellmaster66\AppData\Local\Temp\SCC.dll
C:\Users\hellmaster66\AppData\Local\Temp\SHSetup.exe
C:\Users\hellmaster66\AppData\Local\Temp\SkypeSetup.exe


==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2014-02-26 12:55:43
Restore point made on: 2014-02-26 13:15:51
Restore point made on: 2014-02-27 14:45:11
Restore point made on: 2014-03-06 12:54:30
Restore point made on: 2014-03-13 07:31:42
Restore point made on: 2014-03-13 14:30:03
Restore point made on: 2014-03-19 08:39:10
Restore point made on: 2014-03-20 12:07:24
Restore point made on: 2014-03-27 12:10:53
Restore point made on: 2014-03-27 12:35:43
Restore point made on: 2014-04-09 10:32:36

==================== Memory info ===========================

Percentage of memory in use: 18%
Total physical RAM: 4043.86 MB
Available physical RAM: 3314.27 MB
Total Pagefile: 4042.01 MB
Available Pagefile: 3306.38 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:444.61 GB) (Free:219.23 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (Recovery) (Fixed) (Total:16.99 GB) (Free:1.83 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: (HP_TOOLS) (Fixed) (Total:3.96 GB) (Free:1.08 GB) FAT32
Drive h: () (Removable) (Total:7.21 GB) (Free:7.15 GB) NTFS
Drive x: (Boot) (Fixed) (Total:0.25 GB) (Free:0.25 GB) NTFS
Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: C69126C0)

Partition: GPT Partition Type.

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 7 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.


LastRegBack: 2014-04-03 11:28

==================== End Of Log ============================

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Pre STELL

#2 Příspěvek od stell »

Ahoj.
Ok vydrz, prestudujem log a zacneme s cistenim.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Pre STELL

#3 Příspěvek od stell »

1:Spust poznamkovy blok, Notepad.
2:Skopiruj tento script,v kod>>bez textu kod>> , a vloz do poznamkoveho bloku.
3:Uloz to ako vsetky subory>> nazov>>fixlist.txt a uloz to na flash disk, tam kde mas program Frst64.exe.
4:Spust znovu program Frst64.exe tak ako si generovala log, Ale POZOR, teraz kliknes na Gombik FIX
Prebehne oprava a pocitac sa restartuje, normalne nechaj pocitac nabehnut do WINDOWS, ak tam budes ci aj nie>.tak napis a pokracujeme dalej.

Kód: Vybrat vše

HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
Startup: C:\Users\hellmaster66\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wlvd7ta0.lnk
ShortcutTarget: wlvd7ta0.lnk -> C:\ProgramData\0at7dvlw.gsa (Microsoft Corporation)
S2 Winmgmt; C:\ProgramData\wlvd7ta0.faa [332020 2014-03-29] (Microsoft Corporation)
C:\ProgramData\wlvd7ta0.bbr
C:\ProgramData\wlvd7ta0.faa
C:\ProgramData\0at7dvlw.gsa
C:\Users\hellmaster66\AppData\Local\Temp
Hosts:
CMD: shutdown /r
Poznamka:
Na Flashdisku sa ulozi aj log >>nazov Fixlog.txt, obsah vloz sem.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

misel5
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 15 dub 2014 19:40

Re: Pre STELL

#4 Příspěvek od misel5 »

Prepáč, večer sa mi už nedalo pokračovať, ale počítač už ide bez problémov :-)

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-04-2014 01
Ran by SYSTEM at 2014-04-16 13:38:56 Run:1
Running from H:\
Boot Mode: Recovery
==============================================

Content of fixlist:
*****************
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
Startup: C:\Users\hellmaster66\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wlvd7ta0.lnk
ShortcutTarget: wlvd7ta0.lnk -> C:\ProgramData\0at7dvlw.gsa (Microsoft Corporation)
S2 Winmgmt; C:\ProgramData\wlvd7ta0.faa [332020 2014-03-29] (Microsoft Corporation)
C:\ProgramData\wlvd7ta0.bbr
C:\ProgramData\wlvd7ta0.faa
C:\ProgramData\0at7dvlw.gsa
C:\Users\hellmaster66\AppData\Local\Temp
Hosts:
CMD: shutdown /r
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\*Restore => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\EnableShellExecuteHooks => Value deleted successfully.
C:\Users\hellmaster66\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wlvd7ta0.lnk => Moved successfully.
C:\ProgramData\0at7dvlw.gsa => Moved successfully.
Winmgmt => Service restored successfully.
C:\ProgramData\wlvd7ta0.bbr => Moved successfully.
C:\ProgramData\wlvd7ta0.faa => Moved successfully.
"C:\ProgramData\0at7dvlw.gsa" => File/Directory not found.
C:\Users\hellmaster66\AppData\Local\Temp => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

========= shutdown /r =========

'shutdown' is not recognized as an internal or external command,
operable program or batch file.

========= End of CMD: =========


==== End of Fixlog ====

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Pre STELL

#5 Příspěvek od stell »

ok, pokracuj takto:
1: Pouzi ADWcleaner ,presne podla navodu.
http://www.viruskasino.com/2012/09/adwcleaner.html
log vloz sem.
2:Malwarebytes,
http://www.bleepingcomputer.com/downloa ... re/dl/241/
Uplna kontrola najdene odstran.
Log vloz sem.
Navod.
http://www.viruskasino.com/2011/03/navo ... bytes.html
Potom sa uvidi ci vsetko, je ok.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Pre STELL

#6 Příspěvek od stell »

temu zatvaram.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

Zamčeno