Pre STELL

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zamčeno
Zpráva
Autor
misel5
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 15 Dub 2014 19:40

Pre STELL

#1 Příspěvek od misel5 »

Je to známeho počítač, neviem prečo tam nemá poriadny antivírus ale Pandu. Potom sa čuduje že chytá vírusy :-D

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-04-2014 01
Ran by SYSTEM on MININT-CR2D3KB on 15-04-2014 20:02:52
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.


The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [168216 2011-05-10] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] => C:\Windows\system32\hkcmd.exe [392472 2011-05-10] (Intel Corporation)
HKLM\...\Run: [Persistence] => C:\Windows\system32\igfxpers.exe [416024 2011-05-10] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912 2011-06-09] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-06-07] (IDT, Inc.)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [932000 2011-06-14] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [795808 2011-06-14] (Atheros Commnucations)
HKLM\...\Run: [SetDefault] => C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [42808 2011-06-27] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-04-29] (Intel Corporation)
HKLM-x32\...\Run: [HPQuickWebProxy] => C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [168504 2011-06-28] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586808 2011-04-08] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2011-01-27] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-05-17] (EasyBits Software AS)
HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAMain.exe [37152 2012-08-26] (Panda Security, S.L.)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
HKLM\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe,
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\Default\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-20] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-20] (Microsoft Corporation)
HKU\hellmaster66\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [15146376 2011-04-18] (Skype Technologies S.A.)
HKU\hellmaster66\...\Run: [uTorrent] => C:\Program Files (x86)\uTorrent\uTorrent.exe [802136 2013-05-26] (BitTorrent Inc.)
Startup: C:\Users\hellmaster66\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wlvd7ta0.lnk
ShortcutTarget: wlvd7ta0.lnk -> C:\ProgramData\0at7dvlw.gsa (Microsoft Corporation)

==================== Services (Whitelisted) =================

S2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-06-14] (Atheros)
S2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe [140064 2012-08-26] (Panda Security, S.L.)
S2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAService.exe [36640 2012-08-26] (Panda Security, S.L.)
S2 Winmgmt; C:\ProgramData\wlvd7ta0.faa [332020 2014-03-29] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

S1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [89128 2012-06-27] (Panda Security, S.L.)
S1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [116776 2012-06-27] (Panda Security, S.L.)
S1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [113192 2012-06-27] (Panda Security, S.L.)
S1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [33320 2012-06-27] (Panda Security, S.L.)
S1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [93224 2012-06-27] (Panda Security, S.L.)
S4 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [68648 2012-06-27] (Panda Security, S.L.)
S1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [116776 2012-06-27] (Panda Security, S.L.)
S1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [304680 2012-06-27] (Panda Security, S.L.)
S1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [109096 2012-06-27] (Panda Security, S.L.)
S1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [112680 2012-06-27] (Panda Security, S.L.)
S1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [219688 2012-07-12] (Panda Security, S.L.)
S1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [105000 2012-06-27] (Panda Security, S.L.)
S2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [168488 2012-08-26] (Panda Security, S.L.)
S2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [120872 2012-08-26] (Panda Security, S.L.)
S1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [205352 2012-08-26] (Panda Security, S.L.)
S2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [124456 2012-08-26] (Panda Security, S.L.)
S2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [130088 2012-08-26] (Panda Security, S.L.)
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [57928 2011-03-10] ()

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-14 20:21 - 2014-04-15 20:02 - 00000000 ____D () C:\FRST
2014-04-09 10:34 - 2011-03-10 08:05 - 00057928 _____ () C:\Windows\System32\Drivers\PSKMAD.sys
2014-03-29 11:22 - 2014-03-29 11:22 - 95027928 ____T () C:\ProgramData\wlvd7ta0.bbr
2014-03-29 11:22 - 2014-03-29 11:22 - 00332020 ____T (Microsoft Corporation) C:\ProgramData\wlvd7ta0.faa
2014-03-29 11:22 - 2014-03-29 11:22 - 00192265 _____ (Microsoft Corporation) C:\ProgramData\0at7dvlw.gsa
2014-03-29 11:17 - 2014-03-29 11:24 - 00000000 ____D () C:\Users\hellmaster66\Downloads\Babovresky 2[2014]DVDRip.XviD[Česko]
2014-03-29 11:17 - 2014-03-29 11:17 - 00015072 _____ () C:\Users\hellmaster66\Downloads\Babovresky_2[2014]DVDRip.XviD[ÄŚesko].torrent
2014-03-23 08:59 - 2014-03-23 08:59 - 01954663 _____ () C:\Users\hellmaster66\Downloads\Vychodiskove_statisticke_udaje_a_podiel_obci_na_vynose_DPFO_pre_rok_2011.htm
2014-03-23 08:57 - 2014-03-23 08:57 - 00022154 _____ () C:\Users\hellmaster66\Downloads\Vychodiskove_statis_udaje_r2008_podiel_vynoseDPFO_VUC.htm
2014-03-17 00:06 - 2014-03-17 00:06 - 00000000 ____D () C:\Users\hellmaster66\Downloads\Walking with Dinosaurs 3D (2013) [1080p]
2014-03-17 00:05 - 2014-03-17 00:05 - 00013384 _____ () C:\Users\hellmaster66\Downloads\Walking_with_Dinosaurs_3D_2013_1080p_BluRay_x264_YIFY_mp4.torrent

==================== One Month Modified Files and Folders =======

2014-04-15 20:02 - 2014-04-14 20:21 - 00000000 ____D () C:\FRST
2014-04-15 07:59 - 2014-03-01 08:07 - 00000944 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-15 07:59 - 2012-12-29 06:41 - 00000000 ____D () C:\Users\hellmaster66\AppData\Roaming\uTorrent
2014-04-15 07:59 - 2009-07-13 21:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-15 07:59 - 2009-07-13 20:51 - 00095358 _____ () C:\Windows\setupact.log
2014-04-14 10:06 - 2011-09-22 15:45 - 01161367 _____ () C:\Windows\WindowsUpdate.log
2014-04-14 10:04 - 2012-09-05 04:29 - 00000000 ____D () C:\Users\hellmaster66\Documents\Bluetooth Folder
2014-04-14 09:59 - 2009-07-13 20:45 - 00032064 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-14 09:59 - 2009-07-13 20:45 - 00032064 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-14 09:25 - 2013-03-20 08:29 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-14 09:21 - 2014-03-01 08:07 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-14 09:21 - 2012-09-07 03:25 - 00000166 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-04-10 11:16 - 2012-09-05 11:25 - 00000000 ____D () C:\Users\hellmaster66\AppData\Roaming\Skype
2014-04-09 10:29 - 2013-08-25 23:17 - 00002019 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-03-29 11:24 - 2014-03-29 11:17 - 00000000 ____D () C:\Users\hellmaster66\Downloads\Babovresky 2[2014]DVDRip.XviD[Česko]
2014-03-29 11:24 - 2012-09-05 04:17 - 00000000 ____D () C:\Users\hellmaster66\AppData\Local\VirtualStore
2014-03-29 11:22 - 2014-03-29 11:22 - 95027928 ____T () C:\ProgramData\wlvd7ta0.bbr
2014-03-29 11:22 - 2014-03-29 11:22 - 00332020 ____T (Microsoft Corporation) C:\ProgramData\wlvd7ta0.faa
2014-03-29 11:22 - 2014-03-29 11:22 - 00192265 _____ (Microsoft Corporation) C:\ProgramData\0at7dvlw.gsa
2014-03-29 11:17 - 2014-03-29 11:17 - 00015072 _____ () C:\Users\hellmaster66\Downloads\Babovresky_2[2014]DVDRip.XviD[ÄŚesko].torrent
2014-03-29 09:37 - 2009-07-13 21:13 - 00006426 _____ () C:\Windows\System32\PerfStringBackup.INI
2014-03-27 13:42 - 2012-12-09 08:05 - 00006080 _____ () C:\ProgramData\NanoRepository.bin
2014-03-27 13:41 - 2014-03-01 08:07 - 00000000 ____D () C:\Users\hellmaster66\AppData\Local\Google
2014-03-23 08:59 - 2014-03-23 08:59 - 01954663 _____ () C:\Users\hellmaster66\Downloads\Vychodiskove_statisticke_udaje_a_podiel_obci_na_vynose_DPFO_pre_rok_2011.htm
2014-03-23 08:57 - 2014-03-23 08:57 - 00022154 _____ () C:\Users\hellmaster66\Downloads\Vychodiskove_statis_udaje_r2008_podiel_vynoseDPFO_VUC.htm
2014-03-20 12:09 - 2013-07-14 10:45 - 00000000 ____D () C:\Windows\System32\MRT
2014-03-20 12:07 - 2013-02-06 11:33 - 90015360 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2014-03-19 12:53 - 2012-12-09 08:05 - 00006080 _____ () C:\ProgramData\NanoRepository.bin.bak
2014-03-19 11:08 - 2013-09-01 02:11 - 00050688 ___SH () C:\Users\hellmaster66\Downloads\Thumbs.db
2014-03-17 12:44 - 2013-06-12 23:40 - 00000000 ____D () C:\Users\hellmaster66\Desktop\face
2014-03-17 00:06 - 2014-03-17 00:06 - 00000000 ____D () C:\Users\hellmaster66\Downloads\Walking with Dinosaurs 3D (2013) [1080p]
2014-03-17 00:05 - 2014-03-17 00:05 - 00013384 _____ () C:\Users\hellmaster66\Downloads\Walking_with_Dinosaurs_3D_2013_1080p_BluRay_x264_YIFY_mp4.torrent

Some content of TEMP:
====================
C:\Users\hellmaster66\AppData\Local\Temp\jjxuc-cs.dll
C:\Users\hellmaster66\AppData\Local\Temp\SCC.dll
C:\Users\hellmaster66\AppData\Local\Temp\SHSetup.exe
C:\Users\hellmaster66\AppData\Local\Temp\SkypeSetup.exe


==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2014-02-26 12:55:43
Restore point made on: 2014-02-26 13:15:51
Restore point made on: 2014-02-27 14:45:11
Restore point made on: 2014-03-06 12:54:30
Restore point made on: 2014-03-13 07:31:42
Restore point made on: 2014-03-13 14:30:03
Restore point made on: 2014-03-19 08:39:10
Restore point made on: 2014-03-20 12:07:24
Restore point made on: 2014-03-27 12:10:53
Restore point made on: 2014-03-27 12:35:43
Restore point made on: 2014-04-09 10:32:36

==================== Memory info ===========================

Percentage of memory in use: 18%
Total physical RAM: 4043.86 MB
Available physical RAM: 3314.27 MB
Total Pagefile: 4042.01 MB
Available Pagefile: 3306.38 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:444.61 GB) (Free:219.23 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (Recovery) (Fixed) (Total:16.99 GB) (Free:1.83 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: (HP_TOOLS) (Fixed) (Total:3.96 GB) (Free:1.08 GB) FAT32
Drive h: () (Removable) (Total:7.21 GB) (Free:7.15 GB) NTFS
Drive x: (Boot) (Fixed) (Total:0.25 GB) (Free:0.25 GB) NTFS
Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: C69126C0)

Partition: GPT Partition Type.

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 7 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.


LastRegBack: 2014-04-03 11:28

==================== End Of Log ============================

Avatar uživatele
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 Pro 2007 09:27
Místo/Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Pre STELL

#2 Příspěvek od stell »

Ahoj.
Ok vydrz, prestudujem log a zacneme s cistenim.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

Avatar uživatele
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 Pro 2007 09:27
Místo/Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Pre STELL

#3 Příspěvek od stell »

1:Spust poznamkovy blok, Notepad.
2:Skopiruj tento script,v kod>>bez textu kod>> , a vloz do poznamkoveho bloku.
3:Uloz to ako vsetky subory>> nazov>>fixlist.txt a uloz to na flash disk, tam kde mas program Frst64.exe.
4:Spust znovu program Frst64.exe tak ako si generovala log, Ale POZOR, teraz kliknes na Gombik FIX
Prebehne oprava a pocitac sa restartuje, normalne nechaj pocitac nabehnut do WINDOWS, ak tam budes ci aj nie>.tak napis a pokracujeme dalej.

Kód: Vybrat vše

HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
Startup: C:\Users\hellmaster66\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wlvd7ta0.lnk
ShortcutTarget: wlvd7ta0.lnk -> C:\ProgramData\0at7dvlw.gsa (Microsoft Corporation)
S2 Winmgmt; C:\ProgramData\wlvd7ta0.faa [332020 2014-03-29] (Microsoft Corporation)
C:\ProgramData\wlvd7ta0.bbr
C:\ProgramData\wlvd7ta0.faa
C:\ProgramData\0at7dvlw.gsa
C:\Users\hellmaster66\AppData\Local\Temp
Hosts:
CMD: shutdown /r
Poznamka:
Na Flashdisku sa ulozi aj log >>nazov Fixlog.txt, obsah vloz sem.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

misel5
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 15 Dub 2014 19:40

Re: Pre STELL

#4 Příspěvek od misel5 »

Prepáč, večer sa mi už nedalo pokračovať, ale počítač už ide bez problémov :-)

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-04-2014 01
Ran by SYSTEM at 2014-04-16 13:38:56 Run:1
Running from H:\
Boot Mode: Recovery
==============================================

Content of fixlist:
*****************
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
Startup: C:\Users\hellmaster66\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wlvd7ta0.lnk
ShortcutTarget: wlvd7ta0.lnk -> C:\ProgramData\0at7dvlw.gsa (Microsoft Corporation)
S2 Winmgmt; C:\ProgramData\wlvd7ta0.faa [332020 2014-03-29] (Microsoft Corporation)
C:\ProgramData\wlvd7ta0.bbr
C:\ProgramData\wlvd7ta0.faa
C:\ProgramData\0at7dvlw.gsa
C:\Users\hellmaster66\AppData\Local\Temp
Hosts:
CMD: shutdown /r
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\*Restore => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\EnableShellExecuteHooks => Value deleted successfully.
C:\Users\hellmaster66\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wlvd7ta0.lnk => Moved successfully.
C:\ProgramData\0at7dvlw.gsa => Moved successfully.
Winmgmt => Service restored successfully.
C:\ProgramData\wlvd7ta0.bbr => Moved successfully.
C:\ProgramData\wlvd7ta0.faa => Moved successfully.
"C:\ProgramData\0at7dvlw.gsa" => File/Directory not found.
C:\Users\hellmaster66\AppData\Local\Temp => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

========= shutdown /r =========

'shutdown' is not recognized as an internal or external command,
operable program or batch file.

========= End of CMD: =========


==== End of Fixlog ====

Avatar uživatele
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 Pro 2007 09:27
Místo/Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Pre STELL

#5 Příspěvek od stell »

ok, pokracuj takto:
1: Pouzi ADWcleaner ,presne podla navodu.
http://www.viruskasino.com/2012/09/adwcleaner.html
log vloz sem.
2:Malwarebytes,
http://www.bleepingcomputer.com/downloa ... re/dl/241/
Uplna kontrola najdene odstran.
Log vloz sem.
Navod.
http://www.viruskasino.com/2011/03/navo ... bytes.html
Potom sa uvidi ci vsetko, je ok.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

Avatar uživatele
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 Pro 2007 09:27
Místo/Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Pre STELL

#6 Příspěvek od stell »

temu zatvaram.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

Zamčeno