Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Máte problém s virem? Vložte sem log z FRST nebo RSIT.
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST
[návod zde] nebo RSIT
[návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte
Pravidlo o zamykání témat . Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Dominovts
Návštěvník
Příspěvky: 51 Registrován: 28 dub 2008 18:08
#17
Příspěvek
od Dominovts » 17 kvě 2014 15:20
Ten eset nepoužívam, a neviem ako ho odtiaľto vymazať.
vyosek
VIP
Příspěvky: 56373 Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno
#18
Příspěvek
od vyosek » 17 kvě 2014 15:28
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen od 1. února 2011.
vyosek
VIP
Příspěvky: 56373 Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno
#20
Příspěvek
od vyosek » 17 kvě 2014 16:10
Tak jdeme dal, ten ESS jsem chtel jen odstreli, aby nebyl v konfliktu a Avirou
Tvorba fixlistu pro FRST
Spustte poznamkovy blok (Start-spustit-notepad)
Zkopirujte skript nize
Kód: Vybrat vše
Start
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-133471220-1541798625-982354155-1001\...\Run: [] => [X]
HKU\S-1-5-21-133471220-1541798625-982354155-1001\...\MountPoints2: F - F:\Setup.exe
HKU\S-1-5-21-133471220-1541798625-982354155-1001\...\MountPoints2: {2371fc67-b9a2-11e0-97e7-00242162c0ea} - I:\setup.exe AUTORUN=1
HKU\S-1-5-21-133471220-1541798625-982354155-1001\...\MountPoints2: {43cfa231-6319-11df-bc68-00242162c0ea} - G:\SETUP.EXE
HKU\S-1-5-21-133471220-1541798625-982354155-1001\...\MountPoints2: {6e6a6859-79dc-11df-b45c-00242162c0ea} - "H:\WD SmartWare.exe" autoplay=true
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x573578C93078CC01
SearchScopes: HKLM - DefaultScope value is missing.
S2 KMService; C:\Windows\system32\srvany.exe [8192 2003-04-18] ()
2014-05-17 15:52 - 2014-05-17 15:52 - 00112640 _____ (forum.viry.cz) C:\Users\xxx\Desktop\FRSTLauncher.exe
2014-05-17 15:49 - 2014-05-17 15:49 - 00112640 _____ (forum.viry.cz) C:\Users\xxx\Downloads\Nepotvrdené 608213.crdownload
2014-05-17 15:49 - 2014-05-17 15:49 - 00112640 _____ (forum.viry.cz) C:\Users\xxx\Downloads\Nepotvrdené 236317.crdownload
2014-05-17 15:48 - 2014-05-17 15:48 - 01056768 _____ (Farbar) C:\Users\xxx\Downloads\FRST (1).exe
2014-05-17 15:47 - 2014-05-17 15:48 - 01056768 _____ (Farbar) C:\Users\xxx\Downloads\FRST.exe
2014-05-17 14:55 - 2014-05-17 14:43 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-17 14:53 - 2014-05-17 14:58 - 00000000 ____D () C:\zoek
2014-05-17 14:44 - 2014-05-17 14:58 - 00011456 _____ () C:\zoek-results.log
2014-05-17 14:43 - 2014-05-17 14:54 - 00000000 ____D () C:\zoek_backup
2014-05-17 14:42 - 2014-05-17 14:42 - 01285120 _____ () C:\Users\xxx\Desktop\zoek.exe
2014-05-17 14:42 - 2014-05-17 14:42 - 01285120 _____ () C:\Users\xxx\Desktop\zoek (1).exe
2014-05-17 11:12 - 2014-05-17 11:12 - 00000732 _____ () C:\Users\xxx\Desktop\JRT.txt
2014-05-17 11:08 - 2014-05-17 11:09 - 01325827 _____ () C:\Users\xxx\Desktop\adwcleaner_3.208.exe
2014-05-16 22:07 - 2014-05-16 22:07 - 00093418 _____ () C:\Users\xxx\Desktop\Extras.Txt
2014-05-16 22:06 - 2014-05-16 22:06 - 00164548 _____ () C:\Users\xxx\Desktop\OTL.Txt
2014-05-16 21:34 - 2014-05-16 21:34 - 00000512 _____ () C:\PhysicalMBR.bin
2014-05-16 21:27 - 2014-05-16 21:27 - 00602112 _____ (OldTimer Tools) C:\Users\xxx\Desktop\OTL.exe
2014-05-16 20:20 - 2014-05-16 20:20 - 00000000 ____D () C:\rsit
2014-05-16 20:20 - 2014-05-16 20:20 - 00000000 ____D () C:\Program Files\trend micro
2014-05-16 20:19 - 2014-05-16 20:19 - 00781383 _____ () C:\Users\xxx\Desktop\RSIT.exe
2014-05-08 15:42 - 2014-05-08 15:42 - 01016261 _____ (Thisisu) C:\Users\xxx\Desktop\JRT.exe
2014-04-30 20:06 - 2014-05-06 16:36 - 00000000 ____D () C:\Windows\AutoKMS
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-133471220-1541798625-982354155-1001Core.job => C:\Users\xxx\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-133471220-1541798625-982354155-1001UA.job => C:\Users\xxx\AppData\Local\Google\Update\GoogleUpdate.exe
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverChecker.exe" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Standby" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f
Hosts:
End
Ulozte vytvoreny TXT jako fixlist.txt
Presunte vytvoreny fixlist vedle FRST
Spustte znovu FRST.exe
Kliknete na Fix
Probehne oprava a vytvori log Fixlog.txt
Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen od 1. února 2011.
Dominovts
Návštěvník
Příspěvky: 51 Registrován: 28 dub 2008 18:08
#21
Příspěvek
od Dominovts » 17 kvě 2014 16:16
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:17-05-2014
Ran by xxx at 2014-05-17 17:16:01 Run:1
Running from C:\Users\xxx\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-133471220-1541798625-982354155-1001\...\Run: [] => [X]
HKU\S-1-5-21-133471220-1541798625-982354155-1001\...\MountPoints2: F - F:\Setup.exe
HKU\S-1-5-21-133471220-1541798625-982354155-1001\...\MountPoints2: {2371fc67-b9a2-11e0-97e7-00242162c0ea} - I:\setup.exe AUTORUN=1
HKU\S-1-5-21-133471220-1541798625-982354155-1001\...\MountPoints2: {43cfa231-6319-11df-bc68-00242162c0ea} - G:\SETUP.EXE
HKU\S-1-5-21-133471220-1541798625-982354155-1001\...\MountPoints2: {6e6a6859-79dc-11df-b45c-00242162c0ea} - "H:\WD SmartWare.exe" autoplay=true
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x573578C93078CC01
SearchScopes: HKLM - DefaultScope value is missing.
S2 KMService; C:\Windows\system32\srvany.exe [8192 2003-04-18] ()
2014-05-17 15:52 - 2014-05-17 15:52 - 00112640 _____ (forum.viry.cz) C:\Users\xxx\Desktop\FRSTLauncher.exe
2014-05-17 15:49 - 2014-05-17 15:49 - 00112640 _____ (forum.viry.cz) C:\Users\xxx\Downloads\Nepotvrdené 608213.crdownload
2014-05-17 15:49 - 2014-05-17 15:49 - 00112640 _____ (forum.viry.cz) C:\Users\xxx\Downloads\Nepotvrdené 236317.crdownload
2014-05-17 15:48 - 2014-05-17 15:48 - 01056768 _____ (Farbar) C:\Users\xxx\Downloads\FRST (1).exe
2014-05-17 15:47 - 2014-05-17 15:48 - 01056768 _____ (Farbar) C:\Users\xxx\Downloads\FRST.exe
2014-05-17 14:55 - 2014-05-17 14:43 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-17 14:53 - 2014-05-17 14:58 - 00000000 ____D () C:\zoek
2014-05-17 14:44 - 2014-05-17 14:58 - 00011456 _____ () C:\zoek-results.log
2014-05-17 14:43 - 2014-05-17 14:54 - 00000000 ____D () C:\zoek_backup
2014-05-17 14:42 - 2014-05-17 14:42 - 01285120 _____ () C:\Users\xxx\Desktop\zoek.exe
2014-05-17 14:42 - 2014-05-17 14:42 - 01285120 _____ () C:\Users\xxx\Desktop\zoek (1).exe
2014-05-17 11:12 - 2014-05-17 11:12 - 00000732 _____ () C:\Users\xxx\Desktop\JRT.txt
2014-05-17 11:08 - 2014-05-17 11:09 - 01325827 _____ () C:\Users\xxx\Desktop\adwcleaner_3.208.exe
2014-05-16 22:07 - 2014-05-16 22:07 - 00093418 _____ () C:\Users\xxx\Desktop\Extras.Txt
2014-05-16 22:06 - 2014-05-16 22:06 - 00164548 _____ () C:\Users\xxx\Desktop\OTL.Txt
2014-05-16 21:34 - 2014-05-16 21:34 - 00000512 _____ () C:\PhysicalMBR.bin
2014-05-16 21:27 - 2014-05-16 21:27 - 00602112 _____ (OldTimer Tools) C:\Users\xxx\Desktop\OTL.exe
2014-05-16 20:20 - 2014-05-16 20:20 - 00000000 ____D () C:\rsit
2014-05-16 20:20 - 2014-05-16 20:20 - 00000000 ____D () C:\Program Files\trend micro
2014-05-16 20:19 - 2014-05-16 20:19 - 00781383 _____ () C:\Users\xxx\Desktop\RSIT.exe
2014-05-08 15:42 - 2014-05-08 15:42 - 01016261 _____ (Thisisu) C:\Users\xxx\Desktop\JRT.exe
2014-04-30 20:06 - 2014-05-06 16:36 - 00000000 ____D () C:\Windows\AutoKMS
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-133471220-1541798625-982354155-1001Core.job => C:\Users\xxx\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-133471220-1541798625-982354155-1001UA.job => C:\Users\xxx\AppData\Local\Google\Update\GoogleUpdate.exe
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverChecker.exe" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Standby" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f
Hosts:
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKU\S-1-5-21-133471220-1541798625-982354155-1001\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKU\S-1-5-21-133471220-1541798625-982354155-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-133471220-1541798625-982354155-1001 => Key not found.
HKU\S-1-5-21-133471220-1541798625-982354155-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2371fc67-b9a2-11e0-97e7-00242162c0ea} => Key deleted successfully.
HKCR\CLSID\{2371fc67-b9a2-11e0-97e7-00242162c0ea} => Key not found.
HKU\S-1-5-21-133471220-1541798625-982354155-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{43cfa231-6319-11df-bc68-00242162c0ea} => Key deleted successfully.
HKCR\CLSID\{43cfa231-6319-11df-bc68-00242162c0ea} => Key not found.
HKU\S-1-5-21-133471220-1541798625-982354155-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6e6a6859-79dc-11df-b45c-00242162c0ea} => Key deleted successfully.
HKCR\CLSID\{6e6a6859-79dc-11df-b45c-00242162c0ea} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
KMService => Service deleted successfully.
"C:\Users\xxx\Desktop\FRSTLauncher.exe" => File/Directory not found.
"C:\Users\xxx\Downloads\Nepotvrdené 608213.crdownload" => File/Directory not found.
"C:\Users\xxx\Downloads\Nepotvrdené 236317.crdownload" => File/Directory not found.
C:\Users\xxx\Downloads\FRST (1).exe => Moved successfully.
"C:\Users\xxx\Downloads\FRST.exe" => File/Directory not found.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
"C:\Users\xxx\Desktop\zoek.exe" => File/Directory not found.
"C:\Users\xxx\Desktop\zoek (1).exe" => File/Directory not found.
C:\Users\xxx\Desktop\JRT.txt => Moved successfully.
C:\Users\xxx\Desktop\adwcleaner_3.208.exe => Moved successfully.
"C:\Users\xxx\Desktop\Extras.Txt" => File/Directory not found.
"C:\Users\xxx\Desktop\OTL.Txt" => File/Directory not found.
C:\PhysicalMBR.bin => Moved successfully.
"C:\Users\xxx\Desktop\OTL.exe" => File/Directory not found.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
"C:\Users\xxx\Desktop\RSIT.exe" => File/Directory not found.
"C:\Users\xxx\Desktop\JRT.exe" => File/Directory not found.
C:\Windows\AutoKMS => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-133471220-1541798625-982354155-1001Core.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-133471220-1541798625-982354155-1001UA.job => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverChecker.exe" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Standby" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
"C:\Windows\System32\Drivers\etc\hosts" => Could not move.
Could not reset Hosts.
==== End of Fixlog ====
vyosek
VIP
Příspěvky: 56373 Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno
#22
Příspěvek
od vyosek » 17 kvě 2014 16:17
Jak se chova PC?
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen od 1. února 2011.
vyosek
VIP
Příspěvky: 56373 Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno
#24
Příspěvek
od vyosek » 17 kvě 2014 16:23
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen od 1. února 2011.