Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

zavirovaný PC ,prosím o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Slictyx
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 07 bře 2016 11:36
Bydliště: Hodonín

Re: zavirovaný PC ,prosím o kontrolu logu

#16 Příspěvek od Slictyx »

zde přikládám cestu k archivu

http://leteckaposta.cz/892421841

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: zavirovaný PC ,prosím o kontrolu logu

#17 Příspěvek od altrok »

Za vzorek dekuji.


  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • fixlog vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    RestoreQuarantine: C:\FRST\Quarantine\C\ProgramData\SMR501
    End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Slictyx
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 07 bře 2016 11:36
Bydliště: Hodonín

Re: zavirovaný PC ,prosím o kontrolu logu

#18 Příspěvek od Slictyx »

mno mel jsem pockat s antivirem ,FRST vyhodnotil špatně a smazal :) tak trochu strpení

Slictyx
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 07 bře 2016 11:36
Bydliště: Hodonín

Re: zavirovaný PC ,prosím o kontrolu logu

#19 Příspěvek od Slictyx »

tady je :

Fix result of Farbar Recovery Scan Tool (x86) Version:05-03-2016 01
Ran by milan (2016-03-13 18:23:46) Run:2
Running from C:\Users\milan\Desktop
Loaded Profiles: milan (Available Profiles: milan)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
RestoreQuarantine: C:\FRST\Quarantine\C\ProgramData\SMR501
End
*****************

RestoreQuarantine: C:\FRST\Quarantine\C\ProgramData\SMR501=> Restoring from Quarantine completed.

==== End of Fixlog 18:23:46 ====

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: zavirovaný PC ,prosím o kontrolu logu

#20 Příspěvek od altrok »

:arrow: Dejte logy FRST.txt a Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pozn. pri druhem a dalsim spusteni FRST je pro vytvoreni logu Addition.txt nutne tuto volbu explicitne zatrhnout pred zacatkem skenu.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Slictyx
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 07 bře 2016 11:36
Bydliště: Hodonín

Re: zavirovaný PC ,prosím o kontrolu logu

#21 Příspěvek od Slictyx »

přeji pěkný den ,zde přidám logy

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-03-2016 01
Ran by milan (administrator) on MILAN-PC92 (14-03-2016 07:37:12)
Running from C:\Users\milan\Desktop
Loaded Profiles: milan (Available Profiles: milan)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) D:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(BitTorrent Inc.) C:\Users\milan\AppData\Roaming\uTorrent\uTorrent.exe
(BitTorrent Inc.) C:\Users\milan\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe
(BitTorrent Inc.) C:\Users\milan\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Google Inc.) C:\Users\milan\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\milan\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\milan\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\milan\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7137664 2016-03-13] (AVAST Software)
HKU\S-1-5-21-970700664-739145876-1605578078-1001\...\Run: [uTorrent] => C:\Users\milan\AppData\Roaming\uTorrent\uTorrent.exe [2026520 2015-12-05] (BitTorrent Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-03-13] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\milan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\milan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\milan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.254
Tcpip\..\Interfaces\{0F399F2C-76CF-45F5-BD8D-CB10351F63CD}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{A69B7D48-CC23-4C8B-9B73-5A5ADCD2F6C9}: [DhcpNameServer] 192.168.2.254

Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-970700664-739145876-1605578078-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-03-13] (AVAST Software)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll [2011-03-09] ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-03-04] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-03-04] (NVIDIA Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-970700664-739145876-1605578078-1001: @tools.google.com/Google Update;version=3 -> C:\Users\milan\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-970700664-739145876-1605578078-1001: @tools.google.com/Google Update;version=9 -> C:\Users\milan\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-02] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-03-13]

Chrome:
=======
CHR HomePage: Default -> hxxps://www.seznam.cz/
CHR Profile: C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-27]
CHR Extension: (Dokumenty Google) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-27]
CHR Extension: (Disk Google) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Vyhledávání Google) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-06]
CHR Extension: (Tabulky Google) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-27]
CHR Extension: (Dokumenty Google offline) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-20]
CHR Extension: (AdBlock) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-12]
CHR Extension: (Avast Online Security) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-03-14]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24]
CHR Extension: (Gmail) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-01]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-03-13]
StartMenuInternet: Google Chrome.MKCNDVG6DVYBTZV7TSRNF4RZEY - C:\Users\milan\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-03-13] (AVAST Software)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
R2 TeamViewer9; D:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe [5037888 2014-07-02] (TeamViewer GmbH)
R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2449624 2015-08-04] (AVG Technologies)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [36568 2015-08-04] (AVG Technologies)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [32792 2016-03-13] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [91168 2016-03-13] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [91232 2016-03-13] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [58776 2016-03-13] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [816304 2016-03-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447848 2016-03-13] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [127432 2016-03-13] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [221240 2016-03-13] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-06-28] (Disc Soft Ltd)
S3 KYEGKB; C:\Windows\System32\Drivers\KYEGKB.sys [27648 2011-07-31] ( )
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1311232 2009-07-13] (NXP Semiconductors)
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [184192 2014-10-13] (DEVGURU Co., LTD.(www.devguru.co.kr))
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [30632 2015-06-25] (TuneUp Software)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [15872 2013-02-12] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\milan\AppData\Local\Temp\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-14 07:37 - 2016-03-14 07:37 - 00010875 _____ C:\Users\milan\Desktop\FRST.txt
2016-03-14 07:36 - 2016-03-14 07:36 - 00112640 _____ (forum.viry.cz) C:\Users\milan\Desktop\FRSTLauncher.exe
2016-03-14 07:35 - 2016-03-14 07:35 - 01725440 _____ (Farbar) C:\Users\milan\Desktop\FRST.exe
2016-03-13 18:48 - 2016-03-13 18:46 - 00334280 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-03-13 18:47 - 2016-03-13 18:47 - 00002035 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-03-13 18:47 - 2016-03-13 18:47 - 00000000 ____D C:\Users\milan\AppData\Roaming\AVAST Software
2016-03-13 18:47 - 2016-03-13 18:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-03-13 18:46 - 2016-03-13 18:47 - 00816304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-03-13 18:46 - 2016-03-13 18:47 - 00091168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-03-13 18:46 - 2016-03-13 18:46 - 00447848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-03-13 18:46 - 2016-03-13 18:46 - 00221240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2016-03-13 18:46 - 2016-03-13 18:46 - 00127432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-03-13 18:46 - 2016-03-13 18:46 - 00091232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-03-13 18:46 - 2016-03-13 18:46 - 00058776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-03-13 18:46 - 2016-03-13 18:46 - 00052184 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-03-13 18:46 - 2016-03-13 18:46 - 00032792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-03-13 18:45 - 2016-03-13 18:45 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-13 18:42 - 2016-03-13 18:43 - 05207096 _____ (AVAST Software) C:\Users\milan\Downloads\avast_free_antivirus_setup_online.exe
2016-03-13 18:33 - 2016-03-13 18:33 - 00000000 ____D C:\Users\milan\AppData\Local\CrashDumps
2016-03-13 18:23 - 2016-03-13 18:23 - 00000000 ____D C:\ProgramData\SMR501
2016-03-13 17:41 - 2016-03-13 17:41 - 00000000 _____ C:\Users\milan\Desktop\Nový textový dokument (2).txt
2016-03-13 17:37 - 2016-03-13 18:23 - 00000537 _____ C:\Users\milan\Desktop\Fixlog.txt
2016-03-13 17:37 - 2016-03-13 17:37 - 00155765 _____ C:\Users\milan\Desktop\Upload.zip
2016-03-13 17:37 - 2016-03-13 17:37 - 00029696 _____ C:\Users\milan\AppData\Local\MSGBOX.EXE
2016-03-13 17:37 - 2016-03-13 17:37 - 00015327 _____ C:\Users\milan\Desktop\LM.bat
2016-03-13 15:35 - 2015-08-04 13:25 - 00036568 _____ (AVG Technologies) C:\Windows\system32\uxtuneup.dll
2016-03-13 15:33 - 2016-03-14 07:32 - 00252654 _____ C:\Windows\ntbtlog.txt
2016-03-13 15:33 - 2015-08-04 13:25 - 00037080 _____ (AVG Technologies) C:\Windows\system32\TURegOpt.exe
2016-03-13 15:33 - 2015-08-04 13:25 - 00025816 _____ (AVG Technologies) C:\Windows\system32\authuitu.dll
2016-03-13 15:32 - 2016-03-13 15:32 - 00002135 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015.lnk
2016-03-13 15:32 - 2016-03-13 15:32 - 00002123 _____ C:\Users\Public\Desktop\AVG PC TuneUp 2015.lnk
2016-03-13 15:32 - 2016-03-13 15:32 - 00002109 _____ C:\Users\Public\Desktop\AVG údržba 1 kliknutím.lnk
2016-03-13 15:32 - 2016-03-13 15:32 - 00000000 ____D C:\Users\milan\AppData\Roaming\AVG
2016-03-13 15:32 - 2016-03-13 15:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015
2016-03-13 15:32 - 2016-03-13 15:32 - 00000000 ____D C:\Program Files\AVG
2016-03-13 15:29 - 2016-03-13 15:41 - 00000000 ____D C:\ProgramData\AVG
2016-03-13 15:26 - 2016-03-13 15:27 - 90844984 _____ (AVG Technologies) C:\Users\milan\Downloads\avg_tuht_stf_all_2015_238.exe
2016-03-13 15:18 - 2016-03-13 15:18 - 00700104 _____ (ESET) C:\Users\milan\Downloads\ESETUninstaller.exe
2016-03-13 15:00 - 2016-03-13 15:03 - 00000000 ____D C:\AVG_Remover
2016-03-13 14:57 - 2016-03-14 07:32 - 00000000 ____D C:\Users\milan\AppData\LocalLow\uTorrent
2016-03-13 14:52 - 2016-03-13 14:52 - 00326144 _____ (AVAST Software) C:\Users\milan\Downloads\aswclear.exe
2016-03-13 14:40 - 2016-03-13 14:40 - 00000000 ____H C:\Users\milan\Documents\Default.rdp
2016-03-13 14:12 - 2016-03-13 14:12 - 00013707 _____ C:\ComboFix.txt
2016-03-13 13:56 - 2016-03-13 13:56 - 00000000 _____ C:\Users\milan\Desktop\Nový textový dokument.txt
2016-03-13 09:25 - 2016-03-13 14:12 - 00000000 ____D C:\Qoobox
2016-03-13 09:25 - 2016-03-13 14:06 - 00000000 ____D C:\Windows\erdnt
2016-03-13 09:25 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2016-03-13 09:25 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2016-03-13 09:25 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2016-03-13 09:25 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2016-03-13 09:25 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2016-03-13 09:25 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2016-03-13 09:25 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2016-03-13 09:25 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2016-03-13 09:16 - 2016-03-13 09:18 - 00003620 _____ C:\Users\milan\Desktop\Rkill.txt
2016-03-13 09:14 - 2016-03-13 09:14 - 05658088 ____R (Swearware) C:\Users\milan\Desktop\ComboFix.exe
2016-03-13 09:13 - 2016-03-13 09:13 - 02032072 _____ (Bleeping Computer, LLC) C:\Users\milan\Desktop\rkill.exe
2016-03-13 01:12 - 2016-03-13 09:09 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-03-13 01:10 - 2016-03-13 01:33 - 00000000 ____D C:\Users\milan\Desktop\mbar
2016-03-13 01:09 - 2016-03-13 01:09 - 16563352 _____ (Malwarebytes Corp.) C:\Users\milan\Desktop\mbar-1.09.3.1001.exe
2016-03-13 01:06 - 2016-03-13 01:06 - 00008934 _____ C:\Users\milan\Desktop\Addition.rar
2016-03-12 23:45 - 2016-03-13 01:50 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-12 23:45 - 2016-03-13 01:10 - 00094936 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-03-12 23:45 - 2016-03-12 23:45 - 22908888 _____ (Malwarebytes ) C:\Users\milan\Downloads\mbam-setup-2.2.0.1024.exe
2016-03-12 23:45 - 2016-03-12 23:45 - 00001020 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-12 23:45 - 2016-03-12 23:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-03-12 23:45 - 2016-03-12 23:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-12 23:45 - 2016-03-12 23:45 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-03-12 23:45 - 2015-10-05 09:50 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-03-12 23:45 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-03-12 23:43 - 2016-03-12 23:43 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2016-03-12 23:38 - 2016-03-12 23:41 - 00000000 ____D C:\Users\milan\AppData\Local\NPE
2016-03-12 23:15 - 2016-03-13 18:41 - 00000000 ____D C:\ProgramData\Norton
2016-03-12 22:49 - 2016-03-12 23:37 - 00000000 ____D C:\ProgramData\NortonInstaller
2016-03-12 22:15 - 2016-03-12 22:15 - 00000000 ____D C:\ProgramData\ESET
2016-03-12 21:56 - 2016-03-12 21:56 - 00000000 ____D C:\RegBackup
2016-03-12 21:45 - 2016-03-12 21:46 - 18025373 _____ C:\Users\milan\Downloads\tweaking.com_windows_repair_aio.zip
2016-03-12 21:40 - 2016-03-12 21:40 - 00359656 _____ (Microsoft Corporation) C:\Users\milan\Downloads\msicuu2.exe
2016-03-11 15:26 - 2016-03-13 17:41 - 00000000 ____D C:\Users\milan\Desktop\Nová složka
2016-03-08 15:17 - 2016-03-12 23:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PRTG Network Monitor
2016-03-08 15:17 - 2016-03-08 15:17 - 00001024 _____ C:\.rnd
2016-03-08 15:17 - 2016-03-08 15:17 - 00000000 ____D C:\ProgramData\TEMP
2016-03-08 15:15 - 2016-03-12 23:20 - 00000000 ____D C:\Program Files\PRTG Network Monitor
2016-03-08 15:10 - 2016-03-08 15:10 - 130301427 _____ C:\Users\milan\Documents\prtg.zip
2016-03-08 12:06 - 2016-03-08 12:06 - 01524224 _____ C:\Users\milan\Downloads\adwcleaner_5.101.exe
2016-03-08 11:55 - 2016-03-13 00:13 - 00000000 ____D C:\Program Files\AdwCleaner
2016-03-08 11:47 - 2016-03-08 11:47 - 01524224 _____ C:\Users\milan\Desktop\adwcleaner_5.101.exe
2016-03-08 11:33 - 2016-03-13 00:11 - 00009528 _____ C:\Users\milan\Desktop\JRT.txt
2016-03-08 11:29 - 2016-03-08 11:29 - 01609216 _____ (Malwarebytes) C:\Users\milan\Desktop\JRT.exe
2016-03-08 01:08 - 2016-03-08 01:08 - 00000000 ____D C:\Users\milan\Downloads\Nová složka (2)
2016-03-07 12:06 - 2016-03-07 12:06 - 00009255 _____ C:\Users\milan\Desktop\Addition1.rar
2016-03-07 11:50 - 2016-03-14 07:37 - 00000000 ____D C:\FRST
2016-03-06 21:09 - 2016-03-07 00:56 - 00000000 ____D C:\Users\milan\AppData\Roaming\vlc
2016-03-06 21:09 - 2016-03-06 21:09 - 00000984 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-06 21:09 - 2016-03-06 21:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-06 21:08 - 2016-03-06 21:08 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-06 21:03 - 2016-03-06 21:07 - 30510920 _____ C:\Users\milan\Downloads\vlc-2.2.2-win32.exe
2016-03-05 10:21 - 2016-03-05 10:21 - 00000000 ____D C:\Users\milan\Downloads\Nová složka
2016-03-05 10:20 - 2016-03-05 10:20 - 01783800 _____ C:\Users\milan\Downloads\healbot.rar
2016-03-04 23:57 - 2016-03-04 23:57 - 02211428 _____ C:\Users\milan\Downloads\HealBot_5.4.2.0_ALL.zip
2016-03-04 20:27 - 2016-03-04 20:45 - 00000000 ____D C:\Users\milan\AppData\Local\PokerStars
2016-03-04 20:27 - 2016-03-04 20:27 - 00000802 _____ C:\Users\Public\Desktop\PokerStars.lnk
2016-03-04 20:27 - 2016-03-04 20:27 - 00000802 _____ C:\ProgramData\Microsoft\Windows\Start Menu\PokerStars.lnk
2016-03-04 17:09 - 2016-03-04 17:09 - 00000000 ____D C:\ProgramData\BlueStacks
2016-03-04 17:08 - 2016-03-04 17:09 - 10125176 _____ (BlueStack Systems, Inc.) C:\Users\milan\Downloads\BlueStacks-SplitInstaller.exe
2016-03-04 16:29 - 2016-03-08 15:04 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2016-03-04 16:28 - 2016-03-04 16:28 - 00000000 ____D C:\Users\milan\AppData\Local\Bluestacks
2016-03-04 14:40 - 2016-03-04 14:47 - 275097952 _____ (BlueStack Systems Inc.) C:\Users\milan\Downloads\BlueStacks2_native.exe
2016-03-03 21:22 - 2016-03-04 20:23 - 00000691 _____ C:\dude.conf
2016-03-03 21:21 - 2016-03-03 21:21 - 03702898 _____ C:\Users\milan\Downloads\dude-install-3.6.exe
2016-03-03 20:07 - 2016-03-03 20:07 - 00000000 ____D C:\Users\milan\AppData\Local\Mumble
2016-03-03 13:20 - 2016-03-05 10:22 - 00000000 ____D C:\Users\milan\Downloads\World of Warcraft - The Burning Crusade
2016-03-01 14:00 - 2016-03-01 14:03 - 264113064 _____ (NVIDIA Corporation) C:\Users\milan\Downloads\Nepotvrzeno 110044.crdownload
2016-02-29 18:32 - 2016-03-02 11:47 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2016-02-29 18:32 - 2016-02-29 18:32 - 00169218 _____ C:\Users\milan\Downloads\WoW_WotLK (1).torrent
2016-02-29 18:31 - 2016-02-29 18:31 - 00169218 _____ C:\Users\milan\Downloads\WoW_WotLK.torrent
2016-02-29 18:11 - 2016-03-12 23:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars.EU
2016-02-29 17:15 - 2016-02-29 17:15 - 00000000 ____D C:\Users\milan\AppData\Local\AVAST Software
2016-02-29 16:37 - 2016-02-06 10:43 - 02280448 ____N (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-02-29 16:37 - 2016-02-06 09:54 - 01312256 ____N (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-02-29 16:37 - 2016-01-22 07:09 - 01310232 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-02-29 16:37 - 2016-01-22 07:06 - 00400896 ____N (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-02-29 16:37 - 2016-01-22 07:06 - 00171520 ____N (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-02-29 16:37 - 2016-01-22 07:06 - 00169984 ____N (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-02-29 16:37 - 2016-01-22 07:06 - 00099840 ____N (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-02-29 16:37 - 2016-01-22 07:06 - 00065536 ____N (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-02-29 16:37 - 2016-01-22 07:05 - 00654336 ____N (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-02-29 16:37 - 2016-01-22 07:05 - 00251392 ____N (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-02-29 16:37 - 2016-01-22 07:05 - 00022016 ____N (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-02-29 16:37 - 2016-01-22 07:02 - 01060864 ____N (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-02-29 16:37 - 2016-01-22 07:02 - 00872448 ____N (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-02-29 16:37 - 2016-01-22 07:02 - 00553472 ____N (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-02-29 16:37 - 2016-01-22 07:02 - 00293888 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-02-29 16:37 - 2016-01-22 07:02 - 00259584 ____N (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-02-29 16:37 - 2016-01-22 07:02 - 00223232 ____N (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-02-29 16:37 - 2016-01-22 07:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-02-29 16:37 - 2016-01-22 06:59 - 00642560 ____N (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-02-29 16:37 - 2016-01-22 06:59 - 00038912 ____N (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-02-29 16:37 - 2016-01-22 06:59 - 00017408 ____N (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-02-29 16:37 - 2016-01-22 06:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-02-29 16:37 - 2016-01-22 06:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-02-29 16:37 - 2016-01-22 06:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-02-29 16:37 - 2016-01-22 06:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-02-29 16:37 - 2016-01-22 06:07 - 02120704 ____N (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-02-29 16:37 - 2016-01-22 05:53 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-02-29 16:37 - 2016-01-22 05:51 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-02-29 16:37 - 2016-01-22 05:51 - 00036352 ____N (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-02-29 16:37 - 2016-01-22 05:51 - 00022016 ____N (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-02-29 16:37 - 2016-01-22 05:51 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-02-29 12:57 - 2016-02-29 12:57 - 00000000 ____D C:\Users\Public\Documents\DAEMON Tools Images
2016-02-29 12:44 - 2016-03-02 11:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
2016-02-29 12:44 - 2016-02-29 17:47 - 00000000 ____D C:\Users\milan\Documents\Bandicam
2016-02-23 13:37 - 2016-02-23 13:41 - 00000000 ____D C:\Users\milan\Documents\NFS Most Wanted
2016-02-23 13:12 - 2016-02-23 13:12 - 00001008 _____ C:\Users\Public\Desktop\Need for Speed™ Most Wanted.lnk
2016-02-22 21:49 - 2016-02-22 21:49 - 00000000 ___HD C:\Windows\PIF
2016-02-22 20:59 - 2005-05-26 14:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2016-02-19 16:41 - 2016-02-23 12:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RAR Password Recovery
2016-02-19 16:41 - 2016-02-19 16:41 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RAR Password Recovery
2016-02-18 23:39 - 2016-02-23 12:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RAR Password Cracker
2016-02-18 23:39 - 2016-02-18 23:39 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RAR Password Cracker

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-14 07:37 - 2014-06-28 12:44 - 00000000 ____D C:\Users\milan\AppData\Roaming\uTorrent
2016-03-14 07:31 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-03-14 07:30 - 2014-06-28 11:08 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-14 00:25 - 2009-07-14 05:34 - 00016864 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-03-14 00:25 - 2009-07-14 05:34 - 00016864 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-03-13 22:26 - 2015-02-13 21:18 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-03-13 18:43 - 2014-06-27 15:27 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-13 17:35 - 2014-06-27 15:58 - 00000000 ____D C:\Program Files\Mumble
2016-03-13 17:34 - 2014-06-28 19:04 - 00000000 ____D C:\ProgramData\Skype
2016-03-13 17:33 - 2015-04-20 12:03 - 00000000 ____D C:\Users\milan\AppData\Local\Samsung
2016-03-13 17:33 - 2015-04-20 11:57 - 00000000 ____D C:\Program Files\Samsung
2016-03-13 17:33 - 2014-06-28 10:43 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-03-13 17:11 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\inf
2016-03-13 17:04 - 2016-02-04 21:44 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Valve
2016-03-13 15:55 - 2015-02-19 21:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live
2016-03-13 15:55 - 2014-06-28 19:04 - 00000000 ____D C:\Users\milan\AppData\Roaming\Skype
2016-03-13 15:55 - 2014-06-26 20:44 - 00000000 ____D C:\Windows\Panther
2016-03-13 15:20 - 2014-06-29 19:52 - 00000000 ____D C:\Users\milan\AppData\Roaming\TS3Client
2016-03-13 15:02 - 2014-06-28 20:52 - 00000000 ____D C:\Users\milan\AppData\Local\AVG
2016-03-13 14:55 - 2009-07-14 03:04 - 00002577 _____ C:\Windows\system32\config.nt
2016-03-13 14:08 - 2009-07-14 03:04 - 00000215 _____ C:\Windows\system.ini
2016-03-13 11:53 - 2015-01-19 20:46 - 00000000 ____D C:\Users\milan\AppData\Local\ElevatedDiagnostics
2016-03-13 01:34 - 2015-01-19 19:16 - 00000000 ____D C:\Windows\Minidump
2016-03-13 00:26 - 2015-02-13 21:18 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-03-13 00:26 - 2015-02-13 21:18 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-03-12 23:22 - 2014-06-26 19:52 - 00000000 ____D C:\Users\milan
2016-03-12 23:21 - 2015-02-13 21:18 - 00000000 ____D C:\Windows\system32\Macromed
2016-03-12 23:21 - 2014-07-01 10:34 - 00000000 ____D C:\Users\milan\AppData\Local\PokerStars.EU
2016-03-12 23:21 - 2014-06-27 15:55 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-03-12 23:21 - 2014-06-27 15:53 - 00000000 ____D C:\Users\milan\AppData\Roaming\Dropbox
2016-03-12 23:21 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF
2016-03-12 23:20 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\registration
2016-03-07 19:53 - 2011-04-12 02:37 - 00668138 _____ C:\Windows\system32\perfh005.dat
2016-03-07 19:53 - 2011-04-12 02:37 - 00140798 _____ C:\Windows\system32\perfc005.dat
2016-03-07 19:53 - 2010-11-20 22:01 - 01582262 _____ C:\Windows\system32\PerfStringBackup.INI
2016-03-03 20:07 - 2014-09-07 01:36 - 00000000 ____D C:\Users\milan\AppData\Roaming\Mumble
2016-03-02 11:50 - 2011-04-12 02:46 - 00000000 ____D C:\Program Files\Windows Journal
2016-03-02 11:50 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-03-02 11:48 - 2014-11-15 00:32 - 00000000 ___RD C:\Users\milan\Documents\Notes
2016-03-02 11:48 - 2014-06-29 02:37 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2016-03-02 11:48 - 2014-06-28 20:44 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2016-03-02 11:47 - 2014-06-29 02:37 - 00000000 ____D C:\Program Files\3DO
2016-03-02 11:47 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-03-02 11:37 - 2014-06-28 20:45 - 00000000 ____D C:\Users\milan\AppData\Roaming\DAEMON Tools Lite
2016-02-29 16:14 - 2015-04-20 12:03 - 00000000 ____D C:\Users\milan\AppData\Roaming\Samsung
2016-02-29 16:14 - 2015-04-20 11:57 - 00000000 ____D C:\ProgramData\Samsung
2016-02-23 13:27 - 2014-06-28 20:33 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-02-23 13:12 - 2016-02-11 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
2016-02-19 15:21 - 2009-07-14 05:33 - 00268128 _____ C:\Windows\system32\FNTCACHE.DAT
2016-02-18 14:59 - 2015-02-10 21:32 - 00000000 ____D C:\Users\milan\AppData\Local\Adobe
2016-02-17 13:57 - 2009-07-14 05:53 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-02-17 13:57 - 2009-07-14 05:53 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU(586).TXT

==================== Files in the root of some directories =======

2016-03-13 17:37 - 2016-03-13 17:37 - 0029696 _____ () C:\Users\milan\AppData\Local\MSGBOX.EXE
2014-11-19 17:18 - 2014-11-19 17:18 - 0000600 _____ () C:\Users\milan\AppData\Local\PUTTY.RND

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll
[2015-12-26 18:40] - [2015-11-10 19:39] - 0811520 ____A (Microsoft Corporation) 8626F0C30D4E3564FFDD25C90F4426F1

C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-03-09 22:55

==================== End of FRST.txt ============================

Slictyx
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 07 bře 2016 11:36
Bydliště: Hodonín

Re: zavirovaný PC ,prosím o kontrolu logu

#22 Příspěvek od Slictyx »

addition log -

Additional scan result of Farbar Recovery Scan Tool (x86) Version:05-03-2016 01
Ran by milan (2016-03-14 07:37:57)
Running from C:\Users\milan\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) (2014-06-26 18:52:20)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-970700664-739145876-1605578078-500 - Administrator - Disabled)
Guest (S-1-5-21-970700664-739145876-1605578078-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-970700664-739145876-1605578078-1002 - Limited - Enabled)
milan (S-1-5-21-970700664-739145876-1605578078-1001 - Administrator - Enabled) => C:\Users\milan

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-970700664-739145876-1605578078-1001\...\uTorrent) (Version: 3.4.5.41372 - BitTorrent Inc.)
Adobe Acrobat Reader DC - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.009.20069 - Adobe Systems Incorporated)
Adobe Flash Player 21 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 21.0.0.182 - Adobe Systems Incorporated)
Aktualizace NVIDIA 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
AutoHotkey 1.0.48.05 (HKLM\...\AutoHotkey) (Version: 1.0.48.05 - Chris Mallett)
Avast Free Antivirus (HKLM\...\Avast) (Version: 11.1.2253 - AVAST Software)
AVG PC TuneUp 2015 (cs-CZ) (Version: 15.0.1001.638 - AVG Technologies) Hidden
AVG PC TuneUp 2015 (HKLM\...\AVG PC TuneUp) (Version: 15.0.1001.638 - AVG Technologies)
AVG PC TuneUp 2015 (Version: 15.0.1001.638 - AVG Technologies) Hidden
Counter-Strike(TM) (HKLM\...\{DF5A03CC-D5AA-43D8-B948-D9903F2AF94A}) (Version: 1.0.0.0 - Valve)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Dropbox (HKU\S-1-5-21-970700664-739145876-1605578078-1001\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.)
Google Chrome (HKU\S-1-5-21-970700664-739145876-1605578078-1001\...\Google Chrome) (Version: 49.0.2623.87 - Google Inc.)
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
Heroes of Might and Magic III Complete (HKLM\...\InstallShield_{EDFB64A7-5BFD-4137-943D-5663149A15F5}) (Version: 1.00.0000 - CD Projekt)
Heroes of Might and Magic III Complete (Version: 1.00.0000 - CD Projekt) Hidden
Imperator Gaming Keyboard (HKLM\...\{12A8DEA6-1DA3-403F-BD28-D61C3908117F}}_is1) (Version: - )
League of Legends (HKLM\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (Version: 3.0.1 - Riot Games) Hidden
Malwarebytes Anti-Malware verze 2.2.0.1024 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Need For Speed Underground Demo (HKLM\...\{B575AC8F-EEDB-4B75-0091-17306783164E}) (Version: - )
Need for Speed™ Most Wanted (HKLM\...\{ADE91A13-434D-4229-00BC-182BAD607303}) (Version: - )
NVIDIA Ovladač 3D Vision 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation)
Ovládací panel NVIDIA 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden
PokerStars (HKLM\...\PokerStars) (Version: - PokerStars)
RAR Password Cracker 4.12 (HKLM\...\RAR Password Cracker) (Version: - dnSoft Research Group)
RAR Password Recovery v1.1 RC16 (remove only) (HKLM\...\Intelore - RAR Password Recovery) (Version: - )
Realtek AC'97 Audio (HKLM\...\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version: 5.35 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.11 - TeamSpeak Systems GmbH)
Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: 8.51 - Ghisler Software GmbH)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WinRAR 5.10 beta 4 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH)
World of Warcraft (HKLM\...\World of Warcraft) (Version: - Blizzard Entertainment)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\milan\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\milan\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\milan\AppData\Local\Google\Update\1.3.29.5\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\milan\AppData\Local\Google\Update\1.3.29.5\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\milan\AppData\Local\Google\Update\1.3.29.5\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\milan\AppData\Local\Google\Update\1.3.29.5\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\milan\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\milan\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\milan\AppData\Local\Google\Update\1.3.29.5\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\milan\AppData\Local\Google\Update\1.3.29.5\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\milan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\milan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\milan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-970700664-739145876-1605578078-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\milan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0A6839E2-4EA7-4DE1-9439-B66154F3016B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-970700664-739145876-1605578078-1001UA => C:\Users\milan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-19] (Google Inc.)
Task: {13CA5E43-A91B-4EA7-BDE2-3BC79FC2EC44} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-970700664-739145876-1605578078-1001Core => C:\Users\milan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-19] (Google Inc.)
Task: {14ADB49F-EC56-4F40-A77F-6E06CEFFFD74} - System32\Tasks\{02302981-B86C-44F2-AC78-C87AC5518AA6} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {15B380A3-3C47-494D-A2A5-781B2A643281} - System32\Tasks\{AFD15094-7436-4755-8A4E-A6F1540AF803} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {17941D0F-1556-4C97-A2A7-CAE92D0F132A} - System32\Tasks\{E07D001B-5309-41EF-A80D-978E7A27DBD9} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {196DDA1F-0476-43B1-9078-A8A767B7F0F6} - System32\Tasks\{ADBBD016-B2D2-4D96-8CAE-61773D1CF2AE} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {24B95278-B5FA-4F42-A55C-E3A7425DEC1A} - System32\Tasks\{6F9F87DB-7EDA-4B17-B521-5088378AE5D0} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {40E75AA9-EBA4-4A8A-891E-AE472F9B8EB9} - System32\Tasks\{A6B83C35-9B77-4CE6-8EC6-529C035D166F} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {4EA45285-DDE3-4651-9103-DD67470FEB6B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-03-13] (AVAST Software)
Task: {4F156640-4B5F-4719-A58F-C895DA6CBBB5} - System32\Tasks\{817D5B95-50B4-4C6A-B9FC-B0C9B40E572C} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {4FFF5F91-004F-42A5-AB38-8546CF03E1E6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-13] (Adobe Systems Incorporated)
Task: {51F1457A-8C59-46C7-983E-A5B26D44FBF8} - System32\Tasks\{CD14007B-132C-4971-BC16-0B2CF3F1B71D} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {5B8974AE-5D3E-4903-B230-4DCF0981A2C5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13] (Adobe Systems Incorporated)
Task: {6A5CF9FF-C73A-4158-A0B9-7E3487D81971} - System32\Tasks\{F2B2FEF0-E389-4198-AF35-CEF8B1515BF2} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {780A778E-FCC7-45E6-BCF2-2E23E1F4BD21} - System32\Tasks\avastBCLRestartS-1-5-21-970700664-739145876-1605578078-1001 => Chrome.exe
Task: {7842CDA6-7C5B-4438-8913-6766B7F72B49} - System32\Tasks\{C739D0E4-E989-4A33-84B0-213575139ACE} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {966EDC19-D41C-49F2-8E55-2FBF1661E504} - System32\Tasks\{357435A5-0A30-46C6-9EBC-CD7E85EC2146} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {A1D8F149-4F90-4A25-A388-9CBF69151C98} - System32\Tasks\{E42D7B7E-B1FE-40AB-BEC1-71135E4C4D1E} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {A531936A-3340-4BF7-B7BC-0238E3E57ED6} - System32\Tasks\{6B2979F1-42CF-435D-A6E6-BAAA8FFAAD83} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {AF057B9F-C1EA-40A5-BF72-F7991E471CB7} - System32\Tasks\{ECC3974C-3413-4ADE-BC5A-9DE98A29C34D} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {B4520300-1525-41D7-A908-01B6DA2D74A7} - System32\Tasks\{B6873158-83EC-44FF-BBEA-0FAD74E62956} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {B4CCA54C-C372-44A2-8E40-8297A469D19B} - System32\Tasks\{A5EC1EBB-5AC9-428E-B467-3773FCC4DB90} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {B88758C5-E45A-4BA2-971D-EC9A960A6383} - System32\Tasks\{E4BF6D84-0219-4FE1-A2EE-C0DF4D4FEB7D} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {BD7FD249-5B78-423A-A886-BAB197E71B17} - System32\Tasks\{517B034C-494C-4E45-869D-03F93F7E1ACF} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {C0B78F3A-67C9-41F3-AAC2-F99EAE8CC0C1} - System32\Tasks\{5F0668CC-2420-4A5C-9B0F-ED6F33B16C3C} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {C3A4F47C-C74E-4E57-82E0-9CC3F1A0EBC9} - System32\Tasks\{28EB9E8C-F701-418D-8463-035F9C810DD6} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {C5087284-F24A-4E83-BAB6-198F800D7829} - System32\Tasks\{16A34CC0-937B-484E-9C48-FF60B1EA2932} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {C7F13686-B19B-4523-A0A3-B2188909A604} - System32\Tasks\{F22C4941-7D06-4132-8CBA-6FD6D5A8BF82} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {C90BDEFD-981E-4B0E-AEED-1066F5E12C2B} - System32\Tasks\{D29E1B4E-D475-46CA-A2D4-CDEC1729EEC4} => Chrome.exe
Task: {CA98E486-7F34-4680-A65D-BFCCECF3E584} - System32\Tasks\{F90510CD-A99B-4076-9CF5-16B2DA5F97B7} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {CB738F6F-32BE-4001-A7DC-FB22CC33D5B9} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-03-07] (AVAST Software)
Task: {DA46E8DE-D7EF-4C3E-AF6E-33C32925BB58} - System32\Tasks\{ADCC2C28-D9AB-4058-91F7-77DFFFF5C46F} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {DC600797-9F6F-432C-821D-AB5268F88DDF} - System32\Tasks\{3F3A512B-6B83-49AC-BE92-C52D4495F9F0} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {E1B03EB9-097A-4A9B-B962-6060EEB4448F} - System32\Tasks\{85EE837D-0B0D-4B12-9B7D-534D692F98B5} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()
Task: {E51E6138-BB63-47FD-825A-093F274F182F} - System32\Tasks\{4E441E56-0420-4008-8B68-6D90CCE679AB} => pcalua.exe -a "C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe"
Task: {E672795A-A9D7-4D67-A978-DD7DB3250587} - System32\Tasks\{C4DEAF40-4AA7-41E1-B3C4-C67E51452FC3} => D:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe [2006-01-06] ()

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2014-06-28 11:08 - 2014-03-04 13:34 - 00109000 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2016-03-13 18:46 - 2016-03-13 18:46 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-03-13 18:46 - 2016-03-13 18:46 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-03-13 18:48 - 2016-03-13 18:48 - 02840576 _____ () C:\Program Files\AVAST Software\Avast\defs\16031301\algo.dll
2016-03-13 18:46 - 2016-03-13 18:46 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2015-08-04 13:26 - 2015-08-04 13:26 - 00610008 _____ () C:\Program Files\AVG\AVG PC TuneUp\avgreplibx.dll
2015-08-04 13:26 - 2015-08-04 13:26 - 00734936 _____ () C:\Program Files\AVG\AVG PC TuneUp\tulngx.dll
2016-03-13 18:46 - 2016-03-13 18:46 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-03-13 00:08 - 2016-03-08 03:48 - 01676440 _____ () C:\Users\milan\AppData\Local\Google\Chrome\Application\49.0.2623.87\libglesv2.dll
2016-03-13 00:08 - 2016-03-08 03:48 - 00086168 _____ () C:\Users\milan\AppData\Local\Google\Chrome\Application\49.0.2623.87\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-02-06 07:51 - 2016-03-13 17:37 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-970700664-739145876-1605578078-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\milan\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.2.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{90539BD6-B651-43C2-AFD0-24BEC23FDED4}] => (Allow) C:\Users\milan\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{2C13E392-C07F-4FDD-8611-D3E77A5E9762}] => (Allow) C:\Users\milan\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{EADD3E22-74B5-4545-8577-3E09EE3CC8CF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1040\Agent.exe
FirewallRules: [{EA258262-6D61-442F-B457-D7DA20C04917}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1040\Agent.exe
FirewallRules: [{8E448A5C-0C1B-49F0-8593-14562BE4E540}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{0E903ACD-E7FB-4374-9C69-EAAEA845BD46}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe
FirewallRules: [{41066086-D6E3-4C9C-82F6-681E1DBE17F7}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe
FirewallRules: [{1A48CC3A-48AB-4BDF-B745-8E95C8E99B09}] => (Allow) D:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{A2309EF4-E542-47D3-8DB0-DEB8EE82DD0A}] => (Allow) D:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{0329B311-A8B3-472A-942A-D272D6607DC3}] => (Allow) C:\Users\milan\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6E82F6C9-F6EE-4ADD-A995-240BB3CD8948}] => (Allow) C:\Users\milan\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{78B9FFD6-F29E-477F-B7D5-99AE89EB7E33}] => (Allow) C:\Users\milan\AppData\Local\Google\Chrome\Application\chrome.exe
FirewallRules: [{29B2DFD9-9C0E-43CF-BF87-BA0A453AEA37}] => (Allow) C:\ProgramData\Google\update\GoogleUpdate.exe
FirewallRules: [{FF41FBCF-B65B-4E4D-9D1A-698986C575BB}] => (Allow) C:\Windows\System32\muzapp.exe
FirewallRules: [{7D259D49-2229-48E2-B379-FF803CFBB8DC}] => (Allow) C:\Windows\System32\muzapp.exe

==================== Restore Points =========================

13-03-2016 15:30:42 Nainstalováno: AVG PC TuneUp 2015
13-03-2016 17:32:34 Removed Samsung Kies
13-03-2016 17:34:27 Removed Skype™ 7.12
13-03-2016 17:34:52 Removed Steam(TM)
13-03-2016 17:35:26 Removed Mumble 1.2.3
13-03-2016 17:37:29 Restore Point Created by FRST

==================== Faulty Device Manager Devices =============

Name: Unknown Device
Description: Unknown Device
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Standardní hostitelský řadič USB)
Service:
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.

Name: Adaptér tunelového režimu Microsoft Teredo
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/14/2016 07:32:05 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/14/2016 07:31:22 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Aktivace licence systému Windows se nezdařila. Chyba 0x00000000.

Error: (03/14/2016 07:31:22 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
0x800401F9

Error: (03/14/2016 12:04:24 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/14/2016 12:03:49 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Aktivace licence systému Windows se nezdařila. Chyba 0x00000000.

Error: (03/14/2016 12:03:49 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
0x800401F9

Error: (03/13/2016 10:30:05 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Generování kontextu aktivace pro Microsoft.Windows.Common-Controls,language="*",processorArchitecture="*",publicKeyToken="436865772d574741",type="win32",version="6.0.0.0"1 se nezdařilo.
Závislé sestavení Microsoft.Windows.Common-Controls,language="*",processorArchitecture="*",publicKeyToken="436865772d574741",type="win32",version="6.0.0.0" nelze najít.
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (03/13/2016 10:17:30 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Generování kontextu aktivace pro Microsoft.Windows.Common-Controls,language="*",processorArchitecture="*",publicKeyToken="436865772d574741",type="win32",version="6.0.0.0"1 se nezdařilo.
Závislé sestavení Microsoft.Windows.Common-Controls,language="*",processorArchitecture="*",publicKeyToken="436865772d574741",type="win32",version="6.0.0.0" nelze najít.
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (03/13/2016 06:42:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/13/2016 06:41:29 PM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Aktivace licence systému Windows se nezdařila. Chyba 0x00000000.


System errors:
=============
Error: (03/14/2016 07:37:05 AM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error: (03/14/2016 07:33:21 AM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error: (03/14/2016 07:33:18 AM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error: (03/14/2016 07:33:16 AM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error: (03/14/2016 07:33:13 AM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error: (03/14/2016 07:33:11 AM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error: (03/14/2016 07:33:08 AM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error: (03/14/2016 07:33:06 AM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error: (03/14/2016 07:33:03 AM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error: (03/14/2016 07:33:01 AM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk0\DR0 má chybný blok.


CodeIntegrity:
===================================
Date: 2016-03-13 15:38:21.628
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.

Date: 2016-03-13 15:38:21.612
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.

Date: 2016-03-13 15:38:18.865
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.

Date: 2016-03-13 15:38:18.850
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.

Date: 2016-03-13 15:38:18.834
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.

Date: 2016-03-13 15:38:18.818
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.

Date: 2016-03-13 15:38:11.097
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.

Date: 2016-03-13 15:38:11.081
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.

Date: 2016-03-13 15:38:10.707
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.

Date: 2016-03-13 15:38:10.691
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3600+
Percentage of memory in use: 35%
Total physical RAM: 3327.43 MB
Available physical RAM: 2143.29 MB
Total Virtual: 6653.18 MB
Available Virtual: 5404.71 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:75.12 GB) (Free:5.46 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:390.63 GB) (Free:335.59 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C916C916)
Partition 1: (Active) - (Size=75.1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=390.6 GB) - (Type=OF Extended)

==================== End of Addition.txt ============================

Slictyx
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 07 bře 2016 11:36
Bydliště: Hodonín

Re: zavirovaný PC ,prosím o kontrolu logu

#23 Příspěvek od Slictyx »

avast jinak při rebootu udělal testy a něco přesunul do truhly ale nevím kde to přesně hledat abych předložil log

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: zavirovaný PC ,prosím o kontrolu logu

#24 Příspěvek od cernohous13 »

Zdravím, klik pravým na pomeranč Avastu -> Virová truhla :wink:
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Slictyx
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 07 bře 2016 11:36
Bydliště: Hodonín

Re: zavirovaný PC ,prosím o kontrolu logu

#25 Příspěvek od Slictyx »

a děkuju tam na spodní liště bych to ani nehledal :)
Přílohy
Bez názvu.png
Bez názvu.png (172.58 KiB) Zobrazeno 2776 x

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: zavirovaný PC ,prosím o kontrolu logu

#26 Příspěvek od altrok »

:arrow: crackovani bezpecnostniho softwaru je jedna z nejabsurdnejsich veci, kterou lide na PC delaji. Ja mel za to, ze bezpecnostni software si uzivatele porizuji za ucelem zvyseni ochrany pocitace a Vy se ho snazite oblbnout crackem, ktery si na pozadi muze delat doslova cokoliv. Kouknete taky do pravidel fora - tohle tu vidim naposledy.


  • Stahnete Crystal Disk Info (CDI) https://osdn.jp/frs/redir.php?m=cznic&f ... o6_7_5.zip
  • archiv extrahujte a spustte vyextrahovany soubor DiskInfo.exe
  • ve spustenem programu kliknete nahore na Upravy -> Kopirovat (log mate nyni zkopirovany ve schrance)
  • log vlozte do dalsi odpovedi (Ctrl + V)
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Slictyx
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 07 bře 2016 11:36
Bydliště: Hodonín

Re: zavirovaný PC ,prosím o kontrolu logu

#27 Příspěvek od Slictyx »

aha ,ja myslel ze avast ten jsem stahnul z hlavnich stranek ,tohle byla pouze nouzovka protoze se me nepodarilo nainstlalovat jedinej antivir ktery by byl funkcni.. za chvilku vlozim log

Slictyx
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 07 bře 2016 11:36
Bydliště: Hodonín

Re: zavirovaný PC ,prosím o kontrolu logu

#28 Příspěvek od Slictyx »

----------------------------------------------------------------------------
CrystalDiskInfo 6.7.5 (C) 2008-2016 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 7 Home Premium SP1 [6.1 Build 7601] (x86)
Date : 2016/03/14 12:16:41

-- Controller Map ----------------------------------------------------------
- ATA Channel 0 (0) [ATA]
- ATA Channel 1 (1) [ATA]
+ PCI Standardní dvoukanálový řadič IDE [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)
+ Řadič NVIDIA nForce s rozhraním Serial ATA [SCSI]
- WDC WD50 00AADS-00M2B SCSI Disk Device

-- Disk List ---------------------------------------------------------------
(1) WDC WD5000AADS-00M2B0 : 500,1 GB [0/2/0, sm] - wd

----------------------------------------------------------------------------
(1) WDC WD5000AADS-00M2B0
----------------------------------------------------------------------------
Model : WDC WD5000AADS-00M2B0
Firmware : 01.00A01
Serial Number : ***************
Disk Size : 500,1 GB (8,4/137,4/500,1/500,1)
Buffer Size : 32767 KB
Queue Depth : 32
# of Sectors : 976773168
Rotation Rate : Neznámy údaj
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : ---- | SATA/300
Power On Hours : 19266 hod.
Power On Count : 4429 krát
Temperature : 41 C (105 F)
Health Status : Pozor
Features : S.M.A.R.T., AAM, 48bit LBA, NCQ
APM Level : ----
AAM Level : 80FEh [OFF]

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Read Error Rate
03 138 113 _21 0000000017D4 Spin-Up Time
04 _96 _96 __0 000000001207 Start/Stop Count
05 199 199 140 000000000002 Reallocated Sectors Count
07 200 200 __0 000000000000 Seek Error Rate
09 _74 _74 __0 000000004B42 Power-On Hours
0A 100 100 __0 000000000000 Spin Retry Count
0B 100 100 __0 000000000000 Recalibration Retries
0C _96 _96 __0 00000000114D Power Cycle Count
C0 200 200 __0 00000000027A Power-off Retract Count
C1 _78 _78 __0 00000005A021 Load/Unload Cycle Count
C2 106 _98 __0 000000000029 Temperature
C4 198 198 __0 000000000002 Reallocation Event Count
C5 200 200 __0 000000000005 Current Pending Sector Count
C6 200 200 __0 000000000007 Uncorrectable Sector Count
C7 200 200 __0 000000000000 UltraDMA CRC Error Count
C8 200 200 __0 00000000000C Write Error Rate

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000 Bz?..7.......?......
010: FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF 3832 ..................82
020: 0000 FFFF 0032 3031 2E30 3041 3031 5744 4320 5744 .....201.00A01WDC WD
030: 3530 3030 4141 4453 2D30 304D 3242 3020 2020 2020 5000AADS-00M2B0
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00 ..../.
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0110 @.......?....?......
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000 ...........x.x.x.x..
070: 0000 0000 0000 0000 0000 001F 1706 0000 0044 0040 .................D.@
080: 01FE 0000 746B 7F61 4123 7469 BC41 4123 407F 0051 ....tk.aA#ti.AA#@..Q
090: 0051 0000 FFFE 0000 80FE 0000 0000 0000 0000 0000 .Q..................
100: 6030 3A38 0000 0000 0000 0000 0000 0000 5001 4EE0 `0:8............P.N.
110: 01D5 F65E 0000 0000 0000 0000 0000 0000 0000 401C ...^..............@.
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000 @................)..
130: 0000 0000 0000 16CE 0000 0000 0000 0000 0000 0000 ....................
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000 ....................
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
200: 0000 0000 0000 0000 0000 0000 3037 0000 0000 0000 ............07......
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
220: 0000 0000 101E 0000 0000 0000 0000 0000 0000 0000 ....................
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000 ....................
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
250: 0000 0000 0000 0000 0000 00A5 ............

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27 .../...........'
010: 00 8A 71 D4 17 00 00 00 00 00 04 32 00 60 60 07 ..q........2.``.
020: 12 00 00 00 00 00 05 33 00 C7 C7 02 00 00 00 00 .......3........
030: 00 00 07 2E 00 C8 C8 00 00 00 00 00 00 00 09 32 ...............2
040: 00 4A 4A 42 4B 00 00 00 00 00 0A 32 00 64 64 00 .JJBK......2.dd.
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00 .......2.dd.....
060: 00 00 0C 32 00 60 60 4D 11 00 00 00 00 00 C0 32 ...2.``M.......2
070: 00 C8 C8 7A 02 00 00 00 00 00 C1 32 00 4E 4E 21 ...z.......2.NN!
080: A0 05 00 00 00 00 C2 22 00 6A 62 29 00 00 00 00 .......".jb)....
090: 00 00 C4 32 00 C6 C6 02 00 00 00 00 00 00 C5 32 ...2...........2
0A0: 00 C8 C8 05 00 00 00 00 00 00 C6 30 00 C8 C8 07 ...........0....
0B0: 00 00 00 00 00 00 C7 32 00 C8 C8 00 00 00 00 00 .......2........
0C0: 00 00 C8 08 00 C8 C8 0C 00 00 00 00 00 00 00 00 ................
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
160: 00 00 00 00 00 00 00 00 00 00 84 00 1C 3E 01 7B .............>.{
170: 03 00 01 00 02 B8 05 00 00 00 00 00 00 00 00 00 ................
180: 00 00 01 03 00 00 00 00 00 00 00 00 00 00 00 00 ................
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E4 ................

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 C8 00 00 00 00 00 00 00 03 15 ...3............
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 ................
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00 ................
030: 00 00 07 00 C8 C8 C8 00 00 00 00 00 00 00 09 00 ................
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00 ................
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00 ................
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 C0 00 ................
070: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00 ................
080: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00 ................
090: 00 00 C4 00 00 00 00 00 00 00 00 00 00 00 C5 00 ................
0A0: 00 00 00 00 00 00 00 00 00 00 C6 00 07 00 00 00 ................
0B0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00 ................
0C0: 00 00 C8 00 C8 C8 C8 00 00 00 00 00 00 00 00 00 ................
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 AE ................

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: zavirovaný PC ,prosím o kontrolu logu

#29 Příspěvek od altrok »

:arrow: Nainstalujte a spustte HD Tune - http://www.hdtune.com/files/hdtune_255.exe
  • Prejdete na zalozku Health a zkontrolujte, ze je ve sloupecku Status vsude hodnota OK a dole sviti zelene Health status: OK
  • Na zalozce Error Scan kliknete na Start. Po dokonceni testu udelejte screen a prilozte ho k dalsi odpovedi.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Slictyx
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 07 bře 2016 11:36
Bydliště: Hodonín

Re: zavirovaný PC ,prosím o kontrolu logu

#30 Příspěvek od Slictyx »

mno health me ,,HD TUNE'' neukazoval tak jsem dal rovnou error scan ,chcete tedy říct že mě odchází HDD?

Odpovědět